AgentixAI Managed Back Office

Phase 1 — Administrative + Finance Operations

Privacy Policy

Effective date: August 5, 2026 · Last updated: August 5, 2026

AgentixAI (“AgentixAI,” “we,” “us”) provides a managed back-office service to small businesses. This policy explains what data we handle, why, where it is stored, who can see it, and how to have it deleted.

Contact: info@agentixai.ai · Mailing address: 1670 Ooltewah Ringgold Rd, Ooltewah, TN 37363 · Phone: (423) 218-2244

1. Who this policy covers

This policy covers two groups:

  • Our clients — businesses that engage AgentixAI to run administrative and finance operations on their behalf.
  • Our clients’ contacts — the customers, vendors, and staff of those businesses, whose information appears in the documents and messages we process on our client’s instruction.

If you are a customer or vendor of one of our clients and want your information removed, contact that business directly, or write to us at info@agentixai.ai and we will route your request.

2. What we collect

Account data. Name, business email address, business name, and phone number for the people authorized to use our service.

Client business data. Only what is needed to perform the services our client has engaged us for:

  • Invoices, bills, receipts, and their line items
  • Customer and vendor records
  • Approval decisions and who made them
  • Documents our client uploads or forwards to us

Connected-service data. When a client connects a third-party system, we access only the data needed for the specific workflows they have enabled:

ServiceWhat we accessWhy
Google (Gmail)Read-only access to email messagesTo classify incoming email, extract action items, and route them for human approval
Intuit QuickBooks OnlineInvoices, bills, customers, vendors, chart of accountsTo keep records in sync with the client’s book of record

We request read-only access wherever the workflow permits it. We do not request, and will not accept, permissions that allow moving money, initiating payments, or making payroll tax filings. Our system rejects such permission scopes at the code level.

Usage data. Log records of actions taken in our system — what happened, when, and under whose approval.

We do not collect biometric data, precise location, or data about children.

3. Google user data — Limited Use

AgentixAI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features our client has explicitly enabled.
  • We do not transfer Google user data to third parties except (a) as necessary to provide those features, (b) for security purposes, (c) to comply with applicable law, or (d) as part of a merger or acquisition after obtaining explicit consent.
  • We do not use Google user data for serving advertisements of any kind.
  • We do not sell Google user data.
  • We do not allow humans to read Google user data unless (a) we have the user’s affirmative agreement for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
  • We do not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models.

On our use of AI. We use a third-party large language model provider (Anthropic) to draft messages and classify documents on behalf of our clients. Content may be transmitted to that provider solely to produce the specific output our client requested. Our provider does not train models on data submitted through its API. Every AI-generated output passes automated checks before a human sees it, and no AI-generated message reaches an outside recipient without explicit human approval.

4. Intuit QuickBooks data

We access QuickBooks Online data only for clients who connect their account, and only for the workflows they enable. QuickBooks remains the client’s book of record; we do not replace it. We do not request payment-initiation or bill-pay permissions. Access tokens are stored encrypted in a dedicated secrets vault, never in our application database. A client may disconnect at any time from within QuickBooks or by contacting us, which revokes our access immediately.

5. How we store and protect data

  • Where. Our production database is hosted on Supabase (Amazon Web Services, United States). Application services run on Vercel and Railway.
  • Isolation. Every record carries an organization identifier, and database-level row security prevents any client from reading another client’s data. This is enforced by the database itself, not only by application code.
  • Credentials. Third-party access tokens are held in an encrypted secrets vault. Our application database stores only a reference to them.
  • Documents. Where a client’s files already live in their own storage (for example Google Drive or OneDrive), we keep the location, metadata, and extracted text rather than copying the original.
  • Access. Access is limited to AgentixAI personnel who need it to deliver the service, under written confidentiality obligations.
  • Audit trail. Every automated action is logged with what happened, when, and under whose approval. Audit records cannot be edited or deleted.
  • Transport and storage. Data is encrypted in transit (TLS) and at rest.

No system is perfectly secure. We will notify affected clients without undue delay if we become aware of a breach affecting their data.

6. Sub-processors

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageUnited States
VercelWeb application hostingUnited States
RailwayBackground workersUnited States
AnthropicAI drafting and classificationUnited States

We will update this list before adding a sub-processor that handles client data.

7. How long we keep data

DataRetention
Client business recordsFor the life of the engagement, then 30 days, then deleted
Audit and approval records7 years — retained to support our clients’ recordkeeping obligations
Google user dataDeleted within 30 days of disconnection or account closure
QuickBooks dataDeleted within 30 days of disconnection or account closure
Account and contact dataUntil account closure, then 30 days

Disconnecting a service revokes our access immediately, ahead of deletion.

8. Your rights and how to exercise them

You may request access to the data we hold about you, correction of it, deletion of it, or an export of it. Write to info@agentixai.ai. We respond within 30 days.

Deleting Google data specifically. A client may revoke our access at any time at myaccount.google.com/permissions, or by emailing us. On revocation we stop accessing the account immediately and delete previously retrieved Google user data within 30 days, except where retention is required by law.

Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

9. Children

Our service is for businesses. We do not knowingly collect data from anyone under 16.

10. Changes

We will post any change here and update the “last updated” date. For material changes affecting how we handle client or Google user data, we will notify clients directly before the change takes effect.

11. Contact

AgentixAI · 1670 Ooltewah Ringgold Rd, Ooltewah, TN 37363 · info@agentixai.ai · (423) 218-2244

This document is provided for transparency and platform-review purposes and is not a substitute for legal advice specific to your business.

Privacy Policy — AgentixAI Managed Back Office