Privacy policy
What we collect, why, and how to ask us to delete it.
We collect three categories of data: (1) workspace data you upload (knowledge sources, custom personas, contact lists); (2) conversation data exchanged through inboxes connected to AgentIQ; (3) operational telemetry (latency, error rate, feature usage). Workspace + conversation data is stored in EU-region infrastructure, encrypted at rest, and isolated per organisation.
We do not sell data, and we do not train shared AI models on your conversations. Anthropic Claude calls are made under their Enterprise terms with no training opt-in. Email privacy@xonlabs.co.uk for data-subject requests; we respond within 30 days.
Terms of service
The contract for using AgentIQ.
By creating a workspace, you agree to the standard SaaS terms: pay your invoices, don't abuse the service, take reasonable care with credentials. We agree to keep the service operational, hold your data in confidence, and notify you of any security incident affecting your workspace within 72 hours.
The platform is provided "as-is" during the free trial. Paid plans include the uptime + support commitments listed under the relevant plan tier. Either party can terminate with 30 days' written notice; we'll export your data on request within that window.
Data Processing Addendum
GDPR-aligned data-processing terms for B2B customers.
We act as the data processor when your customers' messages flow through AgentIQ. You remain the data controller. We process data only on your documented instructions, restrict access to personnel who need it, and maintain TOMs (technical & organisational measures) appropriate to the risk — encryption, RBAC, audit logging, incident response.
Sub-processors include cloud hosting (AWS / Hetzner depending on tier), Anthropic for AI inference, SendGrid for transactional email. A current list is available on request; we'll notify customers in advance of any material change.
A signed DPA copy is available on request from legal@xonlabs.co.uk.
Acceptable use policy
What you can't do with AgentIQ.
You must not use AgentIQ to:
- Send unsolicited commercial messages (spam) or violate platform rules (Meta, Twilio, etc.).
- Process payment card data (PCI scope is your responsibility — use a tokenising provider).
- Operate scams, harvest credentials, distribute malware, or facilitate harm.
- Generate AI responses that pretend to be a human agent when explicitly asked. The platform supports persona naming; misrepresentation is your call but is also your liability.
We may suspend or terminate workspaces that breach this policy. We will give you an opportunity to remediate when the breach is unintentional.