Security and privacy at Agendaflow
Your workshop content is client-confidential. Here is exactly where it lives, who can reach it, and what happens when you press an AI button.
Where your data lives
All customer content is stored in the European Union: our database, file storage and authentication run on Supabase in Frankfurt, Germany. Product analytics runs on PostHog’s EU cloud (Frankfurt) with no session recording — we never capture your screen, keystrokes or content.
Encryption
All traffic is encrypted in transit with TLS. All data at rest is encrypted with AES-256. Passwords are stored only as secure hashes. Card details are handled entirely by Stripe and never touch our servers.
Sign-in and access
Agendaflow supports Google sign-in, Microsoft Entra ID, and enterprise SSO (SAML/OIDC via WorkOS), alongside email/password. Every API request is authenticated and authorised server-side; access to your agendas is restricted to you and the people you explicitly share with.
AI and your content
AI features run only when you invoke them — nothing is sent to AI providers in the background, and your content is never used to train AI models. AI can be switched off per agenda, enforced on our servers. No field in Agendaflow is designed to collect special-category personal data (for example health or religious information).
Read the full AI data-handling noteHow we build and ship
Every change passes automated quality gates — linting, a full automated test suite, and a production build — before it can be deployed. Production deploys are a separate, deliberate step from development, with a rollback that restores the previous version in under a minute. Database changes follow an additive-only policy while customers are active.
Vulnerability management
We run recurring automated secret scanning and dependency vulnerability scanning, and patch actively exploited paths with priority. Security reports are welcome at hello@agendaflow.com.
Compliance
Agendafix AS is a Norwegian company under EU/EEA data-protection law. We offer a Data Processing Agreement based on the EU Commission’s standard clauses, publish our subprocessor list with 30 days’ change notice, and support GDPR data-subject rights.