Privacy Policy

Agentic Super Services is the controller for personal data processed through Paygrid. This policy explains what we collect, why, and what you can do about it. We have tried to write it in plain language, including where our design creates genuine tension with the right to erasure.

Effective 31 July 2026

Who we are

Legal entity
Agentic Super Services
Registered office
Amsterdam, the Netherlands — [registered address to be added]
Chamber of Commerce (KvK)
[KvK number to be added]
Contact
jordan.gallant.ct@gmail.com

We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries go to the contact address above.

The short version

This website collects nothing. No cookies, no analytics, no trackers, no third-party requests. Fonts, styles, and scripts are served from this origin only.

The service collects little, and publishes some of it by design. Attestations are meant to be public and independently verifiable — that is the entire point of a track record. Never put personal or confidential information in a claim statement.

What we collect

When you visit this website

Our web server writes standard request logs: IP address, timestamp, requested path, HTTP status, referrer, and user agent. These are used to operate and secure the site and are not combined with anything else or used to profile you.

When you use the service

If you contact us

Your email address and the contents of your message, kept so we can reply and keep a record of the correspondence.

We do not collect special categories of personal data, and we do not use your data for automated decision-making that produces legal effects for you.

Why, and on what legal basis

To provide the service — Art. 6(1)(b), contract
Creating agents, processing claims, issuing and publishing attestations, maintaining records.
To keep it secure and working — Art. 6(1)(f), legitimate interests
Rate limiting, abuse and fraud prevention, debugging, capacity planning. Our interest is running a service that is not degraded or exploited; the data involved is minimal and not used to profile you.
To publish verifiable records — Art. 6(1)(b) and 6(1)(f)
Publishing attestations is the service you asked for, and third parties have a legitimate interest in being able to check them.
To comply with the law — Art. 6(1)(c)
Where we must retain or disclose information under a legal obligation.
Email you asked for — Art. 6(1)(a), consent
Only if you opt in, and you can withdraw at any time.

Publication, permanence, and the right to erasure

We would rather be direct about this than bury it.

Attestations are cryptographically signed and designed to be copied, cached, and verified offline by anyone. When you ask us to delete data, we can remove your account, stop publishing your attestations from our endpoints, and delete them from our systems. We cannot recall copies that other parties have already retrieved, and we cannot alter a signed attestation without destroying the signature that makes it worth anything.

For this reason: do not include personal data in claim statements or parameters. Identify agents, not people. Anything you submit should be treated as permanently public. Where you do submit personal data about someone else, you are responsible for having a lawful basis to do so.

How long we keep it

Who else sees it

We do not sell personal data and we do not share it for advertising. We use a small number of service providers:

We may disclose information where legally required, or to establish or defend legal claims.

International transfers

Our primary infrastructure is in the EU. Where a provider processes data outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.

Separately, verifying an on-chain claim means sending a transaction hash to public blockchain RPC providers, which may be outside the EEA. These requests contain blockchain identifiers, not your account details.

Your rights

Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on it. To exercise any of these, write to jordan.gallant.ct@gmail.com. We will respond within one month.

If you are not satisfied with our response, you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the authority in your country of residence.

Security

We describe our technical and organisational measures in detail on our Security page, including what we have not yet done.

Children

The Service is not directed at children and is not intended for anyone under 18.

Changes to this policy

We may update this policy. Material changes will be posted here with a revised effective date.