1. Who handles your request
The data controller for everything described here is SoKKoS AI — eenmanszaak (sole proprietorship in the Netherlands), KvK 42029374, BTW-id NL005441743B74, Beuningen, Gelderland, NL. Contact: [email protected]. We answer GDPR requests ourselves — there is no third-party processor handling them on our behalf.
2. Your rights at a glance
Under the EU General Data Protection Regulation (GDPR), Articles 15–22, you have six rights over the data we hold about you. They apply whether you're an EU/EEA resident or not — we extend them to everyone.
- Access (Art. 15)Ask what we have on you.
- Rectify (Art. 16)Fix anything wrong.
- Erase (Art. 17)Delete your account and data.
- Restrict (Art. 18)Pause processing while a question is open.
- Port (Art. 20)Get a machine-readable copy of your data.
- Object (Art. 21)Object to processing based on legitimate interest.
3. How to exercise each right
Most of these are self-service. For anything that isn't, send a one-line email to [email protected] with the suggested subject line. We don't need a form — we just need to know which right you're invoking.
We may ask you to confirm the request from the email on file (to make sure someone else isn't trying to access your data). That's the only verification step.
4. Our response time
We respond to GDPR requests within 30 days, as required by Art. 12(3). In practice we aim for under a week. If a request is unusually complex, we may extend by up to two months and we'll tell you why before doing so.
No fee for the first request. Manifestly unfounded or repetitive requests may incur a reasonable fee (Art. 12(5)) — this has never happened.
5. Data export
Self-service: go to /dashboard/export and click “Export everything”. You get a tarball with:
- Your agent's state directory — its configuration
(
openclaw.jsonand its backups), workspace, the skills you wrote, memory, identity and its own logs, with credential literals scrubbed and the gateway token removed. - Its databases as live SQLite files — scheduled tasks in
state/, and its sessions, history and embeddings underagents/. - Not in the tarball: the raw per-session model transcripts
(
*.trajectory.jsonl, excluded for size — ask and we send them), your account records (auth, billing metadata, dashboard settings), support conversations and server logs, and any site-chat conversation kept under the retention window in /privacy §7. Ask by email and we send those too — and «GDPR: erase» removes them, including the chat turns.
The archive is built fresh at the moment you ask, and its name carries the date. It is not cryptographically signed. If anything looks missing, email us with “GDPR: access” and we'll regenerate it within 30 days.
6. Account deletion
Request deletion from /dashboard → Settings → “Delete account”, or by emailing us. We action the request within 30 days (GDPR Art. 17). As part of fulfilment we:
- Cancel any active subscription so it does not renew.
- Keep your hosted container available for 14 days so you can still export, then destroy it.
- Delete your auth record.
- Retain only the legally required payment records (7 years, Dutch tax law).
Once the hosted container is destroyed its contents cannot be recovered, so export anything you need during the 14-day window. Need it done faster? Email us and we'll prioritise it.
7. Right to lodge a complaint
If you think we haven't handled your data properly and we can't resolve it by email, you can complain to the Dutch supervisory authority:
Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30, 2594 AV The Hague, NL
autoriteitpersoonsgegevens.nl
Last updated 2026-05-27
You can also lodge a complaint with the supervisory authority in your EU/EEA country of residence if it differs from the Netherlands.