Privacy Policy

Last updated: September 2026

Executive Privacy Summary

At XELVANT, enterprise trust is our core foundation. We build and deploy autonomous AI digital workers. We never sell your proprietary data, we never use your proprietary client conversations to train public base models, and all system memories remain strictly confined within your enterprise tenant.

1. Data Collection

We collect information to provide, configure, monitor, and optimize your autonomous AI workforce. When you interact with XELVANT, deploy an agent, or integrate our software with your company infrastructure, we collect only the necessary data required to deliver reliable operational execution.

Specifically, data collected by XELVANT and its agent orchestrators includes:

  • Contact & Account Identifiers: Email addresses, representative names, company domain names, billing addresses, and secure authentication tokens.
  • Usage & Telemetry Analytics: Dashboard interaction data, agent runtime logs, click counts, execution timestamps, and error incident rates.
  • Agent Workflow Inputs: Prompts, customer ticket texts, and operational data submitted to the agent for task execution and resolution.
  • CRM & Tool Synchronization Metadata: Webhook payloads, status updates, appointment bookings, and lead attribution parameters.
  • System Diagnostics: IP addresses, browser runtime environments, device information, and latency metrics.

2. Use of AI Agents & Model Processing

XELVANT agents leverage frontier reasoning models and proprietary logic orchestrators. By design, runtime information processed by our AI employees is executed through enterprise zero-retention agreements with certified model inference providers.

Your proprietary business inputs, sensitive client communications, and database schemas are never indexed into public foundation model corpora or used to train third-party machine learning models without your explicit, written consent.

3. Client Responsibilities & Safeguards

As a client deploying autonomous AI agents into your business operations, you maintain sovereign control over your enterprise data feeds. You are responsible for ensuring that:

  • You possess appropriate rights and legal bases to process any consumer personal data ingested by the agents.
  • Secret keys, API tokens, and webhook signatures granted to your XELVANT agents are maintained under secure access controls.
  • Your end-users and customers are notified of automated AI processing where mandated by local jurisdictions (such as GDPR, CCPA, or regional AI regulations).

4. Data Security & Encryption Standards

All data transmitted between your services, your users, and XELVANT agent orchestrators is encrypted in transit using TLS 1.3 cryptographic protocols. Stored data, vector database embeddings, and audit logs are protected using industry-standard AES-256 encryption at rest.

Access to production systems is guarded by hardware multi-factor authentication, least-privilege role-based access control (RBAC), and continuous threat monitoring.

5. Third-Party Integrations

When enabled by you, XELVANT agents communicate directly with approved third-party platforms, such as HubSpot, Apollo, Cal.com, WhatsApp Business API, Slack, and QuickBooks. We are not responsible for the independent data handling practices of external third parties once data is transferred outside our infrastructure per your workflow instructions.

6. Data Retention & Deletion

We retain personal data and agent execution telemetry only as long as necessary to fulfill contractual obligations, resolve operational anomalies, and comply with legal requirements. You may request complete erasure of your tenant data, logs, and agent vector databases at any time by contacting our data protection team.

7. Contact & Inquiries

If you have any questions, compliance inquiries, or data privacy requests regarding this Privacy Policy or XELVANT's data handling practices, please contact our Data Governance Officer at:

XELVANT Data Protection Office

Email: [email protected]

Subject: Data Privacy & Governance Inquiry