Trust and privacy
What we do with data, who processes it with us, and what you can verify for yourself.
Data protection
Algomo Limited is registered with the UK Information Commissioner's Office as a data controller, reference ZA821756, registered since 27 January 2021. The entry is public: you can look it up on the ICO register and download our registration certificate without asking us.
We comply with the UK GDPR and the Data Protection Act 2018, and with the EU GDPR where we process data about people in the EU. Because the European Commission renewed the UK adequacy decision in December 2025, personal data can move from the EU to us in the UK without standard contractual clauses.
- Data controller: Algomo Limited, 20-22 Wenlock Road, London N1 7GU.
- ICO registration: ZA821756, tier 1, renewed annually.
- Privacy questions and data subject requests: privacy@algomo.com.
How we handle your data
When Algomo runs on your site we are your processor: we act on your instructions, for your purposes, and your customers' conversations are never used to train models.
- Hosted in the EU. Your data stays in the European Union.
- Encrypted in transit and at rest.
- Never used for model training. Conversations run your agents. They do not improve anyone else's product, ours included.
- Access is limited to two named people and requires database credentials.
- Deletion on request. Ask and conversation data is removed.
There is also less of your data here than you might expect. Algomo answers from your systems at the moment a visitor asks, so we do not migrate your database, hold a copy of your catalogue, or keep a mirror of your prices and orders. Some work happens in the visitor's own browser session and never reaches us at all.
Data processing agreement
We offer a data processing agreement with the Article 28 terms your legal team expects: processing only on documented instructions, confidentiality, security obligations, sub-processor terms, help with data subject requests and breach notification, and deletion or return at the end.
Sub-processors
These are the companies that process data alongside us to deliver the product. We tell customers before this list changes.
Security
We would rather show you what we actually do than display a badge we have not earned.
- No SOC 2, ISO 27001 or HIPAA claims. We do not hold those reports, so we do not display them.
- Independent penetration testing, including testing aimed at the agent itself, is the next thing on our list.
Reporting a vulnerability
If you have found a security issue in Algomo, we want to hear about it and we will not come after you for telling us.
- Email security@algomo.com. Reports can be anonymous.
- We acknowledge within five working days and tell you what we plan to do.
- Good-faith research under this policy is authorised. We will not pursue legal action, and testing done within it does not breach our terms.
- We do not pay bounties, and we say so up front rather than wasting your time.
- Out of scope: automated scanner output on its own, missing security headers, SPF, DKIM and DMARC configuration, TLS cipher grades, self-XSS, rate limiting, and anything without a demonstrated impact.
Our disclosure policy follows ISO/IEC 29147 and our internal handling follows ISO/IEC 30111. Machine-readable contact details are published at /.well-known/security.txt.
FAQ
Are you GDPR compliant?
Yes. We are ICO registered as a data controller under reference ZA821756, we act as your processor under a data processing agreement, and we publish who processes data with us.
Can we see your ICO registration?
Yes, and you do not need us to send it. Search ZA821756 on the ICO register and download the certificate directly.
Will you sign our DPA?
Yes. We have our own with the Article 28 terms, and we will review yours.
Do you train models on our customers' conversations?
No. Conversations belong to you and are processed to run your agents, not to improve anyone else's.
Where is our data held?
In the European Union, encrypted in transit and at rest.
How much of our data do you actually hold?
Less than most vendors in this category. Algomo reads your systems when a visitor asks, so there is no migration, no copy of your catalogue and no mirror of your prices or orders.
Do you have SOC 2 or ISO 27001?
Not today, and we will not imply otherwise. If a report is a condition of buying, tell us and we will tell you honestly where we are.
Where can we send a security or privacy question?
privacy@algomo.com, and we answer rather than routing you to a form.