Who we are
Lever AI is the trading name of AgentLayer Systems Private Limited. We build AI agent infrastructure: our platform makes our customers' software products callable by AI agents, and for enterprise engagements our implementation agents configure customers' business platforms (for example, HR systems) on their behalf, with a chat interface for the customer's administrators.
This notice explains what personal data we handle, why, and what your rights are. It covers two different situations, and it matters which one applies to you:
- You are visiting this website— we are the "controller" of the small amount of data involved, and this notice tells you everything.
- Your data is processed inside our service— for example, you are an end-user of a product built by one of our customers, or an employee of a company whose business platform our customer is setting up. Here we act as a "processor": we handle data only on our customer's instructions, and your primary privacy relationship is with them. This notice explains our role honestly, but for requests about that data, the controlling organisation's own privacy notice is the one that governs.
What we collect on this website
If you simply browse the site, we collect little. If you contact us, we receive what you send us: typically your name, work email address, company, and your message. We use it to reply to you and to follow up about our service. We do not use it for anything else without asking.
Cookies and analytics
This website sets no cookies and uses no analytics or tracking tools. Signing in to the product dashboard (a separate application) uses strictly-necessary authentication cookies only — no advertising or analytics cookies.
What we process inside the service
When a customer uses Lever AI, the data flowing through the service belongs to and is controlled by that customer. It can include:
- Customer code and configuration the customer connects to the platform, and the integration artifacts we generate from it;
- Requirement documents the customer uploads (for example Word and Excel files), which may contain employee personal data — names, employee codes, contact details, organisational assignments — and compensation structures;
- Business-platform datawe read and write through the platform's own APIs or interfaces, on the customer's instruction;
- Chat transcriptsof conversations between our agents and the customer's administrators;
- Service credentials the customer provisions so our agents can access their systems, held in a restricted credential store;
- Operational recordsof the service's own activity (usage and cost telemetry, logs).
For all of this data we act as a processor. We process it only to deliver the service the customer has asked for, under a contract with that customer. We do not decide what data goes into the service — our customer does.
Data is sent to our AI provider (Anthropic) to power the agents. We do not train or fine-tune AI models on customer data, and our AI provider's commercial terms exclude customer data submitted through its API from model training by default.
We do not sell personal data. Ever, in either situation.
Who we share data with (subprocessors)
We use a small number of service providers to run Lever AI. The complete list of subprocessors that can touch service data is:
| Provider | What they do for us |
|---|---|
| Microsoft Azure | Cloud hosting and managed data storage |
| Anthropic | AI model API (Claude) that powers our agents |
| GitHub (Microsoft) | Source code hosting and CI — no customer data |
We do not share personal data with anyone else, except where the law requires it or our customer instructs it.
Where data is stored
Our primary data stores run on Microsoft Azure in the United States (West US 2 region). Customers outside the United States should be aware that using the service involves a transfer of their data to the US, covered by the data-processing terms in their contract with us.
Two options exist for customers with residency requirements: a customer-hosted execution mode, in which the execution component runs inside the customer's own infrastructure so platform credentials and in-flight data stay in the customer's environment, and regional Azure deployment on request.
How long we keep data
Our defaults are below. Where a customer's contract sets different terms, the contract always wins.
| Data | How long we keep it |
|---|---|
| Engagement data (conversations, transcripts, uploaded documents, attachments) | Duration of the engagement plus 90 days, then deleted on schedule |
| Operational telemetry | 24 months |
| Application and audit logs | 12 months |
| Backups | Per our cloud provider's managed backup schedule; deleted data ages out of backups within that window |
| Website contact enquiries | As long as needed to handle the enquiry and any follow-up |
When a customer asks us to delete their data, we delete it and verify the deletion within 30 days.
Your rights
Depending on where you live — including under the EU/UK GDPR and India's Digital Personal Data Protection Act, 2023 — you have rights over your personal data, which can include the right to access it, correct it, delete it, restrict or object to its processing, and receive a copy of it.
If your data reached us through our service(for example, it appeared in a document your employer's HR team uploaded), please direct your request to the organisation that controls it. That is not a brush-off: as a processor we genuinely act only on their instructions, and we will assist them promptly with any request they pass to us.
If your data came from this website, contact us directly using the address below and we will handle your request ourselves.
You also have the right to complain to your data protection authority. We would appreciate the chance to resolve any concern first.
Security
We protect data with encryption in transit (TLS) and at rest (AES-256 on our cloud data stores), tenant isolation that refuses cross-customer access to sessions server-side, least-privilege access controls, and engineering safeguards that verify what our agents write. Our full security programme is published at uselever.ai/security.
Contact
For any privacy question or request: hello@uselever.ai
AgentLayer Systems Private Limited (operating as Lever AI)
Changes to this notice
If we change this notice in a way that matters, we will update it here and revise the "last updated" date. Significant changes affecting service customers are communicated to them directly.