This policy explains how we handle personal data when you visit this website, send an agent request, or use the service as a client. It follows the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, which apply to us as a UK company, and the EU General Data Protection Regulation (GDPR) and the French Data Protection Act, which apply because we offer the service in France. In short, we collect what we need to answer you, build and run your agent and bill it; we do not store the content of your API calls, and the content an agent keeps to do its job is deleted after the period set for that agent (30 days by default); the examples you send us to build an agent you buy are deleted within 30 days after acceptance or cancellation, unless you ask us to keep them; we do not sell data.
1. Who is responsible
The data controller is UNDERM LTD, a private limited company registered in England and Wales, company number 16973293, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We have not appointed a data protection officer. For any question about your data, write to [email protected].
If you are in the European Union, you can reach us directly at the same address, in English or in French.
2. What we collect
When you send an agent request
- Your name, work email, company, role and, if you give it, your company website.
- What you tell us about the job, that is the task, what goes in and comes out, examples, volume, tools, timeline, plan interest and how you would like to buy the agent (pay per token or buy it once). Please remove confidential or personal details from examples when you can.
- The example files you choose to attach (up to 3), your sector and how you heard about us, if you tell us.
- Technical details stored with your request, that is a pseudonymized hash of your IP address (not the address itself), the type and version of your browser (user agent), the language of the form and the page or campaign that brought you to the form (the campaign parameters of the link you followed, such as utm_source, and an advertising click identifier when you came from one of our ads).
The fields marked as required in the form are needed to answer you. Without them we cannot process your request. The other fields are optional.
When you are a client
- Client details, that is name, company, email, preferred language, plan, balance and the history of payments, credits and plan changes.
- Payment details, that is the name and bank account details that appear on your bank transfers, kept with our accounting records.
- Usage metadata for each call, that is time, agent, API key prefix, token counts, cost, response status and response time.
- The content an agent keeps to do its job, when it is built to keep any (for example the emails you forward to it, the files you send it and the results it produces), as described in section 3.
- Emails you exchange with us.
When you buy an agent outright
- Order details, that is what we build, the quoted price, the payment status and method, and the dates of delivery and acceptance.
- The examples you send us to build and test the agent (inputs and expected results), and the test set we build from them. Please remove or replace the personal details they contain when you can.
- The access details you give us to set up the agent on your own AI provider account or server.
When you visit the website or call the API
- Server logs, that is IP address, date and time, requested address, response status and the type and version of the browser (user agent), recorded by our servers to keep the service running, troubleshoot it and prevent abuse.
3. Prompts, outputs and examples
The content of your API calls (prompts, documents, and the outputs the agent writes) is processed only to produce the response. We do not store it, except content an agent keeps to do its job (see below). We keep token counts for billing.
Each agent runs either on servers we operate or with a third-party AI provider that we select for that agent. A backup provider, which may be a third party, can also handle a call when the main provider is unavailable. When a third-party provider is used, the content of each call is sent to it to produce the response. It acts as our sub-processor under a data processing contract. The sub-processors used for your agent, including any backup provider, are listed in the written list we send you before it goes live (section 8.3 of our terms of service). Our network provider also carries this content between you and our servers (see section 6).
When that content includes personal data about other people, you are the controller for it and we process it on your behalf, only to run the service. Our commitments as your processor under article 28 of the GDPR and of the UK GDPR are set out in section 8.3 of our terms of service.
Content an agent keeps to do its job
Some agents keep content to do their job, for example the emails you forward to them, the files you send them and the results they produce. We keep that content only for the period set for that agent in your quote, 30 days from the receipt of each item by default, then delete it automatically, and in any case at the latest 30 days after the end of your contract. We open it only when needed for support or to correct an error. Each time a person opens it, we record who opened it, when and why. This access record does not contain the content, is kept 3 years and is sent to you on written request. As for the content of calls, when that content includes personal data about other people, you are the controller for it and we process it on your behalf (section 8.3 of our terms of service).
Examples for an agent you buy
Unlike the content of API calls, the examples you send us to build and test an agent you buy outright are stored while we build and test it, then deleted (section 5). When they contain personal data about other people, you are the controller for it and we process it on your behalf, only to build and test your agent (sections 4.3 and 8.3 of our terms of service). If we test the agent with a third-party AI provider, the examples used in test calls are sent to it as described above. Once delivered, an agent that runs on your own AI provider account or server sends its content to that provider under your own contract with it, and we do not receive it.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer your request, ask questions, suggest a plan | Our legitimate interest in answering the businesses that contact us (steps taken before a contract, when you are yourself the contracting party) |
| Know which page or campaign brought a request, to improve our website and campaigns | Our legitimate interest in knowing how businesses find us |
| Build and run your agent, issue API keys, open the portal, meter usage and bill it, send service emails (API key delivery, low balance and payment alerts) | Our legitimate interest in managing the business relationship with your company (performance of the contract, when you are yourself the contracting party) |
| Build and test an agent you buy outright with the examples you send us, deliver it with its recorded handover video, answer your written questions and handle acceptance | Our legitimate interest in carrying out the order placed by your company (performance of the contract, when you are yourself the contracting party). For personal data about other people in your examples, we act as your processor (section 3). |
| Keep invoices and accounting records, including accepted quotes and orders | Legal obligation |
| Prevent spam and abuse, apply rate limits, keep server logs and secure the service | Our legitimate interest in a reliable, safe service |
| Handle disputes and legal claims | Our legitimate interest in defending our rights |
We do not use your data for advertising, we do not sell it, and we do not send marketing emails unless you agree to receive them. We do not make decisions about you based solely on automated processing.
5. How long we keep it
- Agent requests that do not lead to a contract are kept up to 3 years after our last exchange. The example files attached to such a request, and the samples and results of a demonstration, are deleted 30 days after we send the result of the demonstration, or 30 days after our last exchange when there is none.
- Client data is kept for the duration of the contract, then 3 years.
- Accepted quotes and orders are kept 6 years from the end of the financial year in which the order or the contract ends (supporting documents for our accounts under UK company and tax rules; for a one-time purchase, they also prove the assignment of rights).
- Examples for an agent you buy, and our copy of the test set and of any deliverable that contains them, are kept while we build and test the agent, then deleted within 30 days after acceptance or cancellation, unless you ask us in writing to keep them longer (for example for hosting or a later change).
- Access details for the setup on your own account or server are used only for the setup and during acceptance, then deleted; you can revoke or change that access once acceptance has taken place.
- Invoices, payments and the usage records behind them are kept 6 years from the end of the financial year they relate to, as UK company and tax rules require, or longer where the law requires it.
- Prompts and outputs are not stored by us, apart from the content an agent keeps to do its job (next item); when a third-party AI provider is used, it may keep them temporarily under its contract (see section 3).
- Content an agent keeps to do its job (forwarded emails, files, results) is deleted automatically once the period set for that agent in your quote has passed since each item was received, 30 days by default, and at the latest 30 days after the end of your contract.
- Record of who opened that content (who, when and why, without the content itself) is kept 3 years.
- Server logs are rotated automatically and kept no longer than 90 days.
- Record of the emails we send (recipient, subject, delivery status) is kept 1 year.
- Record of the actions taken in our back office (who changed what, and when) is kept 3 years.
- Encrypted backups of our database are overwritten in their normal cycle; data deleted from the database is gone from them at the latest 35 days after its deletion. The files of the content kept by agents are not in these backups.
- Cookies and local storage are described in section 8.
6. Who receives it
Your data is accessed only by the people at UNDERM LTD who need it for the purposes above, and by the recipients listed below.
Providers acting on our instructions
They help us run the service, under contract, and process your data only on our instructions.
- Email provider, for sending service emails.
- Hosting provider (Scaleway SAS), for the servers that run the website, portal and API.
- Network provider (Cloudflare, Inc.), which carries the traffic between you and our servers (website, client portal and API, including the content of API calls) and filters abuse; it processes this traffic only to deliver and protect it.
- Third-party AI providers, only for agents that use one, as main or backup provider. They receive the content of the calls to that agent, including the test calls made with your examples while we build an agent you buy, as described in section 3.
Recipients acting as independent controllers
They also use the data they receive for their own purposes and legal obligations, and are responsible for that use.
- Our bank, which receives the transfers you send us and handles them under its own banking obligations.
We may also disclose data when the law requires it.
7. Transfers outside the United Kingdom and the European Economic Area (EEA)
We are a company established in the United Kingdom. Personal data from the EEA can be transferred to us under the European Commission's adequacy decision for the United Kingdom (article 45 of the GDPR), which allows it to flow from the EEA to the United Kingdom without further safeguards. This covers in particular the content of the calls we process for our clients.
Some of the recipients listed in section 6, in particular our network provider and some third-party AI providers, may process data outside the United Kingdom and the EEA. When they do, the transfer relies on an adequacy decision (of the European Commission or, under UK law, of the UK government) or on appropriate safeguards such as the standard contractual clauses adopted by the European Commission, with the UK addendum to them where UK law applies. You can ask us for a copy of these safeguards at [email protected].
9. Your rights
You can ask to access your data, correct it, erase it, restrict its processing, object to processing based on our legitimate interest, and receive it in a portable format. Where processing relies on your consent, you can withdraw it at any time. You can also give instructions about what happens to your data after your death.
To exercise these rights, email [email protected]. We answer within one month and may ask you to confirm your identity. Some data must be kept despite a request to erase it, for example invoices we are legally required to keep.
10. Complaints
If you think we do not handle your data properly, please tell us first so we can fix it, by writing to [email protected]. We acknowledge your complaint within 30 days and tell you the outcome.
You also have the right to lodge a complaint with a data protection authority, in particular the ICO in the United Kingdom (ico.org.uk) or, in France, the CNIL (Commission nationale de l'informatique et des libertés), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr, or with the authority of the country where you live or work.
11. How we protect it
We apply measures suited to the risk. Access is limited to the people who need it, connections are encrypted, API keys are stored only as one-way hashes, and the IP addresses of visitors and clients are kept only as pseudonymized hashes in our database.
12. Changes to this policy
We may update this policy when the service or the law changes. The date at the top shows the latest version. We tell clients about material changes by email.