Privacy Policy

Last updated: 22 August, 2026

1. Our Commitment to Your Privacy

Agion ("we," "us," "our") is committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we collect, use, process, and safeguard your personal data in compliance with the General Data Protection Regulation (GDPR), the EU AI Act, and other applicable laws.

This policy applies to data we collect from visitors to our website, our customers, and any other individuals whose data we process in the course of our business.

2. The Data Controller

Agion Oy is the Data Controller responsible for the personal data described in this policy. This means we decide what data is collected and why. We are responsible for:

  • Data you provide when you visit our website (e.g., through contact forms, cookies).
  • Data related to the management of our customer accounts (e.g., billing and contact information).
  • Data collected for marketing and sales purposes.

Contact Details of the Data Controller

Company:
Agion Oy
Address:
Nummikatu 18-20, 90100 Oulu, Finland
Privacy email:
privacy@agion.ai

When you use our AI agent platform to process data you own, you are the Data Controller, and Agion acts as the Data Processor on your behalf. Our respective roles and responsibilities for this processing are governed by a Data Processing Agreement (DPA), available upon request at privacy@agion.ai.

3. What Personal Data We Collect and Why

We process different categories of personal data for specific purposes, and we only do so when we have a lawful basis.

Account & Billing Data

Examples
Name, business email, phone number, billing address, payment details.
Purpose
To create and manage your account, provide our services, process payments, and communicate with you about your subscription.
Lawful basis
Performance of a contract (Art. 6(1)(b))

Platform Operational Data

Examples
System logs, IP addresses, audit trails, usage metadata.
Purpose
To secure the platform, monitor performance, prevent fraudulent activity, and provide customer support.
Lawful basis
Legitimate interest (Art. 6(1)(f)) to ensure the security and stability of our service.

Website & Marketing Data

Examples
Name, email, company name (from contact forms), cookie data, IP address.
Purpose
To respond to your inquiries, provide you with marketing communications (with your consent), and analyze website traffic to improve our site.
Lawful basis
Consent (Art. 6(1)(a)) for marketing communications and analytics; legitimate interest (Art. 6(1)(f)) for responding to direct inquiries.

Customer Content Data

Examples
Any personal data contained within the missions, workflows, tools, or other content you upload to our platform.
Purpose
To perform the services you have requested as part of your contract. We only process this data based on your documented instructions.
Lawful basis
As a Data Processor, we process this on your behalf. Your lawful basis as the Controller applies.

4. Data Sharing and Third Parties

Agion does not sell your personal data.

We use a limited number of third-party service providers to help us operate our website and deliver our services. We have Data Processing Agreements (DPAs) in place with these providers, as required under GDPR Article 28.

Website services

  • Google Analytics 4 / GA4 (Google Ireland Ltd, deployed via Google Tag Manager) — We use Google Analytics 4 to measure aggregate website traffic (pages visited, session duration, referral source). Google processes IP addresses and usage data to produce anonymised analytics reports; no personal profiles of individual visitors are created. GTM is the container that deploys the GA4 script; GTM itself does not independently process personal data. Data is processed under Google's Data Processing Amendment (GDPR-compliant). Legal basis: consent.
  • Leadfeeder / Dealfront (Dealfront Group GmbH) — We use Leadfeeder to identify which companies (not individuals) visit our website, based on IP address lookup against public company databases. Leadfeeder does not identify natural persons. The data processed is your company's IP address and pages visited. This service is only loaded if you accept analytics cookies. Legal basis: consent. Dealfront is headquartered in Germany (EEA); data does not leave the EEA.

Platform sub-processors

For customers using the Agion platform, we use sub-processors including cloud infrastructure providers and payment processors. A full sub-processor list is available upon request at privacy@agion.ai. We will notify customers at least 30 days before making any changes to our sub-processor list.

Cookies

We use a small number of cookies and similar technologies on this website. You can manage your preferences via the cookie banner. The cookies we use:

  • cc_cookie (first-party) — Set by the cookie consent banner to remember your cookie preferences. Strictly necessary. Expires after 6 months.
  • _ga, _ga_* (Google Analytics 4, via GTM) — Set only if you accept analytics cookies. Used to measure website traffic in aggregate. Both expire after 2 years; the session ID cookie is refreshed on each visit.
  • Leadfeeder / Dealfront cookies — Set only if you accept analytics cookies. Used to attribute company-level website visits. Session and persistent cookies; typical retention 30 days.

Strictly necessary cookies (consent record) are set regardless of your preference. All analytics and tracking cookies are loaded only after you grant consent.

5. International Data Transfers

Our platform is cloud-agnostic and can be deployed in various regions (AWS, Azure, GCP). Where personal data is transferred outside of the European Economic Area (EEA), we ensure it is protected through EU Standard Contractual Clauses (SCCs).

6. Data Security

We take the security of your data seriously and have implemented appropriate technical and organizational measures to protect it. These include:

  • Encryption: Data is encrypted both in transit (using TLS) and at rest.
  • Access Controls: We enforce strict role-based access controls to limit access to personal data to authorized personnel only.
  • Immutable Logs: We maintain immutable audit logs to track access and changes to data, which are accessible to our customers.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected.

  • Customer Account Data: Retained for the duration of your subscription and for a subsequent period as required by law (e.g., for tax and accounting purposes).
  • Website & Marketing Data: Email addresses and contact details collected via website forms (including waitlist and demo sign-ups) are retained until you withdraw consent or request erasure. We review marketing contacts at least annually and delete those who have not opened an email or visited our website in the preceding 12 months.
  • Operational Data: System logs are typically retained for a rolling period of 90 days, unless a longer period is required for security investigations.
  • Customer Content Data: Retained for the duration of your subscription term, as defined in your agreement with us. Data is securely deleted upon contract termination.

8. Your Rights as a Data Subject

Under GDPR, you have the following rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request that we correct any inaccurate or incomplete data.
  • Right to Erasure: You can request that we delete your personal data.
  • Right to Restrict Processing: You can request that we limit the processing of your data.
  • Right to Data Portability: You can request to receive your data in a machine-readable format.
  • Right to Object: You can object to us processing your data for our legitimate interests.
  • Right to Withdraw Consent: Where we process your data based on consent, you can withdraw that consent at any time — including via the cookie banner on this website for analytics cookies. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us at privacy@agion.ai. We will respond within one month of receiving your request.

You also have the right to lodge a complaint with a supervisory authority in your country of residence if you believe we have not processed your personal data in accordance with GDPR.

9. Breach Notification

In the event of a personal data breach, Agion will notify the relevant supervisory authority — the Finnish Data Protection Ombudsman (tietosuoja.fi), or the authority in your country of residence — without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

For customers using the Agion platform: where a breach involves personal data you control, we will notify you as the Data Controller without undue delay so that you can fulfil your own regulatory notification obligations.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically.