Legal
Privacy Policy
Last updated: January 2026
TL;DR — Our Privacy Commitment
- ✓ Non-Custodial: Your data stays in your systems. We don't store it.
- ✓ No Training: We never use your proprietary data to train AI models.
- ✓ Self-Hosted Option: Enterprise customers can run everything on-premise.
- ✓ Full Audit Trail: Every data access is logged for your compliance needs.
1. Introduction
Hagonel, Inc. ("Hagonel," "we," "us," or "our") respects your privacy and is committed to protecting the data you entrust to us. This Privacy Policy explains how we collect, use, and safeguard information when you use our "Invisible Business OS" service.
Hagonel is fundamentally different from traditional SaaS applications. We operate on a non-custodial architecture—meaning your business data never resides on our servers. We access it via APIs only when needed to perform requested orchestration tasks.
2. Information We Access (Not Store)
When you connect Hagonel to your tools (Slack, Gmail, CRM, etc.), we access data from these systems at runtime to fulfill your requests. This includes:
- Messages and conversations in connected communication platforms
- Calendar events and scheduling data
- CRM records (contacts, deals, activities)
- Project management data (tasks, sprints, assignments)
- Financial transaction metadata (when Stripe/QuickBooks connected)
Key distinction: Accessing ≠ Storing. Data flows through Hagonel's processing layer but is not persisted to our databases. Think of us as a secure conduit, not a repository.
3. Knowledge Graph Data
Hagonel builds a Knowledge Graph ("Institutional Memory") from your business data. This graph stores entities (people, projects, budgets) and relationships between them. Storage location depends on your plan:
Founder Plan
Knowledge Graph stored in Hagonel-managed secure cloud infrastructure (SOC 2 Type II compliant).
Enterprise Plan
Self-hosted option available. Knowledge Graph runs entirely within your infrastructure—we never see it.
4. What We Explicitly Do NOT Do
- ✕ Train AI models on your data: Your proprietary business data is never used to train or fine-tune Hagonel's AI systems.
- ✕ Sell data to third parties: We do not monetize customer data in any form.
- ✕ Aggregate cross-customer data: Each customer's Knowledge Graph is completely isolated.
- ✕ Retain data after disconnection: When you revoke an integration, we lose all access immediately.
5. Information We Collect Directly
We do collect limited information necessary to operate the service:
- Account Information: Email, name, company, billing details
- Usage Telemetry: Feature usage, error logs, performance metrics (anonymized)
- Audit Logs: Records of all orchestration actions for compliance
- Support Communications: Emails, chat transcripts with our team
6. HIPAA & Healthcare Data
For customers in healthcare or handling Protected Health Information (PHI), Hagonel offers HIPAA-compliant deployments through our partnership with proxiML.
proxiML AI Clean Room Features:
- • Cryptographically provable zero data exposure
- • Air-gapped, on-premise deployment
- • SOC 2 certification
- • BAA (Business Associate Agreement) available
7. Data Retention
- Runtime Data: Not retained beyond the immediate request
- Knowledge Graph: Retained until you delete it or terminate service
- Audit Logs: 90 days (or longer per enterprise contract)
- Account Data: Until account deletion + 30 days
- Billing Records: 7 years (legal requirement)
8. Third-Party Subprocessors
Hagonel uses the following categories of subprocessors:
- Cloud Infrastructure: AWS / GCP (SOC 2, ISO 27001)
- LLM Providers: Anthropic, OpenAI (Enterprise agreements, no training on data)
- Payment Processing: Stripe (PCI DSS compliant)
- Analytics: PostHog (self-hosted instance, EU data residency option)
Enterprise customers may request the full subprocessor list and receive 30-day notice of any changes.
9. Your Rights (GDPR/CCPA)
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of data we hold about you
- Rectification: Correct inaccurate personal data
- Deletion: Request erasure of your data
- Portability: Export your Knowledge Graph in standard formats
- Objection: Object to certain processing activities
- Restriction: Limit how we process your data
To exercise these rights, contact privacy@hagonel.ai
10. Security Measures
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- SOC 2 Type II audited infrastructure
- Regular penetration testing and security audits
- Role-based access control (RBAC) for all internal systems
- Mandatory security training for all employees
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email and/or a prominent notice in the Hagonel interface at least 30 days before taking effect.
12. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@hagonel.ai
Data Protection Officer: dpo@hagonel.ai