Legal
Privacy Policy
Last updated: 2 October 2026
1. Overview
OATHERA ("OATHERA", "we", "us") provides an agentic identity platform that gives AI agents cryptographically verifiable, human-approved, short-lived identities. This Privacy Policy explains what personal data we process, why, and the choices and rights you have. It applies to our websites at oathera.ai and oathera.com and to the OATHERA services (together, the "Services").
For personal data we process on behalf of a customer as part of delivering the Services, the customer is the data controller and OATHERA acts as a processor under our Data Processing Agreement.
2. Data we collect
Information you provide
Account and contact details such as your name, work email, company, and any information you include when you contact us, request a demo, or sign up for updates.
Service data
When you use the Services, we process operational metadata needed to issue and verify agent identities — for example tenant and agent identifiers, approval records, token issuance events, and audit logs. Private keys are generated in your environment and never leave it; we do not receive them.
Technical data
Device and connection information such as IP address, browser type, pages viewed, and timestamps, collected through server logs and, with your consent, analytics cookies.
3. How we use data
- To provide, operate, secure, and improve the Services.
- To authenticate users and enforce access controls.
- To respond to enquiries and provide support.
- To send service and, where permitted, product communications.
- To detect, prevent, and investigate abuse or security incidents.
- To comply with legal obligations.
4. Legal bases
Where the GDPR or similar laws apply, we rely on: performance of a contract, our legitimate interests in running and securing the Services, your consent (for example for analytics or marketing cookies), and compliance with legal obligations.
6. Data retention
We keep personal data only as long as needed for the purposes above or as required by law. Audit and token-issuance records are retained for the period agreed with the relevant customer; account data is deleted or anonymised after an account is closed.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, least-privilege access, a fail-closed enforcement model, and tamper-evident audit records. No system is perfectly secure, but security is central to how the Services are designed.
8. International transfers
Where personal data is transferred across borders, we use safeguards such as the European Commission's Standard Contractual Clauses or an equivalent approved mechanism.
9. Your rights
Depending on your location, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us using the details below. You may also complain to your local data protection authority.
11. Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with a revised "Last updated" date.
13. Contact
Questions about this Policy or your personal data? Email privacy@oathera.ai.