Five things, in writing. Here's the writing.
This is the document the commitments block on the homepage points to — the five commitments as contract terms, what the Watchdog agents actually do with your account, and the company details required to sell these services in the EU.
Draft, published in good faith rather than held back for a formal legal review. If anything here needs clarifying before you rely on it, email hello@agencyrebuilt.com.
Who you're contracting with
Agency Rebuilt is a service of Mersey Cloud Kft, trading under its own name for its build, fix and account oversight work. Invoices and contracts are issued by Mersey Cloud Kft.
The five commitments, as contract terms
These terms govern all three services: Build, Fix, and Watchdog (every tier, and the Account Check). They're the same five commitments from the homepage, stated as terms rather than marketing copy. Build and Fix work is additionally governed by the written scope and quote agreed before it starts.
Nothing changes without your approval
The IAM role we ask you to create for Watchdog and the Account Check is read-only. It cannot create, modify, or delete anything in your AWS account. Fix work, and Build work in your account, is the only exception: write access is granted explicitly by you, scoped to the specific job, and revoked at the end of it — never left standing. Fixes offered from a Watchdog digest are proposals; nothing is changed until you approve the quoted job.
Quoted before we start, no setup fee
Build and Fix work is scoped and quoted in writing before anything starts. Watchdog onboarding is one IAM role and a fifteen-minute call, at no charge, on any tier.
Cancellation
Retainer tiers (Watchdog Auto, Reviewed, Priority) run month-to-month with no minimum term. Either party may end the retainer on 7 days' written notice (an email is sufficient). The Account Check is a one-off engagement, not a retainer, and completes on delivery of the findings.
No results guarantee
We do not promise cost savings, a specific number of findings, or an incident-free period. The commitment is that the agreed agents run on the agreed schedule, and you see the output — the digest, delivered, whatever it contains.
The same people, not a ticket queue
On Watchdog Reviewed and Priority, someone reviews every digest before it reaches you and answers email questions directly. There is no support portal, no tier-one queue, and no handover to someone else partway through an engagement.
Fees & invoicing
Watchdog and Account Check prices are as published on this site, excluding VAT, and are per AWS account — an AWS Organizations setup with several accounts is quoted for the set. Retainer tiers are invoiced monthly in advance. The Account Check is paid upfront via the Stripe payment link on this site. Fix work is scoped and quoted before anything starts, and invoiced on completion; the €800/day figure on this site is a guide price, not a fixed rate. Build work is quoted per project, with payment terms set out in the quote. Invoices are payable within 14 days.
Prices exclude VAT. Reverse charge applies for VAT-registered business clients outside Hungary.
Liability
Agency Rebuilt provides its services with reasonable skill and care, based on the read-only access granted and the information available at the time. Findings and recommendations reflect professional judgment when given and are not a guarantee of any technical or business outcome. Agency Rebuilt is not liable for indirect or consequential loss. Total liability arising from an engagement is capped at the fees paid for that engagement in the three months preceding the claim, except where liability cannot be limited by law.
Governing law
These terms are governed by Hungarian law. Any dispute not resolved by agreement is subject to the jurisdiction of the Hungarian courts.
What the Watchdog agents actually do
Eight AI agents read specific, scoped parts of your AWS account and produce a written digest. This is what that means in concrete terms.
What the agents read
Only what the read-only IAM role exposes: billing and Cost Explorer data, GuardDuty and Security Hub findings, IAM configuration (users, roles, access key age, MFA status), backup and snapshot metadata, certificate and domain expiry, and resource configuration relevant to resilience checks (single-AZ dependencies, missing alarms). The role cannot read application data, database contents, or object storage contents unless a specific engagement scope says otherwise.
Where it's processed
The configuration and metadata above is pulled through the IAM role and processed on our infrastructure to produce the findings. It is not copied to any other party except where a commercial LLM is used to help generate the written findings, described below.
What is sent to the model provider
Only the configuration and metadata described above — never the contents of a data store (no object storage contents, no database rows, no application data). A finding like "S3 bucket X allows public read" is generated from the bucket's configuration; the contents of that bucket are never read, and never sent anywhere.
Which models are used
Commercial large language models (currently Anthropic's Claude) process the configuration and metadata described above to generate findings, under terms where customer data is not used to train any model — this is a contractual commitment, not just a technical default.
What is stored, and for how long
The findings and digests produced from that processing — not the raw configuration data itself. Stored to produce the monthly (or weekly, on Priority) comparison and to answer follow-up questions about a previous finding. Retained for the life of the engagement plus 12 months, then deleted. You can request earlier deletion at any time.
Sub-processors
Parties who touch data in the course of delivering this service:
A data processing agreement is available on request.
The IAM boundary, concretely
You create a cross-account role from a policy we provide, built primarily on AWS's own SecurityAudit and ViewOnlyAccess managed policies, with additional read access to Cost Explorer and billing where those two policies don't already cover it — named here so the claim is checkable against your own account rather than taken on trust. These are broad read-only policies: they cover configuration and metadata (IAM setup, security findings, resource inventory, billing) without granting the ability to read the contents of your data stores — unlike AWS's broader ReadOnlyAccess policy, which also permits reading object and record contents. They can still expose configuration values that hold secrets (for example Lambda environment variables, EC2 user data, or ECS task definitions); we don't currently apply extra Deny statements narrowing that, so treat the role as able to see anything AWS classes as "configuration," not only the categories in the paragraph above. The role is assumed using an external ID, the standard AWS safeguard against a third party being tricked into acting on the wrong account. You can revoke access at any time by deleting the role in your own AWS console — no action on our side is required for that to take effect immediately.
Personal data in scope
Account configuration data is mostly not personal data, but IAM user names, resource tags, and billing contact details can be. Where that happens, it's processed under the same read-only, no-training terms as everything else, and covered by the privacy notice below.
No automated changes, ever
The agents inspect and report. They do not modify your account. If a finding needs fixing, we offer Fix work — a separate, quoted, hands-on engagement that starts only when you approve it, with its own explicitly granted and revoked write access. Never an automatic action taken on the strength of a finding.
What this website collects
This section covers agencyrebuilt.com itself — the website, not the AWS account data described above (that's the data-handling section).
Data controller
Analytics (Google Analytics 4)
If you accept cookies, we use Google Analytics 4 to collect pseudonymised usage data — pages visited, time on site, device type, approximate location. Legal basis: consent (Art. 6(1)(a) GDPR). Processor: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Retention: 14 months (we haven't independently re-verified this against the current GA4 property setting; treat it as the intended, not confirmed, value). If you decline, no analytics data is collected. Withdraw consent at any time via "Cookie settings" in the footer.
Cookies used on this site
| Name | Purpose | Duration | Set when |
|---|---|---|---|
| cookie-consent | Remembers your cookie choice (accepted/rejected). Stored in your browser's local storage, not a cookie. | Until cleared | Always (as soon as you choose) |
| _ga | Google Analytics — distinguishes users | 13 months | Only if you accept |
| _ga_<container-id> | Google Analytics 4 — persists session state | 13 months | Only if you accept |
Payment (Stripe)
If you use the Account Check payment link, Stripe processes your payment details, billing address, and (where required) VAT information directly — this data does not pass through or get stored on agencyrebuilt.com. Legal basis: contract performance (Art. 6(1)(b) GDPR). Processor: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland.
Booking (Cal.com)
If you book a call, Cal.com processes your name, email, and the meeting details you provide. Legal basis: contract performance / legitimate interest in scheduling the call you requested (Art. 6(1)(b)/(f) GDPR). Processor: Cal.com, Inc.
Your rights
Under the GDPR you have the right to access, rectify, or erase your personal data, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. To exercise any of these, email hello@agencyrebuilt.com.
Supervisory authority
Questions about any of this before booking or paying — book a call or email hello@agencyrebuilt.com.
Last updated: September 2026.