1Roles
You are the controller. You decide what data goes into your agent, what it may do, and who it talks to. Block9 LLC is the processor — in US privacy law, your service provider. We process your data only to deliver the service you have engaged us for, and only on your documented instructions — which for most purposes means your Order Form, your approved knowledge base, and the permissions you granted.
Being the processor does not mean we run the underlying systems ourselves. The service is built on third-party platforms — the AI providers, database, hosting, payments, and email listed below. Those are our subprocessors: we engage them to deliver specific parts of the service, they act on our instructions (which carry yours), and each is bound by contract to protect your data and use it only for that purpose. Running on their infrastructure is exactly what makes them subprocessors — it does not change who is accountable to you. That stays us.
One narrow exception. For the account, billing, and usage records we keep to run and invoice your service, Block9 LLC acts as the controller of that limited data. Everything your agent handles on your behalf — customer conversations, approved knowledge, connected-system records — we handle as your processor.
2What we process and why
- Knowledge base content — your website, policies, FAQs, SOPs, and documents. Used to ground the agent so it answers from your approved material rather than guessing.
- Conversation data — calls, transcripts, chat messages, and the outcomes of each. Used to operate the agent, report on outcomes, and improve configuration.
- Connected-system data — records the agent reads or writes in your CRM, calendar, accounting, or project tools, limited to the fields the agreed actions require.
- Usage and cost records — minutes, tokens, and tool calls. Used to meter your plan, bill accurately, and manage margin.
- Account and billing records — contacts, agreements, invoices, and payment status.
3Model training
Client data is not used to train foundation models. The model providers we use commit, in their published business-API terms, that data submitted through those APIs is not used to train their models. We do not contribute your data to model training, and we never use one client's data to shape another client's agent. Our commitment here is bounded by those published provider terms — if a provider changed them materially, we would tell you rather than quietly absorb it.
Two honest boundaries inside those provider terms: providers may retain content their safety systems flag for abuse review beyond the normal ~30-day window, and may produce de-identified, aggregated statistics from service usage (never your content itself) unless a zero-retention arrangement is in place. Neither involves training on your data.
You can read those provider commitments directly: xAI's legal terms and Trust Center, and Anthropic's Trust Center along with the published model constitution that governs how Claude is trained to behave.
4Isolation between clients
Each client has their own knowledge store, instructions, and agent configuration. Access is enforced at the database level: every record is scoped to a single client, and a signed-in user can only reach their own rows. Our cost and margin data is visible to Block9 only. Agents are instructed and technically prevented from discussing any account other than the one they serve.
We never merge knowledge collections, phone numbers, tool permissions, or logs across clients. That rule holds at every tier and is not negotiable.
Isolation comes in tiers:
- Shared platform account (default). Your agent runs on accounts we control, with your knowledge, configuration, numbers, and logs logically separated from everyone else's. Efficient, and right for most engagements.
- Dedicated capacity. Separate account or reserved capacity for clients whose volume, concurrency, or risk profile warrants it. Priced as an add-on.
- Client-owned account. You hold the provider account; we manage the agent inside it. The strongest separation, and the right answer for regulated work or where your own compliance program requires it. Any credentials you give us for this are encrypted with a key stored outside our database.
- Client-owned infrastructure & zero-retention (option). The fullest version of the above: your own telephony account (so recordings and texts rest with you), your own AI account with zero-retention enabled (so the provider persists nothing), and a portal configured to store as little as possible — we keep only the usage counts and invoices needed to run and bill your service. The honest tradeoff: with nothing stored, features that depend on saved conversation — transcript review, post-call analysis, the live conversation view — are reduced or unavailable, and knowledge-base grounding is more limited. We’ll size that with you. (Data is still processed in real time by the AI and carried by the phone network — controlling where it rests is not the same as it never being seen.)
- US data residency (option). Where you need a written guarantee that inference runs on US infrastructure, we can pin it: on the Claude service line via US-only inference plus a US data-storage region, and on the xAI service line via xAI’s own residency controls. Our default AI providers already process in the United States (see the table below), so this turns a default into an enforced commitment. US-only inference carries a small provider premium (about 10% on Claude tokens) that we fold into your quote. This is one of a growing set of data-handling options — residency, retention window, zero-retention, client-owned storage — we’ll match to your requirements.
Healthcare BAA (option). For clients handling protected health information, a HIPAA business associate chain can be arranged: you sign a BAA with Block9, and Block9 operates on an AI backend covered by the provider's own BAA program. Two honest constraints: the BAA must be in place before any PHI flows (until then, our Terms exclude PHI and we are not your business associate), and provider BAA programs can constrain model choice and retention settings — so the configuration is scoped with you rather than assumed.
We will recommend moving you up a tier when usage approaches shared limits, when an agent needs write access to money or sensitive systems, or when your industry requires it — and you can request the move at any time.
4bWhat shared infrastructure means for you
On the default tier, your agent shares platform accounts with other clients. Your data stays separate, but an account-level event at a provider — a rate limit, a policy action, a suspension — can affect more than one client at once. We monitor headroom, act quickly to contain misuse by any client, and move clients to isolated capacity where their usage or risk warrants it. If you would rather not share that exposure, the dedicated or client-owned tiers exist for exactly that reason.
5Subprocessors we use today
These are the vendors that process data for every client, because they run the platform itself.
| Subprocessor | Role | Data involved | Location |
|---|---|---|---|
| AnthropicTrust Center ↗ · Constitution ↗ | Reasoning models for agents on the Claude service line | Conversation content and approved knowledge context | United States |
| xAILegal ↗ · Trust Center ↗ | Reasoning models for agents on the xAI service line | Conversation content and approved knowledge context | United States |
| SupabasePrivacy ↗ | Application database, authentication, and storage for the client portal | Account records, agent configuration, usage records, invoices, transcripts | United States |
| VercelPrivacy ↗ | Application hosting and content delivery | Request logs and application traffic | Global edge network |
| StripeLegal ↗ | Invoicing, payment processing, and credit balances | Billing contact and invoice records. Card data is held by Stripe and never reaches our systems | United States |
| ResendPrivacy ↗ | Transactional email delivery | Recipient address and message content for reports, invoices, and alerts | United States |
Which reasoning provider applies to you depends on your service line — an agent runs on one, not both.
6Vendors engaged only if your configuration needs them
These are not part of every engagement. An Operations Agent with no phone line involves none of them. Where one applies to you, the specific vendor is named in your Order Form before we connect anything, and it becomes a subprocessor for your service at that point.
| Category | Role | Data involved | When it applies |
|---|---|---|---|
| Voice orchestration & telephony | Carries and routes calls for voice-enabled Support or Sales Agents | Call audio, transcripts, caller number | Only when your agent answers a phone line |
| Speech-to-text / text-to-speech | Converts speech for voice agents | Call audio and transcripts | Only when your agent answers a phone line |
| SMS delivery | Sends and receives text messages | Mobile numbers and message content | Only when text follow-up is part of your configuration |
| Workflow middleware | Bridges an agent to a system without a direct integration | Only the fields that specific Connection requires | Only when a Connection has no native path |
7Your own systems are not our subprocessors
When we connect an agent to your CRM, calendar, accounting, or field-service software — ServiceTitan, Jobber, HubSpot, QuickBooks, Google Calendar, and the rest — those are your vendors, under your existing agreements with them. We are not introducing them as subprocessors and we do not control how they handle your data.
What we do is access them with credentials and permissions you grant, limited to the actions we agreed, and revocable by you at any time. Your relationship and contract with those providers is unchanged.
8Changes to this list
We will give reasonable notice before adding a subprocessor that materially changes how your data is handled. If you object, you may cancel — which on a prepaid month-to-month service means simply not renewing.
9Security measures
- Encryption in transit and at rest.
- Row-level security scoping every record to a single client.
- Least-privilege access to every connected system, granted only for agreed actions.
- Human approval gates on money movement, irreversible changes, and mass outbound communication.
- Audit logging of agent actions, with logs available to you.
- Client-held credentials encrypted with a key stored outside the database.
- Elevated monitoring for the first two weeks after any launch.
10Return and deletion
On cancellation, at your request, we will send you all of your data and then delete it from our systems. That includes knowledge base content, configuration, transcripts, recordings, and reports. Backups expire on their normal cycle. Records we must retain by law — invoices and tax records — are kept for the statutory period and nothing more.
11Incidents
If a security incident affects your data, we will notify you promptly with what we know, what we are doing, and what we recommend — and keep updating you as it develops rather than waiting for a complete picture.
12Contact
support@block9.app · Block9 LLC, PO Box 2, Barnhart, MO 63012 · 636-224-8069