Privacy Policy

Version 2.9 · Last updated 2026-09-03 · supersedes v2.8 (2026-08-11)
Effective: upon any use of the System.

Operator: TUARA KURI LIMITED
Trading as: AgenticRail
Email: hello@agenticrail.nz

1. Overview

This Privacy Policy explains how AgenticRail collects, uses, and handles data when you use the System.

AgenticRail is designed as a deterministic execution gate, not a data processing or storage platform. We minimise data collection and avoid reliance on user content wherever possible.

2. What We Collect

2.1 Metadata (Primary)

We collect operational metadata required to run the System, including:

2.2 Technical Data (Limited)

We may also collect:

2.3 What We Do NOT Intentionally Collect

AgenticRail is designed to avoid collecting personal data except where necessary (e.g., account email). We do not rely on personal data for core system operation.

We do not intentionally collect prompt content, agent messages or responses, or user-generated data payloads.

Important: Clients control what they send to the System. If you submit personal or sensitive data, it may pass through system infrastructure. You are responsible for avoiding this.

2.4 Sensitive Data Guidance

The System is not designed for processing sensitive personal data, including health data, financial account data, or biometric or identity data.

Clients must not submit such data unless they have implemented appropriate safeguards and legal basis.

3. How We Use Data

We use collected data to:

We do not:

Legal basis (GDPR): Legitimate interest (operating and securing the Service) and contract performance (where account data such as email is provided).

4. Data Minimisation Principle

If the System does not need the data to enforce a rule, it should not store it.

The System is designed to operate on structure (step, function, action_type) rather than content.

5. Data Retention

AgenticRail retains two distinct categories of data on different schedules.

Enforcement receipts (Ed25519-signed decision records stored in R2): retained to preserve the integrity of the verifiable receipt chain and to enable compliance reporting. There is no tiered or automated deletion schedule — retention is not differentiated by plan. A client requiring a specific retention or deletion schedule can agree one directly by contract.

Server and operational logs (HTTP access logs, error logs, latency metrics): retained for 90 days, then automatically deleted.

Account information (email address, optional name): retained while the account is active, plus a reasonable period for legal or security purposes.

You may request deletion of your account data at any time (see Section 11). Enforcement receipts cannot be individually deleted, as doing so would break the verifiable receipt chain — contact hello@agenticrail.nz to discuss a specific retention or deletion arrangement.

6. Data Security

We implement reasonable technical and organisational measures, including:

No system is completely secure. Clients should not rely on AgenticRail for storage of sensitive data.

7. Data Breach Notification

In the event of a data breach affecting personal data, AgenticRail will notify affected users and relevant authorities where required by law.

8. Client Responsibility

Clients are solely responsible for:

AgenticRail holds two roles and they should not be confused. In respect of data a Client sends through the gate, AgenticRail is a processor, acting only on the Client's instructions; those terms are set out in the Data Processing Agreement. In respect of its own account records — the email address, key identifier and subscription status described in Section 5 — AgenticRail is the controller, and this Privacy Policy governs them.

9. International Use & Data Transfers

AgenticRail is operated from New Zealand but uses Cloudflare's global network, which may process data in multiple countries.

Transfers are not made in reliance on your consent. They rest on the adequacy decision below and, where data moves beyond it, on the safeguards in Cloudflare's Data Processing Addendum.

For EU users, we rely on Cloudflare's compliance mechanisms, including Standard Contractual Clauses. New Zealand has been recognised by the European Commission as providing an adequate level of data protection (Commission Implementing Decision 2013/65/EU, confirmed in the Commission's January 2024 review of the eleven adequacy decisions adopted under Directive 95/46/EC).

10. EU AI Act & Privacy Context

AgenticRail does not determine the purpose of AI systems.

The Client is responsible for classification of their AI system, handling of personal data, and compliance with privacy and AI regulations (including the EU AI Act).

AgenticRail provides enforcement logic, not data governance.

11. Your Rights (Including GDPR)

Depending on your jurisdiction, you may have the right to:

Because AgenticRail stores minimal personal data, these rights may be limited in practice.

To exercise your rights, contact hello@agenticrail.nz. We aim to respond within 30 days.

New Zealand users may contact the Office of the Privacy Commissioner: privacy.org.nz.

12. Third-Party Services & Subprocessors

AgenticRail uses the following infrastructure providers:

ProviderPurposePrivacy Policy
Cloudflare API hosting, Durable Objects, R2 storage, KV, D1, networking cloudflare.com/privacy
Stripe Payment processing for subscription plans stripe.com/privacy
Resend Transactional email delivery (welcome emails, API key delivery) resend.com/privacy

These providers process data only under contractual obligations and appropriate safeguards. We do not sell or share user data for marketing.

A Data Processing Agreement (DPA) incorporating Standard Contractual Clauses is available at agenticrail.nz/dpa. The DPA takes effect automatically upon your first paid API call — no separate signature required.

13. Changes to This Privacy Policy

We may update this Privacy Policy at any time. Material changes will be communicated via email (if provided) or through the Service. Continued use of the System constitutes acceptance of updates.

14. Contact

AgenticRail — TUARA KURI LIMITED
Email: hello@agenticrail.nz

By using AgenticRail, you acknowledge that you have read and understood this Privacy Policy.

Document Fingerprint — SHA-256 — v2.9
ca116a5d2e3296f4dc2219277c992826eb43fc4a81f1e55da90d8e0b70fe6ffb
Reproducible independently using any SHA-256 implementation over the pipe-delimited canonical string below.

Canonical string (UTF-8, no trailing newline):
Privacy Policy|2.9|2026-09-03|TUARA KURI LIMITED|GDPR + NZ Privacy Act 2020|Cloudflare,Stripe,Resend|metadata-only; no payload retention|no tiered retention; receipts retained to preserve chain integrity|no model training; no marketing sale|New Zealand|supersedes v2.8 2026-08-11

Version: 2.9 · Effective date: 2026-09-03 · Operator: TUARA KURI LIMITED · Supersedes v2.8 (2026-08-11)

v2.9 (2026-09-03): three corrections from a fact-check sweep run against the sources rather than against the neighbouring documents. (1) The New Zealand adequacy decision was cited as “Adequacy Decision, 2012”. The European Commission's own reference is Implementing Decision 2013/65/EU; the claim was right and the pointer was wrong. Now cited so it can be looked up, with the January 2024 review named for what it was. (2) Section 8 said AgenticRail acts as a processor of structure and not a controller of user data. That is not a term of art and it was contradicted by Section 5 of this same document, which describes account records held on AgenticRail's own behalf. Both roles are now stated separately. (3) Section 9 said that by using the Service you consent to international transfer. Consent is not the basis relied on and is a poor one; the adequacy decision and Cloudflare's safeguards are, and now say so. The canonical string's retention field is narrowed from “no tiered plans” to “no tiered retention”, matching the Data Processing Agreement and this document's own Section 5. No change to what is collected, how it is used, how long it is kept, or to any individual's rights. This fingerprint supersedes the v2.8 hash 05e319d2bda51d626a7b721af079f4bf1366b78624497caf918d87208987279f.

v2.8 (2026-08-11): removes the registered street address from the operator block and Section 14, and the NZBN from the fingerprint metadata and canonical string. Neither was an address for service: notices are given by email to hello@agenticrail.nz, and TUARA KURI LIMITED remains identifiable on the public New Zealand Companies and NZBN registers. No change to what is collected, how long it is kept, who processes it, or any individual's rights. This fingerprint supersedes the v2.7 hash cc9a1fd11471e87464d4c2222ebd804bcc6cdc527fc9bad52649ced64a92860c.

v2.7 (2026-08-08): removes the AI Provider from the subprocessor list in Section 12. Verification report summaries are composed by AgenticRail's own code from the enforcement data in the receipts; no language model or external service is involved, so Google (Gemini) is no longer a subprocessor and the category is retired rather than reassigned. The subprocessor list is now Cloudflare, Stripe and Resend. No change to what is collected, how long it is kept, or any individual's rights, and no personal data was ever within the removed entry's scope. This fingerprint supersedes the v2.6 hash 6acc0ae5fed5d2e9c855788d4ffe5fb48fc327fbc95596abc4156f5f200f9a2d.

v2.6 (2026-07-08): removes the tiered (Free/Growth/Scale/Enterprise) receipt retention schedule from Section 5 — no such tiered plan structure or automated deletion mechanism exists; the prior text named a specific "R2 lifecycle policy" that does not exist in the deployed system. Replaced with an accurate statement: receipts are retained indefinitely by default to preserve chain integrity, with no automated tiered deletion, and a specific schedule available by direct agreement. No other change; this fingerprint supersedes the v2.5 hash 041eba3fe3c5123241ffb0f27701a9f632235f63ae977aaa67083d44d9ff2490.

He toi whakairo, he mana tangata