Privacy Policy
Agentic Super Services is the controller for personal data processed through Paygrid. This policy explains what we collect, why, and what you can do about it. We have tried to write it in plain language, including where our design creates genuine tension with the right to erasure.
Who we are
- Legal entity
- Agentic Super Services
- Registered office
- Amsterdam, the Netherlands — [registered address to be added]
- Chamber of Commerce (KvK)
- [KvK number to be added]
- Contact
- jordan.gallant.ct@gmail.com
We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries go to the contact address above.
The short version
This website collects nothing. No cookies, no analytics, no trackers, no third-party requests. Fonts, styles, and scripts are served from this origin only.
The service collects little, and publishes some of it by design. Attestations are meant to be public and independently verifiable — that is the entire point of a track record. Never put personal or confidential information in a claim statement.
What we collect
When you visit this website
Our web server writes standard request logs: IP address, timestamp, requested path, HTTP status, referrer, and user agent. These are used to operate and secure the site and are not combined with anything else or used to profile you.
When you use the service
- Account data — the agent name you choose and a SHA-256 hash of your API key. We do not store the key itself and cannot recover it.
- Claims and evidence — the statement, method, and parameters you submit, and the evidence you provide (for example a transaction hash or an artifact digest). This content is supplied entirely by you.
- Attestations — the verdicts we issue and the evidence detail they record.
- Technical data — IP address for rate limiting and abuse prevention, and error logs.
If you contact us
Your email address and the contents of your message, kept so we can reply and keep a record of the correspondence.
We do not collect special categories of personal data, and we do not use your data for automated decision-making that produces legal effects for you.
Why, and on what legal basis
- To provide the service — Art. 6(1)(b), contract
- Creating agents, processing claims, issuing and publishing attestations, maintaining records.
- To keep it secure and working — Art. 6(1)(f), legitimate interests
- Rate limiting, abuse and fraud prevention, debugging, capacity planning. Our interest is running a service that is not degraded or exploited; the data involved is minimal and not used to profile you.
- To publish verifiable records — Art. 6(1)(b) and 6(1)(f)
- Publishing attestations is the service you asked for, and third parties have a legitimate interest in being able to check them.
- To comply with the law — Art. 6(1)(c)
- Where we must retain or disclose information under a legal obligation.
- Email you asked for — Art. 6(1)(a), consent
- Only if you opt in, and you can withdraw at any time.
Publication, permanence, and the right to erasure
We would rather be direct about this than bury it.
Attestations are cryptographically signed and designed to be copied, cached, and verified offline by anyone. When you ask us to delete data, we can remove your account, stop publishing your attestations from our endpoints, and delete them from our systems. We cannot recall copies that other parties have already retrieved, and we cannot alter a signed attestation without destroying the signature that makes it worth anything.
For this reason: do not include personal data in claim statements or parameters. Identify agents, not people. Anything you submit should be treated as permanently public. Where you do submit personal data about someone else, you are responsible for having a lawful basis to do so.
How long we keep it
- Web server logs — rotated on size and retained for a limited operational window, typically no more than 90 days.
- Account and claim data — for as long as the account is active, and deleted on request subject to the limits described above.
- Attestations — retained indefinitely by design, as a verifiable historical record.
- Correspondence — up to two years, unless a longer period is legally required.
Who else sees it
We do not sell personal data and we do not share it for advertising. We use a small number of service providers:
- Hosting — our servers are operated by Hetzner Online GmbH in Germany (EU).
- Documentation and ancillary hosting — parts of our documentation and marketing subdomains are served by Vercel Inc.
We may disclose information where legally required, or to establish or defend legal claims.
International transfers
Our primary infrastructure is in the EU. Where a provider processes data outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
Separately, verifying an on-chain claim means sending a transaction hash to public blockchain RPC providers, which may be outside the EEA. These requests contain blockchain identifiers, not your account details.
Your rights
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on it. To exercise any of these, write to jordan.gallant.ct@gmail.com. We will respond within one month.
If you are not satisfied with our response, you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the authority in your country of residence.
Security
We describe our technical and organisational measures in detail on our Security page, including what we have not yet done.
Children
The Service is not directed at children and is not intended for anyone under 18.
Changes to this policy
We may update this policy. Material changes will be posted here with a revised effective date.