Privacy Policy

Last updated 20 August 2026

Drafted for review. This document has been prepared for AI Explorers but has not yet been reviewed by a legal practitioner. If you are relying on it for a compliance decision, please contact us at sales@aetheragents.cloud first.

Who we are

AETHER is operated by AI Explorers, registration number 2025/460302/07, a company incorporated in South Africa. For the purposes of the Protection of Personal Information Act 4 of 2013 (POPIA) we are the responsible party for the information described below. Where the General Data Protection Regulation applies, we are the controller of that same information.

There is one important split. For your account we are the responsible party. For the content you put into an agent, such as documents you upload or messages your users send, you are the responsible party and we act as an operator (a processor, in GDPR terms) on your instructions. We do not decide what to do with that content; you do.

What we collect

Information you give us

  • Account details: name, email address, password (stored only as a hash, never in readable form), and the organisation you belong to.
  • Organisation details: company name, the people you invite, and the role you give each of them.
  • Billing details: what you bought, when, and how much. Card and bank details are handled by our payment provider and never reach our servers.
  • Support correspondence: anything you send us by email or through the platform.

Content you or your users put into agents

  • Prompts and conversations, including messages sent by people using an agent you have published.
  • Documents and other knowledge you upload for an agent to draw on.
  • Configuration: instructions, connected tools, and the settings that shape how an agent behaves.

Information we generate

  • Usage records: which agents ran, when, how many tokens they consumed and what that cost. This is how billing and budgets work.
  • Audit records of significant actions, such as invitations, role changes and administrative operations.
  • Technical logs: IP address, browser type, timestamps and error traces. These exist to keep the service running and secure.

What we do not collect

We do not buy personal information from data brokers, we do not run advertising on AETHER, and we do not build behavioural profiles for marketing. As set out in our Cookie Policy, we currently run no analytics or advertising trackers at all.

Why we use it

What we do Information used Lawful basis
Give you an account and run the platform Account details, technical logs Performance of our contract with you
Run your agents and return their answers Prompts, uploaded knowledge, configuration Performance of our contract, on your instructions as operator
Charge you correctly and enforce budgets Usage records, billing details Performance of our contract, and our legal obligation to keep accounting records
Keep the service secure and investigate abuse Technical logs, audit records Our legitimate interest in protecting the platform and its users
Send service messages, such as invitations and receipts Email address, account details Performance of our contract
Improve the product Aggregated usage records that do not identify a person Our legitimate interest in understanding how the platform is used

We do not use your content to train AI models, ours or anyone else's, and we do not permit our model providers to do so with data sent through AETHER.

What happens when an agent runs

This section matters more than the rest, so please read it even if you skip the others.

An AI agent is not self-contained. When an agent runs, the material it needs in order to answer is sent to a large language model operated by a third party. Depending on which model the agent is configured to use, that can include:

  • the instructions you gave the agent,
  • the message the person is asking about,
  • relevant extracts from documents you uploaded,
  • the results returned by any tools the agent is connected to, and
  • earlier turns of the same conversation.

These providers operate outside South Africa. Choosing a model is therefore also a decision about where your data goes, and it is a decision you control: each agent names the model it uses, and you can change it.

We hold the resulting conversation, the uploaded knowledge and the usage record on our own infrastructure so that you can review history, so budgets can be enforced, and so invoices can be reconciled. You can delete an agent and its conversations, and doing so removes them from our systems, subject to the retention periods below.

Two practical consequences worth stating plainly. First, an agent's answers can be wrong, so they should not be treated as professional advice without review. Second, if you put special personal information into an agent, for example health or biometric data, POPIA places extra duties on you as the responsible party for that content, and you should satisfy yourself that you have a lawful basis before uploading it.

Who we share it with

We do not sell personal information. We share it only with the operators listed here, each of whom processes it on our instructions under a written agreement.

Operator What they do for us Where
Amazon Web Services Hosting, database and file storage Cape Town, South Africa (af-south-1)
Anthropic Language model inference, when an agent is configured to use a Claude model United States
OpenAI Language model inference, when an agent is configured to use a GPT model United States
Google Language model inference, when an agent is configured to use a Gemini model United States
DeepSeek Language model inference, when an agent is configured to use a DeepSeek model China
Deepgram Converting speech to text, for voice features only United States
Ozow Processing payments when you buy credit South Africa
Zoho Sending transactional email such as invitations and receipts Outside South Africa

The model providers in that table are only involved when an agent is configured to use them. An organisation that only ever uses one provider's models will never have data sent to the others.

We will also disclose information where the law requires it, such as a lawful court order, and to professional advisers where necessary. If our business is ever sold or merged, information may transfer with it, and we will tell you before that happens.

Sending data abroad

Your account and content are stored in South Africa. Sending prompts to a model provider means personal information leaves the country, which section 72 of POPIA permits where the recipient is bound by an agreement providing an adequate level of protection, or where the transfer is necessary to perform a contract with you. Both apply here: we have data processing terms in place with each provider, and running the agent you asked for is not possible without the transfer.

Where the GDPR applies, these transfers rely on the European Commission's Standard Contractual Clauses. Copies of the relevant terms are available on request.

How long we keep it

  • Account details: while your account is open, then 12 months after closure so the account can be restored if the closure was a mistake.
  • Agent content and conversations: until you delete them, or until 30 days after the account is closed.
  • Usage and billing records: five years from the end of the relevant tax year, which is what South African tax law requires.
  • Technical logs: 90 days, unless a log is part of an ongoing security investigation.
  • Audit records of administrative actions: three years.

Your rights

Under POPIA and, where it applies, the GDPR, you may:

  • ask what personal information we hold about you and get a copy of it,
  • have inaccurate information corrected,
  • have information deleted where we no longer have grounds to keep it,
  • object to processing we carry out on the basis of legitimate interest,
  • ask us to restrict what we do with your information while a dispute is resolved,
  • receive the information you gave us in a portable format, and
  • withdraw consent, where we relied on consent, without affecting what was lawful beforehand.

Write to sales@aetheragents.cloud and we will respond within 30 days. We do not charge for this unless a request is repetitive or excessive, in which case we will tell you the fee before doing the work.

If the request concerns content inside an agent belonging to an organisation, we will refer you to that organisation, since they are the responsible party for it and we may not act on their data without instruction.

Security

Passwords are stored only as hashes. Traffic is encrypted in transit. Data at rest is encrypted by our hosting provider. Access to production systems is limited to the people who need it, and administrative actions are logged. Every organisation's data is separated so that one tenant cannot read another's.

We also run automated checks that look for personal information and secrets in material being sent to model providers, and block or redact where configured to do so.

No system is perfectly secure. If a breach occurs that creates a risk to you, we will notify you and the Information Regulator as section 22 of POPIA requires.

Children

AETHER is a business product and is not directed at children. We do not knowingly collect the personal information of anyone under 18. If you believe a child has given us information, contact us and we will delete it.

Changes to this policy

We will post any change here and update the date at the top. If a change materially affects your rights, we will tell account holders by email before it takes effect.

Contact and complaints

  • Email: sales@aetheragents.cloud
  • Phone: +27 079 11 00 596
  • AI Explorers, registration number 2025/460302/07, South Africa

You may complain to the Information Regulator of South Africa at any time, whether or not you have raised the matter with us first. The Regulator can be reached at inforegulator.org.za. If you are in the European Economic Area or the United Kingdom, you may instead complain to your local supervisory authority.