agenthost asks for as little as it can: an email address to sign you in, a name for your organization, and the files you choose to deploy. Here is exactly what we hold, why we are allowed to, and how to get it back or get rid of it.
Bernskiold Media AB, company registration number 556893-1652, Box 190, 101 23 Stockholm, Sweden, is the controller for the personal data described here. Contact us atsupport@agenthost.eu. We are not required to appoint a data protection officer and have not appointed one; that address reaches the people who decide these things.
| Data | Why | Legal basis |
|---|---|---|
| Email address, your name, organization name | To create and run your account, and to identify you when you sign in | Performance of a contract (Art. 6(1)(b)) |
| Sign-in codes, access and refresh tokens, API tokens, session records — all stored only as hashes | To authenticate you and the clients you authorize | Performance of a contract (Art. 6(1)(b)) |
| Which clients you authorized, and when tokens were last used | So you can see and revoke access, and so we can detect misuse | Legitimate interest in securing the service (Art. 6(1)(f)) |
| Server logs: IP address, timestamps, requested URLs, error detail | To operate the service, investigate faults, and prevent abuse | Legitimate interest in a working, secure service (Art. 6(1)(f)) |
| Projects, applications, hostnames, deployment history, and the files you deploy | To provide the hosting you asked for | Performance of a contract (Art. 6(1)(b)) |
| Billing details and invoices | To charge for the service and to keep our books | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Support correspondence | To answer you and keep track of the issue | Legitimate interest in supporting our customers (Art. 6(1)(f)) |
| Which pages of this website and the docs were visited, and roughly from where — no cookie, no identifier stored on your device | To see which pages are read and which are not, so we know what to write next | Legitimate interest in understanding our own site (Art. 6(1)(f)) |
We do not buy personal data, we do not run advertising, and we do not profile you. There is no automated decision-making with legal or similarly significant effects in the sense of Art. 22.
We use a small number of providers, each of them a processor bound by a data processing agreement. The list is deliberately short, and nothing on it sees more than the one thing it is there to do: there is no advertising network and no third-party analytics on it.
| Provider | What for | Where |
|---|---|---|
| Postmark (ActiveCampaign, Inc.) | Sending sign-in codes and account email | USA — see section 4 |
| DigitalOcean, LLC | Servers, databases, and backups | EU data centres, US company — see section 4 |
| Stripe Payments Europe, Limited | Card payments, subscriptions, and invoices | Ireland, with support access from the USA — see section 4 |
Beyond that we disclose personal data only where the law requires it, or to advisers and acquirers in connection with a sale of the business, under confidentiality.
Your account, your projects, and everything you deploy are stored on servers in the EU, and they stay there. Three of the providers above are nonetheless reachable from the United States, so we say plainly what that means:
All three rest on the European Commission's standard contractual clauses, together with a transfer impact assessment, and on the EU–US Data Privacy Framework where the provider is certified under it. You may request a copy of the safeguards from us.
agenthost sets two cookies, both strictly necessary to sign you in. Because they are strictly necessary, they need no consent under the Electronic Communications Act — which is why you are not being asked to click a banner. There is no advertising and no third-party tracking on this site.
The public pages and the docs do count page views, using Matomo running on our own infrastructure at analytics.bmedia.io. It is configured to set no cookies and to store nothing on your device, so it cannot follow you here from another site or recognise you on your next visit — which is why it too needs no banner. It is not switched on inside your account, so what you do with your projects and apps is not measured.
| Cookie | Purpose | Lifetime |
|---|---|---|
ah_session | Keeps you signed in so authorizing another client is one click | 30 days |
ah_csrf | Ensures an authorization was approved by you and not forged by another site | 30 days |
Traffic runs over TLS. No password exists to be stolen: you sign in with a one-time code, and every credential we store — sign-in codes, session identifiers, access, refresh, and API tokens — is kept only as a salted hash, so a copy of our database does not let anyone into your account. Access to production is limited to those who need it. If a breach occurs that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay.
You can ask us at any time to:
Write to support@agenthost.eu and we will answer within one month. If you think we are handling your data wrongly, you can complain to the Swedish Authority for Privacy Protection —Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se — or to the authority where you live.
If we change this policy we will post the new version here with a new date, and email you before anything material takes effect.