Data processing
How Agentik processes customer data, where it flows, and how to arrange processing terms.
Last updated 19 September 2026.
1. Account data and customer instructions
Agentik administers accounts, protects the service and keeps payment records for its own service purposes. When your organisation submits personal data through a tool for its own purposes, your organisation determines the instructions and lawful basis. The selected provider’s role and terms must also be checked.
The information on this page describes the service. It is not an executed Data Processing Agreement (DPA). Contact the publisher to arrange the agreement appropriate to your organisation before using Agentik for processing that requires one.
2. How data moves
Your browser connects to the website on Vercel and authenticates with Clerk. API and MCP requests pass through Cloudflare Workers. Workspace, membership, execution, security and ledger records are stored in a Neon PostgreSQL database, accessed through Cloudflare Hyperdrive in production. Hyperdrive is the database connection layer, not a separate customer database.
A tool call sends the required inputs to the selected provider and returns its output. Some tools use additional downstream services described by their provider. Raw tool payloads are processed in transit; the Agentik ledger retains execution metadata and billing evidence. The user or agent receiving the result may store it independently.
Checkout takes place at Stripe. Optional support uses Vercel’s Eve workflow infrastructure and AI Gateway to send your conversation and permitted account context to the configured model provider. Transactional email delivery uses Resend when configured, including selected authentication messages, invitations, welcome messages, payment confirmations and alerts.
3. Scope to agree before processing
A customer DPA needs to identify the parties, the service and processing duration, purposes, instructions, personal-data categories and data subjects. It must address confidentiality, security, further processors, international transfers, assistance with rights and breaches, audits, and return or deletion of data at the end of the service.
The provider register describes technical recipients. It does not grant a provider blanket access to every workspace and does not substitute for contractual authorisation of further processors. Request the applicable locations, transfer safeguards, retention and provider-change process for your use case.
4. Minimise what you send
Only submit data needed for the selected tool. Do not put credentials or payment details in tool prompts or support messages. Do not assume that a public enrichment result is consent to outreach or that every tool supports sensitive or regulated data. Check the applicable purpose, provider terms and contractual safeguards before use.