AAgent Self-Audit

Privacy Policy

The Agent Self-Audit Report is an AI-generated self-audit summary report based only on the log you provide. It is not legal advice, not a certification and not a guarantee of compliance with the EU AI Act or any other law.

Who we are

The Agent Self-Audit Report is a service operated by UNIHOLIX OÜ, a private limited company registered in Estonia (registry code 17479878), Sepapaja tn 6, 11415 Tallinn, Estonia. We are the controller of the personal data described in this policy. Contact: ceo@uniholix.com.

What we process and why

In short: your file is read in your browser and is never uploaded. After payment, only a short, masked summary of it is sent to us to write your report, and we do not keep that summary or the report.

  • Your file. You load a log of your own AI agent, or a file that shows its activity, such as a JSON, CSV, spreadsheet or text file, a chat export, a PDF, Word or PowerPoint file, a saved web page, a photo or a screenshot. Your browser reads it, recognises text in images, builds the free preview and masks secrets and personal data. The file never leaves your device.
  • The summary. After payment, your browser sends a short, masked summary of the log, such as tool names, counts, times, the domain names of services the agent contacted and brief excerpts, to our server. Our server passes it to our AI model provider to write your report. We do not keep the summary or the report after your report has been produced. Only a one-way fingerprint of the summary travels with your payment, so that we can deliver what you paid for. The fingerprint cannot be turned back into the summary.
  • Text recognition files. If you load a photo or a screenshot, your browser downloads the text recognition engine and its language files from a public content delivery network. That network receives your IP address, as with any web request, but never your file.
  • Payment data. Our payment processor handles your payment. We receive your email address, your country, the amount, the currency and the payment status, together with your confirmation that you asked for immediate delivery. Your card details go only to the payment processor and never reach us.
  • Emails to us. If you write to us, we use your email address and your message to answer you.
  • Technical data. Our server uses your IP address for a short time to limit the number of requests and to keep the service secure. Our hosting provider keeps standard request logs, such as the IP address, the time and the page requested. These logs do not contain your file or your summary.
  • Data on your device. The page keeps the masked summary, your report and your language in your browser's local storage, so that they are still there when you come back from the payment page. This data stays on your device. You can delete it at any time in your browser settings.
  • No tracking. We do not use analytics or advertising cookies, and we do not use any analytics or advertising trackers.

Remove personal data first. Agent logs can contain personal data and secrets. Remove them before you load a log. The page masks common kinds, such as email addresses, phone numbers, keys and card-like numbers, but masking is a safety net, not a guarantee. Before you pay, the page shows you exactly what would be sent.

If the summary still contains personal data about other people, such as your customers or staff, you decide why and how it is processed. We then process it only on your behalf and on your instructions, to produce your report, as a processor under GDPR Art. 28. Business customers who need a data processing agreement can write to ceo@uniholix.com.

Your report is produced by AI for your own information. It can be wrong, and it is not professional advice. We do not use it to make any decision about you.

We do not sell your personal data, we do not use it for advertising, and we do not use your summary or your report to train AI models.

The service is for people aged 13 or older (or the higher minimum age in their country), people under 18 may use it only with the permission of a parent or guardian, and we do not knowingly process personal data of younger children.

Legal bases

  • Contract (GDPR Art. 6(1)(b)): producing your report, taking your payment and answering your questions about a purchase.
  • Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing fraud and abuse, and answering other messages.
  • Legal obligations (Art. 6(1)(c)): keeping accounting records, including payment records, as Estonian law requires.

Who processes it for us

We use service providers that process personal data on our behalf and on our instructions. We describe them here by category.

  • Payment processor: takes payments and emails your receipt. It also processes payment data as an independent controller for its own legal duties, such as fraud prevention, under its own privacy policy.
  • AI model providers: produce your report from the masked summary. We use only commercial services that do not use your data to train their models. They may keep inputs and results for a limited time to detect misuse, under their own terms.
  • Hosting provider: runs the website and keeps request logs.
  • Email provider: receives and stores the emails you send us.
  • Content delivery network: delivers the text recognition files to your browser when you load a photo or a screenshot. It receives your IP address but none of your content.

Some of these providers process data outside the European Economic Area, for example in the United States. Where they do, the transfer relies on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses.

How we protect it

All connections to the service and to our providers are encrypted. Access to our systems is limited to the people who need it and is protected by two-step sign-in. Card details are handled only by our payment processor.

How long we keep it

  • Your file: never received by us.
  • The summary and the report: not kept. They are used only while your report is being produced.
  • Payment records, including the fingerprint of the summary and your confirmation of immediate delivery: 7 years, as the Estonian Accounting Act requires.
  • Emails to us: as long as we need them to deal with your request, and no longer than 2 years after it is closed, unless they are part of accounting records.
  • Request and security logs: up to 2 years. Data used to limit requests is held in memory only, for a few minutes.

Your rights

You can ask us to give you access to your personal data, to correct it or delete it, to restrict its processing or to stop processing it, and to give you a copy in a portable format.

To use these rights, email ceo@uniholix.com. We answer within one month. If a request is complex, we may need up to two more months, and we will tell you so within the first month. Because we do not keep your summary or your report, we usually hold no personal data about you other than payment records and emails you sent us.

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI, www.aki.ee) or to the data protection authority in the country where you live or work.

Additional notices for some regions

California. If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the right to know what personal information we collect, use and disclose, the right to have it deleted, the right to have it corrected, and the right not to be discriminated against for using these rights. We do not sell or share your personal information, as those terms are defined in that law. To use your rights, email ceo@uniholix.com.

United Kingdom. If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 give you the rights described above. You can also complain to the Information Commissioner's Office (ICO).

Brazil. If you are in Brazil, the General Personal Data Protection Law (LGPD) gives you rights that include confirmation that we process your data, access, correction, anonymisation, blocking or deletion, portability, and information about who we share it with. To use these rights, email ceo@uniholix.com. You can also complain to the National Data Protection Authority (ANPD).

Republic of Korea. If you are in the Republic of Korea, the Personal Information Protection Act (PIPA) gives you the right to access your personal information and to ask us to correct it, delete it or stop processing it. To use these rights, email ceo@uniholix.com. Your personal information is processed outside Korea by the service providers described in this policy.

Changes

We may update this policy when the service or the law changes. The current version is always on this page. If a change significantly affects how we process your personal data, we will announce it on the service before it takes effect.

The Agent Self-Audit Report is an AI-generated self-audit summary report based only on the log you provide. It is not legal advice, not a certification and not a guarantee of compliance with the EU AI Act or any other law.