Privacy Policy
Last updated: 5 August 2026 · Version 1.0
1. Data controller
The data controller is Dokoyo Koyo Holding OÜ, a company registered in Estonia under registration number 17432821, with registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Sakala tn 7-2, 10141.
The AgentID.ee platform is managed and operated by Dokoyo Koyo Holding OÜ.
DPO email: privacy@agentid.ee
2. Data we collect
| Category | Data | Legal basis |
|---|---|---|
| Identity | Name, email, job role | Contract (Art. 6.1.b GDPR) |
| Company account | Company name, VAT number, country | Contract |
| AI agents | Agent name, AI ID Code, provider, permissions | Contract |
| Audit log | Agent actions, timestamps, SHA-256 hash chain | Legal obligation (Art. 6.1.c) + Contract |
| Usage data | Access logs, anonymised session metrics | Legitimate interest (Art. 6.1.f) |
| Payment | We do not handle payment data — processed by Stripe | — |
3. How we use your data
- Service delivery: creating and managing accounts, issuing AI ID Codes, recording immutable audit logs.
- Security: preventing unauthorised access and fraud, verifying the integrity of the audit chain.
- Regulatory compliance: adhering to Estonian AI law (AI Act, Estonia AI ID Code framework).
- Service communications: alert notifications, expiry warnings, critical updates.
- We do not use your data for marketing without explicit consent.
4. Data retention
- Account data: for the duration of the contract + 2 years after termination.
- Audit logs: 7 years (AI Act compliance obligations), then irreversible anonymisation.
- Session data: 90 days.
- After account deletion, identifiable personal data is removed within 30 days (Art. 17 GDPR). Audit logs are de-identified and retained as required by law.
5. Data recipients
Your data is never sold. We share it only with:
- Google Firebase / Firestore (database hosting, EU-west1 / Belgium) — Data Processing Agreement in place.
- Stripe Inc. (payments) — processes only data necessary for transactions.
- Public authorities — only upon formal request with a valid legal basis.
6. Your rights (GDPR)
Art. 15 — Access
Obtain a copy of all data we hold about you
Art. 16 — Rectification
Correct inaccurate or incomplete data
Art. 17 — Erasure
Have your data deleted ("right to be forgotten")
Art. 18 — Restriction
Restrict processing in specific circumstances
Art. 20 — Portability
Receive your data in a machine-readable format
Art. 21 — Objection
Object to processing based on legitimate interest
To exercise your rights: privacy@agentid.ee or via Settings → Privacy & GDPR. We will respond within 30 days.
You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (AKI) or the supervisory authority of your country of residence.
7. Security
We implement appropriate technical and organisational measures: TLS encryption in transit, at-rest encryption on Firestore, role-based access control (RBAC), audit logs with SHA-256 hash-chaining, Firestore rules that block direct client writes to logs, Cloud Functions executed server-side in eu-west1.
8. Cookies
We use only strictly necessary technical cookies required for the service to function. See our Cookie Policy for details.
9. Changes to this Privacy Policy
For material changes, we will notify you by email at least 30 days before they take effect. The current version is always available on this page.