1. Who is responsible
Boundlane AG, Switzerland, is the controller for account administration, authentication, billing, service security, support, legal acceptance records and communications about Boundlane. Contact our privacy function at hello@boundlane.com.
For personal data contained in a Customer’s process descriptions, connected systems, automation inputs, outputs and run history (Customer Personal Data), the Customer normally decides why and how the data is used and is the controller. We process it for the Customer under the Data Processing Addendum. People represented in that data should usually direct requests to the relevant Customer; we will assist the Customer as required.
2. The personal data we process
Depending on how the Service is configured and used, we process:
- Identity and account data: name, work email, workspace, memberships, invitations, platform and business roles, identity-provider identifiers and the person who granted access.
- Authentication and security data: hashed one-time codes, signed sessions, sign-in events, IP-derived rate-limit keys, SSO/SAML/SCIM events, audit entries, device/browser request information and security diagnostics.
- Automation data: build conversations, prompts, model responses, packages, generated source, configuration, skills, uploaded process documents and their embedded content.
- Connected-system data: connection records, hostnames, schemas, field names and samples of records retrieved under the Customer’s instructions. Redaction rules are applied before samples are stored, but redaction does not necessarily make data anonymous.
- Runtime and decision data: trigger inputs, tool calls, outputs, traces, exceptions, approvals, comments, reversals, rollout decisions and audit evidence.
- Billing and transaction data: plan, subscription identifiers, invoices, payment status and usage. Stripe receives payment-card details directly; Boundlane does not receive full card numbers.
- Support and communications: messages, questionnaires, contact details, requested demonstrations, incident correspondence and preferences for service communications.
- Legal records: the Terms and Privacy versions accepted, their digests, time, method, contracting identity shown and the capacity in which the user accepted.
Automation and connected-system data may concern the Customer’s staff, candidates, suppliers, customers, patients, counterparties or other people. The Customer determines which data enters its workspace.
3. Where the data comes from
We receive data directly from users; from workspace owners and administrators; from Google, GitHub or an enterprise identity provider used to sign in; from Stripe for billing status; and from systems, documents, webhooks, mailboxes and databases the Customer chooses to connect. We also generate operational records when people and automations use the Service.
We do not buy personal-data lists. We do not sell personal data or share it for cross-context behavioural advertising.
4. Why we process it and our legal grounds
| Purpose | Data | Ground under GDPR where applicable |
|---|---|---|
| Provide accounts and the Service | Identity, workspace, automation, connected-system and runtime data | Performance of the contract; processing on the Customer’s documented instructions |
| Authenticate users and protect tenants | Authentication, roles, request and security records | Contract and legitimate interests in secure, fraud-resistant operation |
| Operate billing and quotas | Plan, invoice, payment status and usage | Contract and legal obligations for accounting and tax |
| Support, diagnose and improve reliability | Support messages, diagnostics, usage and limited relevant Customer Data | Contract and legitimate interests in maintaining the Service; Customer instructions where Customer Personal Data is involved |
| Send sign-in, security, approval and product notices | Email, role, event and communication data | Contract, legal obligations and legitimate interests; consent where required for optional marketing |
| Meet legal duties and defend claims | Account, billing, audit, acceptance and relevant correspondence | Legal obligation and legitimate interests in establishing or defending legal rights |
Under Swiss law, we process personal data in accordance with the principles and requirements of the Federal Act on Data Protection. Where we rely on legitimate interests under the GDPR, those interests include operating a secure B2B service, preventing abuse, keeping reliable evidence and improving availability. You may object as explained below.
5. Models and automation decisions
Prompts, relevant context and model responses are processed for the build agent and for model-enabled runtime steps. Hosted production deployments use the Vercel AI Gateway and may enable team- or request-level zero- data-retention routing. Zero retention is a configured control, not a universal property of every model route: direct provider use, explicit caching, files, beta tools or a Customer-provided endpoint may follow different terms. The Subprocessor page identifies the configured categories; enterprise documentation records deployment-specific routes.
Boundlane does not make employment, credit, medical, legal or similarly significant decisions about people for its own purposes. The Customer defines its automations, data, rules, rollout stage and human approvals. An automation may assist or execute a Customer decision, but the Customer is responsible for deciding when meaningful human review is required and for giving affected people any notice, explanation or review right required by law. The audit trail records the inputs, steps and human decisions available to support that review.
6. Recipients and subprocessors
We disclose personal data only as needed to operate the Service, follow the Customer’s instructions, complete a transaction, protect people and systems, or comply with law. Categories of recipients are:
- Vercel for hosting, compute, sandboxing, workflow, optional storage and AI Gateway;
- Neon for managed PostgreSQL and recovery;
- enabled model providers, normally Anthropic for the default model route;
- Stripe where hosted billing is enabled and Resend where service email is enabled;
- optional KMS, storage, identity and model providers selected for a deployment;
- the systems and recipients the Customer instructs an automation to contact; and
- professional advisers, auditors, authorities or a transaction successor where lawfully necessary and subject to appropriate protections.
The current provider entities, functions, countries and transfer safeguards are maintained on the Subprocessor page. Customer-connected systems and Customer-provided endpoints are recipients selected by the Customer, not our subprocessors.
7. International transfers
Boundlane AG is based in Switzerland. Depending on the selected deployment region and providers, data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States and the region of a Customer-selected system or model endpoint.
For transfers to a country without an adequate level of protection, we use recognised safeguards such as the European Commission’s Standard Contractual Clauses with the adaptations required for Swiss law, together with technical and organisational measures where appropriate. We may also rely on an applicable adequacy decision or another lawful mechanism. Contact us for a copy of the relevant safeguard, subject to necessary redactions.
8. Workspace separation and security
Pooled workspaces are separated using tenant identity on every data operation and PostgreSQL row-level security. Dedicated-tier workspaces use a separate database. Customer credentials are stored in an encrypted vault and automation packages contain credential references rather than plaintext secrets. External tool calls are policy-checked and Customer-system connectors use hostname allowlists.
We use administrative, technical and organisational measures appropriate to the risk, including access control, encryption in transit, encryption or envelope encryption at rest where applicable, audit trails, backups and incident handling. No system is perfectly secure; suspected compromise should be reported to hello@boundlane.com.
9. Retention, deletion and backups
Retention depends on the data’s purpose, contractual settings, unresolved cases and legal requirements. Sign-in codes expire after 10 minutes; sessions after seven days. Workspace and automation data is retained for the workspace lifetime unless a deployment-specific run-history window is configured. Audit is not pruned independently because removing an entry would invalidate the chain. The full Retention schedule states the current defaults and criteria.
A workspace owner can request complete erasure. The active deletion path enumerates tenant-scoped database tables and removes stored trace objects before confirming success; if the trace archive cannot be cleared, the operation fails without claiming completion. Protected backups expire under provider rotation schedules and are not used for ordinary processing. Limited invoices, tax records, legal holds and a minimal erasure receipt may remain where necessary. An erasure receipt records that deletion happened but is designed not to retain Customer content.
11. Your rights
Subject to applicable law and exceptions, you may ask whether we process your personal data and request access, correction, deletion, restriction or portability. You may object to processing based on legitimate interests and withdraw consent for future processing where consent is the ground. You may also request human review and express your view about a qualifying automated individual decision.
Send a request to hello@boundlane.com. We may need to verify identity and authority. We will respond within the period required by applicable law and do not discriminate against a person for exercising a right. If the data belongs to a Customer workspace, we may refer the request to that Customer and assist it as processor.
You may complain to the Swiss Federal Data Protection and Information Commissioner at edoeb.admin.ch. If the GDPR applies, you may also complain to the supervisory authority where you live, work or believe an infringement occurred.
12. Required data, children and sensitive data
A verified email and essential workspace information are required to create and secure an account. Without them we cannot provide access. Payment information is required only for a paid plan. Other Customer Data is supplied at the Customer’s choice, although an automation cannot work without the fields its process requires.
The Service is for organisations and is not directed to children. We do not knowingly create accounts for people under 16. A Customer must not use the Service to process children’s data or sensitive personal data unless it has a lawful basis, gives required notices, completes any required impact assessment and chooses controls appropriate to the risk.
13. Changes and contact
We will update this notice when processing materially changes and notify workspace owners where required. Prior versions remain in the version archive. A new purpose incompatible with the one originally disclosed will not be applied without the notice or permission required by law.
Privacy questions, rights requests, DPA requests and transfer-safeguard requests may be sent to hello@boundlane.com or through the contact page.