Data processing
Last updated 26 August 2026
This page describes how 24on.ai processes workspace data when you are a customer. It is the thin version of a DPA, honest about what happens today, not a certificate we do not hold.
Roles
You are the controller of your workspace content. 24on.ai is the processor: we host it, run jobs against it, and keep the audit log. We do not use your workspace content to advertise to other customers.
Where it lives
Data is stored in the hosted workspace we operate, isolated per customer at the database level. We can access it to run the service. It is not end-to-end encrypted.
Subprocessors
AI model providers (we route between current models rather than running our own) and the connectors you choose. We will name specific vendors in a signed DPA when you need one.
Security measures
Access scoped by role, per-agent tool permissions enforced outside the model, spend caps checked before paid actions, append-only logs. We do not claim SOC 2 or similar unless we hold it. We don’t, today.
Your rights
Export on request. Deletion when you leave, except records we must keep. To ask for a signed DPA, write to [email protected] on a demo call or after.
