Zásady ochrany osobních údajů
Privacy Policy
MyAgent Workforce Management Platform
Effective date: 2026-09-04 Version: 1.2 Status: PUBLIC. Published without authentication. This is the only document in this folder that is public.
1. Who we are
MyAgent is operated by 3D Steel Labs s.r.o., Chvalín 79, 413 01 Nové Dvory, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Ústí nad Labem, file ref. C 48241 ("we", "us", the "Operator").
For any question about this policy or about your personal data, contact privacy@3dsteellabs.cz.
2. Who this policy is for
MyAgent is a business platform used by organisations ("Tenants") to manage their workforce, timesheets, projects and documents. Most personal data in MyAgent is entered by a Tenant about its own people, and that Tenant is the controller of it — if you are an employee, worker, customer representative or agency contact using MyAgent, the organisation that gave you your account decides what data it holds about you and why, and is your first point of contact.
This policy describes the processing for which we are the controller: what we do to operate, maintain and improve the Platform, and the optional integrations you may choose to connect.
3. What we process, why, and on what basis
| What | Why | Legal basis |
|---|---|---|
| Account data (name, email, role, language, timezone) and the content you enter | To operate the Platform and provide the service to your organisation | Our legitimate interests in operating and supporting the Platform (Art. 6(1)(f)) |
| Selected free-text fields, where translation is requested | To display content in your chosen language | Legitimate interests (Art. 6(1)(f)) |
| Recipient name and email address for system messages | To deliver password resets and notifications | Legitimate interests (Art. 6(1)(f)) |
| Document templates, and material an administrator chooses to attach, in the optional AI features | To analyse a template's structure, and to assist an administrator in drafting documents | Legitimate interests (Art. 6(1)(f)) |
| Usage records: which pages and functions are opened, by which role, in which Tenant, and whether the request succeeded | To develop and maintain the Platform | Legitimate interests (Art. 6(1)(f)) |
| Calendar data, where you connect an external calendar — see §4 | To synchronise your appointments with the Platform | Your consent (Art. 6(1)(a)) |
| The name and email address of a person invited to a meeting, and the meeting's details | To send them the invitation, and any later update or cancellation for the same meeting | Legitimate interests (Art. 6(1)(f)) |
| Your own calendar, where you connect a phone or desktop calendar application — see §4a | To show your appointments and reminders on your own device | Legitimate interests (Art. 6(1)(f)) |
We do not record page addresses, IP addresses or text you enter in our usage records, we do not sell personal data, and we do not use it for advertising or automated decision-making with legal effect.
4. Connecting an external calendar (Google and Microsoft)
This applies only if you choose to connect a calendar account. Nothing happens until you do, and you can disconnect at any time.
What we access. With your permission we read and write the events on the calendars you select, and read the list of your calendars so you can choose which ones to synchronise. We request the narrowest permissions that allow this — the ability to read and write events, not to administer or share your calendars.
Why. To show your existing commitments inside MyAgent, and to write appointments you make in MyAgent back to your own calendar so they appear on your other devices.
What we store. The events on the calendars you select — their titles, times, locations, descriptions and participants, including each participant's response and who organised the meeting — together with the identifiers and synchronisation state needed to keep both sides consistent, and an access credential held in encrypted form.
Participants. Where you organise a meeting in MyAgent, the guest list you enter is sent to your calendar provider along with the event. For a meeting somebody else organised, we mirror the guest list and never rewrite it. If you ask us to, we will also email an invitation to each guest — see §4b.
How long. Until you disconnect the calendar or your account is closed. Disconnecting deletes the stored credential and the synchronised events we hold for that connection.
Google Limited Use. MyAgent's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised artificial-intelligence or machine-learning models, we do not transfer it except as needed to provide or improve this feature or as required by law, and we do not sell it or use it for advertising.
We name Google LLC and Microsoft Corporation here because you connect your own account with them directly and knowingly; they are not otherwise recipients of your data.
4a. Connecting a phone or desktop calendar application
Separately from §4, you may connect a calendar application on your own device directly to MyAgent, so your MyAgent calendar appears alongside your others.
To do so you create a device password in the Platform. It is shown to you once, we keep only a one-way hash of it, you can revoke it at any time for that device alone, and it is not your MyAgent password — it cannot be used to sign in and reaches nothing but your own calendar.
Your device receives your own events and the calendar reminders MyAgent already shows you, in the categories you choose. It can add and change your own events; it can never change a reminder derived from another record, which is served read-only. No third party is involved — your device talks to our server directly, and we send nothing to Apple, Google, Microsoft or any other device maker for this. Revoking a device password stops further access, but it cannot remove what your device has already stored.
4b. Meeting invitations
If you organise a meeting in MyAgent and ask us to invite your guests, we email each of them an invitation from your organisation's own sending address. It carries the meeting's details, your address as the reply address, and — as every calendar invitation does — the addresses of the other guests, so each recipient's calendar can show who else is coming.
We never send an invitation unless you ask for it. Connecting a calendar, importing an event, or creating one on your phone invites nobody. We do not add recipients of our own, and we do not use a guest's address for anything beyond that meeting and its later updates or cancellation.
If you have received an invitation from MyAgent and would rather not have, reply to the person who sent it — their own address is on the message — or contact us at privacy@3dsteellabs.cz. We hold your address because the organiser entered it; the organisation they work for is the controller of that meeting's details.
4c. Artificial intelligence, and the data we take from your calendar
We do not use data from your Google account to build, train, improve or evaluate any artificial intelligence or machine learning model — our own or anyone else's — and we do not transfer it to any third party that would. This applies to the data exactly as we receive it, and equally to anything aggregated, anonymised, summarised or otherwise derived from it.
MyAgent does contain optional AI features, so we state plainly how they relate to your calendar data: they do not.
- The AI features exist for one purpose — helping an administrator analyse and draft document templates for their own organisation. Their only inputs are a template that administrator uploaded and a file that administrator deliberately attached to the conversation.
- Calendar data is not an available input to them. It is not offered to them, and they have no means of requesting it: the AI features can act only on the document being written, and there is no capability by which they could reach a calendar, an event, an appointment or a participant. This is a property of how the software is built, not a policy we apply on top of it.
- The two are separate parts of the product. The AI features are switched on for an organisation individually and most organisations do not have them at all; calendar synchronisation is switched on separately again, and is connected by each person for themselves.
Our AI provider. Where the AI features are used, the material described above is sent to Anthropic, PBC (United States), which provides the Claude API. We call that service directly — not through any aggregator, gateway, model hub or reseller — and Anthropic's commercial terms provide that inputs and outputs are not used to train its models. No self-hosted or offline model is used, and no other AI or machine-learning provider is integrated into MyAgent.
Nothing from your calendar reaches them, or anyone. Data we receive from Google Calendar is stored in your organisation's own area of our database and is used only to display and synchronise your calendar. It is not sent to Anthropic, not sent to our email provider, not sent to our translation provider, and not sent to anyone else. Where you ask us to email a meeting invitation (§4b), we can only do so for a meeting created in MyAgent — an event that came from your Google calendar cannot generate an email.
We do not sell Google user data, do not use it for advertising, and do not use it for any purpose other than providing the calendar features you connected it for. This is the Limited Use commitment in §4, restated here because it is the question most worth answering directly.
5. Who receives personal data
Beyond your own organisation and its Account holders, personal data may be disclosed to service providers who process it on our behalf, under written data processing agreements and only on our instructions:
- a machine-translation provider established in the European Union, which deletes submitted text immediately after translation;
- an email delivery provider established in the United States, which receives recipient names, email addresses and the content of system messages in order to deliver them, holds them on European infrastructure, and keeps its delivery logs for one day;
- an artificial-intelligence provider established in the United States, which receives document templates and material attached by an administrator in the optional AI features, retains inputs and outputs for 30 days, and does not use them to train its models;
- a hosting provider established in the Czech Republic, which supplies infrastructure and has no logical access to application data.
Meeting invitations (§4b) are delivered by the same email provider. Our usage records (§3), and the device connection described in §4a, involve no service provider at all and never leave our own systems.
We may also disclose personal data where required by law or to establish, exercise or defend legal claims.
A complete and current list of our processors, naming each one, is available to Tenants on request at privacy@3dsteellabs.cz.
6. Transfers outside the EU/EEA
Two of the service providers in §5 are established in the United States: the artificial-intelligence provider, and the email delivery provider — which, although it holds the data on European infrastructure, is a US company. Both transfers are governed by Standard Contractual Clauses adopted by the European Commission, and the email delivery provider is additionally covered by the EU–US Data Privacy Framework, in accordance with Chapter V GDPR. Where you connect a Google or Microsoft calendar (§4), that provider may process data outside the EU/EEA under its own safeguards.
6a. How we protect your data
These are the measures we actually operate, described so you can judge them rather than be reassured by them. They apply to all personal data in MyAgent, and every one of them applies to the data we access from a connected calendar account.
In transit. Everything travels over an encrypted connection (HTTPS/TLS). In production we instruct browsers to refuse an unencrypted connection to us for a year at a time, including on our subdomains. Every call we make to Google is likewise over an encrypted connection.
Credentials, at rest. The access credential we hold for a connected calendar account is encrypted in our database, and is never displayed anywhere in the product, never included in any export, and deliberately excluded from our internal change history — so no readable copy of it accumulates anywhere. Account passwords are stored as one-way hashes and cannot be recovered by us or by anyone else. A password you create to connect a phone or desktop calendar application (§4a) is likewise stored only as a one-way hash, is shown to you exactly once, and can be revoked for that one device without affecting anything else.
Separation between organisations. Each customer organisation's data lives in its own separate area of the database rather than mixed into shared tables. A request is resolved to one organisation before any data is read, so one organisation's people cannot reach another's records.
Access control inside an organisation. Access follows a person's role, and the calendar data we receive from your account is narrower still: it is visible only to you. No administrator, no colleague and no customer contact in your organisation can see the events imported from your calendar, and none of them can connect, disconnect or inspect your calendar connection. Our own staff do not access customer data except where a support request requires it, and such access is recorded.
Least privilege at Google. We ask Google for the narrowest permissions the feature can work with — the ability to read and write events, and to read the names of your calendars so you can choose which to synchronise. We do not request the ability to administer or share your calendars, and we cannot do either.
Change history. Changes to records are recorded with who made them and when, so a question about what happened to a piece of data has an answer. Credentials are excluded from this record by design.
Backups. Backups are taken daily, are held off-site with a different provider from the one hosting the service, are encrypted at rest, and are kept to a defined retention schedule rather than indefinitely. Restoring from them has been tested rather than assumed.
Deletion. Disconnecting your calendar revokes our access at Google, destroys the stored credential, and deletes the events we imported through that connection (§4). Revoking a device password (§4a) ends that device's access immediately. Usage records are deleted after 90 days.
Boundaries we keep. We do not sell personal data, do not use it for advertising, do not use it for automated decisions with legal effect, and — as set out in §4c — do not use it to train artificial intelligence models or pass it to anyone who would.
Where we are not there yet. Two-step verification is not yet available for MyAgent accounts, and our database files are not separately encrypted beyond the credential encryption and backup encryption described above. We would rather tell you that than imply protections we do not operate.
If something goes wrong. If a breach of personal data occurs that is likely to result in a risk to people's rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform affected people directly where the risk to them is high.
7. How long we keep it
A device password (§4a) is kept until you revoke it or your account is closed. A guest's details on a meeting are kept for as long as the meeting record is. Account data and content are kept for as long as your organisation's use of the Platform continues, and are deleted or returned on termination in accordance with our agreement with it. Usage records are deleted after 90 days. Text sent for translation is deleted immediately after translation. Our email delivery provider keeps its delivery logs for one day. Material sent to the AI provider is retained by it for 30 days. Calendar data is kept until you disconnect (§4).
8. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. Where processing rests on your consent — as with the calendar integration — you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
Because most data in MyAgent is controlled by the organisation that gave you your account, please direct requests to that organisation first; we will give it the technical assistance it needs. For the processing described in this policy for which we are the controller, contact us directly at privacy@3dsteellabs.cz.
9. Complaints
You may lodge a complaint with the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů, ÚOOÚ), or with the supervisory authority of your habitual residence.
10. Changes to this policy
We will update this policy when our processing changes, and will publish the new version here with a new effective date. Material changes affecting Tenants are notified to them separately.
11. Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-08-31 | Initial public version. Describes recipients by category rather than by name (Art. 13(1)(e) GDPR); Google and Microsoft are named in §4 because the integration is one the data subject connects directly. |
| 1.1 | 2026-09-03 | Added §4a (connecting a phone or desktop calendar application) and §4b (meeting invitations), with matching rows in §3, §5 and §7. Both describe processing that did not exist at v1.0. §4b includes a route for a recipient who is not a user of the Platform and has no other way to reach us. §4 and the Google Limited Use commitment are unchanged. |
| 1.2 | 2026-09-04 | Added §6a, the data protection measures we operate, including what we do not yet operate; and §4c, stating that data from a connected Google account is never used to train any AI or ML model and never transferred to any third party that would, and that our AI features have no means of reaching calendar data. Both sections respond to points raised in Google's OAuth verification review of 2026-09-04. §4, §4a and §4b are unchanged, as is the Limited Use commitment. |