AgentMesh
/ Legal · Privacy

Privacy Policy

Effective: 2026-05-15 · GDPR (EU 2016/679) compliant

/ 1

Who we are

yeison riascos (AgentMesh) is the data controller of personal data processed via agentmesh.eu and related services.

/ 2

What data we collect

We only process the minimum data needed to operate the service:

Waitlist signupemail addressconsent (Art. 6(1)(a))
Agent submissionname, email, agent name, website, descriptionperformance of contract / pre-contract (Art. 6(1)(b))
Featured listing checkoutbilling data handled by Lemon Squeezy as merchant of record (we receive only order metadata)performance of contract (Art. 6(1)(b))
Report pre-orderemail + Lemon Squeezy order metadataperformance of contract (Art. 6(1)(b))
Server logsIP address, user-agent, timestamplegitimate interest (Art. 6(1)(f)) — security

We do not use third-party advertising trackers, behavioural analytics, or fingerprinting. We do not buy or sell personal data.

/ 3

Cookies & local storage

AgentMesh uses strictly necessary storage only:

  • · am_cookie_ack — remembers that you closed the cookie banner.
  • · Lemon Squeezy may set its own cookies on the checkout domain when you click “Pay”. See Lemon Squeezy’s policy.

No analytics, no Google Tag Manager, no Meta Pixel, no Hotjar. If we add analytics in the future, it will be a privacy-respecting tool (e.g. Plausible / Umami, no personal data collected) and this page will be updated before activation.

/ 4

Why we process it (legal bases)

  • · Consent — waitlist subscription. Withdraw anytime by replying “unsubscribe”.
  • · Contract — paid services (featured listings, report pre-orders). Required to deliver what you bought.
  • · Legal obligation — invoicing, accounting, tax records (typically 10 years under EU/IT law).
  • · Legitimate interest — security logs, fraud prevention, basic service operation.
/ 5

Who we share data with (processors)

We use the following sub-processors. All are bound by data-processing agreements:

ProcessorPurposeLocation
Lemon Squeezy LLC (merchant of record)Payment processing, EU VAT collection, invoicing — independent controller for billing dataUnited States (DPF)
Resend (Resend.com Inc.)Transactional email deliveryUnited States (DPF)
Vercel Inc.Hosting & edge runtimeEU regions (fra1) + US (DPF)
Vercel KV / UpstashEmail & submission storage (when enabled)EU regions

Transfers to processors located outside the EEA rely on the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) where applicable.

/ 6

Retention

  • · Waitlist email: until you unsubscribe.
  • · Submission data: 24 months after last update, then archived or deleted.
  • · Invoicing & accounting records: 10 years (legal obligation).
  • · Server logs: maximum 30 days.
/ 7

Your rights (GDPR Art. 15–22)

You have the right to:

  • · access your data
  • · rectify inaccurate data
  • · erase your data (“right to be forgotten”)
  • · restrict processing
  • · data portability
  • · object to processing
  • · withdraw consent at any time
  • · lodge a complaint with your supervisory authority (in Italy: Garante per la protezione dei dati personali)

Email privacy@agentmesh.eu from the address tied to your account. We respond within 30 days.

/ 8

Security

We host on Vercel’s SOC 2 / ISO 27001 infrastructure, force HTTPS, verify webhook signatures (HMAC-SHA256), sanitise all email content, and rate-limit all public forms. We never store card data — Lemon Squeezy handles all payment information directly as merchant of record.

/ 9

Children

AgentMesh is a B2B service not directed at children. We do not knowingly process data of users under 16.

/ 10

Changes

We may update this policy. Material changes will be notified via email to active users at least 14 days before they take effect.

Last updated: 2026-05-15