AgentPrepare Legal
Privacy Policy
Operated by AgentPrime Ltd
Last updated: To be completed: publication date to be set when this policy is signed off
This document contains items marked for completion.
Who we are
AgentPrepare is an AI readiness audit service: you give us a website address and we produce a report on how well that website works for AI agents.
Data controller: AgentPrime Ltd, a company registered in England and Wales (company number 17073425). Company registration details, our registered office, and our ICO registration are on our Legal page.
ICO registration: ZC114543.
Data protection contact: contact@agentprime.co.uk.
We are not required to appoint a Data Protection Officer, but the contact above handles all data protection enquiries.
This policy covers you if you visit our website, run a free audit, hold an account, or receive our emails. If your personal data appears on a website that someone else asked us to audit, a separate notice applies: see our Website Data Notice.
Summary
- We collect your email address and the website address you submit when you run a free audit.
- We log a one-way hashed fingerprint of your IP address to limit how many free audits can be run from one connection. We never store your actual IP address.
- We only send you marketing if you tick the consent box. It is unticked by default.
- We use no advertising or analytics cookies. The only cookies we set are the ones that keep you signed in to an account.
- We never sell your data.
The free audit (no account needed)
When you run a free audit we collect:
| Data | Why | Legal basis |
|---|---|---|
| The website address you submit | To run the audit you asked for | Legitimate interests (delivering the audit you requested) |
| Your email address | To send you the audit result, and to let you retrieve it later (your email plus the audit reference together act as the key to your result) | Legitimate interests (delivering the audit you requested) |
| A salted, one-way hash (SHA-256) of your IP address | Rate limiting and abuse prevention: free audits are limited to 30 per IP address per rolling 30 days | Legitimate interests (preventing abuse of a free service) |
| A consent record (your email, the consent wording version, a timestamp, and the same hashed IP), only if you tick the marketing consent box | To prove what you consented to and when, as UK GDPR requires | Legal obligation / legitimate interests (demonstrating consent under Article 7(1)) |
Three things worth being clear about, because most services are not:
- We never store your actual IP address. It is converted to a salted SHA-256 hash before anything is written to our database, and the plain address is discarded. The hash lets us count audits from the same connection without keeping the address itself.
- The rate-limit record is written whether or not you tick the consent box. Declining marketing consent does not exempt a connection from the abuse limit.
- Ticking the consent box is genuinely optional. The audit runs identically without it. Consent only governs whether we may email you beyond the audit result itself.
Emails we send
Service emails. When your audit finishes (or fails), we email the result to the address you gave us. These are part of delivering the audit, not marketing, and are sent whether or not you ticked the consent box. We record the time the email was sent.
Marketing emails. Sent only if you ticked the consent box. You can withdraw consent at any time using the unsubscribe link in any marketing email or by contacting us; withdrawal stops future marketing but does not affect the record that consent was given at the time.
Our emails are dispatched through Resend (see “Who we share your data with”).
Accounts
If you create an account we additionally process: your email address, an optional display name, your organisation’s name and contact email, and your sign-in credentials (held by our authentication provider, Supabase; we never see your password). Legal basis: performance of a contract (providing the service you signed up for).
Signing in sets session cookies. These are strictly necessary for the service to work and are the only cookies we set (see “Cookies”).
Payments
If you buy a subscription or credits, payment is handled by Stripe. We never see or store your card details. We hold your subscription tier, billing status, and Stripe reference identifiers so we know what you have paid for. Legal basis: performance of a contract. Billing records are kept for 6 years to meet UK tax and accounting obligations (legal obligation).
The websites we audit
The audits themselves examine websites, and websites sometimes contain personal data (staff names on a team page, a contact email address). If your data appears on a site someone else submitted for an audit, you are covered by our separate Website Data Notice (our Article 14 UK GDPR notice). In short: we do not target, extract, or report personal data from audited sites; anything encountered is incidental to analysing site structure, and our reports contain scores and technical findings, not personal data.
AI processing
Part of each report (the narrative summary) is generated using a large language model provided by Anthropic. What we send is structured technical output about the audited website, not your account details. Anthropic acts as our processor and does not use data submitted through our API to train its models.
We do not make automated decisions about you that have legal or similarly significant effects. The audit scores websites, not people.
International transfers
Some of these processors process data outside the UK, principally in the United States. Where they do, transfers are protected by one of the safeguards UK GDPR recognises: the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the processor is certified. To be completed: the specific transfer mechanism for each processor is being confirmed and will be listed here
How long we keep your data
| Data | Retention |
|---|---|
| Email address from a free audit | We retain the email address associated with a free audit until you ask us to delete it. |
| Consent records | 6 years, to meet our legal obligation to demonstrate consent. If you ask us to erase your data, the email address in the consent record is replaced with a tombstone value; the record of the consent event survives without identifying you. |
| Hashed IP rate-limit records | To be completed: retention period under review; it will be stated here once confirmed |
| Raw audited-site content captured during an audit | Nullified after 12 months (365 days) |
| Audit scores and reports | To be completed: retention period will be stated here once our automated deletion process is live |
| Downloadable report links | Links expire 30 days after issue |
| Account data | For the life of your account, then deleted on request or account closure |
| Billing records | 6 years (UK tax law) |
| Scan failure diagnostics linked to a user | Anonymised after 90 days |
| AI invocation logs | Purged after 12 months |
| Hosting logs (IP addresses and request metadata held transiently by our hosting provider) | To be completed: hosting provider log retention period to be confirmed |
Your rights
Under UK GDPR you have the right to: access a copy of your personal data; have inaccurate data corrected; have your data erased; restrict processing; object to processing based on legitimate interests (including the hashed-IP rate limiting, though we may demonstrate compelling grounds for abuse prevention); and withdraw consent at any time where processing is based on consent (marketing). Data portability applies to data you provided to us under consent or contract.
To exercise any right, contact contact@agentprime.co.uk. We respond within one month and there is no charge.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office: ico.org.uk, 0303 123 1113.
What erasure covers. If you ask us to erase your data we delete your account identity, your lead record, and the email address attached to your audits, and we anonymise failure diagnostics. Consent records are tombstoned rather than deleted (6-year legal retention, with your email removed). The audit results themselves (scores and technical findings about the audited website) are retained as business records: they contain no personal data about you once the email link is removed.
Changes to this policy
We may update this policy as the service changes. The date at the top shows the current version. Material changes will be flagged on the site. To be completed: whether material changes are also emailed to account holders is being confirmed and will be stated here
AgentPrepare legal
Website Data Notice
Our Article 14 UK GDPR notice for people whose data appears on an audited site.
AgentPrepare legal
Terms of Service
The terms that govern access to and use of AgentPrepare.
AgentPrepare legal
Legal Information
Company registration, registered office, and ICO registration details.
AgentPrime Ltd, company number 17073425. Registered office and ICO registration details are on our Legal page.