Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how Aristokrates OÜ ("AgentaOS", "we", "us", "our") collects, uses, shares, and protects personal data when you visit our website, use AgentaOS as a merchant, or buy a product through a checkout we operate as Merchant of Record. It is written to meet the EU General Data Protection Regulation (GDPR) and applicable Estonian law.
Contents
1. Who we are, and our roles
Aristokrates OÜ, registered in Estonia under registry code 16948108, operates AgentaOS (agentaos.ai). Because we act as Merchant of Record, our data-protection role depends on the data:
- We are the controller for personal data of website visitors and merchants, and for Buyer data we handle as the seller of record (payment, tax, invoicing, and fraud prevention).
- We act as a processor where we process personal data on a merchant's documented instructions, for example, analytics or AI features run on a merchant's own data. That processing is governed by our Data Processing Agreement, and the merchant is the controller for it.
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Merchant & account data | Name, email, business details, login credentials, and identity or business-verification (KYC/KYB) documents where required by law. | You, and verification partners. |
| Buyer data (as seller of record) | Name, email, billing country, and the payment metadata needed to complete the sale, calculate tax, and issue an invoice. | The Buyer at checkout. We do not store full card numbers; card details are handled by our Payment Partners. |
| Transaction data | Orders, amounts, taxes, refunds, chargebacks, and payout records. | Generated through the Service. |
| Usage & device data | Log data, IP address, device and browser information, and privacy-friendly analytics. | Automatically, when you use the Service. |
| Communications | Messages you send us for support or sales, and our replies. | You. |
We do not intentionally collect special categories of personal data, and you should not submit them through the Service.
3. How and why we use it (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the Service; operate the checkout, sales, payouts, tax, and invoicing. | Performance of a contract. |
| Verify identity; prevent fraud, money laundering, and abuse; meet tax, accounting, and sanctions obligations. | Legal obligation and legitimate interests. |
| Provide support and send service communications. | Contract and legitimate interests. |
| Send product or marketing updates. | Consent or legitimate interests; you can opt out at any time. |
| Secure, maintain, and improve the Service. | Legitimate interests. |
Where we rely on legitimate interests, we have weighed those interests against your rights; you may object at any time (see Section 10).
4. AI features and automated processing
AgentaOS includes features that analyse merchant data to surface revenue and growth insights (for example, highlighting an underpriced plan or a churn risk). These insights are suggestions to help you decide; they are not decisions that produce legal or similarly significant effects on any individual, and we do not use them for solely-automated decision-making within the meaning of Article 22 of the GDPR. Where such features process a merchant's own data on the merchant's instructions, we act as processor under the DPA.
5. Cookies and analytics
We use privacy-friendly analytics and, by default, only essential cookies needed to operate the site and checkout. Any non-essential cookies are used only with your consent, which you can manage or withdraw through the notice shown on our site. Analytics help us understand and improve how the Service is used.
6. Sharing and sub-processors
We share personal data only as needed to run AgentaOS, with providers that are bound by contracts requiring them to protect it. Categories include:
- Payment Partners: licensed Payment Service Providers, Electronic Money Institutions, and e-money / stablecoin issuers that provide regulated payment, e-money, custody, and settlement services.
- Cloud hosting & infrastructure providers.
- Identity, KYC/KYB, and fraud-prevention providers.
- Analytics and communications providers.
- AI / model providers, for merchant-directed insight features.
- Professional advisers and authorities, where required by law or to protect our rights and users.
We do not sell personal data. A current list of sub-processors is available on request to [email protected].
7. International transfers
Where personal data is transferred outside the European Economic Area, we rely on an appropriate safeguard, an adequacy decision or the European Commission's Standard Contractual Clauses, with any supplementary measures required, so that your data continues to be protected.
8. Retention
We keep personal data only as long as needed for the purpose we collected it, then delete or anonymise it. In particular:
- Transaction, tax, invoicing, and accounting records: kept for the period required by tax and accounting law (generally up to 7 years).
- KYC/KYB and anti-money-laundering records: kept for the period required by AML law (generally up to 5 years after the end of the relationship).
- Account and merchant data: kept for the life of your account and a reasonable period afterwards.
- Support and marketing data: kept until no longer needed or until you opt out.
9. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role-based access on a least-privilege basis, multi-factor authentication for administrative access, logging and monitoring, and regular testing and review. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to incidents.
10. Your rights
Subject to applicable law, you may request access to, rectification, erasure, restriction, or portability of your personal data, and you may object to certain processing or withdraw consent where we rely on it (without affecting processing already carried out). To exercise these rights, email [email protected]. We will respond within the time required by law. You may also lodge a complaint with your local supervisory authority; in Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
If we handle your data as a processor on a merchant's behalf, please direct your request to that merchant; we will assist them as required.
11. Marketing
We may send you product or marketing updates where the law allows. You can opt out at any time using the unsubscribe link in the message or by contacting us. Opting out of marketing does not stop essential service communications.
12. Children
AgentaOS is not intended for anyone under 18, and we do not knowingly collect personal data from children.
13. Changes
We may update this Policy from time to time. We will post the updated version with a new "last updated" date and, where a change is significant, take reasonable steps to tell you.
14. Contact
Aristokrates OÜ · Estonia, EU · Registry code 16948108 · [email protected]