Privacy Policy
Last updated: 29 July 2026 · DATALAB360 · 5 rue Louis Pergaud, 78500 Sartrouville, France
This Privacy Policy explains how DATALAB360 (“Agentik”, “we”, “us”) collects, uses and protects personal data in connection with the Agentik platform (the “Service”). DATALAB360 is the data controller for personal data relating to our business clients and website visitors, and a data processor for Traveller Data processed on behalf of our clients.
We are committed to protecting your privacy and to complying with the EU General Data Protection Regulation (GDPR) and applicable French data-protection law.
1. Who We Are
Controller: DATALAB360, 5 rue Louis Pergaud, 78500 Sartrouville, France. For privacy questions or to exercise your rights, contact privacy@agentik.travel.
2. Data We Collect
- Account & business data — name, work email, phone, company, role, billing details.
- Usage & technical data — API logs, IP address, device/browser, timestamps, feature usage and diagnostics.
- Traveller Data (as processor) — traveller names, contact details, passport/ID and travel-document data, dates of birth, booking and payment references, submitted by our clients to search, book and manage travel.
- Cookies & similar technologies on our website and dashboards (see section 9).
3. How We Use Data & Legal Bases
We process personal data to:
- provide, operate and secure the Service (performance of contract);
- authenticate users and prevent fraud and abuse (legitimate interests / legal obligation);
- route booking requests to Suppliers and return results (performance of contract);
- provide support, communicate with you and manage billing (contract / legitimate interests);
- improve and develop the Service, including analytics (legitimate interests);
- comply with legal, tax, accounting and regulatory obligations (legal obligation).
4. Controller & Processor Roles
For our clients’ account and billing data, and for website visitors, we act as controller. For Traveller Data submitted by clients, we act as a processor and process it only on the client’s documented instructions under a data-processing agreement.
6. International Transfers
Where personal data is transferred outside the EEA (for example to a Supplier or sub-processor), we rely on appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses.
7. Data Retention
We retain personal data only as long as necessary for the purposes described, to comply with legal obligations, resolve disputes and enforce agreements. Traveller Data is retained per our clients’ instructions and applicable law.
8. Security
We implement appropriate technical and organisational measures — including encryption in transit and at rest, access controls, monitoring and a PCI-DSS-aligned payment stack — to protect personal data against unauthorised access, loss or misuse.
10. Your Rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent. You may also lodge a complaint with the French supervisory authority (CNIL).
To exercise your rights, contact privacy@agentik.travel. Where we process Traveller Data as a processor, please direct requests to the relevant client (controller); we will assist them as required.
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect data directly from children.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via the dashboard or email, and the “last updated” date will be revised.
13. Contact
DATALAB360 — 5 rue Louis Pergaud, 78500 Sartrouville, France. Privacy enquiries: privacy@agentik.travel.