| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | June 2026 |
| Next review | June 2027 |
| Classification | Public |
1. Purpose
This policy sets out how Lever AI protects personal data and the principles it follows when handling it. It supports the company's obligations under the EU and UK General Data Protection Regulation, the Indian Digital Personal Data Protection Act, 2023, and equivalent laws.
2. Scope
This policy applies to all personal data the company processes, in any capacity, and to all personnel and processors acting on its behalf.
3. Our role
For the services it provides, Lever AI generally acts as a processor, handling personal data on behalf of its customer, who is the controller. In that capacity the company processes personal data only on the customer's documented instructions and only to provide the service. Lever AI is a controller for the limited personal data it holds about its own staff and business contacts.
4. Principles
Lever AI processes personal data lawfully, fairly, and transparently; only for specified purposes; limited to what is necessary; kept accurate; retained no longer than needed; and protected with appropriate security. The company keeps records sufficient to demonstrate its compliance.
5. Privacy by design
The service is built to minimise the personal data it touches. It is stateless: it does not store customer credentials, does not store access or refresh tokens, and does not retain end-user personal data. HR data is processed only for the duration of a request. Users enter their credentials directly into the connected system's own login, so the company never receives a user's password. Any transfer of data to an AI provider is carried out by the user's own AI client under the user's agreement with that provider; the service itself does not send data to an AI provider. Logs contain operational information only and never the content of requests or responses.
6. Instructions and agreements
As a processor, Lever AI processes personal data only on the documented instructions of the customer, as recorded in the services agreement and any Data Processing Agreement. The company enters into a Data Processing Agreement with customers where required.
7. Rights of individuals
Lever AI supports the rights individuals hold under applicable law, including access, correction, and erasure. Because the company usually acts as a processor and holds little or no personal data at rest, requests are ordinarily routed to the controller, whom Lever AI assists in responding within the required timeframes.
8. International transfers
Where personal data is transferred across borders, the company relies on an appropriate transfer mechanism and records it. The service is hosted on Microsoft Azure.
9. Sub-processors
Lever AI maintains a list of sub-processors and places data-protection obligations on them by contract. The primary sub-processor is Microsoft Azure. The end user's AI provider is engaged by the user and is not a Lever AI sub-processor.
10. Breach management
Suspected breaches are reported immediately and handled under the Incident Response Policy. Where a breach affects personal data, the company notifies the affected controller without undue delay and assists with any regulatory notification, including notification to a supervisory authority within 72 hours where the GDPR applies, and to the Data Protection Board and affected persons as required under the DPDP Act.
11. Retention and disposal
Personal data is retained only as long as necessary for its purpose or as required by law, and is then securely deleted. Given the stateless design of the service, the data in scope is limited.
12. Classification
| Class | Examples | Handling |
|---|---|---|
| Public | Marketing material | No restriction |
| Internal | Internal documents, operational logs | Limited to personnel |
| Confidential | Customer data processed in transit | Least privilege, encrypted in transit |
| Restricted | Secrets, keys, credentials | Vault-managed, never logged |
13. Responsibilities
The Data Protection lead oversees this policy. Everyone who handles personal data is responsible for following it.
14. Review
This policy is reviewed at least annually and whenever there is a relevant legal or business change.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI