Privacy

Privacy Policy

How AgentLayer handles personal data across the website, demos, pilots and enterprise services.

Last updated: July 7, 2026

This Privacy Policy explains how AgentLayer, a product operated by Rapadcin Inc. (dcSpark) or by the entity identified in the applicable proposal, order form or contract, collects, uses, stores, discloses and protects personal data.

It was drafted with Chilean Law 19.628 on privacy protection currently in force, Law 21.719 on personal data protection and processing and the creation of the Personal Data Protection Agency, and good practices for SaaS services, AI agents and enterprise integrations.

If your company has a signed contract, data processing addendum, order form or confidentiality agreement with AgentLayer, that document may set additional or more specific obligations for a pilot or production deployment.

1. Controller and contact

AgentLayer is operated by Rapadcin Inc. (dcSpark). For data collected directly through this website, commercial forms, demos, communications, events or prospecting activities, Rapadcin Inc. (dcSpark) acts as data controller when it determines the purposes and means of processing.

For data that a customer uploads, connects or processes within an agent, AgentLayer usually acts as processor or mandatary, following the customer's instructions, unless the contract says otherwise.

You can exercise rights or send privacy questions through the contact form available at agentlayer.cl/#contacto. If your organization has an active contract, you may also use the administrative, legal or security contact listed in the order form.

2. Scope of this policy

This policy applies to agentlayer.cl, demo requests, commercial communications, pilots, proofs of concept, implementation services, support, account administration, site analytics and use of AI agents where AgentLayer determines or participates in personal data processing.

It does not replace the privacy policies of customers, vendors or third parties. When a customer uses AgentLayer to process data about its own users, workers, customers, vendors or prospects, the customer must inform those individuals and rely on an appropriate lawful basis.

3. Data we may process

The categories depend on how you interact with AgentLayer and on the contracted services.

  • Identity and contact data: first name, last name, email, phone, role, company, country and contact preferences.
  • Professional and commercial data: industry, company size, operational needs, systems used, budget, commercial stage, meetings and follow-up notes.
  • Technical and usage data: IP address, device identifiers, browser, operating system, pages visited, interaction events, logs, timestamps and performance data.
  • Contract, administrative and billing data: information needed for quotes, orders, payments, taxes, access control, support and compliance.
  • Customer-uploaded or connected data: documents, messages, tickets, operational records, images, files, knowledge bases, integration metadata and agent outputs, depending on the pilot or service scope.
  • Derived data: classifications, summaries, extractions, scores, alerts, quality metrics, audit data, security data and platform usage data.

4. Sensitive data and minors

We do not request sensitive data through public forms. In enterprise services, the customer must not upload sensitive data, data about children or adolescents, health data, biometric data, highly sensitive financial data or equivalent categories unless the contract expressly authorizes it and an appropriate legal basis exists.

If we detect unexpected sensitive data, we may block, delete, anonymize it or request additional instructions from the customer to reduce risk and comply with applicable law.

5. Data sources

We may obtain data directly from you, your company, account administrators, forms, meetings, customer-authorized integrations, infrastructure and security providers, public sources or third parties where a legal or contractual basis exists.

For prospecting, competitive intelligence or open-source analysis agents, the customer must define permitted sources, search criteria and restrictions so processing respects data-subject rights and applicable sector rules.

6. Purposes

We process personal data for specific, explicit and legitimate purposes, and seek to limit processing to what is necessary to meet them.

  • Respond to information requests, demos, pilots, support and commercial contact.
  • Assess automation needs, propose agents, prepare quotes and manage contractual relationships.
  • Configure, operate, monitor, secure and improve agents, integrations, workflows and related services.
  • Authenticate users, control access, keep audit records, prevent abuse, investigate incidents and protect platform availability.
  • Generate aggregate analytics, performance metrics, usage reports and operational learnings to improve the service.
  • Send commercial communications, newsletters or invitations when there is consent, a prior business relationship or another permitted basis, with an opt-out option.
  • Comply with legal, regulatory, tax, accounting and contractual obligations, and exercise or defend legal rights.

7. Lawful bases and purpose map

Depending on the context, we process data based on consent, pre-contractual or contractual measures, legal obligations, legitimate interests, the establishment, exercise or defense of rights, data from public sources where allowed by law, or a specific authorization under applicable rules.

As a practical rule, we map each lawful basis to a concrete purpose before starting or expanding a processing activity.

  • Pre-contractual measures or contract: respond to requests, assess needs, prepare proposals, run pilots, configure agents, administer accounts, provide support and operate contracted services.
  • Legal obligation or statutory authorization: comply with tax, accounting, regulatory, authority-request, mandatory retention, claim-management, security and privacy obligations.
  • Legitimate interests: prevent fraud, abuse or unauthorized access; measure performance; maintain operational continuity; improve security; analyze aggregate usage; conduct internal audits; and protect rights, assets and infrastructure, while balancing data-subject rights and freedoms.
  • Establishment, exercise or defense of rights: prepare, file, respond to or manage actions, claims, investigations, audits, administrative, judicial, contractual or equivalent proceedings.
  • Consent: send commercial communications where applicable, process sensitive data or special categories where authorized, enable optional processing, use certain non-necessary cookies or similar technologies, and perform other voluntary processing not covered by another basis.
  • Public sources or authorized third parties: enrich commercial context, validate information, analyze open sources or execute customer-approved use cases, always within the stated purposes and applicable rules.
  • Aggregated, anonymized, statistical or scientific data: improve services, security, performance, internal benchmarks and operational learning without identifying a natural person.
  • Until Law 21.719 is fully enforceable, processing that the new law recognizes under expanded lawful bases will rely on the available bases under current Law 19.628, consent, contract, legal obligations or other applicable authorizations. From December 1, 2026, we will apply the Law 21.719 regime where applicable.
  • When Law 21.719 becomes fully enforceable, we will apply its lawful bases, accountability, transparency, purpose limitation, proportionality, security, confidentiality and quality principles, together with the duties corresponding to our role as controller or processor.

8. Customer-controlled and third-party data

When a customer uses AgentLayer to process its own data or third-party data, the customer is responsible for defining the purpose, informing data subjects, obtaining consents or identifying another lawful basis, managing data-subject rights and ensuring that data sent to AgentLayer may be lawfully processed.

AgentLayer processes that data under documented instructions, reasonable security measures, confidentiality commitments, access controls and processing agreements or addenda where applicable.

If a customer provides, connects or authorizes access to personal data about its users, workers, customers, vendors, prospects, applicants or other third parties, the customer represents that it has the authority, notices, lawful bases, permissions and contracts needed to do so, and can respond to claims or requests from those data subjects.

If the customer includes data about minors, sensitive data, health data, biometric data, sensitive financial information or special categories, the customer must have express contractual authorization, a sufficient lawful basis and enhanced safeguards agreed with AgentLayer.

If we receive a request from a data subject regarding customer-controlled data, we may redirect it to the customer or assist the customer according to the applicable contract.

9. Automated processing and AI agents

AgentLayer agents may read, classify, summarize, extract, compare, suggest responses, prioritize, generate alerts and produce drafts or recommendations. These outputs depend on the data, instructions, configurations, integrations and rules defined for each use case.

Applied logic: in general terms, agents process documents, messages, records or connected sources to identify patterns, extract fields, compare rules, infer categories, estimate relevance, generate responses or propose actions. The specific logic depends on the use case, available data, prompts, rules, tools, models, thresholds and approvals configured with the customer.

Unless expressly agreed otherwise, we do not use customer confidential data or customer-uploaded environment data to train public models or general-purpose third-party models. We may use aggregated, anonymized data or technical telemetry for security, performance and service improvement.

AgentLayer is not designed to make solely automated individual decisions that produce legal effects or significantly affect a person without human involvement, unless there is a specific contractual configuration, an appropriate lawful basis and customer-approved review controls.

For decisions with legal, employment, financial, material commercial or equivalent effects, the customer must configure human review, thresholds, audit trails and approval controls before final actions are executed.

10. Disclosure, subprocessors and transfers

We do not sell personal data. We may share data with providers, subprocessors, customer-authorized integrations, affiliates, advisers, authorities or specific third parties, always for compatible purposes and under appropriate contractual or technical measures.

  • Subprocessors and service providers: cloud infrastructure, hosting, storage, security, observability, backup, content delivery, model providers, APIs, OCR, email, CRM, analytics, support, billing, payments, electronic signature and productivity tools.
  • Customer-authorized integrations: CRMs, ERPs, help desks, email, messaging, storage, document repositories, internal channels or systems connected by the customer to operate an agent.
  • Advisers and corporate operations: lawyers, auditors, accountants, banks, payment processors, insurers, financial advisers, affiliates, successors or acquirers in reorganizations, mergers, financings, asset sales or corporate transactions.
  • Authorities and defense of rights: public authorities, courts, regulators, supervisory bodies or third parties where there is a legal obligation, valid request, need to prevent abuse, protect security or defend rights.
  • Independent controllers: in some cases a third party may receive data as its own controller, for example if the customer instructs an integration, an authority requires it or a corporate transaction requires it. In those cases the third party must process the data under its own lawful basis and applicable duties.

11. International transfers

AgentLayer works with technology providers that may be located or process data outside Chile. When we transfer data internationally, we seek to use contractual, technical and organizational safeguards consistent with applicable law.

If a recipient is located in a country that does not have an adequate level of data protection, we seek to apply appropriate safeguards, such as contractual clauses, confidentiality obligations, access controls, minimization, encryption, vendor review and use restrictions, depending on the type of data and service.

Under Law 21.719, international transfers will need to consider adequate countries, appropriate safeguards, contractual clauses, binding corporate rules, express consent or other authorized grounds, as applicable and in line with instructions from the Personal Data Protection Agency when available.

12. Retention

We retain personal data for as long as necessary to fulfill the stated purposes, provide services, maintain security records, comply with legal obligations, resolve disputes and exercise rights.

Retention periods may vary by data type and applicable contract. In general, we may retain data while a commercial, contractual or support relationship exists; for the period needed to support operations, audits, security, billing, taxes, regulatory compliance or incident response; during limitation periods or defense against claims; or for an additional period authorized by the data subject or customer.

Once applicable periods are met, we seek to securely delete, return, anonymize or aggregate data so it no longer identifies a person, unless a legal or contractual obligation or valid authority instruction requires retention.

13. Security and confidentiality

We apply reasonable and risk-based measures, considering the state of the art, implementation costs, nature, scope, context, processing purposes and likelihood and impact of risks to data subjects.

These measures may include access control, least privilege, environment segregation, audit logs, encryption in transit and, where appropriate, at rest, credential management, vendor review, minimization, backups, monitoring, internal training, testing, periodic control review and incident investigation.

When we disclose or provide access to data to providers or subprocessors, we seek to limit disclosure to what is strictly necessary for the corresponding purpose and require confidentiality, security and compatible-use standards consistent with our instructions or the applicable contract.

No system is completely immune to incidents. If a breach affecting personal data occurs, we will assess its scope and notify customers, data subjects or authorities when required by law or contract.

14. Data-subject rights

You may request access, rectification, update, deletion or cancellation, objection, blocking and withdrawal of consent where applicable. Once Law 21.719 enters into force, we will also consider additional applicable rights, including portability and strengthened rules for automated decisions.

The right of access may include information about whether we process your data, the origin of the data, purposes, categories processed, recipients or categories of recipients, retention period, lawful bases, applicable legitimate interests and, where relevant, meaningful information about logic used in automated processing.

The right to object may apply to processing based on legitimate interests, marketing or other legally recognized cases. Blocking may request temporary suspension of processing while a rectification, deletion or objection request is resolved. Portability may apply when permitted by law and where data exists in a structured, generic and commonly used format.

To exercise rights, contact us through the channels listed in this policy and provide the information needed to verify your identity and locate the data. If the data belongs to a customer acting as controller, we may forward your request to that customer.

You may also file a claim with the competent authority. Once operational, the Personal Data Protection Agency will have supervisory, interpretive and claim-resolution powers under Law 21.719.

15. Cookies and similar technologies

We may use cookies, local storage, pixels or similar technologies to operate the site, remember preferences, measure performance, understand interactions and improve communications. Some are necessary for the site to work; others may depend on consent settings or browser controls.

You can limit or block cookies from your browser. If you disable necessary technologies, some site functions may not operate correctly.

We use Google Analytics (Google LLC) and PostHog (PostHog Inc.) to measure site usage and understand the journey to the contact form, using cookies or local storage with a pseudonymous identifier. We do not use them to identify you by name or for personalised advertising. You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout or limit both tools by blocking cookies in your browser.

16. Changes to this policy

We may update this policy to reflect legal, technical, commercial or service changes. We will publish the current version on this page and indicate its update date. If a material change requires additional notice or consent, we will manage it according to law or the applicable contract.