Legal›Privacy Policy

Privacy Policy

Effective Date: June 9, 2026

Contents

  1. Overview
  2. Information We Collect
  3. How We Use Information
  4. How We Share Information
  5. Client Data & Model Training
  6. Cookies & Tracking
  7. Data Retention
  8. Security
  9. Your Rights
  10. Children's Privacy
  11. International Transfers
  12. Changes to This Policy
  13. Contact

01Overview

BusinessAIOS LLC ("BusinessAIOS," "we," "us," or "our") is an AI-powered back-office automation platform designed for small and mid-sized businesses. This Privacy Policy describes how we collect, use, share, and protect information in connection with our website at businessaios.com and all related services, software, and platforms (collectively, the "Services").

By using the Services, you agree to the practices described in this Policy. If you do not agree, you should discontinue use of the Services.

This Policy applies to: (a) visitors to our website; (b) clients who subscribe to or purchase our Services; and (c) individuals whose data is processed by our platform on behalf of our clients. It does not apply to third-party websites or services linked from our platform.

02Information We Collect

2.1 Information You Provide Directly

We collect information you provide when you create an account, purchase a subscription, contact us, or otherwise interact with the Services. This includes:

  • Contact information: name, email address, phone number, company name, job title
  • Account credentials: username, password (stored in hashed form)
  • Billing information: payment card details (processed by our payment processor; we do not store raw card data), billing address, and transaction history
  • Communications: messages, support tickets, feedback, and other correspondence you send to us
  • Onboarding data: business information, workflow configurations, integration preferences, and other inputs you provide during setup

2.2 Information We Collect Automatically

When you access the Services, we automatically collect certain technical and usage data, including:

  • Log data: IP address, browser type and version, operating system, referring URLs, pages visited, timestamps, and error logs
  • Device information: device type, screen resolution, language settings, and hardware identifiers
  • Usage analytics: feature interactions, session duration, workflow execution counts, and similar behavioral data used to improve the platform
  • Cookies and similar tracking technologies (see Section 6)

2.3 Information from Third-Party Integrations

BusinessAIOS integrates with platforms such as CRM systems, email providers, telephony services, and marketing tools at your direction. When you connect a third-party integration, we may receive data from that service consistent with your authorization. We process such data solely to deliver the Services you have requested.

2.4 Client-Submitted Data

Clients and their authorized users may upload, transmit, or cause to be processed through the Services data about their own customers, leads, or contacts ("Client Data"). BusinessAIOS acts as a data processor with respect to Client Data. The client remains the data controller responsible for that data. We do not use Client Data for any purpose other than delivering and supporting the Services contracted for by that client.

03How We Use Information

We use the information we collect for the following purposes:

Service Delivery

  • Provision, configuration, and operation of the AI automation platform and all contracted services
  • Executing automated workflows, CRM updates, voice agent interactions, email sequences, and related tasks on your behalf
  • Processing payments and managing your subscription and billing history

Platform Improvement

  • Diagnosing bugs, improving system reliability, and optimizing performance
  • Analyzing aggregated, de-identified usage patterns to develop new features and capabilities
  • Conducting internal research and testing on platform functionality

Communications

  • Sending transactional communications (receipts, service notifications, security alerts)
  • Providing customer support and responding to inquiries
  • Delivering product updates, change notices, and policy modifications
  • Sending marketing communications where you have consented or where we have a legitimate interest, with opt-out available at any time

Legal and Compliance

  • Detecting and preventing fraud, unauthorized access, and abuse of the platform
  • Complying with applicable laws, regulations, and legal process
  • Enforcing our Terms of Service, Acceptable Use Policy, and other agreements

04How We Share Information

We do not sell your personal information. We do not share your personal information with third parties for their own independent marketing purposes. We may share information in the following limited circumstances:

4.1 Service Providers and Subprocessors

We engage vetted third-party vendors who process data on our behalf to deliver the Services. These include cloud infrastructure providers, payment processors, email delivery services, telephony platforms, analytics tools, and customer support systems. All subprocessors are bound by data processing agreements that restrict use of your data to the performance of services for BusinessAIOS.

4.2 At Your Direction

When you authorize integrations with third-party platforms or instruct us to transmit data to external systems, we will share data as directed. You are responsible for reviewing the privacy practices of those third-party platforms.

4.3 Legal Requirements and Safety

We may disclose information if we believe in good faith that disclosure is required by applicable law, regulation, subpoena, court order, or governmental demand; or is necessary to protect the rights, property, or safety of BusinessAIOS, our clients, or the public.

4.4 Business Transfers

If BusinessAIOS is involved in a merger, acquisition, asset sale, or similar transaction, client and user data may be transferred as part of that transaction. We will provide notice before your personal information becomes subject to a materially different privacy policy.

4.5 With Your Consent

We may share information in other circumstances when you have given explicit consent.

05Client Data & Model Training

5.1 No Training on Client Data

BusinessAIOS does not use Client Data—including any data submitted by clients or processed through automated workflows on clients' behalf—to train, fine-tune, or otherwise improve any AI or machine learning model, whether operated by BusinessAIOS or any third party, without explicit written consent from the applicable client.

5.2 AI Processing of Client Data

Our platform may use AI inference capabilities to execute tasks you have configured, such as generating responses, classifying records, or drafting communications. These inference operations are performed in service of your workflows. Any underlying language model processing is governed by applicable subprocessor agreements and does not result in your data being used for model training absent your express consent.

5.3 Platform Usage Data

Aggregated, de-identified telemetry and usage patterns—data from which individual identities and client-specific content have been removed or obscured—may be used to improve BusinessAIOS platform performance and develop new capabilities. No personal information or identifiable Client Data is used for this purpose.

5.4 High-Stakes Decision Restrictions

Our Acceptable Use Policy prohibits use of the platform as the sole decisional factor in high-stakes determinations covered by applicable law, including decisions related to credit, employment, housing, insurance, education, or healthcare, without appropriate human oversight and compliance with relevant regulations (including FCRA, ECOA, FHA, and ADA where applicable).

06Cookies & Tracking

6.1 Types of Technologies We Use

We use the following types of cookies and similar technologies on our website and platform:

  • Essential cookies: Required for the operation of the Services, including session management and authentication. Cannot be disabled without impairing functionality.
  • Functional cookies: Remember your preferences and settings across sessions.
  • Analytics cookies: Collect aggregated data about how visitors interact with our site to help us understand usage patterns and improve performance.
  • Marketing cookies: Used on our marketing website (not the platform application) to understand campaign effectiveness. Not used to build advertising profiles for sale to third parties.

6.2 Your Cookie Choices

You may control cookies through your browser settings. Most browsers allow you to refuse new cookies, delete existing cookies, or be notified when cookies are set. Note that disabling essential cookies will impair your ability to use the Services.

We honor Global Privacy Control (GPC) signals as a valid opt-out of sale or sharing of personal information under applicable state law. If your browser transmits a GPC signal, we will treat it as a request to opt out of any data sale or cross-context behavioral advertising where required by law.

We do not respond to Do Not Track (DNT) browser signals, as there is no universally accepted standard for DNT compliance at this time.

07Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Our general retention guidelines are:

  • Account and contract data: Retained for the duration of the client relationship plus 7 years to satisfy tax, accounting, and legal compliance obligations.
  • Client Data (workflow data, contact records, automation outputs): Retained for the duration of the applicable subscription. Upon contract termination, clients may request export of their data within 30 days of termination. After 30 days, Client Data is deleted from active systems within 90 days and from backup systems within 180 days.
  • Usage and log data: Retained for up to 24 months in identifiable form, then aggregated or deleted.
  • Marketing and communications data: Retained until you opt out or withdraw consent, plus a reasonable period for compliance documentation.

You may request deletion of your personal information at any time (see Section 9). We will honor deletion requests subject to legal hold obligations and other lawful retention requirements.

08Security

BusinessAIOS implements and maintains a comprehensive information security program designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our measures include:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of sensitive data at rest using industry-standard algorithms
  • Access controls and role-based permissions limiting data access to authorized personnel with a legitimate business need
  • Multi-factor authentication requirements for administrative and privileged access
  • Regular security assessments, penetration testing, and vulnerability management
  • Incident response procedures with defined notification timelines

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information using commercially reasonable means, we cannot guarantee absolute security. In the event of a data breach that triggers statutory notification obligations, we will notify affected individuals and relevant authorities as required by applicable law.

09Your Rights

9.1 General Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to lawful retention requirements.
  • Portability: Request a machine-readable copy of personal information you have provided to us.
  • Objection / Restriction: Object to or request restriction of certain processing activities.
  • Opt-Out of Sale or Sharing: Opt out of the sale or sharing of your personal information for cross-context behavioral advertising (we do not engage in such practices, but you may assert this right through a GPC signal or written request).

9.2 California Residents (CCPA/CPRA)

California residents have the rights listed above, plus the right to opt out of the sale or sharing of personal information, the right to limit use of sensitive personal information, and the right to non-discrimination for exercising privacy rights. We do not sell personal information. To submit a California privacy request, contact us at privacy@businessaios.com.

9.3 Residents of Virginia, Colorado, Connecticut, and Other U.S. States

Residents of states with comprehensive privacy laws in effect—including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon, Texas, and others—may exercise the rights described in Section 9.1 above. BusinessAIOS processes privacy requests consistently across applicable state laws, applying the most protective standard reasonably available.

9.4 How to Submit a Request

To exercise any of the above rights, submit a request to privacy@businessaios.com with subject line "Privacy Request." We will verify your identity before processing your request and will respond within 45 days (extendable by an additional 45 days with notice where permitted by law). We do not charge a fee for reasonable requests.

10Children's Privacy

The Services are intended for use by businesses and business professionals. We do not knowingly collect personal information from individuals under the age of 18. If you are a parent or guardian and believe that a minor has provided us with personal information, please contact us at privacy@businessaios.com and we will promptly delete that information from our systems.

11International Transfers

BusinessAIOS is based in the United States. Personal information we collect is processed and stored on servers located in the United States. If you access the Services from outside the United States, your information will be transferred to, processed in, and stored in the United States, which may have data protection laws that differ from those in your country.

Where required by applicable law, we rely on lawful transfer mechanisms for cross-border data transfers, including Standard Contractual Clauses approved by relevant data protection authorities. By using the Services from outside the United States, you acknowledge and consent to this transfer and processing.

12Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the Effective Date at the top of this Policy
  • Post the revised Policy on our website at businessaios.com/legal
  • Provide notice via email or in-platform notification for changes that materially affect how we use your personal information

Your continued use of the Services following notice of changes constitutes acceptance of the updated Policy. If you do not agree to the updated terms, you should discontinue use of the Services and may request deletion of your account per Section 9.

13Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

BusinessAIOS LLC
Attn: Privacy
1626 Central Ave
Cheyenne, WY 82001

Email: privacy@businessaios.com
Website: businessaios.com/legal

Related Policies

Terms of Service Acceptable Use Policy Refund & Cancellation Policy Contact Us