Trust & Security · Policy 02 of 21

Data Protection and Privacy Policy

How Lever AI protects personal data, aligned to the GDPR and the DPDP Act, 2023.

EntityAgentLayer Systems Private Limited (Lever AI)
Document ownerSecurity and Compliance, Lever AI
Approved byKshitij Arora, Founder, Lever AI
Effective dateJune 2026
Next reviewJune 2027
ClassificationPublic

1. Purpose

This policy sets out how Lever AI protects personal data and the principles it follows when handling it. It supports the company's obligations under the EU and UK General Data Protection Regulation, the Indian Digital Personal Data Protection Act, 2023, and equivalent laws.

2. Scope

This policy applies to all personal data the company processes, in any capacity, and to all personnel and processors acting on its behalf.

3. Our role

For the services it provides, Lever AI generally acts as a processor, handling personal data on behalf of its customer, who is the controller. In that capacity the company processes personal data only on the customer's documented instructions and only to provide the service. Lever AI is a controller for the limited personal data it holds about its own staff and business contacts.

4. Principles

Lever AI processes personal data lawfully, fairly, and transparently; only for specified purposes; limited to what is necessary; kept accurate; retained no longer than needed; and protected with appropriate security. The company keeps records sufficient to demonstrate its compliance.

5. Privacy by design

The service is built to minimise the personal data it touches. It is stateless: it does not store customer credentials, does not store access or refresh tokens, and does not retain end-user personal data. HR data is processed only for the duration of a request. Users enter their credentials directly into the connected system's own login, so the company never receives a user's password. Any transfer of data to an AI provider is carried out by the user's own AI client under the user's agreement with that provider; the service itself does not send data to an AI provider. Logs contain operational information only and never the content of requests or responses.

6. Instructions and agreements

As a processor, Lever AI processes personal data only on the documented instructions of the customer, as recorded in the services agreement and any Data Processing Agreement. The company enters into a Data Processing Agreement with customers where required.

7. Rights of individuals

Lever AI supports the rights individuals hold under applicable law, including access, correction, and erasure. Because the company usually acts as a processor and holds little or no personal data at rest, requests are ordinarily routed to the controller, whom Lever AI assists in responding within the required timeframes.

8. International transfers

Where personal data is transferred across borders, the company relies on an appropriate transfer mechanism and records it. The service is hosted on Microsoft Azure.

9. Sub-processors

Lever AI maintains a list of sub-processors and places data-protection obligations on them by contract. The primary sub-processor is Microsoft Azure. The end user's AI provider is engaged by the user and is not a Lever AI sub-processor.

10. Breach management

Suspected breaches are reported immediately and handled under the Incident Response Policy. Where a breach affects personal data, the company notifies the affected controller without undue delay and assists with any regulatory notification, including notification to a supervisory authority within 72 hours where the GDPR applies, and to the Data Protection Board and affected persons as required under the DPDP Act.

11. Retention and disposal

Personal data is retained only as long as necessary for its purpose or as required by law, and is then securely deleted. Given the stateless design of the service, the data in scope is limited.

12. Classification

ClassExamplesHandling
PublicMarketing materialNo restriction
InternalInternal documents, operational logsLimited to personnel
ConfidentialCustomer data processed in transitLeast privilege, encrypted in transit
RestrictedSecrets, keys, credentialsVault-managed, never logged

13. Responsibilities

The Data Protection lead oversees this policy. Everyone who handles personal data is responsible for following it.

14. Review

This policy is reviewed at least annually and whenever there is a relevant legal or business change.

Approval and adoption

This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.

Kshitij Arora

Founder, Lever AI