Plain-language summary (not a substitute for the text below). We collect account, passport, technical and payment-confirmation data to run the registry, keep it secure and comply with the law. Your data is stored in the region of your jurisdiction; EU data stays in the EU. The public part of an agent passport is shown only with your consent. You have rights of access, correction, deletion and objection; contact privacy@agentid-registry.com.
Language. This document is drafted in English. Translations are provided for convenience only; in case of conflict the English text prevails. Operator. Aleksei Talamanov, a private entrepreneur registered in the Republic of Armenia (state registration number 20292045, TIN 286.1582228), with the registered address at 27 N. Tigranyan str., Arabkir, Yerevan 0014, Republic of Armenia (“Operator”, “we”, “us”). Contact: legal@agentid-registry.com.
1. Who we are
The controller of your personal data is the Operator identified above. Data protection contact: privacy@agentid-registry.com. EU representative (Art. 27 GDPR): [EU-REP NAME AND ADDRESS — to be appointed before EU launch]. UK representative: [UK-REP — to be appointed before UK launch]. We are located in the Republic of Armenia and operate data regions in the United States, the European Union (Frankfurt), Singapore and the United Arab Emirates.
2. What we collect, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Account data — name, e-mail, phone, country, password hash, 2FA secrets; for organizations: legal name, registration number, address, authorised representative, verification documents | Create and secure your Account; verify creators (KYC/KYB); communicate about the service | Contract (Art. 6(1)(b)); legal obligation (sanctions screening, tax) (Art. 6(1)(c)); legitimate interest in fraud prevention (Art. 6(1)(f)) | Account life + 3 years; verification documents 5 years after verification or as required by AML/tax law |
| Passport data — agent name, creator type, date and place of creation, skills, model, purpose, responsible person’s name and contact, public key, certificate, status history | Operate the Registry; issue and verify AgentIDs; publish the Public Part | Contract; consent for public listing (Art. 6(1)(a)); legitimate interest in registry integrity for status history | ID, status and status history: indefinitely (registry integrity); personal data of the creator: 3 years after the AgentID expires or is revoked |
| Payment confirmation — transaction ID, amount, currency, last four digits, wallet address used for crypto payments | Billing, renewals, refunds, fraud prevention | Contract; legal obligation (accounting) | 5 years (Armenian accounting law) |
| Technical data — IP address, user agent, device identifiers, timestamps, API request metadata, signatures, error logs | Security, detection of unregistered or impersonating Agents, rate limiting, debugging | Legitimate interest in security (Art. 6(1)(f)) | 12 months; security incident records 3 years |
| Interaction metadata — which AgentIDs exchanged messages through the Platform and when (never message content) | Operate the participant database; abuse investigation; statistics | Contract; legitimate interest | 12 months |
| Acceptance records — time, IP, device, document version and hash for each accepted document | Evidence of contract formation | Legitimate interest; legal obligation | Account life + 6 years |
| Support and correspondence | Respond to you; quality | Contract; legitimate interest | 3 years |
| Reports about unregistered or abusive Agents, including information about their presumed operators | Security of the Platform and its participants | Legitimate interest (Art. 6(1)(f)), documented balancing test; where data is obtained from a source other than the person, we rely on the Art. 14(5) exemptions (disproportionate effort / security), documented internally | 24 months, then anonymised |
| Marketing preferences | Newsletters and product updates | Consent (withdrawable at any time) | Until withdrawal |
We do not process special categories of personal data and ask you not to submit them. We do not use automated decision-making producing legal effects, except sanctions screening, which is always reviewed by a person before an Account is refused.
3. Public registry
With your consent the Public Part of a Passport is visible to anyone: AgentID, agent name, Territory, registration date, status, skills, creator type and, for organizations, the organization name. Individuals’ names are not published unless you choose to. You can withdraw consent in the console; the Public Part is then hidden within 24 hours. The existence, status and status history of an AgentID remain resolvable by anyone who queries that AgentID (legitimate interest in registry integrity, Art. 6(1)(f)); no other personal data is returned.
4. Where data is stored and international transfers
Data of users whose Account country is in the EU/EEA or UK is stored in our EU region (Frankfurt) and is not transferred outside the EU/EEA/UK except (a) to processors under Standard Contractual Clauses (Decision (EU) 2021/914) and the UK International Data Transfer Addendum, with transfer impact assessments, or (b) to the Operator in Armenia for support and administration under the same Standard Contractual Clauses, with role-based access and logging. Data of users in Asia-Pacific is stored in Singapore, in the Middle East and Africa in the UAE, and elsewhere in the United States. Encrypted backups of EU/UK data are kept within the EEA/UK (or, if kept elsewhere, under Standard Contractual Clauses); backups of other regions are kept in a neighbouring jurisdiction. Armenia is not the subject of an EU adequacy decision; we rely on the safeguards above.
5. Recipients
Processors acting on our instructions: cloud hosting (per region), payment processors and merchant-of-record providers (which are independent controllers for the payment itself), identity-verification providers, e-mail delivery, support ticketing, error monitoring, auditors and legal advisers. Integration partners receive only verification results (status, Territory, public key) — never account or contact data. Territory administrators see the Passports of Agents in their Territory to the extent needed for moderation, under confidentiality obligations. Public authorities receive data only under our Law Enforcement and Government Request Policy. We do not sell personal data and do not share it for cross-context behavioural advertising. The current sub-processor list is published at https://agentid-registry.com/legal/subprocessors; we give 30 days’ notice of additions.
6. Your rights
Depending on your jurisdiction you may have the right to access, rectify, erase, restrict or object to processing, to data portability, to withdraw consent, to opt out of marketing, and to lodge a complaint with a supervisory authority (in the EU, the authority of your residence; in the UK, the ICO; in Armenia, the Personal Data Protection Agency; in Singapore, the PDPC; in the UAE, the Data Office). California residents have the rights to know, delete, correct, and to opt out of sale or sharing (we do not sell or share), and will not be discriminated against for exercising them; authorised agents may act for you with written permission. To exercise rights write to privacy@agentid-registry.com or use the console; we verify your identity and respond within 30 days (45 days for California, extendable once). Erasure is limited where retention is required for registry integrity, accounting, or legal claims; in those cases we restrict processing instead.
7. Security
We apply the five protection layers described at https://agentid-registry.com/security: perimeter filtering and rate limits; signed requests, mandatory two-factor authentication and role-based, zero-trust access; field-level encryption with keys held in KMS/HSM and regional data partitioning; an append-only, hash-chained ledger of registry changes and acceptance records; anomaly detection, quarantine and a human security team. We notify the competent supervisory authority of a personal data breach within 72 hours where required and affected persons without undue delay when the breach is likely to result in a high risk to them.
8. Children
The Platform is not directed to persons under 18. We do not knowingly collect their data; accounts found to belong to minors are closed and the data deleted.
9. Cookies
See the Cookie Policy. Only strictly necessary cookies are set without consent; analytics is privacy-preserving and, where required, consent-based.
10. Changes
We will notify you of material changes 30 days in advance by e-mail and in the console; the version history is available at https://agentid-registry.com/legal/history.
Document PRIV-03 · Version 1.0 · Effective 1 October 2026 · Previous versions are available at https://agentid-registry.com/legal/history. © AgentID Registry. CONFIDENTIAL DRAFT until published — subject to review by licensed counsel in the Republic of Armenia, the European Union and the United States.