Block9Agents by Block9
Why AgentsSupport AgentSales AgentOperations AgentHow It WorksPricingFAQClient Portal
LAUNCHING 8 · 12 · 2026◆SITE FUNCTIONALITY CURRENTLY DISABLED◆CONFIGURED AI AGENTS FOR YOUR BUSINESS◆LAUNCHING 8 · 12 · 2026◆SITE FUNCTIONALITY CURRENTLY DISABLED◆CONFIGURED AI AGENTS FOR YOUR BUSINESS◆
Legal

Data Processing & Subprocessors

What we do with your data, the role each party plays, and every third party involved in delivering your service.

Last updated August 10, 2026

This page supplements our Privacy Policy and forms part of the Data Processing Addendum for clients who have one. Where a signed DPA exists, it controls.

1Roles

You are the controller. You decide what data goes into your agent, what it may do, and who it talks to. Block9 LLC is the processor. We process your data only to deliver the service you have engaged us for, and only on your documented instructions — which for most purposes means your Order Form, your approved knowledge base, and the permissions you granted.

The subprocessors listed below are engaged by us to deliver specific parts of the service. Each is bound by contract to protect the data and to process it only for that purpose.

2What we process and why

  • Knowledge base content — your website, policies, FAQs, SOPs, and documents. Used to ground the agent so it answers from your approved material rather than guessing.
  • Conversation data — calls, transcripts, chat messages, and the outcomes of each. Used to operate the agent, report on outcomes, and improve configuration.
  • Connected-system data — records the agent reads or writes in your CRM, calendar, accounting, or project tools, limited to the fields the agreed actions require.
  • Usage and cost records — minutes, tokens, and tool calls. Used to meter your plan, bill accurately, and manage margin.
  • Account and billing records — contacts, agreements, invoices, and payment status.

3Model training

Client data is not used to train foundation models. The model providers we use commit, in their published business-API terms, that data submitted through those APIs is not used to train their models. We do not contribute your data to model training, and we never use one client's data to shape another client's agent. Our commitment here is bounded by those published provider terms — if a provider changed them materially, we would tell you rather than quietly absorb it.

4Isolation between clients

Each client has their own knowledge store, instructions, and agent configuration. Access is enforced at the database level: every record is scoped to a single client, and a signed-in user can only reach their own rows. Our cost and margin data is visible to Block9 only. Agents are instructed and technically prevented from discussing any account other than the one they serve.

We never merge knowledge collections, phone numbers, tool permissions, or logs across clients. That rule holds at every tier and is not negotiable.

Isolation comes in tiers:

  • Shared platform account (default). Your agent runs on accounts we control, with your knowledge, configuration, numbers, and logs logically separated from everyone else's. Efficient, and right for most engagements.
  • Dedicated capacity. Separate account or reserved capacity for clients whose volume, concurrency, or risk profile warrants it. Priced as an add-on.
  • Client-owned account. You hold the provider account; we manage the agent inside it. The strongest separation, and the right answer for regulated work or where your own compliance program requires it. Any credentials you give us for this are encrypted with a key stored outside our database.

We will recommend moving you up a tier when usage approaches shared limits, when an agent needs write access to money or sensitive systems, or when your industry requires it — and you can request the move at any time.

4bWhat shared infrastructure means for you

On the default tier, your agent shares platform accounts with other clients. Your data stays separate, but an account-level event at a provider — a rate limit, a policy action, a suspension — can affect more than one client at once. We monitor headroom, act quickly to contain misuse by any client, and move clients to isolated capacity where their usage or risk warrants it. If you would rather not share that exposure, the dedicated or client-owned tiers exist for exactly that reason.

5Subprocessors we use today

These are the vendors that process data for every client, because they run the platform itself.

SubprocessorRoleData involvedLocation
AnthropicReasoning models for agents on the Claude service lineConversation content and approved knowledge contextUnited States
xAIReasoning models for agents on the xAI service lineConversation content and approved knowledge contextUnited States
SupabaseApplication database, authentication, and storage for the client portalAccount records, agent configuration, usage records, invoices, transcriptsUnited States
VercelApplication hosting and content deliveryRequest logs and application trafficGlobal edge network
StripeInvoicing, payment processing, and credit balancesBilling contact and invoice records. Card data is held by Stripe and never reaches our systemsUnited States
ResendTransactional email deliveryRecipient address and message content for reports, invoices, and alertsUnited States

Which reasoning provider applies to you depends on your service line — an agent runs on one, not both.

6Vendors engaged only if your configuration needs them

These are not part of every engagement. An Operations Agent with no phone line involves none of them. Where one applies to you, the specific vendor is named in your Order Form before we connect anything, and it becomes a subprocessor for your service at that point.

CategoryRoleData involvedWhen it applies
Voice orchestration & telephonyCarries and routes calls for voice-enabled Support or Sales AgentsCall audio, transcripts, caller numberOnly when your agent answers a phone line
Speech-to-text / text-to-speechConverts speech for voice agentsCall audio and transcriptsOnly when your agent answers a phone line
SMS deliverySends and receives text messagesMobile numbers and message contentOnly when text follow-up is part of your configuration
Workflow middlewareBridges an agent to a system without a direct integrationOnly the fields that specific Connection requiresOnly when a Connection has no native path

7Your own systems are not our subprocessors

When we connect an agent to your CRM, calendar, accounting, or field-service software — ServiceTitan, Jobber, HubSpot, QuickBooks, Google Calendar, and the rest — those are your vendors, under your existing agreements with them. We are not introducing them as subprocessors and we do not control how they handle your data.

What we do is access them with credentials and permissions you grant, limited to the actions we agreed, and revocable by you at any time. Your relationship and contract with those providers is unchanged.

8Changes to this list

We will give reasonable notice before adding a subprocessor that materially changes how your data is handled. If you object, you may cancel — which on a prepaid month-to-month service means simply not renewing.

9Security measures

  • Encryption in transit and at rest.
  • Row-level security scoping every record to a single client.
  • Least-privilege access to every connected system, granted only for agreed actions.
  • Human approval gates on money movement, irreversible changes, and mass outbound communication.
  • Audit logging of agent actions, with logs available to you.
  • Client-held credentials encrypted with a key stored outside the database.
  • Elevated monitoring for the first two weeks after any launch.

10Return and deletion

On cancellation, at your request, we will send you all of your data and then delete it from our systems. That includes knowledge base content, configuration, transcripts, recordings, and reports. Backups expire on their normal cycle. Records we must retain by law — invoices and tax records — are kept for the statutory period and nothing more.

11Incidents

If a security incident affects your data, we will notify you promptly with what we know, what we are doing, and what we recommend — and keep updating you as it develops rather than waiting for a complete picture.

12Contact

support@block9.app · Block9 LLC, PO Box 2, Barnhart, MO 63012 · 636-224-8069

Questions about this document?Block9 LLC · PO Box 2, Barnhart, MO 63012 · 636-224-8069
Back to home →
Block9Agents by Block9

Configured, managed AI agents for individual businesses. A Block9 service.

Products

Support AgentSales AgentOperations AgentPricing

Company

Why AgentsHow It WorksStart A Scope

Legal

Terms of ServicePrivacy PolicyData ProcessingYour DataAcceptable UseAI & RecordingSMS TermsSecurity
© 2026 Block9 LLC · PO Box 2, Barnhart, MO 63012 · 636-224-8069
XLinkedIn