Legal
Privacy policy
Last updated: July 9, 2026
Draft — for review by your solicitor before launch.
1. Who we are
Just Agents (“we”, “us”) operates justagents.co, a platform that provides AI agents for business communication and operations. This policy explains what personal data we collect, why, and what rights you have over it. It covers our website, dashboard, chat widget, and voice services.
For the purposes of data protection law, we act as a controller for account and website data, and as a processor for the data your agents handle on your behalf (your customers’ emails, calls, and messages) — see our Data Processing Agreement.
2. Data we collect
Account data: name, email address, password hash, organisation name, and billing details (payment card data is held by Stripe, never by us).
Business Brain data: the content of the website you ask us to read, documents you upload (menus, price lists, policies), FAQs you write, and your tone-of-voice settings.
Agent activity data: the emails, call transcripts, chat messages, reviews, invoices, and social posts your agents process — including personal data of your customers contained in them.
Usage data: log data (IP address, browser type, pages visited), task counts, and feature usage, used for security, billing, and product improvement.
Homepage demo: if you use the “try it on your website” demo, we fetch the public pages of the site you enter and hold the extracted text in memory for up to one hour. Nothing from the demo is written to our database.
3. How we use data
We use data to:
- provide the service — run your agents, ground their answers in your Business Brain, and show you the activity feed;
- bill you accurately (task counts, voice minutes);
- secure the platform (fraud and abuse prevention, rate limiting);
- communicate with you (approval digests, service notices, and — with consent — product updates);
- improve the product using aggregated, de-identified usage statistics.
We do not sell personal data. We do not use your Business Brain or your customers’ content to train AI models. Content sent to our AI provider (Anthropic) is processed under terms that prohibit training on it.
4. Legal bases
Where GDPR or UK GDPR applies, we rely on: contract (providing the service you signed up for), legitimate interests (security, product analytics, B2B communications), consent (marketing emails, optional cookies), and legal obligation (tax and accounting records).
5. Processors and subprocessors
We share data only with the service providers needed to run the platform:
- Anthropic — AI model inference (drafting, triage, answers).
- Supabase — database, authentication, and file storage.
- Stripe — payments, subscriptions, and invoicing.
- Resend — transactional email delivery.
- Twilio and Vapi — phone numbers, telephony, and voice AI (if you enable Echo).
- Vercel — application hosting and content delivery.
The full subprocessor table, including locations and transfer safeguards, is in the DPA. We may also disclose data where the law requires it.
6. International transfers
Some providers process data in the United States. Where data leaves the UK or EEA, we rely on adequacy decisions or Standard Contractual Clauses (and the UK Addendum) with each provider.
7. Retention
Account and Business Brain data are kept while your account is active. After cancellation, your data is retained for 30 days (so you can export or reactivate), then deleted from production systems; encrypted backups roll off within a further 35 days. Billing records are kept as long as tax law requires (typically 6–7 years). Demo scrape data is held in memory for at most 1 hour. You can request earlier deletion at any time.
8. Your rights
Depending on where you live (including under GDPR, UK GDPR, and CCPA), you have the right to: access the personal data we hold about you; correct it; delete it; export it in a portable format; restrict or object to certain processing; and withdraw consent at any time. You also have the right to complain to your supervisory authority (the ICO in the UK).
To exercise any of these rights, email privacy@justagents.co. We respond within 30 days. If your data was processed by one of our customers’ agents (for example, you called a business that uses Echo), contact that business first — we will assist them in fulfilling your request.
9. Security
Data is encrypted in transit (TLS) and at rest. Access is scoped per tenant with row-level security, restricted internally on a need-to-know basis, and logged. Payment card data never touches our servers. If a breach affects your data, we will notify you without undue delay and within any legally required window.
10. Cookies
We use strictly necessary cookies for authentication and session state. We do not run third-party advertising trackers on this site. Any optional analytics cookies are set only with consent.
11. Children
The service is for businesses and is not directed at children under 16. We do not knowingly collect data from children.
12. Changes and contact
We will notify account owners by email of material changes to this policy before they take effect. Questions: privacy@justagents.co.