Privacy Policy
Last updated: 13 September 2026
Requires review and approval by qualified EU/Spanish legal counsel before being presented as final contractual/legal documentation.
AgentLane ("we", "us", or "our") provides AI-powered communication automation services that marketing agencies resell to local businesses. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our services, interact with our automations, or visit our website.
For the personal data of our business clients' customers, we act on behalf of others: normally as a sub-processor for the agency, which acts for the business (the controller). Where a business contracts with us directly, we are its processor. For agency partner accounts, billing and website visitors, we are the controller. The exact roles for each business are confirmed with the agency and recorded before an EU pilot.
For recipients in the United States, SMS communications are designed to align with the Telephone Consumer Protection Act (TCPA) and carrier 10DLC registration requirements.
1. Who We Are
Company: AgentLane Ltd Registered Address: 20 Wenlock Road, London, N1 7GU, United Kingdom Company Number: 17400209 (registered in England and Wales) Contact Email: contact@agentlane.agency
AgentLane Ltd is established in the United Kingdom, not in the EU. Whether we need an EU representative under Article 27 GDPR is under legal review.
2. What Data We Process
2.1 End-Customer Data (processed on behalf of our clients)
When a customer of one of our clients calls and misses the business, or texts it, we process:
- Phone numbers (caller ID / SMS sender)
- Message content (SMS text)
- Missed-call metadata (calling number, called number, call status, timestamps)
- Appointment details (requested dates, times, services), where given
- Names, if the customer provides them
- Contact preferences (opt-outs, do-not-contact entries and, where applicable, recorded consent to be called)
We do not run live AI voice calls and we do not store call recordings or call transcripts.
Legal basis: determined by our client as controller.
2.2 Agency Partner Data
- Name and job title
- Business email address
- Company name and registration number
- Phone number
- Billing information (processed via Stripe)
- Communication history (emails, support chat)
Legal basis: Contractual necessity and legitimate interest (business relationship management).
2.3 Website Visitor Data
- Form submissions (name, email, company, message)
- With your consent only: analytics data collected by Google Analytics 4 (online identifiers, pages visited, device and browser information, referral source). See our Cookie Policy.
Legal basis: Legitimate interest (responding to enquiries, website security) and consent (analytics).
3. How We Use Your Data
3.1 End-Customer Data
We use this data solely to:
- Send and receive SMS messages on behalf of our clients
- Generate AI-powered replies using large language models
- Create appointments via integrated calendar systems
- Escalate enquiries to the business owner
- Produce performance reports for our agency partners
We do NOT use end-customer data to:
- Train our own AI models
- Sell or share with third parties for marketing
- Profile individuals for purposes unrelated to the client's business
3.2 Agency Partner Data
To manage partner accounts, bill fees, provide support, send service updates and meet legal obligations.
3.3 Website Visitor Data
To respond to enquiries, keep the website secure and, with consent, understand traffic.
4. Data Sharing and Sub-Processors
Our platform (application, database, job queue, object storage and automation engine) runs on one server in Frankfurt am Main, Germany. We are confirming this against the hosting contract. We use the following third parties. The current register is published in our Compliance Center.
| Sub-Processor | Purpose | Location |
|---|---|---|
| VPS hosting provider | Hosting of all platform data | Germany (Frankfurt), to be confirmed against contract |
| Twilio | Phone numbers, missed-call detection, SMS | United States-headquartered |
| Anthropic | AI replies in automations and the support chat | United States-headquartered |
| OpenAI | AI replies (alternate provider) | United States-headquartered |
| Cal.com | Appointment booking (client's own account) | Depends on the client's account |
| Resend | Transactional and automation email | United States-headquartered |
| Stripe | Payments for agency partners | United States-headquartered |
| Slack | Internal operational alerts (no conversation content) | United States-headquartered |
| Google (Analytics 4) | Website analytics, only with consent | Google infrastructure |
Important notes:
- The workflow automation engine (Activepieces) is self-hosted on the server above. It is not a separate third party.
- Where an agency or client connects its own Twilio, Anthropic, OpenAI, Cal.com or Resend account, that provider processes the data under the agency's or client's own agreement.
- We do not currently claim that any AI provider applies zero data retention to our requests.
- New sub-processors: we will notify agency partners before a new sub-processor processes their data.
5. Data Retention
| Data Category | Retention Period | How it is deleted |
|---|---|---|
| SMS and missed-call conversations | 12 months after last activity by default; agencies/clients can set 1–3650 days | Automated daily job |
| Data export archives | 7 days | Automated |
| Closed accounts | Purged 30 days after an approved deletion request | Automated |
| Database backups | 14 days | Rotation |
| Support chat | 12 months (automated deletion being enabled) | Scheduled job, currently count-only |
| Appointment records in legacy home-services tables | Deleted when the client account is purged | Automated deletion on account purge only |
| Agency partner contract and billing data | Duration of contract + period required by tax law | Manual review |
| Website analytics | Per our Google Analytics retention setting |
These periods are safe defaults for our platform. Controllers remain responsible for deciding whether they meet their own legal obligations.
6. Your Rights Under GDPR
If you are a customer of one of our clients, the business you contacted is the controller. Please contact that business first. You can also email us and we will pass your request on.
- Access and portability: a copy of your data in a structured format.
- Rectification: correction of inaccurate data.
- Erasure: deletion of your data, unless a legal obligation requires retention.
- Restriction and objection: limiting or objecting to processing.
- Stopping texts: reply STOP to stop automated texts from that business's number. Text START to opt back in.
- Automated decisions: our automations qualify enquiries and propose appointments on behalf of businesses. You can ask the business for human review.
- AI transparency: where our clients use AI voice agents in the future, the agent will identify itself as an AI at the start of the call.
- Complaints: your local data protection authority (for Spain, the Agencia Española de Protección de Datos — aepd.es; for the UK, the ICO — ico.org.uk).
We respond within one month.
7. Security Measures
- Encryption in transit: TLS on all public endpoints.
- Credential encryption: provider API keys and tokens are encrypted with AES-256-GCM before storage.
- Access control: role-based access with view-only agency roles. Two-factor authentication is available and strongly recommended, but not currently enforced.
- Tenant isolation: each agency and client can only access its own data.
- Audit logging: application-level actions (account, billing, credential, compliance and admin changes) are logged. This does not cover raw database-level access.
- Network: only SSH, HTTP and HTTPS are exposed publicly.
- Incident response: we notify affected agency partners without undue delay after becoming aware of a personal data breach. The partner or business, as controller, handles regulatory and customer notification where required.
8. International Data Transfers
Platform data is hosted in Germany. Some sub-processors are headquartered in the United States (Twilio, Anthropic, OpenAI, Resend, Stripe, Slack, Google), so data may be transferred outside the EEA/UK. The transfer mechanism for each provider (for example Standard Contractual Clauses or the EU-US Data Privacy Framework) is being confirmed as part of our legal review. Until that review is complete, we do not represent any particular mechanism as in place.
9. Children's Privacy
Our services are not directed at children under 16. We do not knowingly process data from children. Contact us if you believe we have.
10. Changes to This Policy
We will notify agency partners of material changes by email. The latest version is always at agentlane.agency/privacy.
11. Contact Us
Email: contact@agentlane.agency Postal address: AgentLane Ltd, 20 Wenlock Road, London, N1 7GU, United Kingdom (Company No. 17400209)
Our Data Processing Agreement is pending legal finalization. Agencies can request the current draft by email.
This Privacy Policy does not constitute legal advice.