Version 2.8 · Last updated 2026-08-11 · supersedes v2.7 (2026-08-08)
Effective: upon any use of the System.
Operator: TUARA KURI LIMITED
Trading as: AgenticRail
Email: hello@agenticrail.nz
This Privacy Policy explains how AgenticRail collects, uses, and handles data when you use the System.
AgenticRail is designed as a deterministic execution gate, not a data processing or storage platform. We minimise data collection and avoid reliance on user content wherever possible.
We collect operational metadata required to run the System, including:
We may also collect:
AgenticRail is designed to avoid collecting personal data except where necessary (e.g., account email). We do not rely on personal data for core system operation.
We do not intentionally collect prompt content, agent messages or responses, or user-generated data payloads.
Important: Clients control what they send to the System. If you submit personal or sensitive data, it may pass through system infrastructure. You are responsible for avoiding this.
The System is not designed for processing sensitive personal data, including health data, financial account data, or biometric or identity data.
Clients must not submit such data unless they have implemented appropriate safeguards and legal basis.
We use collected data to:
We do not:
Legal basis (GDPR): Legitimate interest (operating and securing the Service) and contract performance (where account data such as email is provided).
If the System does not need the data to enforce a rule, it should not store it.
The System is designed to operate on structure (step, function, action_type) rather than content.
AgenticRail retains two distinct categories of data on different schedules.
Enforcement receipts (Ed25519-signed decision records stored in R2): retained to preserve the integrity of the verifiable receipt chain and to enable compliance reporting. There is no tiered or automated deletion schedule — retention is not differentiated by plan. A client requiring a specific retention or deletion schedule can agree one directly by contract.
Server and operational logs (HTTP access logs, error logs, latency metrics): retained for 90 days, then automatically deleted.
Account information (email address, optional name): retained while the account is active, plus a reasonable period for legal or security purposes.
You may request deletion of your account data at any time (see Section 11). Enforcement receipts cannot be individually deleted, as doing so would break the verifiable receipt chain — contact hello@agenticrail.nz to discuss a specific retention or deletion arrangement.
We implement reasonable technical and organisational measures, including:
No system is completely secure. Clients should not rely on AgenticRail for storage of sensitive data.
In the event of a data breach affecting personal data, AgenticRail will notify affected users and relevant authorities where required by law.
Clients are solely responsible for:
AgenticRail acts as a processor of structure, not a controller of user data.
AgenticRail is operated from New Zealand but uses Cloudflare's global network, which may process data in multiple countries.
By using the Service, you consent to this transfer.
For EU users, we rely on Cloudflare's compliance mechanisms, including Standard Contractual Clauses. New Zealand has been recognised by the European Commission as providing an adequate level of data protection (Adequacy Decision, 2012, reaffirmed 2024).
AgenticRail does not determine the purpose of AI systems.
The Client is responsible for classification of their AI system, handling of personal data, and compliance with privacy and AI regulations (including the EU AI Act).
AgenticRail provides enforcement logic, not data governance.
Depending on your jurisdiction, you may have the right to:
Because AgenticRail stores minimal personal data, these rights may be limited in practice.
To exercise your rights, contact hello@agenticrail.nz. We aim to respond within 30 days.
New Zealand users may contact the Office of the Privacy Commissioner: privacy.org.nz.
AgenticRail uses the following infrastructure providers:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Cloudflare | API hosting, Durable Objects, R2 storage, KV, D1, networking | cloudflare.com/privacy |
| Stripe | Payment processing for subscription plans | stripe.com/privacy |
| Resend | Transactional email delivery (welcome emails, API key delivery) | resend.com/privacy |
These providers process data only under contractual obligations and appropriate safeguards. We do not sell or share user data for marketing.
A Data Processing Agreement (DPA) incorporating Standard Contractual Clauses is available at agenticrail.nz/dpa. The DPA takes effect automatically upon your first paid API call — no separate signature required.
We may update this Privacy Policy at any time. Material changes will be communicated via email (if provided) or through the Service. Continued use of the System constitutes acceptance of updates.
AgenticRail — TUARA KURI LIMITED
Email: hello@agenticrail.nz
By using AgenticRail, you acknowledge that you have read and understood this Privacy Policy.
He toi whakairo, he mana tangata