Privacy Policy

Version v1.1

1. Who controls this data

Agentic Zero is operated by Dis-Solutions, a consultancy company registered in Spain, EU, trading under the name "Agentic Zero," who is the data controller for the account/contact information described below. For your own operational and business data processed while delivering the Service, Agentic Zero acts as a data processor on your behalf — that relationship is governed by a separate Data Processing Agreement (DPA), not by this page. Your acceptance of this policy is recorded when you submit the AUDIT form.

2. What we collect, and why

DataPurposeSource
Company name, sector, process descriptionGenerate your feasibility preview and tier classificationYou, via the AUDIT form
Contact name and emailSend your preview, respond to your inquiry, send account credentialsYou, via the AUDIT form or checkout
Payment confirmation (not the card itself)Activate your Essential purchaseStripe, our payment processor
Portal login (email + password hash)Authenticate you to your own dashboardCreated automatically at onboarding
Operational data from your connected systems (e.g. SAP)Perform the certified business processYour own systems, per the DPA
Usage/audit logs of autonomous actionsGive you an auditable record of every autonomous decisionGenerated by the Service

3. Payment processing

Essential purchases are paid through Stripe. We never see, store, or transmit your card number — Stripe's own hosted checkout collects it directly. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.

4. How long we keep it

Account and billing records are kept for as long as your account is active, plus 6 years thereafter to comply with EU/Spanish commercial record-keeping obligations (Código de Comercio) and tax law. Operational data processed under a DPA is retained and deleted according to the terms of that specific agreement.

5. Who we share it with

6. Your rights

Subject to applicable law (including the GDPR, where it applies to you), you may request access to, correction of, or deletion of your personal data, and object to or restrict certain processing. To exercise any of these rights, contact alberto@agentic-zero.com. Given the current scale and nature of processing — a small number of business clients, no large-scale or systematic monitoring, no large-scale processing of special-category data — a Data Protection Officer is not currently required under Article 37 GDPR; this will be reassessed as the business grows. Agentic Zero is established within the EU, so no separate EU representative under Article 27 GDPR applies.

7. Security

Security is not a policy statement layered on top of the Service — it is enforced in the same runtime that executes your autonomous processes, on every request, not only reviewed periodically. Concretely:

If we become aware of a data incident affecting your personal data, we will assess and notify affected parties and any applicable authority as required by law.

8. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected in the version and date at the top of this page.

9. Contact

Questions about this policy: alberto@agentic-zero.com.