Delagents

Privacy Policy

What Delagents collects on the website and in the preview app, why, how long it is kept, who processes it, and the rights you have over it.

Effective 17 September 2026

Delagents is in preview. The website is live, the workspace app runs on demo data, and the backend that will process customer data is being built. Sections marked 'when the app launches' describe processing that has not started. We will update this policy before it does.

1. Who we are and what this policy covers

Delagents (the operator, 'we') runs the website at delagents.com and the Delagents workspace app. This policy explains what personal data we collect when you visit the website, write to us or use the preview app, how we use it, and the choices you have. It applies to visitors, to people who contact us and, when the app launches, to account holders.

When a customer uses Delagents to process data about their own customers, contacts or candidates, the customer is the controller of that data and we act on their instructions as a processor. That relationship is described in our Data Processing Addendum. This policy covers the data we handle as a controller.

2. What we collect

On the website

  • Contact form and email: your name, email address, the message you send and, if you include it, your company name. We collect this when you write to us through the form or at hello@delagents.com.
  • Server and security logs: IP address, browser type, requested pages and timestamps, recorded by Cloudflare, which hosts and protects the website. These logs keep the site running and block abuse.
  • Analytics: we do not currently run analytics scripts on the website. If we add measurement, we will prefer aggregated, cookie-free methods and update this section before it goes live.

In the preview app

The preview app runs on demo data. It does not create accounts and does not connect to your tools. If you ask for early access, we collect the email address and name you give us so that we can write back.

When the app launches

  • Account data: name, email address, workspace name, role, and sign-in identifiers handled by our sign-in provider.
  • Billing data: plan, invoices and payment status. Card details are entered directly with our billing provider and are never stored on our systems.
  • Customer content: briefs, attachments, transcripts of agent runs, deliverables, and data read from the tools you connect, within the scopes you grant.
  • Integration tokens: the credentials that let an agent act in a connected tool, kept in an encrypted vault and used only inside the tool call.
  • Activity and usage records: the append-only log of tool calls, approvals and policy changes, and the usage records that make up your bill.

3. How we use it

  • To answer your message and follow up on it.
  • To run, secure and improve the website and the service.
  • To operate your workspace: run delegations, show progress, file approvals, deliver results and keep the audit log.
  • To bill you, and to send receipts, notices about your account and changes to these documents.
  • To meet legal obligations and to establish or defend legal claims.

We do not sell personal data, and we do not use customer content to train models, whether our own or a provider's.

4. Legal bases for visitors in the EU, EEA, UK and Switzerland

PurposeLegal basis
Answering your messageLegitimate interest in responding to people who write to us, or your consent when you ask to be contacted
Security and server logsLegitimate interest in keeping the website available and safe
Providing the service to account holdersPerformance of the contract with you
Billing, tax and accountingLegal obligation, and performance of the contract
Product notices and changes to these documentsPerformance of the contract; legitimate interest
Marketing email, if we ever send itConsent, which you can withdraw at any time

5. Cookies

The website sets no marketing or tracking cookies. Cloudflare may set cookies that are strictly necessary for security and load balancing. When the app launches it will use a session cookie to keep you signed in, and nothing else without asking you first.

6. How long we keep it

  • Contact messages: up to 24 months after our last exchange, unless the conversation leads to a contract, in which case they are kept with the account.
  • Security logs: for the short period Cloudflare retains them, typically days rather than months.
  • Account data: for the life of the account and up to 30 days after it is closed, then deleted.
  • Customer content: for the retention period shown on your plan, then removed by a nightly purge that deletes transcript content and files while keeping the audit skeleton (which step ran, when, and who approved it) for the plan's audit retention period.
  • Billing records: for the period required by tax and accounting law.
  • Model provider: Anthropic retains data sent to its API for up to 30 days, after which it is deleted on their side.

7. Who processes data for us

We use a small number of providers to run the website and the service. Each processes data only on our instructions, under a written agreement, for the purpose listed.

ProviderPurposeStatus
CloudflareHosting, content delivery, security and edge services for the website and appIn use now
AnthropicModel inference for delegations; API data retained up to 30 days; not used for trainingWhen the app launches
ClerkSign-in, sessions and identityPlanned
StripeBilling, invoices and payment processingPlanned
NeonManaged Postgres databasePlanned

We update this list before a new provider begins processing personal data. Account holders are notified of changes as described in the Data Processing Addendum.

8. International transfers

Our providers may process data outside the country you live in, including in the United States. Where data leaves the EU, EEA, UK or Switzerland, we rely on the European Commission's standard contractual clauses or an equivalent lawful safeguard, together with the security measures described on our security page. Regional hosting is on our roadmap and is not available in the preview.

9. Your rights

Depending on where you live, you have some or all of the following rights over your personal data. We honor them for everyone, wherever you are.

  • Access: ask what data we hold about you and receive a copy.
  • Correction: have inaccurate data fixed.
  • Deletion: ask us to delete your data, subject to records we must keep by law.
  • Portability: receive your data in a common, machine-readable format.
  • Restriction and objection: ask us to limit or stop processing that is based on legitimate interests.
  • Withdrawal of consent: at any time, where consent is the basis.
  • Complaint: to your local data protection authority, if you believe we have handled your data unlawfully.

To exercise a right, email hello@delagents.com from the address concerned. We reply within 30 days. When the app launches, account data and customer content will also be exportable and deletable from the workspace settings.

10. Security

Data is encrypted in transit and at rest. Access to connected tools is granted per agent and scoped to what was approved. Integration tokens are held in an envelope-encrypted vault and never appear in prompts or logs. The activity log is append-only. Our security page describes these measures in more detail. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you without undue delay.

11. Children

Delagents is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

12. Changes to this policy

When we change this policy we publish the new version here with a new effective date. For material changes affecting account holders we also send an email before the change takes effect. The effective date at the top of the page is the date of the current version.

13. Contact

Questions, requests and complaints go to hello@delagents.com. A person reads and answers them.