이 페이지는 아직 번역되지 않아 영어 원문을 표시합니다.

Privacy Policy

최종 수정일: 2026-07-18

SUCHKA Spółka z ograniczoną odpowiedzialnością ("SUCHKA sp. z o.o.", "agent4.io", "we", "us") operates the agent4.io platform. This policy explains what personal data we handle, why, and what rights you have.

Registered office: ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland. Entered in the register of entrepreneurs of the National Court Register (KRS) under no. 0001219139; NIP 7011295965; REGON 543797920; share capital PLN 5,000 paid in full.

Privacy contact: contact@agent4.io.

1. Two different roles

This distinction determines who is responsible for what, and it runs through the whole policy.

We are the controller of data about our own customers — the businesses and individuals who create an agent4.io account: account details, billing records, and how the product is used.

We are a processor for the data those customers put into the platform: the documents they upload, the conversations their end users have with their agents, and the memories derived from those conversations. Our customer is the controller of that data. They decide what is collected and why; we process it on their documented instructions to provide the service.

If you are an end user who has chatted with an agent built on agent4.io, the business operating that agent is your data controller — address requests about your data to them in the first instance.

Business customers subject to the GDPR or UK GDPR can request a Data Processing Agreement, including standard contractual clauses — see the Data Processing Agreement.

2. Data we handle as controller

Account data. Name, email address, password (stored only as a salted hash), preferred language, and any organisation details you provide. Where you sign in with Google, GitHub or X, we receive the profile identifiers those services release under your authorisation — never your password for them.

Billing data. Plan, subscription status, billing period, invoices and payment history. Card details are collected and stored by our payment processor, not by us — we receive a token, the card brand, the last four digits, and the outcome of a charge. We cannot see or reconstruct a full card number.

Usage data. Token consumption against your quota, request volumes, feature usage, and the diagnostic records needed to operate the service (timestamps, IP address, user agent, error traces).

Communications. Messages you send us, and records of support and sales correspondence.

Pre-signup consultation. You can talk to the assistant on this website without an account. Those conversations are held under a random identifier generated for your browser, not under your name.

If you then create an account in that same browser, we offer to carry the conversation forward. Two things are worth being precise about:

  • We ask first. The offer appears on the sign-up form with a checkbox you can clear, and nothing is carried over if you do.
  • What moves is a summary of the key points, not the transcript. The original anonymous conversation stays where it was and is not attached to your account.

The carry-over happens once. We keep a marker on the anonymous identifier recording that it has been claimed, so the same conversation cannot later be pulled into a different account.

If you never sign up, the anonymous conversation is never linked to an identified person by us.

3. Data we process on behalf of our customers

Acting on our customers' instructions, the platform processes:

  • Knowledge base content — documents and text a customer uploads for their agents to answer from.
  • Conversations — messages between a customer's end users and their agents, across the web widget, Telegram and WhatsApp.
  • Derived memories — facts and topics extracted from those conversations so an agent recognises a returning end user.
  • End-user identifiers — the identifier the customer chooses to pass, plus any contact details their agent is configured to collect.
  • Records — enquiries, document checklists, booking requests and escalations that a customer's agent files for a person to act on, together with the notes their staff add. The contents of a record are encrypted at rest; only the type, status, timestamps and the identifiers pointing back at the conversation are held in the clear, and none of those identifies anyone.

We do not decide what goes into these, do not use them to build our own profiles of end users, and do not sell them.

A customer can also have each new record sent to a URL of their own as it is filed. Where they switch that on, they are instructing us to transfer that record — contact details included — to a system they have chosen, and it becomes their responsibility from the moment it arrives. They can switch it off at any time, and we do not send records anywhere else.

4. Why we process it, and on what basis

PurposeLegal basis (GDPR Art. 6)
Providing the service you signed up forPerformance of a contract
Billing, invoicing and collecting paymentPerformance of a contract
Security, abuse prevention, service integrityLegitimate interests
Product analytics and improvementLegitimate interests
Service and security announcementsContract / legitimate interests
Marketing emailConsent, withdrawable at any time
Meeting tax, accounting and legal obligationsLegal obligation

Where we rely on legitimate interests we have assessed that our interest does not override your rights, and you may object at any time.

5. Model providers, and what is sent to them

Answering a message requires sending relevant content to a language model and an embedding model. What is sent is the message, the passages retrieved from the relevant knowledge base, and any retrieved memories — not a customer's entire knowledge base, and not other end users' data.

Where we operate models ourselves, that content stays within our infrastructure. Where a customer configures a third-party model provider, content is sent to that provider under the customer's own arrangement, and that provider's terms apply. Customers choosing an external provider should confirm its retention and training terms, which we do not control.

6. Sub-processors

ProviderPurpose
Payment processor (Stripe, where enabled)Subscription billing and card processing
Amazon Web Services — region us-west-2 (Oregon, USA)Compute, database and file storage
Email delivery providerTransactional email (verification, receipts, notifications)
Model providersLanguage and embedding inference, as described above

A current list, and notice of changes, is available at contact@agent4.io.

7. International transfers

We are established in Poland, and the platform is currently hosted on Amazon Web Services in the us-west-2 region (Oregon, United States). Personal data processed through the service is therefore transferred to the United States, as it is to the other sub-processors listed above.

These transfers are made under the European Commission's standard contractual clauses — incorporated into the AWS GDPR Data Processing Addendum — together with the supplementary technical measures described in section 9, in particular field-level encryption of customer content keyed per space. The UK addendum applies to transfers of UK personal data. A copy of the transfer mechanism relied on is available at contact@agent4.io.

8. Retention

DataRetained for
Account dataWhile the account exists, then deleted or anonymised within 90 days of closure
Customer content (documents, conversations, memories)Until the customer deletes it, or 30 days after account closure
Billing and tax recordsAs long as tax and accounting law requires, typically 6–7 years
Security and diagnostic recordsTypically up to 12 months
Pre-signup consultationsHeld under the browser identifier; removed with the rest of that browser's conversation history, or 30 days after account closure where the summary was carried into an account
BackupsPurged on the ordinary backup rotation after deletion

Deleting a document also removes what it contributed to derived memories, rather than leaving it recoverable through them.

9. Security

  • Customer content is encrypted at rest at field level, keyed per space, so a database copy alone does not yield readable conversations or documents.
  • Isolation between end users is enforced by database-level row security, not only application code, so a faulty query cannot reach another space's data.
  • Optional end-to-end encryption is available for sensitive conversations.
  • Transport is encrypted with TLS. Passwords are stored only as salted hashes. Administrative access is restricted to personnel who need it, and is logged.

No system is perfectly secure. Where a breach affects personal data and the law requires it, we will notify you and the relevant authority within the applicable deadline.

10. Your rights

Subject to the conditions in applicable law you may request: access; correction; erasure; restriction of processing; portability in a machine-readable format; objection to processing based on legitimate interests; and withdrawal of consent where consent was the basis.

Write to contact@agent4.io. We respond within one month and will tell you if we need longer. Verifying your identity may be necessary before we act.

If you are in the UK or EEA and believe we have handled your data unlawfully, you may complain to your local supervisory authority. Ours is the Polish authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland — uodo.gov.pl. California residents have rights under the CCPA/CPRA including to know, delete, correct, and opt out of "sale" or "sharing" — we do not sell or share personal information as those terms are defined.

11. Cookies

Cookies we set without asking

NEXT_LOCALE records the language you chose so the site opens in it next time. Signing in to the dashboard additionally sets a session cookie for as long as you stay signed in. Both are strictly necessary or a preference you asked for, so under the ePrivacy rules no consent is required.

Your light/dark preference and your analytics choice below are kept in your browser's local storage, which is not a cookie and is never sent to us.

Analytics — only if you agree

We use Google Analytics 4 to see which pages help people and which do not. It sets cookies, so we ask first: the tag is not loaded at all until you choose "Allow" in the banner. If you decline, or simply ignore the banner, nothing is loaded, no cookie is set and no request reaches Google. We do not use advertising cookies, and we do not sell or share what analytics collects.

When it is enabled, Google Analytics records the pages you visit, roughly where you are (from a truncated IP address — we enable IP anonymisation), and a few named actions such as starting a signup or opening a solution page. Google LLC acts as our processor for this, and data may be handled in the United States under the European Commission's Standard Contractual Clauses. Our lawful basis is your consent (Art. 6(1)(a) GDPR).

To change your mind, clear this site's data in your browser (Settings → Privacy → Site data), which removes the stored choice and the analytics cookies; the banner will ask again on your next visit. You can also write to contact@agent4.io and we will confirm what to do for your browser.

We use no advertising or cross-site tracking of any kind, with or without consent.

12. Children

The platform is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, write to contact@agent4.io and we will delete it.

13. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means. Agents generate replies automatically, but they are a communication tool operated by our customers, not a mechanism for deciding anyone's rights.

14. Changes

Changes are posted here with a new date. Account holders are notified by email of material changes before they take effect.

Questions: contact@agent4.io.