Privacy Policy
Last updated: July 2026
1. Information We Collect
When you use BusinessOS, we collect information you provide directly:
- Account Information: Name, email address, and password when you register.
- Organization Information: Business name, address, and billing details.
- Contact Data: Names, email addresses, phone numbers, and other information you store about your contacts.
- Communications: Emails, SMS messages, and call recordings sent or received through our platform.
- Phone Numbers: Numbers purchased through BusinessOS, call metadata (duration, direction, timestamps), and routing configuration.
- Payment Information: Billing information is processed and stored by Stripe. We do not store full credit card numbers.
- AI Interactions: Prompts, responses, and decisions generated by AI agents operating on your data.
- Enterprise Identity Data: When you configure SSO, SCIM, or LDAP, we store your external identity provider user ID, provider organization ID, authentication provider type, and sync metadata to maintain the link between your BusinessOS account and your identity provider.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve BusinessOS features and functionality.
- Process billing, manage subscriptions, and maintain credit balances.
- Route voice calls and deliver SMS messages through our telephony provider.
- Power AI agents that analyze your data to generate suggestions, summaries, and recommendations.
- Send technical notices, security alerts, and support messages.
- Respond to your comments, questions, and support requests.
- Monitor and analyze usage patterns to improve our platform.
- Authenticate you via your configured identity provider and synchronize user accounts when SSO, SCIM, or LDAP is enabled.
3. AI Processing
BusinessOS uses AI agents to process your data:
- AI agents may analyze your contacts, communications, pipeline, and usage patterns to provide suggestions and automation.
- AI-generated content and recommendations are derived from your data and the instructions you provide to each agent.
- You control which AI agents are active and can configure approval modes (auto, suggest, or assist) for each agent.
- AI processing occurs on our infrastructure. We do not sell or share AI outputs with third parties.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Third-party services that help us operate — Stripe (payments), Telnyx (telephony/SMS), Firebase (file storage, authentication), and Supabase (database). These providers are contractually bound to protect your data.
- Identity Providers: When you configure SSO, SCIM, or LDAP, BusinessOS communicates with your identity provider (Microsoft Entra ID, Google Workspace, Okta, or your LDAP/AD server) to authenticate users and synchronize account data. Only the minimum data required for authentication and provisioning is exchanged.
- Legal Requirements: If required by law or to protect our rights, we may disclose information to authorities.
- Organization Members: Data within an organization is accessible to its members according to their role permissions.
5. Call Recordings and Communications
BusinessOS records and stores communications made through the platform:
- Voice call recordings are stored in your organization's cloud storage and can be downloaded or deleted at any time.
- SMS message content is stored to maintain conversation history and enable AI analysis.
- Call metadata (duration, direction, phone numbers, timestamps) is logged for analytics and billing.
- You are responsible for obtaining necessary consent from call participants before recording, in compliance with applicable laws.
6. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS 1.3.
- Data at rest is encrypted using AES-256.
- Two-factor authentication is available for all accounts.
- Role-based access controls within organizations (Owner, Admin, Manager, Member).
- Webhook payloads are verified using HMAC signatures.
- API keys and credentials are encrypted at rest.
- Enterprise identity provider credentials (OAuth client secrets, SCIM bearer tokens, LDAP bind passwords) are stored encrypted and are never exposed in the admin interface.
- SCIM provisioning events are logged with timestamps, actor identity, and action details for audit purposes.
7. Data Retention
We retain your data for as long as your account is active. Upon account cancellation:
- Your data will be retained for 30 days to allow for data export.
- After 30 days, your data will be permanently deleted from our systems.
- Call recordings are deleted along with your other data.
- Backup copies are purged within 90 days of account deletion.
- Enterprise identity data (external user IDs, provider metadata, SCIM logs) is deleted along with your account data. SCIM provisioning logs are retained for 90 days for audit purposes before deletion.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Export your data in a portable format (CSV/JSON) via the platform's built-in export tool.
- Withdraw consent for data processing where applicable.
- Request deletion of specific records (contacts, communications, call recordings) at any time.
- Request disconnection of your enterprise identity provider integration, which will remove stored external identity data and revert your organization to BusinessOS-managed authentication.
To exercise these rights, contact us at tech@jamdriveja.com.
9. Cookies and Tracking
We use minimal cookies:
- Session cookies: Required for authentication and maintaining your logged-in state.
- CSRF tokens: Protect against cross-site request forgery attacks.
- SSO session cookies: When using SSO, your browser stores a session cookie after successful authentication with your identity provider. This cookie is used only to maintain your authenticated session.
- We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
10. Contact
For privacy-related inquiries, please contact us at tech@jamdriveja.com.