AGENTCORE / LEGAL
Privacy Policy
Last updated: 2026-09-26
This policy covers the AgentCore website, CRM, the Meta application AgentCore Notify, and the WhatsApp Business Platform connection.
Provider and contact
AgentCore is the service brand. The legal provider and monitored privacy contact are listed below.
Data we process
The categories actually processed in the service are:
The public site receives information sent through the contact form or to the contact email and technical request logs. The CRM processes administrator and staff account details; organisation, Meta business portfolio, WABA and phone identifiers; customer and supplier contacts; conversation content and metadata; supported attachments; message templates and delivery statuses; and access and action logs. Categories vary with the functions a company uses.
Why we process it
We use the data to establish and maintain the Meta connection, display and handle CRM conversations, send messages requested by the company or its configured rules, provide support, and protect the service.
Roles and instructions
The business customer decides whom to contact, the content of its messages, and its automation rules. For data about that customer’s counterparties, AgentCore processes data to provide the service on the customer’s instructions. AgentCore decides how to process its own website, account administration, security and support data.
Storage, retention and suppliers
The current storage location, retention and infrastructure suppliers are described below.
- Storage
- The application, PostgreSQL database, Redis and application-managed file storage run on Hetzner infrastructure in Finland. PostgreSQL stores CRM records; Redis supports queues and cache. Technical logs and uploaded files are stored in application-managed storage according to the functions used. Contact form submissions are sent to the monitored Gmail mailbox, which is separate from the Finland-hosted CRM storage.
- Retention
- CRM data is retained while the internal pilot is in use. A separate external SaaS customer account and automatic post-closure deletion period are not yet available. Contact enquiries in the monitored mailbox have no documented automatic deletion schedule. An authorised person can request access, disconnection or deletion by email; the scope and any legal or audit retention are reviewed for each request.
- Backups
- A restricted-access PostgreSQL backup is made before production API deployments. Older manual backups also exist. No automatic maximum backup lifetime is currently configured. Removing data from the live database does not immediately remove it from existing backups; the requester is informed about backup handling and any exceptions in the response.
- Infrastructure suppliers
- Hetzner hosts the application and primary data stores in Finland. Google operates the monitored Gmail mailbox receiving contact enquiries. Meta provides the WhatsApp Business Platform. OpenAI and Anthropic can receive content when a corresponding CRM AI function is used; those providers process data under their own API terms and infrastructure.
AI processing
The current use of AI for WhatsApp data is described below.
Agent functions in the CRM can process records, documents or message content supplied to them by authorised users or configured workflows. Receiving a message through the pilot WABA integration does not by itself establish that the message is automatically sent to an AI provider.
Depending on the agent function, content may be sent to the APIs of OpenAI or Anthropic.
The providers' API terms and the relevant account settings govern their processing and retention. AgentCore does not claim that AI providers have no retention or that an account-specific no-training arrangement has been verified.
Cookies and analytics
The actual cookies and analytics are described below.
- Cookies
- The new public pages do not set cookies. The CRM uses an essential Secure, HttpOnly, SameSite=Strict refresh cookie; language and theme preferences are stored locally in the browser. Opening Meta Embedded Signup can involve cookies set by Meta.
- Analytics
- The new public pages do not load an analytics script. Technical application and web-server logs may still record requests and errors.
Access, disconnection and deletion
A company administrator can ask for access to company data, disconnection of WhatsApp, or deletion through the contact below. Individuals whose conversations are held by a customer can also contact us; we coordinate the request with that business customer. See Data Deletion for the steps.
Data Deletion →Security and changes
The current security measures are described below. We publish changes to this policy on this page and update the date shown at the top. Material changes affecting customers are communicated through the service or the registered contact.
The public site and CRM use HTTPS. CRM access is controlled through user accounts and roles. The CRM refresh cookie is Secure, HttpOnly and SameSite=Strict; deployment database dumps are created with restricted file permissions.
Legal basis and customer instructions
Business customers determine the lawful basis for their messages and contact records. AgentCore processes those records under the customer’s instructions. Contact and account information is used to respond to enquiries, provide the requested service and maintain its security. Contact us for the basis applicable to a specific processing activity.
Your data rights
Where applicable law grants these rights, you may request access, correction, erasure, restriction, portability or object to processing. You may also contact a competent data protection authority. Requests about a business customer’s conversations are coordinated with that customer.
Data Deletion →