New research: The 2026 AI Visibility Report

Legal

Data & AI policy.

How we handle your business’s data when we build AI for you or run your channels. What we do, and what we never do.

The short version

  • Your data stays yours. We work on it under your instructions, for your project only.
  • We ask for the least access that does the job, and you can take it back at any time.
  • A person approves what an AI agent sends or changes, unless you have agreed otherwise in writing.
  • We do not use your data to train AI models, and we only use AI providers whose business terms say they will not either.
  • You know which providers are involved before we build.
  • When the work ends, we hand your data back or delete it.

1. What this policy covers

This policy covers the information your business gives Bodhi and Co., LLC (“Bodhi & Co”, “we”, “us”) access to when we work for you: the inboxes, documents, customer records, systems and social accounts we need in order to build an AI agent, run a search project or manage your channels. We call it client data.

It sits alongside your written agreement with us. If the two ever disagree, the agreement wins for that work.

How we treat visitors to our own website is a separate matter, covered by our Privacy policy.

2. Your data stays yours

You own your data, including everything in it about your customers. We act on your instructions.

  • We use client data to do the work you have asked for, and for nothing else.
  • We do not sell it, and we do not share it for advertising.
  • We do not use one client’s data in work for another client.
  • We do not name you as a client, or show the work, without your permission.

3. Access

  • The least that does the job. One mailbox rather than the whole domain. Read-only where reading is enough.
  • Roles, not passwords. We ask for access through each system’s own roles, connected accounts or API keys. Please do not send us your personal passwords.
  • Kept properly. Keys and credentials are kept in a password manager, never in email, chat or code.
  • Only the people on your project can reach your systems.
  • Yours to withdraw. You can take access away at any time, and we will show you how.

4. AI providers

An AI agent works by sending text to an AI model and reading what comes back. That means some of your data goes to the company that runs the model. So:

  • You are told first. Before we build, we tell you in writing which AI providers your project uses and what is sent to each.
  • Business terms only. We use AI providers under their business or API terms, which state that customer data is not used to train their models. We do not put client data into free or consumer AI tools.
  • The least the task needs. If an agent needs the order, it is sent the order, not the customer’s whole history.
  • If the terms change in a way that affects you, we tell you.

Each provider handles what it receives under its own terms and privacy policy. We will point you to them.

5. A person approves

The agents we build draft. People decide. By default an agent prepares the email, the order or the update, and a person at your business approves it before anything is sent or saved.

A step runs without approval only where you have agreed to that in writing. Every agent keeps a record of what it did, so that its work can be checked.

6. Where it is kept, and for how long

We build so that your data stays in your own systems wherever we can.

Sometimes we need working copies: sample emails to test an agent against, or an export for a report. We keep them for the length of the project and no longer.

Within 30 days of the work ending we return or delete client data and remove our own access, unless the law requires us to keep something. We confirm in writing when that is done.

7. Security

  • Two-step sign-in on the accounts we use to reach client systems.
  • Encrypted connections to the systems we work with.
  • Encrypted, locked laptops.
If something goes wrong

If we learn that client data has been lost, exposed or reached by someone who should not have it, we will tell you within 72 hours of finding out, with what we know and what we are doing about it.

No system is perfectly secure, and we cannot promise that ours is. We take reasonable care, and we tell you when it matters.

8. Regulated and sensitive data

Some data carries legal duties of its own. If your project involves any of the following, tell us before it starts, and we will agree in writing how it is handled before we touch it.

  • Health information. We do not handle protected health information (HIPAA) without a business associate agreement in place with us and with every provider involved.
  • Privileged or confidential legal material.
  • Payment card and bank details. We design agents so that they never see full card numbers.
  • Information about children.
  • Government ID numbers.

If the safeguards a project needs cannot be put in place, we will say so, and we will not build it.

9. Social media accounts

We manage client channels through each platform’s own business roles, not through shared personal logins. Messages and comments from your customers are answered in the platform. We do not export them to build lists.

10. Requests from your customers

If one of your customers asks to see, correct or delete their information, and it is held in something we built or manage for you, tell us and we will help you respond.

11. People we work with

If a specialist outside Bodhi & Co works on your project, we tell you who they are, and they work under the same rules as we do.

12. Changes to this policy

When we change this policy we post the new version here with a new “Last updated” date. If a change affects work we are doing for you, we tell you directly.

13. Contact

Questions about how we would handle your data? Ask before you sign anything.

Bodhi and Co., LLC
West Greenville · Upstate, South Carolina, USA
hello@wearebodhiandco.com
864.553.1830

See also our Privacy policy and Terms of use.