1. Who we are
This Privacy Policy explains how BossBack collects, uses, discloses, retains, and protects personal information when you visit bossback.ai, contact us, use a BossBack account, or interact with a BossBack capability on a customer’s website.
For privacy questions or requests, contact the BossBack Privacy Officer at [email protected].
2. Who this policy covers
- BossBack customers and account users — business owners, employees, or representatives who use BossBack.
- Website visitors and prospective customers — people who visit bossback.ai, use the contact form, or communicate with us.
- End users of customer websites — people who interact with BossBack Answers or another BossBack capability on a customer’s website.
Customer websites have their own privacy responsibilities. The customer decides why it is using BossBack and is responsible for notices and consent required for its website and use case. BossBack processes end-user information to provide and secure the service and, where applicable, acts as a service provider or processor for the customer.
3. Information we collect
Information provided directly
- Name, email, business name, website, inquiry type, and message content.
- Account and profile information.
- Business information and Sources a customer provides, approves, connects, or asks BossBack to use.
- Support correspondence.
- Billing and transaction information when paid billing is enabled. Payment-card details are intended to be handled by the payment provider rather than stored by BossBack.
The public contact form sends submissions to BossBack through a local contact service and Microsoft 365 email. The contact-form service does not maintain a separate submission database.
Answers conversations
- Questions, messages, and conversation content submitted by an end user.
- BossBack responses and relevant approved business information.
- Contact or lead details an end user voluntarily submits.
- Timestamps and limited technical data needed to operate, secure, and troubleshoot the service.
BossBack customers may review recent conversations involving their own website so they can understand customer questions and follow up where appropriate.
Technical information
BossBack and its infrastructure providers may process IP addresses, request details, browser/device information, timestamps, and security signals for delivery, abuse prevention, rate limiting, diagnostics, and security.
4. How we use information
- Provide and operate BossBack services and customer-facing capabilities.
- Generate business-specific responses using approved Sources.
- Allow customers to review recent conversations from their own website.
- Respond to inquiries, beta requests, support requests, and account questions.
- Manage accounts, subscriptions, and billing when applicable.
- Protect the service, detect abuse, troubleshoot, and enforce our terms.
- Understand service performance and improve BossBack using aggregated or de-identified information where practical.
- Meet legal obligations and protect legal rights.
We do not sell personal information, create advertising profiles from customer or end-user conversations, or use customer content to train a general-purpose BossBack AI model.
5. AI processing
BossBack Answers uses third-party AI services. BossBack is designed to send only information reasonably needed to generate an answer, which can include the end user’s question, relevant conversation context, and approved business information.
BossBack uses the OpenAI API. OpenAI states that API inputs and outputs are not used to train its models by default. Under OpenAI’s current default API data controls, abuse-monitoring logs may retain API content for up to 30 days unless another eligible retention control applies or longer retention is legally required. BossBack intends to use non-persistent API settings such as store:false where applicable.
AI output can be incorrect or incomplete. BossBack is designed to rely on approved business information and avoid inventing unsupported business facts, but customers remain responsible for configuring and monitoring their use of the service.
7. Where information is processed
BossBack’s primary application server and active customer data are hosted on an OVHcloud server located in Canada. Some providers, including Cloudflare, Microsoft, and OpenAI, may process information in Canada, the United States, or other jurisdictions depending on the service and network path.
8. Retention and deletion
Swipe horizontally to view the full table.
| Information | Typical retention |
|---|---|
| End-user Answers conversationsQuestions, responses, and any lead details submitted in the conversation. | 30 days, unless a shorter period is configured or a longer period is required for legal or security reasons. |
| Customer account, Sources, and configuration | While active. After cancellation, active data may be kept for up to 30 days for recovery, then deleted from active systems. |
| Backups | Daily OVHcloud backups may retain deleted server data for up to 7 additional days as backup copies expire. |
| Contact/support correspondence | As long as reasonably needed to respond, maintain appropriate business records, resolve disputes, or meet legal obligations. |
| Third-party AI processing | OpenAI may retain API content in abuse-monitoring logs for up to 30 days under default API controls, subject to applicable exceptions. |
Deletion from active systems does not necessarily remove information immediately from time-limited backups or records that must be retained for legal, accounting, fraud-prevention, or dispute purposes.
10. Security safeguards
We use administrative, technical, and operational safeguards appropriate to the information and current stage of the service, including HTTPS/TLS, restricted administrative access, protected secrets, firewalling, security headers, service isolation, software updates, and backups.
No online service can guarantee absolute security. Suspected security vulnerabilities can be reported to [email protected]. Customers should avoid placing unsupported sensitive information into BossBack and should follow the Acceptable Use Policy.
11. Access, correction, and privacy requests
You may ask to access, correct, or delete personal information that BossBack controls, subject to applicable law and legitimate exceptions. We may need to verify your identity. If your request concerns information collected through a customer’s website, we may coordinate with that customer.
Send requests to [email protected]. We will respond within timelines required by applicable law.
12. Children
BossBack is designed for business use and is not intended as a service directed to children. Customers must not knowingly use BossBack to collect personal information from children without appropriate legal authority or consent.
13. Changes
We may update this policy as BossBack changes. The “Last updated” date will show when it was revised. Material changes to how we handle personal information will receive additional notice where appropriate.
14. Contact the Privacy Officer
Questions, concerns, access requests, or privacy complaints can be sent to [email protected].
BossBack is based in Ontario, Canada and handles personal information in accordance with applicable privacy law, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.
