Our Commitment to GDPR
Summary
Pocodot is committed to full GDPR compliance and treats data protection as a core product principle, not an afterthought.
Pocodot ("we", "us", "our") is committed to protecting the personal data of all individuals who interact with our AI agent marketplace. We comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national implementations across the European Economic Area.
This page explains how we meet our obligations under GDPR, what rights you have, and how to exercise them. It supplements our Privacy Policy, which provides a broader overview of our data practices.
Controller Information
Summary
Pocodot acts as the data controller for personal data processed through our platform.
Data Controller: Pocodot Labs, Inc.
Contact Email: privacy@pocodot.ai
Data Protection Officer: dpo@pocodot.ai
When you deploy an AI agent through our marketplace, you may also act as a data controller for any personal data that agent processes. In such cases, Pocodot acts as a data processor on your behalf under a Data Processing Agreement.
Lawful Bases for Processing
Summary
We rely on contract performance, legitimate interests, legal obligations, and consent depending on the processing activity.
We process personal data under the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation & authentication | Contract performance |
| Billing & payment processing | Contract performance |
| Agent execution & AI processing | Contract performance |
| Platform security & fraud prevention | Legitimate interest |
| Product analytics (anonymous) | Legitimate interest |
| Marketing communications | Consent |
| Legal & regulatory compliance | Legal obligation |
| Cookie preferences (non-essential) | Consent |
Your Rights Under GDPR
Summary
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data.
Under GDPR, you have comprehensive rights over your personal data. Select your region below to see the specific rights that apply to you:
Under the General Data Protection Regulation (GDPR), EU residents have the following rights:
- Access:Request a copy of the personal data we hold about you.
- Rectification:Ask us to correct inaccurate or incomplete data.
- Erasure:Request deletion of your personal data ('right to be forgotten').
- Restriction:Ask us to limit how we process your data in certain circumstances.
- Portability:Receive your data in a structured, machine-readable format.
- Object:Object to processing based on legitimate interest or direct marketing.
- Automated decisions:Not be subject to decisions based solely on automated processing, including profiling.
- Withdraw consent:Withdraw consent at any time where processing is based on consent.
Data Subject Access Requests
Summary
Submit a DSAR using the form below. We respond within 30 days, free of charge.
You can exercise any of your GDPR rights by submitting a Data Subject Access Request (DSAR). We will verify your identity and respond within 30 calendar days. Extensions of up to 60 additional days may apply for complex requests - we will notify you within the initial 30-day period.
DSARs are processed free of charge. We may charge a reasonable fee for manifestly unfounded or excessive requests, as permitted by Article 12(5) GDPR.
AI & GDPR Compliance
Summary
AI agents process data per your instructions. No automated decision-making with legal effects occurs without human oversight.
AI agents deployed through Pocodot process data based on the instructions you configure. We implement the following safeguards:
- Purpose limitation: Agents only process data for the specific tasks you define.
- Data minimization: Agents receive only the data fields required for execution.
- No profiling: We do not use AI agents to profile individuals or make automated decisions with legal effects.
- Human oversight: All agent outputs are presented for human review before any consequential actions are taken.
- Audit trail: Every agent run is logged with timestamps, inputs (hashed), and outputs for accountability.
Under Article 22 GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Pocodot agents do not make such decisions.
Data Processing Agreement
Summary
Enterprise customers can execute a DPA that covers all GDPR-required processor obligations.
When Pocodot acts as a data processor on your behalf (e.g., when your deployed agents handle customer data), we offer a Data Processing Agreement (DPA) that includes:
- Standard Contractual Clauses (SCCs) for international transfers
- Technical and organizational security measures (Article 32)
- Sub-processor management and notification obligations
- Data breach notification within 72 hours
- Assistance with DSARs and Data Protection Impact Assessments
To request a DPA, contact us at legal@pocodot.ai.
Our Subprocessors
Summary
We use a limited set of vetted subprocessors. You'll be notified 30 days before any new subprocessor is added.
We share personal data with the following subprocessors to deliver our services:
| Subprocessor | Purpose | Location |
|---|---|---|
| Anthropic | AI model inference (assistant replies) | US (SCCs) |
| OpenAI | Backup AI provider (vision, audio) | US (SCCs) |
| Google Gemini | Meeting and video understanding | US (SCCs) |
| Composio | Third-party integration connections | US (SCCs) |
| DigitalOcean | Server and database hosting | Singapore (SCCs) |
| Stripe | Payment processing | US / Ireland (SCCs) |
| Resend | Transactional email | US (SCCs) |
| Vapi, Inc. | Phone calls with Cole: call handling, speech recognition and the voice assistant during a call | US (SCCs) |
| Twilio, Inc. | Telephone numbers and call carriage for Cole's phone numbers | US (SCCs) |
| ElevenLabs, Inc. | Cole's spoken voice on calls and in voice notes | US (SCCs) |
| Deepgram, Inc. | Transcribing voice notes and audio you send to Cole | US (SCCs) |
| Google LLC (Maps Platform) | Turning a location pin you share into an address, and finding places near you | US (SCCs) |
| 1Password (AgileBits Inc.) | Reading logins from a 1Password vault you chose to share, using a token you provide | Canada (adequacy decision) |
We will notify you at least 30 days in advance of adding any new subprocessor, giving you the opportunity to object.
International Data Transfers
Summary
Data may be transferred to the US under Standard Contractual Clauses and supplementary security measures.
Some of our subprocessors are located in the United States. For transfers outside the EEA, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms with each subprocessor.
- Supplementary measures: Encryption in transit (TLS 1.3) and at rest (AES-256), access controls, and audit logging.
- Transfer Impact Assessments: We evaluate the data protection laws of each recipient country.
You may request a copy of the applicable SCCs by contacting privacy@pocodot.ai.
Data Breach Notification
Summary
We notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
In the event of a personal data breach, Pocodot will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33).
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34).
- Document the breach, its effects, and the remedial actions taken in our internal breach register.
- If acting as a processor, notify the controller without undue delay.
Data Protection Officer
Summary
Contact our DPO at dpo@pocodot.ai for any GDPR-related inquiries or complaints.
Our Data Protection Officer can be reached at:
Email: dpo@pocodot.ai
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU/EEA data protection authorities is available at edpb.europa.eu.
Related Policies
Questions about this policy? Email us at privacy@pocodot.ai