Legal
Data processing agreement
Last updated: May 15, 2026
When we run a virtual employee, the client is the data controller and AIXEL is the processor. This page is the substance of our processing terms in plain language. A signed agreement is provided before any paid engagement begins.
Subject and duration
We process personal data only to provide the virtual employee service, for as long as the client's workspace exists, and on the client's documented instructions. Instructions given through the product - what to write, what to publish, who to talk to - count as documented instructions.
Categories of data and people
Data subjects: the client's own team members who use the product, and people whose names appear in content or in public comments under published posts. Categories: account identities, messages exchanged with the employee, content drafts and their history, memory the employee holds about people it works with, and delivery records.
Security
Data is isolated per client at the database level and enforced by row-level security, not only by application code. Credentials are stored under envelope encryption and are never exported, logged or shown in the interface. Access by AIXEL staff to client content requires the client to open support access themselves, for a limited period and with a reason, and every such read is written into the client's own audit log.
Subprocessors
The current list is published on this site and generated from the system itself. We remain responsible for their performance. We notify clients before adding a subprocessor that would process their content, and a client may object.
Rights of data subjects
The product supports erasure of a specific person, including what the employee remembers about them, without deleting the rest of the workspace. Access and portability are covered by the export described below.
Export and deletion
A client can export everything at any time, in one file: content and every version of it, memory, goals, plans, measurements, reports, the activity log and settings. Credentials are deliberately not included - they are the client's own keys, and putting them in a file would place them somewhere they have never been. On request we delete the workspace permanently; deletion is irreversible, so we confirm with the client before carrying it out.
No training on client data
We do not use client data to train models, ours or anyone else's, and we use model providers in modes without training retention.
Breach notification
We notify affected clients without undue delay after becoming aware of a personal data breach, with what we know at the time rather than waiting until the picture is complete.