Legal
Privacy Policy
Plain-English summary below. The full legal text is available on request. Last updated May 2026.
Summary
What we collect
Account data (name, email, workspace), product telemetry (feature usage, error events), and policy-decision metadata when you use the engine. We do not retain prompt content or PII passing through customer policies beyond the retention window you configure.
How we use it
To operate the service, secure it, bill you, improve the product, and support your team. We don't sell your data, and we don't use customer policy or audit data to train models.
Marketing & lead data
When you contact us, request an assessment, or submit a form or ad — including LinkedIn Lead Gen Forms — we collect the details you provide, typically your name, work email, job title, company, and answers to any questions. We use this to respond to your request (for example, to scope your Agent Exposure Assessment), to contact you about our products and services, and for related marketing. We rely on your consent and, where applicable, our legitimate interest in business outreach. In Canada, we send commercial electronic messages only with consent, as required by CASL. You can unsubscribe from marketing at any time via the link in our emails or by emailing privacy@boundaryai.ai. We keep prospect data only as long as needed for these purposes, then delete or anonymise it.
Sub-processors
Cloud infrastructure, email delivery, analytics, and support tooling. A current list is available in the trust center under NDA.
Retention
Customer-configurable per workspace. Default 90 days for hosted audit; longer on Business and above. Account data retained for the life of the contract plus 30 days.
Your rights
Access, export, correction, and deletion on request. Email privacy@boundaryai.ai. GDPR / CCPA / UK DPA rights honored.
Security incidents
We notify affected customers without undue delay and in line with applicable law. See our Security page for our controls.
Questions? privacy@boundaryai.ai