AgentDonkey

Privacy Policy

Last updated: 6 August 2026

1. Controller

This website (agentdonkey.com, the "Site") is operated by DonkeyCat GmbH, Lindengasse 43/19, A-1070 Vienna, Austria (FN 385726 w, Commercial Court of Vienna; VAT ID ATU67516459), which is the controller for the personal data described here within the meaning of the EU General Data Protection Regulation ("GDPR"). Contact: office@donkeycat.com.

2. Scope

This policy covers both the public Site (including the waitlist) and the AgentDonkey application — in particular its use of Google user data obtained through Google OAuth, which is described in section 4. AgentDonkey is not yet generally available; where we process data on a customer's behalf under a commercial agreement, a separate data processing agreement applies in addition to this policy. This policy does not apply to third-party websites we link to; we are not responsible for their practices.

3. Data we process, and why

We deliberately collect as little as possible.

a) Waitlist. If you choose to submit the form we process:

Legal basis: your consent (Art. 6(1)(a) GDPR), given by submitting the form, for the contact details; and our legitimate interest in preventing abuse and keeping the Site available (Art. 6(1)(f) GDPR) for the hash.

b) Operator login. A strictly necessary session cookie to maintain your authenticated session (Art. 6(1)(f) GDPR). It is not used for tracking or profiling.

c) Server logs. Our hosting provider records standard technical request data for security and operation of the service (Art. 6(1)(f) GDPR).

Providing waitlist data is entirely voluntary. There is no statutory or contractual obligation to provide it; the only consequence of not doing so is that we cannot contact you about availability.

4. Google user data (Google OAuth)

When an authorised operator connects a Google account to AgentDonkey, they grant access via Google OAuth. AgentDonkey then acts on that operator's behalf, against their own accounts, to automate marketing and app-store operations. We request only the scopes needed for the features actually in use:

Scope What it is used for
youtube.readonly List the connected channel's videos, titles, descriptions and public statistics.
youtube.upload Upload marketing videos to the operator's own channel at their request.
youtube.force-ssl Read captions/transcripts of the operator's own videos, and manage video metadata.
adwords Read Google Ads campaign structure and performance, and manage campaigns the operator owns.
androidpublisher Read and update Google Play store listings, releases, in-app products and reviews.
playdeveloperreporting Read Play developer reporting metrics for the operator's apps.
admob.readonly, admob.report, admob.monetization Read AdMob accounts and revenue reports, and manage ad units and mediation.
cloud-platform, devstorage.read_only Access the operator's own Google Cloud storage buckets holding their creative assets and reports.

How that data is handled:

5. What we do not do

6. Recipients and processors

The Site and its database are hosted on Google Cloud Platform in the European Union (region europe-west1, Belgium), acting as our processor under Art. 28 GDPR. We may disclose data where required by law, court order or a competent authority, or where necessary to establish, exercise or defend legal claims. If we later engage an email provider to contact waitlist members, this policy will be updated beforehand.

7. International transfers

Waitlist data is stored within the EU. Where a processor may access personal data from outside the EEA, such transfers are safeguarded by the European Commission's Standard Contractual Clauses together with supplementary measures where required.

8. Retention

Waitlist entries are retained until public sign-up opens and we have contacted you, until you request erasure, or until we decide not to proceed with the product — whichever occurs first — after which they are deleted. Abuse-prevention hashes are retained for the life of the associated entry. Server logs are retained for a short period in line with our provider's standard configuration. We may retain data longer where required by law or to defend legal claims.

9. Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; and to object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise any right, email office@donkeycat.com. We will respond within one month, extendable by two further months for complex requests as permitted by Art. 12(3) GDPR. We may need to verify your identity before acting. Asking to be removed from the waitlist is enough — no particular form of words is required.

You may also lodge a complaint with a supervisory authority, in particular in your Member State of residence or place of the alleged infringement — in Austria, the Datenschutzbehörde.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), access controls, and restriction of database access to authorised personnel and service accounts. We do not collect passwords, payment details or special categories of data through this Site. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Changes

We may update this policy at any time by posting a revised version with a new date. Where a change materially affects waitlist members, we will notify those affected by email.