LEGAL

Privacy Policy

Last updated: March 2026

1. Data Controller

dcode technologies S.A. Luxembourg Email: [email protected] We are committed to protecting your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Luxembourg's data protection legislation.

2. Data We Collect

We collect the following categories of personal data: • Email address — collected during account creation via Supabase magic link authentication • Name, role, company, industry — optionally provided during the agent configuration wizard • Wizard configuration — your agent setup choices, stored in Supabase to enable download delivery • Payment data — processed entirely by Stripe. We receive confirmation of payment but do NOT store card numbers, CVVs, or bank details • Basic analytics — page views and referral sources via Plausible Analytics (no personal data, no cookies, no IP tracking)

3. Legal Basis for Processing

We process your data under the following legal bases: • Contract performance (Art. 6(1)(b) GDPR) — processing your purchase, delivering the product, managing your account • Legitimate interest (Art. 6(1)(f) GDPR) — anonymous analytics to improve the product, fraud prevention, system security • Consent (Art. 6(1)(a) GDPR) — optional email communications about product updates (you can opt out at any time)

4. Cookies

We use essential cookies only: • Supabase authentication session cookie — required for login functionality We do NOT use tracking cookies, advertising cookies, or third-party analytics cookies. Our analytics provider (Plausible) is fully cookieless and does not collect any personally identifiable information.

5. Third-Party Processors

We share data with the following processors, all of whom maintain GDPR-compliant data processing agreements: • Supabase (auth + database) — EU data region. Stores your account and wizard configuration. Privacy: https://supabase.com/privacy • Stripe (payments) — PCI DSS Level 1 certified. Processes payments. Privacy: https://stripe.com/privacy • Plausible Analytics — EU-hosted, cookieless, no PII collected. Privacy: https://plausible.io/data-policy We do not sell, rent, or trade your personal data to any third party.

6. Data Retention

• Account data (email, profile) — retained until you request deletion • Purchase records — retained for 10 years as required by Luxembourg commercial law • Wizard configuration — retained as long as your account exists, to enable re-downloads • Wizard localStorage data — stored only in your browser, cleared by your browser's storage policies • Analytics data — aggregated and anonymous, retained by Plausible per their data policy

7. Your Rights

Under the GDPR, you have the following rights: • Right of access — request a copy of all personal data we hold about you • Right to rectification — correct any inaccurate personal data • Right to erasure — request deletion of your personal data ("right to be forgotten") • Right to data portability — receive your data in a structured, machine-readable format • Right to object — object to processing based on legitimate interest • Right to restrict processing — request limitation of processing in certain circumstances • Right to withdraw consent — where processing is based on consent, withdraw it at any time To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Luxembourg data protection authority (CNPD): https://cnpd.public.lu

8. Data Processing Agreement

For B2B customers who require a Data Processing Agreement (DPA) under Article 28 of the GDPR, we provide one on request. Contact [email protected].

9. International Transfers

Your data is processed within the European Economic Area (EEA). In cases where data may be transferred outside the EEA (e.g., Stripe's global infrastructure), appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Children

AI Agent Builder is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.

11. Security

We implement appropriate technical and organizational measures to protect your personal data, including: • Encryption in transit (TLS/HTTPS) • Encryption at rest for stored data • Access controls and authentication • Regular security reviews The agent systems you download and run are entirely self-hosted. We have no access to your deployed agents, their data, or your API keys.

12. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email to registered users. The "Last updated" date at the top of this page will always reflect the most recent revision.

13. Contact

For any privacy-related questions or requests: dcode technologies S.A. Luxembourg Email: [email protected] Website: https://d-code.lu