Privacy Notice
Effective date: 24/08/2026 Last updated: 25/08/2026
1. Who we are
Reaigent is a business/project name operated by Andreas Christofi, an individual established in Cyprus.
For the processing described in this notice, Andreas Christofi is the data controller.
For privacy questions or requests, contact:
- Email: privacy@reaigent.systems
2. Scope of this notice
This notice explains how personal data is handled when you:
- visit the Reaigent website;
- interact with the Reaigent AI assistant;
- submit messages or upload documents and images;
- use microphone transcription or generated voice;
- request or arrange a meeting; or
- contact Reaigent regarding consultancy services.
3. Personal data we process
Depending on how you use the website, we may process the following information.
Website and technical information
- IP address;
- browser, device and operating-system information;
- request timestamps and basic server logs;
- security, error and diagnostic information;
- anonymous session identifiers;
- cookie and consent preferences; and
- interface preferences stored in your browser.
AI-assistant information
- messages submitted to the AI assistant;
- responses generated during the conversation;
- conversation timestamps and interaction history;
- technical identifiers used to associate messages with the correct session; and
- information voluntarily included in your messages.
Uploaded material
- documents and images you choose to upload;
- file names, formats and sizes;
- text, images and other content extracted from uploaded material; and
- processing status and related technical metadata.
You should only upload material that you are authorised to share.
Voice information
When you activate the microphone, your audio is transmitted to a speech-processing service so it can be transcribed. The resulting transcript may be stored as part of your conversation.
Reaigent does not retain a separate copy of raw microphone audio in its own systems after transcription. The speech-processing provider may temporarily process or retain limited data under the applicable contractual and security arrangements.
When generated voice is enabled, the assistant's response text is transmitted to a speech-synthesis service to produce audio.
Voice data is not used by Reaigent to identify you biometrically.
Booking and contact information
- email address;
- name, if supplied;
- requested meeting time and related scheduling details;
- meeting agenda or reason for contact;
- email-verification and booking status; and
- correspondence with Reaigent.
4. Purposes and legal bases
We process personal data for the following purposes.
Providing requested website features
Messages, uploads, voice transcription, generated speech and conversation history are processed to provide the features you choose to use.
The legal basis is taking steps at your request before entering into a contract or performing a requested service under Article 6(1)(b) GDPR.
Responding to enquiries and arranging meetings
Contact and booking information is processed to respond to your request, discuss possible services and arrange meetings.
The legal basis is taking pre-contractual steps at your request under Article 6(1)(b) GDPR.
Operating and securing the website
Technical information may be processed to maintain the website, diagnose failures, prevent abuse, protect systems and investigate security incidents.
The legal basis is our legitimate interest in providing a secure and reliable service under Article 6(1)(f) GDPR.
Optional analytics
Reaigent uses Google Analytics 4, provided by Google Ireland Limited, to understand how visitors use the website, measure performance, identify technical problems and improve the visitor experience. This may include pages visited, interactions, referral information, approximate geographic region, browser and device information, and performance measurements.
Google Analytics remains disabled until you provide consent. Reaigent does not use Google Analytics advertising features, Google Signals or advertising personalisation.
The legal basis is consent under Article 6(1)(a) GDPR. You may withdraw that consent at any time through the website's cookie preferences. Withdrawal stops future optional analytics processing but does not affect processing lawfully carried out before consent was withdrawn.
Legal obligations and claims
Information may be retained or disclosed where necessary to comply with applicable law, respond to a lawful request, or establish, exercise or defend legal claims.
The legal basis is compliance with a legal obligation under Article 6(1)(c) GDPR or our legitimate interests under Article 6(1)(f) GDPR, as applicable.
Whether information is required
Providing information through the AI assistant, file-upload, voice and booking features is voluntary. If you do not provide the information needed for a requested feature, Reaigent may be unable to provide that feature. Consent to optional analytics is not required to use the website or its interactive features.
5. AI transparency
The website's interactive assistant is an AI system, not a human representative. Visitors are informed of this before interacting with it.
6. Service providers and recipients
We may share personal data with carefully selected service providers where necessary to operate the website and provide requested functionality. These categories may include:
- cloud hosting, database and file-storage providers;
- AI language-processing and information-retrieval providers;
- speech-to-text and speech-synthesis providers;
- email-delivery, calendar and conferencing providers;
- Google Ireland Limited, as provider of Google Analytics 4, where the visitor has consented to analytics;
- website security, monitoring and error-diagnostic providers;
- public authorities, regulators or law-enforcement bodies where disclosure is legally required.
These providers may process information only for the relevant service and subject to applicable contractual and data-protection obligations.
7. International transfers
Some service providers may process personal data outside Cyprus or the European Economic Area.
Where personal data is transferred to a country that does not benefit from a European Commission adequacy decision, we rely on appropriate safeguards where required, such as the European Commission's Standard Contractual Clauses and supplementary technical or organisational measures.
You may contact us for more information about the safeguards applicable to a particular transfer.
8. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described above.
The retention periods are:
- Anonymous conversations: 60 days after the last activity, unless deleted earlier
- Uploaded files and extracted content: 60 days after the last activity in the related conversation, or earlier if deleted
- Booking proposals and verification records: 60 days after the last activity in the related anonymous session, unless deleted earlier
- Direct enquiries, privacy requests and email correspondence: 12 months after the request is closed or the last substantive communication
- Application and public website access logs: 30 days in the ordinary course; relevant records may be isolated and retained for up to 90 days where needed to investigate a specific security incident, suspected abuse or technical fault
- Google Analytics user-level and event-level data: 14 months after collection; aggregated reports that no longer identify a visitor may be kept for longer
- Browser session storage: normally deleted when the browser tab or session ends
- Cookie-consent preference: 6 months from the visitor's most recent choice
- Backups containing deleted information: up to 30 additional days after deletion from active systems
- AI service-provider copies: up to 60 days after processing under the provider's standard security and abuse-monitoring retention, unless a shorter contractual retention period applies
A longer period may apply when information is needed to comply with law, resolve a dispute or establish or defend a legal claim.
The anonymous-session cookie, the cookie-consent preference and server-side information have separate purposes and retention periods. Expiry or deletion of either browser cookie does not itself delete a conversation, uploaded file or other information held on the server. Server-side information is deleted according to the periods above or following a valid deletion request where an applicable right to deletion exists.
9. Your rights
Subject to the conditions of the GDPR, you may have the right to:
- request access to your personal data;
- correct inaccurate or incomplete information;
- request deletion of your personal data;
- restrict particular processing;
- object to processing based on legitimate interests;
- receive eligible information in a portable format;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with a supervisory authority.
To exercise your rights, contact privacy@reaigent.systems. We may need to verify that a request relates to you. We normally respond within one month. If an anonymous-session identifier has already been removed, we may be unable to associate an anonymous conversation with you. We will not require additional personal data solely to identify an otherwise anonymous visitor.
You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus.
10. Cookies and browser storage
The website uses cookies and similar browser-storage technologies. Further information is available in our Cookie Policy.