API TO AGENTS · NEOVAL GMBH
Privacy Policy
Version 2026-09-12.v1. Neoval GmbH operates API to Agents and is responsible for the personal information described here. Contact contact@apitoagents.com for privacy questions or requests.
Information we process
We process your work email, company website, company and product details, audit answers, submitted API documentation, payment references, accepted policy versions, and customer-dashboard activity. Payment card details are collected by Stripe on its hosted Checkout page; the application does not collect or store your card number.
Why we use it
We use this information to verify access, prevent abuse, generate your requested audit and quote, fulfill paid services, provide secure dashboard access, deliver transactional messages, and maintain service security. Submitted documentation and conversation content are processed by OpenAI to generate the automated audit. Apparent secrets are redacted before analysis, but you must not submit credentials or real customer data.
Service providers and international processing
Google Cloud Platform/Firebase provides hosting, database, document storage, queues, and operational logging. The application infrastructure is located in the EU; public delivery can use a global CDN. OpenAI processes audit inputs and generates analysis; requests disable response storage where supported. Stripe handles payments. Brevo sends transactional email. Cloudflare may provide optional cookieless website analytics when enabled. No submitted API information is sent to browser analytics. These providers may process information in other countries under their applicable contractual safeguards. EU infrastructure alone does not mean every provider processes data exclusively in the EU.
Retention
Unverified access records are removed after 24 hours; activation-code challenges expire after 10 minutes and are removed after expiry or use. Verified unpaid audits and uploaded documents are removed after 30 days. Paid audit inputs are retained for delivery under the customer contract. Rate-limit records are removed after 48 hours unless required for an abuse investigation. Payment, accounting, acceptance, and event-deduplication records are retained according to applicable accounting and operational obligations.
Security, cookies, and access
Essential host-only cookies maintain audit and dashboard sessions. Audit access is tied to verified email. Dashboard links are single-use and expire after 30 minutes; portal sessions expire after 30 days and can be revoked. We restrict provider secrets and database access to server identities and avoid recording submitted content in application logs.
Your choices and rights
You may request access, correction, or deletion of your personal information, or raise an objection where applicable, by contacting us. Legal retention and service-delivery obligations may limit deletion. Transactional service messages do not subscribe you to marketing. Any future marketing subscription requires separate explicit consent.
API to Agents is a brand of Neoval GmbH.
UID/MWST: CHE-359.683.532
Registered seat: Basel, Switzerland
Registered address: Inselstrasse 49, 4057 Basel, Switzerland
Commercial Register entry: 21.11.2022
Commercial Register Office: BS
contact@apitoagents.com