In effect from 21 August 2026 · version 1.2
Privacy Policy
agenthost asks for as little as it can: an email address to sign you in, a name for your organization, and the files you choose to deploy. Here is exactly what we hold, why we are allowed to, and how to get it back or get rid of it.
1. Who is responsible
Bernskiold Media AB, company registration number 556893-1652, Box 190, 101 23 Stockholm, Sweden, is the controller for the personal data described here. Contact us at support@agenthost.eu. We are not required to appoint a data protection officer and have not appointed one; that address reaches the people who decide these things.
2. What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Email address, your name, organization name | To create and run your account, and to identify you when you sign in | Performance of a contract (Art. 6(1)(b)) |
| Your acceptance of these terms: the date, and which version of the terms and of this policy you were shown | To show what you agreed to, and when, if either of us ever needs to | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Sign-in codes, access and refresh tokens, API tokens, session records — all stored only as hashes | To authenticate you and the clients you authorize | Performance of a contract (Art. 6(1)(b)) |
| Which clients you authorized, and when tokens were last used | So you can see and revoke access, and so we can detect misuse | Legitimate interest in securing the service (Art. 6(1)(f)) |
| A record of what is done on your account: the action, who took it, when, from which IP address and client, and whether it succeeded, failed or was refused | So there is a reliable record of who changed what, to investigate abuse and mistakes, and to answer you when you ask | Legitimate interest in an accountable, secure service (Art. 6(1)(f)) |
| Server logs: IP address, timestamps, requested URLs, error detail | To operate the service, investigate faults, and prevent abuse | Legitimate interest in a working, secure service (Art. 6(1)(f)) |
| Projects, applications, hostnames, deployment history, and the files you deploy | To provide the hosting you asked for | Performance of a contract (Art. 6(1)(b)) |
| Billing details and invoices | To charge for the service and to keep our books | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Support correspondence | To answer you and keep track of the issue | Legitimate interest in supporting our customers (Art. 6(1)(f)) |
| Which pages of this website and the docs were visited, and roughly from where — no cookie, no identifier stored on your device | To see which pages are read and which are not, so we know what to write next | Legitimate interest in understanding our own site (Art. 6(1)(f)) |
We do not buy personal data, we do not run advertising, and we do not profile you. There is no automated decision-making with legal or similarly significant effects in the sense of Art. 22.
3. Who else sees it
We use a small number of providers, each of them a processor bound by a data processing agreement. The list is deliberately short, and nothing on it sees more than the one thing it is there to do: there is no advertising network and no third-party analytics on it.
| Provider | What for | Where |
|---|---|---|
| Postmark (ActiveCampaign, Inc.) | Sending sign-in codes and account email | USA — see section 4 |
| OVH SAS (OVHcloud) | Servers, databases, and backups | France, EU company |
| Stripe Payments Europe, Limited | Card payments, subscriptions, and invoices | Ireland, with support access from the USA — see section 4 |
Beyond that we disclose personal data only where the law requires it, or to advisers and acquirers in connection with a sale of the business, under confidentiality.
4. Transfers outside the EU/EEA
Your account, your projects, and everything you deploy are stored on servers in the EU, and they stay there. The company that runs those servers is French, with no parent outside the EU, so the hosting itself involves no transfer out of the EU at all. The other two providers above are reachable from the United States, so we say plainly what that means:
- Email. Our email provider is established in the United States, so sending you a sign-in code transfers your email address there.
- Payments. Our payment provider contracts with us through its Irish entity and keeps payment data in the EU, but its group can reach that data from the United States for support and fraud prevention.
Both rest on the European Commission's standard contractual clauses, together with a transfer impact assessment, and on the EU–US Data Privacy Framework where the provider is certified under it. You may request a copy of the safeguards from us.
5. How long we keep it
- Sign-in codes — minutes. They expire in ten and are deleted within a day.
- Access tokens — until they expire; refresh tokens until they expire or you revoke them. Spent records are removed 30 days later.
- Browser sessions — 30 days, or until you sign out.
- Account, projects, and deployed content — while your account is open, then deleted 30 days after it closes.
- Server logs — 90 days.
- The record of what is done on your account — five years. The questions it exists to answer, about a mistake or a misuse, tend to arrive long after the event.
- Accounting records — seven years, as the Swedish Accounting Act (bokföringslagen) requires.
6. Cookies
agenthost sets two cookies, both strictly necessary to sign you in. Because they are strictly necessary, they need no consent under the Electronic Communications Act — which is why you are not being asked to click a banner. There is no advertising and no third-party tracking on this site.
The public pages and the docs do count page views, using Matomo running on our own infrastructure at analytics.bmedia.io. It is configured to set no cookies and to store nothing on your device, so it cannot follow you here from another site or recognise you on your next visit — which is why it too needs no banner. It is not switched on inside your account, so what you do with your projects and apps is not measured.
| Cookie | Purpose | Lifetime |
|---|---|---|
ah_session | Keeps you signed in so authorizing another client is one click | 30 days |
ah_csrf | Ensures an authorization was approved by you and not forged by another site | 30 days |
7. How we protect it
Traffic runs over TLS. No password exists to be stolen: you sign in with a one-time code, and every credential we store — sign-in codes, session identifiers, access, refresh, and API tokens — is kept only as a salted hash, so a copy of our database does not let anyone into your account. Access to production is limited to those who need it. If a breach occurs that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay. The security page sets out the rest of the measures, including the ones this policy does not need to name.
8. Your rights
You can ask us at any time to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your data — we will, unless we must keep it (accounting records, for example);
- restrict or object to processing we base on legitimate interests;
- hand your data over in a portable, machine-readable form; or
- withdraw consent, where we relied on it, without affecting what came before.
Write to support@agenthost.eu and we will answer within one month. If you think we are handling your data wrongly, you can complain to the Swedish Authority for Privacy Protection — Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se — or to the authority where you live.
9. Changes
If we change this policy we will post the new version here with a new date, and email you before anything material takes effect.