⚠ DRAFT FOR REVIEW — placeholder wording, not yet reviewed by a solicitor. This is not legal advice.

Draft for review · not legal advice

Privacy Policy

Version: draft · Last reviewed: — · Owner: Staffgent

How Staffgent handles personal data for the founding beta. This draft describes current practice and must be reviewed by a privacy adviser before publication.

Who we are

Staffgent is a managed AI Employee service (“we”, “us” — the operating legal entity will be stated here at review). We provide a managed AI “employee” that researches leads, scores them, drafts replies and updates a private CRM for each client organisation.

The data we process

  • Account data: the name, email and role of each invited user, and login/session records.
  • Client business data: the leads, opportunities, tasks, notes and reports created for your organisation.
  • Lead/prospect data: business information about the companies your AI employee researches, drawn from public sources.
  • Billing data: subscription and payment status held by our payment processor (Stripe). We do not store full card numbers.
  • Operational data: audit logs, usage/metering records and support notes needed to run the service safely.

Why we process it (purpose & lawful basis)

  • To provide the service you asked for (performance of a contract).
  • To keep the service secure, prevent abuse and meet our legal/accounting obligations (legitimate interests / legal obligation).
  • We do NOT sell personal data, and we do NOT use client data to contact prospects on your behalf — the service prepares work for your approval only.

Roles: controller and processor

For your account and billing data we act as a data controller. For the client business data and lead/prospect data inside your workspace, you are the controller and we act as your processor — the draft Data Processing Addendum outline sets out those terms.

Sharing & subprocessors

We share data only with the subprocessors needed to run the service (hosting, payments, the AI execution worker). See the Subprocessor list. We never share your data for advertising.

International transfers

Some subprocessors may process data outside the UK/EEA. Where they do, appropriate safeguards (such as standard contractual clauses) are to be confirmed during review.

Retention

  • Your workspace data is retained while your organisation is active.
  • On offboarding, data is retained for a configurable grace period (default 30 days) before a confirmed deletion or anonymisation.
  • Billing, invoicing and audit records are retained for longer where required for tax, accounting and dispute resolution.

Your rights

Individuals may request access, correction, deletion, restriction or portability of their personal data, and may object to certain processing. We provide an organisation data export and a deletion/anonymisation workflow. Contact the organisation owner or us to make a request; deletion of shared billing/audit records may be limited where retention is legally required.

Security

Access is private to each organisation and role-based; every organisation’s data is isolated per tenant and enforced server-side. See the Security overview for detail.

Contact

To exercise a right or ask a question, contact your organisation owner or the Staffgent OS team. A monitored contact address will be inserted here before publication.