Version 2.2 — September 13, 2026 download the PDF
Added Logo.dev among the providers (display of company logos on oto.cx and in Scout).
We believe your data belongs to you. oto minimizes data collection and encrypts sensitive items: your secrets and credentials for third-party tools are encrypted at rest (AES-256-GCM), with the master key kept out of the database. Each encrypted secret is bound to its row: it cannot be transplanted to another connector or another organization. Secrets are isolated per user and partitioned per organization. An organization can require two-factor authentication from its members.
The data controller is Otomata, a SASU registered in Marseille (SIREN 106 974 637, EU VAT FR05106974637) — see the legal notice.
Two roles, two documents. This policy covers the processing for which the Publisher is the controller on its own behalf: your account and organization, billing, the proof of acceptance of the contractual documents, the technical call log, platform monitoring and security. The data you entrust to the platform — content, contacts, messages and documents handled by your connectors and agents — is processed on your behalf, as a processor: it is governed by the data processing agreement (DPA). Details of our security measures are published on trust.oto.zone.
| Data | Purpose | Legal basis |
|---|---|---|
| Sign-in identity (Logto), email address, name, avatar, preferred language | Authentication, account identification, notifications | Contract |
| Two-factor authentication factors, when your organization requires them (held by the authentication service) | Account security | Contract |
| Usage profile (job, goals, desired connectors), filled in by you or by your agents | Tailoring the session to your context | Contract |
| Organizations, members, roles, invitations | Access management | Contract |
| Secrets and credentials for connected tools (encrypted AES-256-GCM) | Running automations | Contract |
| Content (pages, documents, files, tables) and its search index | Search and running your automations | Contract — processed on your behalf, see DPA |
| Data | Purpose | Legal basis |
|---|---|---|
| Billing identity: legal name, country, EU VAT number, address, postal code, city, billing email address | Determining the applicable VAT, issuing the invoice | Contract, legal obligation |
| Subscription: tier, status, billing dates, customer and mandate identifiers at Mollie | Subscription and charge management | Contract |
| Payment log: amounts excluding VAT, VAT and including VAT, VAT scheme, country retained, Mollie payment identifiers, status, attempt number | Collection, reconciliation, handling of failed payments | Contract, legal obligation |
| Invoices and credit notes: number, amounts, period covered, PDF document, recipient address and sending date | Accounting and tax obligations | Legal obligation |
The amount charged, its breakdown and the VAT scheme are frozen at each payment and shown on the corresponding invoice (see the terms of sale).
Each acceptance of the terms, the terms of sale and the DPA is logged, never overwritten: account, organization on whose behalf it is given, document and version accepted, context (access to the service or purchase), IP address, browser (user-agent string, truncated to 512 characters) and date. Purpose: proof of contractual consent. Legal basis: legitimate interest (establishing evidence).
Call log. Every tool call (by an agent via MCP, or by the dashboard via the API) is logged: date, account (identifier and email), tool called, truncated arguments — tokens and secrets are masked at write time —, success or error, duration, session, run, organization, client application (for example claude.ai or Claude Code) and, for a code error, the identifier of the error report. Purposes: platform monitoring, your organization's audit log (available to its administrators), reconstruction of your runs, incident investigation. Legal basis: contract and legitimate interest.
| Data | Retention period |
|---|---|
| Call log | 90 days online; beyond that, each closed month is exported to an offline archive (private object, storage hosted in the European Union) and then deleted from the database. The opening and closing facts of a run are kept with it. |
| Execution thread of hosted agents (intermediate messages) | 30 days |
| Usage counters per tool and per day; usage signals (feedback on a tool, unmet need) | Lifetime of the account |
| Account, organization, content and secrets | Lifetime of the account; deletion on request (see "Your rights") |
| Billing identity, payment log, invoices and credit notes | Ten years from the close of the financial year (accounting records, Article L.123-22 of the French Commercial Code) |
| Proof of acceptance of the contractual documents | For the applicable limitation period |
| Error reports (Sentry) | Kept by the provider, in the European Union, for diagnosis |
To detect and fix platform defects, code errors are sent to Sentry (hosted in the European Union, Germany):
Legal basis: legitimate interest (reliability and security of the service). This processing is not subject to the analytics consent.
Sub-processors (process on behalf of your organizations, bound by an Article 28 GDPR contract):
Connector services (used only if you enable and use the connector):
When you connect a tool with your own key or your own account, oto carries out your instruction with a service you already have a relationship with: the Publisher adds no processor.
The Publisher's billing providers (the Publisher's own processing):
In accordance with Article 28 GDPR, the data processing agreement (DPA) governs this processing; it is also available on trust.oto.zone. Transfers outside the European Union (Anthropic, Browserbase) are covered by the European Commission's standard contractual clauses.
The Publisher's technical providers (the Publisher's own processing, contacted directly by your browser):
To exercise your rights: email alexis@otomata.tech. We respond within 30 days.
This policy supplements the legal notice, the subscription terms, the terms of sale and the data processing agreement (DPA). Previous versions remain available.