XuperBoss public notice
Privacy Notice
This notice explains the information XuperBoss processes, why it is processed, and the controls that apply to organization workspaces, connected services, files and the XuperBoss Agent.
Last updated August 26, 2026
1. Scope and current release boundary
This notice applies to the XuperBoss Portal at xuperbossportal.work. Access is invite-only. The service identifies its active data boundary on the sign-in and administration screens. Unless that boundary expressly states that approved customer data is permitted, only internal synthetic data may be entered.
2. Information processed
- Account identity, organization membership, roles, permissions and MFA state.
- Authentication, session, security, audit, rate-limit and administrative events.
- Authorized CRM, education, task, activity and configuration records.
- Files, knowledge sources, extracted text, search indexes and Agent artifacts uploaded by authorized users.
- Agent prompts, plans, tool results, approvals, cancellations and execution history.
- Scoped connection metadata and encrypted OAuth credentials for services an administrator enables.
- Subscription, invoice and payment-operation metadata when live billing is separately enabled.
3. How information is used
XuperBoss uses information to provide tenant-isolated business workflows, enforce authorization, execute approved Agent tasks, deliver requested integrations, secure and operate the service, investigate incidents, maintain backups and satisfy applicable legal obligations. XuperBoss does not sell workspace data.
4. AI and connected services
External processing occurs only for a provider and organization capability that is enabled on the server. Agent actions remain permission-scoped, audited and subject to explicit human confirmation before a proposed mutation is committed. Requests to an AI provider are minimized to the authorized task context; provider retention and data-control terms still apply even when application-level storage is disabled.
Microsoft Graph, Google Workspace, OpenAI, Stripe and transactional email may be used only after their production configuration and organization authorization are complete. Salesforce Live is not enabled. Disabled providers reject requests at the API layer rather than relying on hidden navigation.
5. Tenant isolation and disclosure
Records and objects are bound to an organization. Direct membership, role and module permissions are rechecked for protected requests and Agent tools. Data may be disclosed to a configured processor, an authorized organization administrator, or a lawful authority only to the extent required for the authorized purpose.
6. Retention, deletion and backups
Operational records are retained according to the active organization policy, security and audit needs, contractual requirements and applicable law. Authorized administrators can request or initiate supported export and deletion workflows. Deleted information may remain in encrypted backups until the bounded backup cycle expires. Legal holds and verified security investigations may delay deletion.
7. Security
XuperBoss uses least-privilege access, tenant-scoped authorization, MFA and revocable sessions, encrypted provider credentials, bounded request bodies, malware scanning for enabled uploads, audit trails, rate limits, backups and a tested rollback path. No system is guaranteed to be completely secure.
8. Requests and choices
To request access, correction, export, restriction or deletion, contact your organization administrator or reply through the invitation or support channel that provided access. Identity and authority will be verified before a request is fulfilled. Available rights depend on the applicable jurisdiction and contract.
9. Education and children
XuperBoss is not directed to children for independent use. Education records may be processed only under the direction of an authorized organization and its approved users. Organizations are responsible for obtaining required notices, consents and authority before entering such records.
10. International processing and changes
Configured processors may operate in other jurisdictions. Appropriate contractual and organizational safeguards must be approved before real customer data is enabled. Material changes to this notice will be posted here with a revised date; where required, affected organizations will receive additional notice.
