Privacy Policy
Version 1.0, effective 8 September 2026.
Agentique is a platform where your company uploads documents and gets an AI assistant that reads them and answers with the source. To do that, the platform processes personal data: yours, as a user, and that of the people who appear in your company's documents. This policy explains what we process, why, where it is kept and what rights you have. We wrote it so a busy person can read it without needing a lawyer.
1. Who we are and how to reach us
The controller for the agentique.eu website and the Agentique platform is ITAILORS - SOFT S.R.L. ("iTailors"), a Romanian limited liability company, tax ID (CUI) 48450662, with its registered office at Calea Aurel Vlaicu, Arad, Arad County, Romania, registered with the Trade Register under no. J2/1018/2023. Company website: https://itailors.eu.
For any question about your data, to exercise your rights or to report a problem, write to the email address shown on the website under "Support contact". The same address handles technical support. We have not appointed a Data Protection Officer (DPO), as our activity does not trigger that obligation.
2. Our roles: when we are a controller and when we are a processor
Agentique holds two kinds of data, and we play a different role for each.
iTailors is the controller for the data needed to run our direct relationship with you and your company: your user account, billing details, support correspondence and the technical logs of the website. For this data we decide the purpose and means of processing and we answer to you directly.
iTailors is a processor for everything your company uploads or generates in its workspace: documents, extracted tables, entities, memories, conversations, the company file, employee CVs. For this content your company is the controller: it decides what to upload, who has access and how long to keep it. We process that content only to deliver the service, following the instructions in the contract and in the application, and we use it for nothing else. The details are set out in the Data Processing Agreement (DPA) attached to the Terms of Service.
The same rule applies to the Agentique web assistant when an institution or company installs it on its own website: the institution is the controller for its visitors' data and iTailors is the processor.
If you appear in a document uploaded by one of our customers (for example you are their employee or supplier) and want to exercise your rights, contact that company first. If you write to us instead, we forward your request to the customer and help them respond.
3. What we process, why, on what basis and for how long
The categories below are grouped by your situation. Legal bases refer to Article 6(1) of the GDPR.
3.1 Visitors of agentique.eu
- Data: server logs (IP address, browser type, page visited, date and time), generated by the AWS/CloudFront infrastructure.
- Purpose: website security, abuse detection, error diagnosis. We do not profile visitors and we do not track them across sites.
- Basis: our legitimate interest in keeping the site secure and working (Art. 6(1)(f)).
- Retention: 7 days.
3.2 Access requests and contact messages
- Data: the name, email address, company and message you send us by email, from your own email client. The website has no form collecting data in the background.
- Purpose: to reply, send you an invitation code and set up your workspace.
- Basis: steps taken at your request before entering into a contract (Art. 6(1)(b)).
- Retention: until your request is handled; if you become a customer, for the term of the contract. Correspondence that does not lead to a contract is deleted after 12 months.
3.3 Platform users
- Data: name, email address, password (stored only as a hash, never in clear text), workspace role (owner, admin, member, viewer), company, interface language, activity log (what you asked, which documents you uploaded), conversations with the assistant, memories saved across conversations, decisions recorded in the app (for example a go/no-go verdict on a tender, with your name and the date), invitations sent to colleagues.
- Purpose: to run your account, authentication, access rights and work history; to provide support; to invoice your company.
- Basis: performance of the contract (Art. 6(1)(b)); legal obligations for invoicing and accounting (Art. 6(1)(c)); our legitimate interest in security, abuse prevention and product improvement, without training AI models (Art. 6(1)(f)).
- Retention: for the term of the contract, plus 30 days after termination, after which we delete it. Invoicing records are kept for 10 years under the Romanian Accounting Law no. 82/1991.
We do not collect card details: there is no payment processor built into the platform. Payment is made against an invoice issued by iTailors, by bank transfer, within 15 days of the invoice date.
3.4 Content of the documents your company uploads
- Data: any personal data contained in uploaded documents (PDF, DOCX, XLSX, XML, TXT, images): your company's employees, customers, suppliers, partners. From the documents we extract text, search chunks, the tables you define and, at your request, entity records and memories.
- Purpose: so the assistant can find information, answer with the source and page, and run the workflows you configured.
- Role and basis: your company is the controller and chooses its own legal basis; we process as a processor on its instructions (Art. 28 GDPR).
- Retention: as long as you keep it in the app. You can delete documents, memories, entities and conversations from the interface at any time. When the contract ends, workspace data is deleted within 30 days of termination, and backups expire 7 days after that, except what we are legally required to keep (invoices).
3.5 Optional integrations you switch on
None of the integrations below is active by default. You enable them in settings and can disable them at any time.
- Google Drive and Google Sheets: you sign in via OAuth to your company's Google account. The documents you select come into Agentique, and the data you send to Sheets goes to Google under Google's terms. You can revoke access at any time from Agentique settings or from your Google account.
- SPV / ANAF e-Invoicing: using your company's qualified certificate, the platform downloads your invoices from the Virtual Private Space. Invoices contain data about your suppliers and customers and fall under the rule in 3.4.
- Programmatic access (MCP): API keys are issued by you from the app and stored only as a hash. What an MCP client does with your data depends on your configuration.
- Messaging channels: the WhatsApp, Messenger and Slack connectors are enabled only by you, using your company's own accounts; the data received is the messages your users send on that channel. By default only the in-app chat and the embeddable assistant (iframe) are active.
3.6 Tender radar (SEAP/SICAP)
This module reads public notices from e-licitatie.ro, scores them against your company profile and, on request, has the AI read the documentation and propose a verdict (GO, MAYBE, NO GO). Notices contain contact details of contracting authorities (name, position, phone, email of the responsible officers), published by those authorities under public procurement law. We process them in your company's legitimate interest of identifying opportunities (Art. 6(1)(f)), without profiling the individuals concerned. The decision and the submission of a bid always rest with a person; the platform does not submit bids in SEAP and does not contact authorities on your behalf.
3.7 Company file and CVs
From the documents your company uploads (certificates, financial statements, contracts, CVs) the platform extracts records about your company so you can reuse them in bids. CVs contain personal data of your employees: name, experience, education, certifications, sometimes contact details. This data is processed solely on behalf of your company, which remains the controller and is responsible for informing its employees. We use it for no other purpose and never combine it with other customers' data.
4. Where data is hosted and how the AI works
All platform data is hosted on Amazon Web Services (AWS) in the eu-central-1 region (Frankfurt, Germany): files (S3), database (RDS MySQL), search index (OpenSearch), application servers (ECS) and processing queues (Redis). Backups: the database has automated daily backups kept for 7 days; files live in AWS S3, durable storage replicated across several availability zones of the Frankfurt region.
Each customer company has an isolated workspace: separate search index, separate storage prefix, separate data. Users of one company cannot see another company's data.
The AI models (Anthropic Claude for answers and OCR, Amazon Titan for embeddings) are accessed through Amazon Bedrock, only in AWS regions inside the European Union (Frankfurt, Ireland, Paris, Stockholm, Milan, Spain). Amazon Bedrock does not store prompts and responses and does not use them to train models. Data does not reach Anthropic. iTailors does not train models on customer data and does not sell data.
In normal operation there is no transfer of data outside the European Union or the European Economic Area. The only exception arises if you connect Google Drive or Google Sheets: the data you select may then be transferred to Google (United States) under standard contractual clauses and Google's certification under the EU-U.S. Data Privacy Framework.
5. Recipients and sub-processors
We do not sell, rent or hand over personal data to third parties for their own purposes. Data may reach:
- Amazon Web Services EMEA SARL (Luxembourg): hosting, storage, databases and Amazon Bedrock, in the EU regions listed above.
- Google (Google Ireland Limited / Google LLC): only if you connect Drive or Sheets.
- Our transactional email provider for invitations, digests and alerts: messages are sent through the SMTP server configured by iTailors, and the sender is the address shown in the messages.
- Public authorities, where the law requires it (for example on a court order).
- Your colleagues in the workspace, according to the roles set by your company's administrator.
The full list of sub-processors, together with our obligation to notify you before adding a new one, is part of the Data Processing Agreement.
6. Security
The main measures we apply:
- encryption in transit (TLS) for all traffic between your browser and the platform and between platform components;
- encryption at rest through AWS services: files in S3 with server-side encryption (AES-256) on all buckets, an encrypted RDS database, and application secrets protected with AWS KMS;
- passwords stored only as a hash; API keys stored only as a hash;
- full workspace isolation between customers;
- role-based access (owner, admin, member, viewer), controlled by your company's administrator;
- technical logs in AWS CloudWatch, kept for 7 days, for diagnostics and incident investigation;
- iTailors staff access to production data only for support and maintenance, on a need-to-know basis.
If a security incident affects your data, we notify the Romanian supervisory authority (ANSPDCP) within 72 hours of becoming aware of it, as the GDPR requires, and inform you or your company without undue delay.
7. Your rights and how to exercise them
You have the following rights over your personal data:
- access: to learn what data we hold about you and receive a copy;
- rectification: to correct inaccurate data (name, email and language can be changed directly in the app);
- erasure: to have your data deleted when we no longer have a legitimate reason to keep it;
- restriction: to limit processing while we review a dispute;
- portability: to receive the data you gave us in a structured, commonly used, machine-readable format;
- objection: to object to processing based on legitimate interest;
- withdrawal of consent: where processing relies on consent, you can withdraw it at any time, without affecting processing carried out before.
To exercise your rights, write to the address under "Support contact" on the website. We respond within 10 working days (the law allows up to 30 days); if a request is complex, we will tell you if we need an extension. For your protection we may ask you to confirm your identity before acting on a request. Exercising your rights is free of charge.
If your data appears in content uploaded by one of our customers, Section 2 applies: we point you to that company and help it respond.
If you believe the processing breaches the law, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro, or to bring the matter before the Romanian courts. We would prefer that you write to us first so we can fix the problem directly.
8. Cookies and local storage
The agentique.eu website uses no analytics or tracking tools. There is no Google Analytics, Meta Pixel, Hotjar or any other third-party script. Fonts are served from our own site, not from Google Fonts, so even loading a page sends no data to third parties.
The application does not use cookies for the login session. The data needed to operate is kept in your browser's local storage (localStorage), on your device, and is never sent to any third party:
- auth_token: the token that keeps you signed in;
- ui_language: interface language (Romanian or English);
- onboarding_completed: whether you have completed the getting-started guide;
- sidebar_collapsed: whether the side menu is collapsed;
- chat_sidebar_width: the width of the conversation panel;
- subscription_block: subscription status, so we can show the renewal page correctly.
You can clear these at any time from your browser settings; doing so signs you out and resets preferences to their defaults.
The only cookies that may appear are the technical ones of the Django framework (csrftoken, sessionid), used only in iTailors' internal administration area, not for website visitors or application users.
Because all of these elements are strictly necessary to deliver the service you requested or to remember your preferences, they do not require prior consent under Art. 4(5) of Romanian Law no. 506/2004 (implementing the ePrivacy Directive). That is why we show no cookie consent banner. If we ever add analytics tools, we will update this policy and ask for consent first.
9. Children
Agentique is a service for companies and is not directed at anyone under 18. We do not knowingly create accounts for minors. If you learn that a minor has been given access through an invitation from your company, write to us and we will delete the account.
10. Changes to this policy
We may update this policy when the service, our providers or the law change. The version and effective date appear at the top of the document. For material changes we notify you by email or in the app at least 30 days before they take effect. Earlier versions are available on request at the contact address.
Applicable law: Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018, Law no. 506/2004, Law no. 365/2002 and the Romanian Civil Code.