1Roles
You are the controller. You decide what data goes into your agent, what it may do, and who it talks to. Block9 LLC is the processor. We process your data only to deliver the service you have engaged us for, and only on your documented instructions — which for most purposes means your Order Form, your approved knowledge base, and the permissions you granted.
The subprocessors listed below are engaged by us to deliver specific parts of the service. Each is bound by contract to protect the data and to process it only for that purpose.
2What we process and why
- Knowledge base content — your website, policies, FAQs, SOPs, and documents. Used to ground the agent so it answers from your approved material rather than guessing.
- Conversation data — calls, transcripts, chat messages, and the outcomes of each. Used to operate the agent, report on outcomes, and improve configuration.
- Connected-system data — records the agent reads or writes in your CRM, calendar, accounting, or project tools, limited to the fields the agreed actions require.
- Usage and cost records — minutes, tokens, and tool calls. Used to meter your plan, bill accurately, and manage margin.
- Account and billing records — contacts, agreements, invoices, and payment status.
3Model training
Client data is not used to train foundation models. The model providers we use commit, in their published business-API terms, that data submitted through those APIs is not used to train their models. We do not contribute your data to model training, and we never use one client's data to shape another client's agent. Our commitment here is bounded by those published provider terms — if a provider changed them materially, we would tell you rather than quietly absorb it.
4Isolation between clients
Each client has their own knowledge store, instructions, and agent configuration. Access is enforced at the database level: every record is scoped to a single client, and a signed-in user can only reach their own rows. Our cost and margin data is visible to Block9 only. Agents are instructed and technically prevented from discussing any account other than the one they serve.
We never merge knowledge collections, phone numbers, tool permissions, or logs across clients. That rule holds at every tier and is not negotiable.
Isolation comes in tiers:
- Shared platform account (default). Your agent runs on accounts we control, with your knowledge, configuration, numbers, and logs logically separated from everyone else's. Efficient, and right for most engagements.
- Dedicated capacity. Separate account or reserved capacity for clients whose volume, concurrency, or risk profile warrants it. Priced as an add-on.
- Client-owned account. You hold the provider account; we manage the agent inside it. The strongest separation, and the right answer for regulated work or where your own compliance program requires it. Any credentials you give us for this are encrypted with a key stored outside our database.
We will recommend moving you up a tier when usage approaches shared limits, when an agent needs write access to money or sensitive systems, or when your industry requires it — and you can request the move at any time.
4bWhat shared infrastructure means for you
On the default tier, your agent shares platform accounts with other clients. Your data stays separate, but an account-level event at a provider — a rate limit, a policy action, a suspension — can affect more than one client at once. We monitor headroom, act quickly to contain misuse by any client, and move clients to isolated capacity where their usage or risk warrants it. If you would rather not share that exposure, the dedicated or client-owned tiers exist for exactly that reason.
5Subprocessors we use today
These are the vendors that process data for every client, because they run the platform itself.
| Subprocessor | Role | Data involved | Location |
|---|---|---|---|
| Anthropic | Reasoning models for agents on the Claude service line | Conversation content and approved knowledge context | United States |
| xAI | Reasoning models for agents on the xAI service line | Conversation content and approved knowledge context | United States |
| Supabase | Application database, authentication, and storage for the client portal | Account records, agent configuration, usage records, invoices, transcripts | United States |
| Vercel | Application hosting and content delivery | Request logs and application traffic | Global edge network |
| Stripe | Invoicing, payment processing, and credit balances | Billing contact and invoice records. Card data is held by Stripe and never reaches our systems | United States |
| Resend | Transactional email delivery | Recipient address and message content for reports, invoices, and alerts | United States |
Which reasoning provider applies to you depends on your service line — an agent runs on one, not both.
6Vendors engaged only if your configuration needs them
These are not part of every engagement. An Operations Agent with no phone line involves none of them. Where one applies to you, the specific vendor is named in your Order Form before we connect anything, and it becomes a subprocessor for your service at that point.
| Category | Role | Data involved | When it applies |
|---|---|---|---|
| Voice orchestration & telephony | Carries and routes calls for voice-enabled Support or Sales Agents | Call audio, transcripts, caller number | Only when your agent answers a phone line |
| Speech-to-text / text-to-speech | Converts speech for voice agents | Call audio and transcripts | Only when your agent answers a phone line |
| SMS delivery | Sends and receives text messages | Mobile numbers and message content | Only when text follow-up is part of your configuration |
| Workflow middleware | Bridges an agent to a system without a direct integration | Only the fields that specific Connection requires | Only when a Connection has no native path |
7Your own systems are not our subprocessors
When we connect an agent to your CRM, calendar, accounting, or field-service software — ServiceTitan, Jobber, HubSpot, QuickBooks, Google Calendar, and the rest — those are your vendors, under your existing agreements with them. We are not introducing them as subprocessors and we do not control how they handle your data.
What we do is access them with credentials and permissions you grant, limited to the actions we agreed, and revocable by you at any time. Your relationship and contract with those providers is unchanged.
8Changes to this list
We will give reasonable notice before adding a subprocessor that materially changes how your data is handled. If you object, you may cancel — which on a prepaid month-to-month service means simply not renewing.
9Security measures
- Encryption in transit and at rest.
- Row-level security scoping every record to a single client.
- Least-privilege access to every connected system, granted only for agreed actions.
- Human approval gates on money movement, irreversible changes, and mass outbound communication.
- Audit logging of agent actions, with logs available to you.
- Client-held credentials encrypted with a key stored outside the database.
- Elevated monitoring for the first two weeks after any launch.
10Return and deletion
On cancellation, at your request, we will send you all of your data and then delete it from our systems. That includes knowledge base content, configuration, transcripts, recordings, and reports. Backups expire on their normal cycle. Records we must retain by law — invoices and tax records — are kept for the statutory period and nothing more.
11Incidents
If a security incident affects your data, we will notify you promptly with what we know, what we are doing, and what we recommend — and keep updating you as it develops rather than waiting for a complete picture.
12Contact
support@block9.app · Block9 LLC, PO Box 2, Barnhart, MO 63012 · 636-224-8069