Privacy Policy
Last updated: July 17, 2026
1. Scope of This Policy
AIQEN(“AIQEN,” “we,” “us,” or “our”) operates two related lines of business: (a) an AI consulting and automation agency that designs and implements custom AI systems for clients (“Consulting Services”), and (b) AI Workforce, a multi-tenant SaaS platform that lets organizations deploy AI employees, run workflow automations, and manage a CRM, knowledge base, and integrations hub (“the Platform”). This Privacy Policy applies to our website, the Platform, and both service lines, and describes how we collect, use, disclose, and safeguard information in each context.
If you use the Platform on behalf of an organization, your organization is typically the data controller for the business data you and your team enter into it (contacts, deals, tickets, campaign content, and similar records), and AIQEN acts as a data processor for that content. See our Data Processing Agreement for the terms that govern that relationship. For everything else described below — account, billing, and website data — AIQEN is the data controller.
2. Information We Collect
Information you provide directly
- Contact details submitted through forms: name, email, company, phone, and message content (assessment requests, strategy call bookings, contact forms, newsletter signups).
- Account information when you sign up for the Platform: name, email, password (stored as a salted hash via Supabase Auth, never in plaintext), organization name, and role.
- Content you create or upload while using the Platform: CRM records, campaign and outreach content, workflow definitions, knowledge base documents, support tickets, chat messages, and files uploaded to client or customer portals.
- Billing details: billing name and address, and payment method metadata (see Section 6 — we do not store full card numbers ourselves).
- Credentials or OAuth tokens you provide when connecting a third-party integration (see Section 6).
Information collected automatically
- Standard web request metadata: IP address, browser type, device type, referring page, and pages visited, collected via server request logs.
- Authentication session cookies required to keep you signed in — see our Cookie Policy.
- Product usage and audit data within the Platform: sign-ins, feature usage, AI employee actions, and administrative changes, used for security auditing and service improvement.
We do not currently use third-party advertising or cross-site analytics trackers on our website or in the Platform.
3. How We Use Your Information
- To provide, operate, and maintain the website and the Platform, including authenticating you and enforcing multi-tenant data isolation between organizations.
- To respond to inquiries, schedule strategy calls, and deliver AI Assessment reports.
- To process subscriptions, invoices, and payments, and to send billing-related notices.
- To operate AI Workforce features on your organization’s behalf, including sending emails, generating content, and executing workflow automations that your organization configures.
- To detect, investigate, and prevent fraud, abuse, and security incidents, and to enforce our Acceptable Use Policy.
- To send service updates, security notices, and — where you have opted in — product and marketing communications. You can opt out of marketing communications at any time.
- To comply with legal obligations and enforce our agreements.
We do not sell your personal information.
4. AI Processing of Your Data
The Platform uses large language models (currently provided by Anthropic and OpenAI) to power AI employees, content generation, assessment scoring, and workflow automation. When these features are used, relevant content from your request or your organization’s connected data is sent to the applicable model provider as an API call to generate a response. These providers process that data under their own enterprise/API data-handling terms, which — per their published policies at the time of writing — do not use API-submitted content to train their general-purpose models. We do not use your organization’s content to train our own foundation models. AI outputs (assessment reports, drafted messages, generated content, automation decisions) may contain errors and should be reviewed by a human before being relied upon for material business decisions.
5. How We Store and Protect Your Information
Platform and website data is stored with Supabase (PostgreSQL), encrypted in transit (TLS) and at rest. Access to production data is restricted to authorized personnel and enforced technically through row-level security policies that isolate each organization’s data from every other organization’s. See our Security Policy for more detail on the technical and organizational measures we maintain, including rate limiting, audit logging, and role-based admin access.
6. Sub-Processors and Third-Party Services
We use the following categories of sub-processors to operate our services. Any integration you or your organization actively connects (see below) receives only the data needed for that integration to function, and only for organizations that have connected it.
- Infrastructure & database: Supabase (hosting, authentication, PostgreSQL database, file storage).
- Transactional email: Resend (account, billing, and notification emails).
- Payments: Stripe, PayPal, Paystack, and Flutterwave — whichever your organization selects for billing. We do not store full card or bank account numbers; these providers handle that data under PCI-DSS-compliant infrastructure.
- AI model providers: Anthropic and OpenAI (see Section 4).
- Optional integrations you connect: the Platform’s Integrations Hub supports connections such as Gmail, Google Calendar, Google Drive, Outlook Mail, Outlook Calendar, Slack, Notion, HubSpot, GitHub, and Calendly, among others. Each is only active, and only receives data, if a member of your organization explicitly authorizes that connection. You can review and revoke connections at any time from the Platform’s Integrations settings.
7. Data Retention
We retain account and billing data for as long as your organization maintains an active subscription, and for a reasonable period afterward to satisfy legal, accounting, or dispute-resolution requirements. Platform content (CRM records, workflow data, documents, and similar) is retained until your organization deletes it or closes its account, after which it is deleted from active systems within 30 days, subject to residual copies in encrypted backups that are purged on our standard backup rotation schedule.
8. Your Rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, restrict or object to certain processing, and withdraw consent where processing is based on consent.
GDPR (EEA/UK residents)
If you are located in the European Economic Area or the UK, you have the rights described above under the General Data Protection Regulation, and the right to lodge a complaint with your local supervisory authority. Where we rely on legitimate interests to process your data, you may object to that processing.
CCPA/CPRA (California residents)
California residents have the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. Exercising these rights will not result in discriminatory treatment.
To exercise any of these rights, contact us at hello@aiqen.co. If you are a member of an organization using the Platform and your data was entered by your organization (e.g., as a CRM contact), please direct your request to that organization first, as they control that data; we will assist them in fulfilling it.
9. International Data Transfers
Our infrastructure providers may process data in regions outside your own. Where required, we rely on appropriate safeguards — such as Standard Contractual Clauses — for transfers of personal data out of the EEA, UK, or Switzerland. See our Data Processing Agreement for details.
10. Children's Privacy
Our website and Platform are intended for business use and are not directed to individuals under the age of 16. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will post the updated policy on this page with a new revision date, and for material changes we will provide additional notice (such as an email to account holders) where required by law.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at hello@aiqen.co. See also our Contact & Support Policy.