Last updated: January 2026
Stiamond Agents is fully compliant with the General Data Protection Regulation (GDPR, Regulation EU 2016/679). As a French company hosting data in the European Union, we process personal data in accordance with GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and accountability.
Each customer's data is logically isolated at the application level. Every database query is scoped to the tenant ID. Cross-tenant data access is prevented at the ORM layer (TypeORM tenant scoping). API keys are tenant-scoped and hashed with bcrypt.
Stiamond Agents acts as both data controller (for account data) and data processor (for end-user conversation data) under GDPR. A Data Processing Agreement is available for Enterprise customers and can be requested at privacy@stiamond.com. The DPA covers:
We facilitate the exercise of data subject rights as defined in GDPR Articles 15-22:
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | EU + US (SCCs) |
| SendGrid | Transactional email | EU + US (SCCs) |
| Twilio | SMS delivery (optional) | EU + US (SCCs) |
| Cloud hosting | Application & database hosting | EU (Frankfurt) |
In the event of a personal data breach, Stiamond Agents will notify affected customers within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Notifications will include the nature of the breach, likely consequences, and measures taken.
Stiamond Agents SAS is subject to the jurisdiction of the CNIL (Commission Nationale de l'Informatique et des Libertés), the French data protection authority. Complaints can be filed with the CNIL at www.cnil.fr.
For GDPR inquiries, DPA requests, or data subject rights: privacy@stiamond.com