First draft pending review by counsel. Bracketed items are open facts, not omissions.
Privacy Policy
Most of this service is about software, not people. Agents are programs; keys, signatures, and spending limits are not personal data. But a person stands behind every agent, and this page says exactly what we learn about that person, what we deliberately never learn, and — unusually — what we publish on purpose.
1Who this covers
This policy applies to the agentvalidate service operated by [LEGAL ENTITY — unresolved] ("Regent", "we"), and to four groups of people: Owners (people accountable for an agent's actions and spending), Builders (people who register an agent), Customer personnel (staff of a business using the service), and visitors to this site.
2Our two roles
We are the controller for our own account, registry, and billing records — we decide why and how they are processed.
When a business sends us a key to check, or routes its traffic through our gateway, we act as a processor on that business's instructions for the data it sends. That business decides what to send us and remains responsible for telling its own users. A data processing addendum governs that relationship.
3What we collect
| Who | What | Why |
|---|---|---|
| Owner | Email address; display name; the binary result of identity verification plus a decentralised identifier; the spending limits they set; the agents they have claimed; their activity, including transactions that were refused. | To let a person authorise an agent, hold that authority to a limit, and stop it. Legal basis: performance of a contract with them. |
| Builder | Public key and its thumbprint; the agent's name and stated intent; a contact email; the domain or issuer the agent identifies with; registration and approval timestamps. | To operate the registry and reach the registrant. Legal basis: contract and our legitimate interest in a trustworthy registry. |
| Customer personnel | Name, work email, account and billing details, API key fingerprints, configuration, usage counts. | To provide, meter, and bill the service. Legal basis: contract. |
| Everyone | Server logs: IP address, user agent, timestamps, endpoint called. Decisions and signed receipts for authorised actions. | Security, abuse prevention, and evidence. Legal basis: legitimate interest, and legal obligation where records must be kept. |
We use no advertising trackers and sell nothing to anyone. [ANALYTICS — PostHog is planned; add cookie/consent detail before it ships]
4What we never collect
This is deliberate architecture, not a promise of good behaviour — the data is not in our systems to lose:
- Card numbers and payment credentials. Payments run on your provider's rails; we never see a PAN.
- Wallet private keys. An agent generates and holds its own key; we see only a public address.
- Identity documents. Verification is performed by a licensed provider on its own systems. We receive a yes/no and an identifier. We never receive, store, or view a passport, ID card, selfie, or liveness capture.
- Special-category data. We do not seek or knowingly hold data on health, beliefs, biometrics, or anything comparable.
5What is public by design
Read this section even if you skip the rest. Parts of the service are public because a revocation nobody can check is worthless:
- Registry state of a key — whether it is known, approved, or revoked — is publicly checkable by anyone holding the key's thumbprint. We never publish the reason for a revocation.
- A single bit about the Owner: whether an accountable party exists, and whether they completed identity verification. No name, no document, no score, no history is ever published about a person.
- Agent name and stated intent, as written by whoever registered the agent. Do not put personal information in these fields — they are published.
- Passports and receipts, which are signed statements designed to be verified by third parties without contacting us.
6Who else processes this data
We use a small number of providers, each for one job: identity verification (a licensed provider that keeps the documents), hosting and infrastructure, email delivery, payment and invoicing, and error monitoring. Where a behavioural evaluation appears on a passport, the evaluation provider receives the agent identifier — not the Owner's identity.
[SUBPROCESSOR LIST — publish names and locations; enterprise security reviews will ask]
We disclose data otherwise only where legally compelled, and will tell you unless prohibited from doing so.
7Where the data lives
Our production infrastructure is hosted in [HOSTING LOCATION — say "the United States" once the migration completes; today it is Kazakhstan. This sentence must state where the data actually is on the day the page goes live].
If you are in the European Economic Area or the United Kingdom, your data is transferred outside that jurisdiction either way — the United States is a third country for these purposes just as Kazakhstan is. [TRANSFER MECHANISM — self-certification to the EU-US Data Privacy Framework requires a US entity; without it, standard contractual clauses and a transfer impact assessment are needed before EU/UK sales]
Customers who cannot accept this can run the enforcement layer as a self-hosted sidecar, in which case traffic and decisions stay inside their own infrastructure.
8How long we keep it
- Passports — 24 hours, then they expire on their own.
- Account and registry records — while the account exists, then [RETENTION — confirm].
- Revocation records — permanently. A revocation that could be erased would not be a revocation.
- Receipts and decision records — up to 10 years, because they exist to be produced years later in a dispute. They describe a transaction — amount, payee, agent, mandate — and contain no name or document.
- Server logs — [LOG RETENTION — confirm].
9Your rights, and one honest limit
Depending on where you live you may ask to access, correct, export, or delete your data, to object to or restrict processing, and to complain to a supervisory authority. Write to us and we will answer within the period the applicable law allows.
The limit: we cannot delete a revocation record or a signed receipt on request. Both exist so that a third party can verify, later, that something was or was not authorised; erasing them on demand would destroy the guarantee everyone else relies on, and receipts are also kept to meet record-keeping obligations. What we can do is delete your account and contact details, disconnect them from those records, and stop all further processing. Signed statements already issued cannot be recalled — they expire.
Where a business sent us your data, address your request to that business; we will assist them as their processor.
10Security
Every agent authenticates by signature rather than a shared secret, so there is no bearer token to steal. The one credential we hold at rest is encrypted. The system fails closed: when a determination cannot be made, the action is refused rather than allowed. Details are on the security page. Report a vulnerability to info@regentprotocol.org.
11Children
The service is for businesses and developers and is not directed to anyone under 16. We do not knowingly collect their data; tell us if you believe we have, and we will delete it.
12Changes
We will update this page when the service changes and note the date at the top. Material changes are announced to account holders before taking effect.
13Contact
Privacy questions and rights requests: info@regentprotocol.org. [POSTAL ADDRESS · EU/UK ART. 27 REPRESENTATIVE if selling there · DPO if required]