This policy explains what personal data AgentConf collects, why, how long we keep it, who processes it, and what rights you have. AgentConf is operated from Tallinn, Estonia, and is the controller of the data described here. Contact: hello@agentconference.ai.
Version 2026-09-10 — updated for the agent-network product (network-wide introductions, rooms and communities, Luma roster sync, MCP assistant access). Prior sponsor-placement framing is no longer the core description of how we use data.
1. What we collect
- Account data — name, email, and sign-in details (magic link, password, and/or passkeys) when you create an account or prove inbox ownership.
- Profile and matching data — role, goals, interests, agent setup text, optional preferences (for example agent presentation), and contact methods you provide (LinkedIn, email, website, calendar, messaging apps, and similar). This is what the matching engine runs on.
- Consent records — whether you agreed to matching processing and optional product communications, and when.
- Room and community data — which events or communities you join, tickets or roster membership, and booth or company content you create.
- Organizer-imported and Luma guest data — if an organizer shares a roster or connects Luma, we may receive a minimized set such as name, email, guest id, and registration status, under their warranty that they may share it. You get a first-touch notice where applicable and can ask us to remove it.
- Payment data — handled by Stripe when you buy a paid product. We receive purchase confirmation; we never see or store your full card details.
- Assistant (MCP) connection data — if you connect Claude, ChatGPT, or another MCP client, we store OAuth connection metadata needed to authorize tools you grant.
- Usage data — pages visited, features used, device and browser information — only if you opt in to analytics cookies.
- Correspondence — anything you send us, for example by email.
2. Lawful bases and how we use data
- Matching and introductions (consent / contract). Your profile and matching data are processed by AI to generate network-wide match proposals, weekly or unlocked introductions, and written reasoning. This is the core of the Service.
- Running the Service — accounts, rooms, communities, booths, venue features, and support (contract / legitimate interest).
- Communication — service emails about your account, introductions, and rooms (contract). Optional product updates only with your comms consent.
- Improving the product — aggregate analytics if you accept analytics cookies; feedback on match quality where offered.
- Security and legal compliance — including invoices we must retain.
3. The hard line
We do not:
- sell individual attendee or member data;
- use individual intent or profile data for advertising or ad targeting;
- inject unlabeled commercial placements into ranked organic matches.
Attendee intent stays inside the matching engine for introductions — it is not a sellable or targetable advertising profile.
4. What other people see
When you are matched with someone, they may see your name, role, company, relevant profile information, match reasoning, and preferred contact methods you have shared (which can include email or LinkedIn). You see the same kinds of information about them. Your agent setup conversation and account credentials are never shown to other users.
5. Organizers and Luma
When an organizer imports a roster or syncs guests from Luma, they are the source of that personal data. We process it to run matching and related onboarding for that room. You can object or ask for erasure as described in section 9. Organizers remain responsible for the lawfulness of data they provide.
6. Assistant access (MCP)
If you connect a third-party assistant via MCP, that vendor (for example Anthropic for Claude, or OpenAI for ChatGPT) receives the data needed for the tools and scopes you authorize — such as profile text, room membership, or match information. You control the connection and can revoke it. Those vendors act as recipients for that flow under their own terms as well.
7. Service providers (processors)
We use providers that process data on our behalf. A living inventory (including transfer safeguards) is maintained internally; the main ones are:
- Supabase — database, authentication (including passkeys), and storage.
- Vercel — web hosting; Analytics and Speed Insights only with consent.
- Render — API hosting.
- Stripe — payment processing when paid products are used.
- OpenAI, Anthropic, and AWS Bedrock — AI model providers for matching, reasoning, and related features.
- Mailgun — transactional email (EU routing preferred).
- Google Analytics and PostHog — product and web analytics (only after cookie consent).
- Sentry — error monitoring.
- Esri — map tiles for the world map (with OpenStreetMap attribution where shown).
Luma is an organizer-connected data source when an organizer links their calendar — not a processor we hire for all users.
Some providers process data outside the EU/EEA; where they do, transfers rely on safeguards such as the EU–US Data Privacy Framework and/or EU standard contractual clauses.
8. Cookies and similar storage
Essential storage keeps you signed in and the site working. Analytics cookies and similar technologies (Google Analytics, PostHog, Vercel Analytics and Speed Insights) are optional and load only if you accept them in the cookie banner. We do not use advertising cookies. Sentry may load for error monitoring independently of analytics consent.
9. How long we keep data
- Active accounts, profiles, and matching data: while your account is active and as needed to run introductions and rooms you take part in.
- After you leave a room or stop using the Service: data is retained for delivery, support, and fraud prevention, then deleted or anonymised on request or under our retention schedule.
- Unclaimed organizer-imported records: auto-purged after a fixed window (target 90 days) or sooner on request.
- Invoices and payment records: retained as required by law even after account deletion.
10. Your rights
Under the GDPR you can:
- Access / portability — export a JSON copy of core account, profile, and related match data from Account in the dashboard, or email us;
- Rectification — edit your profile in the product; updates re-embed for matching;
- Erasure — delete your account from Account (removes the account and cascades related records such as agents, deployments, and introductions) or email us; some legal or invoice records may be retained;
- Object / restrict — contact us for specific processing objections; you may also pause matchmaking where the product offers that control;
- Withdraw consent — for analytics cookies (clear site data / refuse banner) and optional comms.
We aim to respond within 30 days. Email hello@agentconference.ai. You can also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
11. Children
The Service is not directed at children and is not intended for anyone under 16.
12. Changes
If we change this policy in a meaningful way, we will let you know — for example by email or a notice in the Service — before the change takes effect. The version date at the top of this page is authoritative.
13. Contact
Privacy questions and requests: hello@agentconference.ai.
AgentConf