Agoria gives businesses an agent-callable interface — a machine-facing twin of their website that AI assistants can read and act on. This policy explains what we collect when you use Agoria, whether you are a business owner, a customer, or an AI assistant connecting to our MCP server.
Agoria is operated from Australia. For any privacy question, or to exercise any right described below, contact mohamed@deep9.com.au.
When a business joins Agoria we collect and publish the information it chooses to make agent-readable: name, description, category, locations, opening hours, contact details, services and prices, products, policies, credentials, team members and reviews. This is public by design — the entire point is that AI assistants can read and cite it. Some of it is gathered by crawling a business's own public website during onboarding.
Business email address, and sign-in state. Sign-in uses single-use email links; we do not store passwords.
When someone books, orders, requests a quote, or messages a business through Agoria — directly or via an AI assistant — we process the details needed to complete that action: name, contact details (email or phone), the content of the request, and appointment or order details. This is passed to the business the request was addressed to.
We log the search queries sent to our discovery endpoints, which tools were called, and which AI source a request appears to come from (from the referrer and user-agent). Query logs are stored as query text plus a count, category and city; they are not linked to an individual person or account, and we publish aggregate, per-category query volumes at /demand.
Card details are never collected or stored by Agoria. Payments and subscriptions are processed by Stripe, which receives the transaction details directly. Where a payment is held in escrow, we retain the transaction record (amount, parties, status) but not the payment instrument.
We do not sell personal information, and we do not use customer contact details for our own marketing.
We share information only with the processors needed to run the service:
We may also disclose information where required by law.
Our discovery connector (/mcp) is read-only and unauthenticated: it exposes public business listings only. An assistant that takes an action on a customer's behalf transmits the details that customer supplied for that action. We do not receive an assistant's conversation history, and we do not ask for it.
Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider. Access to production systems is limited to those who need it. Sign-in is by short-lived single-use link rather than stored passwords.
You can ask us to access, correct, or delete the personal information we hold about you, or to stop processing it. Email mohamed@deep9.com.au and we will respond within 30 days.
Under the Australian Privacy Act you may also complain to the Office of the Australian Information Commissioner. If you are in the EEA or UK, GDPR rights including portability and objection apply, and our lawful bases are contract (to deliver what you asked for) and legitimate interests (to operate and secure the service).
Agoria is not directed at children and we do not knowingly collect information from anyone under 16.
If we change this policy we will update the date at the top of this page, and for material changes we will notify businesses on the platform by email.