Privacy Policy
Effective Date: February 10, 2026
Version 1.0
Last Updated: February 11, 2026
Introduction
BORING WORKFLOWS PTE. LTD. ("Boring Workflows," "Company," "we," "us," or "our"), a company incorporated in Singapore with its registered address at 380 Jalan Besar #06-02, Arc 380, Singapore 209000, operates the Boring OS platform and related services (collectively, the "Services") accessible via https://boringworkflows.ai.
This Privacy Policy describes how we collect, use, disclose, and protect personal data when you access or use our Services, including our web dashboard, APIs, messaging integrations (Slack, WhatsApp), and Voice AI interfaces. This Policy applies to all users of our Services, including enterprise clients, their authorized end users, and visitors to our website.
We are committed to protecting your privacy and processing personal data in compliance with applicable data protection laws, including the Singapore Personal Data Protection Act 2012 ("PDPA"), the European Union General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and the Australian Privacy Act 1988 ("APA").
Definitions
- "Client" means an enterprise organization that has entered into an agreement with Boring Workflows to use the Services.
- "End User" means an individual authorized by a Client to use the Services on the Client's behalf.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- "Sub-Processor" means a third-party service provider engaged by Boring Workflows to process Personal Data on behalf of a Client.
- "Boring OS" means our proprietary AI-powered semantic operating system that orchestrates AI agents across enterprise systems.
Categories of Personal Data We Collect
Depending on how you interact with our Services, we may collect the following categories of Personal Data:
Customer Personal Information
- Full name, email address, phone number, and business address
- Job title, department, and organizational affiliation
- Account credentials and authentication tokens
- Communication preferences and language settings
Telecommunications Data
- Customer account and subscription information from BSS/OSS systems
- Billing records, usage data, and service history
- Network configuration and service provisioning details
- Customer support interaction logs and ticket data
CRM and Support Interaction Data
- Customer relationship management records
- Support tickets, case notes, and resolution histories
- Customer feedback, surveys, and satisfaction scores
- Sales pipeline data and engagement metrics
Voice Recordings and Transcripts
- Audio recordings from Voice AI interactions
- Automated transcriptions of voice conversations
- Voice biometric data (if applicable, with explicit consent)
- Call metadata including timestamps, duration, and routing information
Technical and Usage Data
- IP addresses, browser type, device identifiers, and operating system
- API usage logs, request/response metadata, and error logs
- Interaction patterns with the Boring OS dashboard and integrations
- Cookies and similar tracking technologies (see Section 10)
How We Collect Personal Data
We collect Personal Data through the following means:
- Directly from you: When you register, configure, or interact with our Services, or contact our support team.
- From your employer/Client: When a Client provisions your access or provides data through system integrations.
- Through integrated systems: When our platform connects to Client BSS, OSS, CRM, billing, and network systems via APIs and connectors.
- Through messaging platforms: When you interact with our AI agents via Slack or WhatsApp integrations.
- Through Voice AI: When you use our voice interface for customer service or operational tasks.
- Automatically: Through cookies, log files, and similar technologies when you access our website or Services.
Legal Basis and Purpose of Processing
We process Personal Data for the following purposes and legal bases:
| Purpose | Legal Basis (GDPR) | Details |
|---|---|---|
| Service Delivery | Performance of contract | Orchestrating AI agents, processing workflows, and providing platform functionality |
| System Integration | Legitimate interest / Contract | Connecting to and processing data from Client BSS, OSS, CRM, and billing systems |
| AI Model Processing | Contract / Consent | Processing data through AI models (including third-party and customer-provided models) to deliver intelligent automation |
| Voice Processing | Consent / Contract | Recording, transcribing, and analyzing voice interactions for service delivery and quality assurance |
| Security & Compliance | Legal obligation / Legitimate interest | Fraud detection, access logging, audit trails, and regulatory compliance |
| Product Improvement | Legitimate interest | Analyzing usage patterns, performance metrics, and error rates to improve our Services (using aggregated/anonymized data) |
| Communications | Consent / Legitimate interest | Sending service updates, security alerts, and (with consent) product announcements |
Data Sharing and Disclosure
We may share Personal Data with the following categories of recipients:
Sub-Processors and Infrastructure Providers
We engage the following categories of sub-processors to deliver our Services. A current list of specific sub-processors is available upon request.
- Cloud Infrastructure: Google Cloud Platform (GCP) and Amazon Web Services (AWS) for hosting, storage, and computing
- AI Model Providers: Anthropic, OpenAI, and other AI providers for natural language processing and intelligent automation
- Communications: Twilio and similar providers for voice, SMS, and messaging capabilities
- Customer-Provided Models: Where Clients deploy their own AI models within the Boring OS environment
Client Organizations
When you use our Services as an End User authorized by a Client, that Client may have access to your usage data, interaction logs, and workflow outputs as the data controller.
Legal and Regulatory Disclosures
We may disclose Personal Data where required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, safety, or property of Boring Workflows, our Clients, or others.
Business Transfers
In connection with a merger, acquisition, reorganization, or sale of assets, Personal Data may be transferred to the acquiring entity, subject to applicable data protection requirements.
International Data Transfers
As a Singapore-incorporated company serving Clients globally, Personal Data may be transferred to and processed in jurisdictions outside the data subject's country of residence, including Singapore, the United States, the European Economic Area, Australia, and other ASEAN countries.
For transfers from the EEA/UK, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements with appropriate technical and organizational measures
For transfers involving Australian data, we comply with Australian Privacy Principle (APP) 8 regarding cross-border disclosure of personal information.
Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data: Retained for the duration of the Client's contract and for 12 months thereafter, unless a longer period is required by law.
- Voice recordings and transcripts: Retained in accordance with the Client's data retention policy, or for a maximum of 24 months if no policy is specified.
- API and usage logs: Retained for 12 months for operational and security purposes.
- Website analytics data: Retained for 26 months in anonymized/aggregated form.
Upon termination of a Client agreement, we will delete or return all Client Personal Data within 90 days, unless retention is required by applicable law.
Data Security
We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and multi-factor authentication
- Regular security assessments and penetration testing
- Audit logging and monitoring of all data access
- Secure development practices and code review processes
- Incident response and breach notification procedures
- Employee security training and confidentiality agreements
Where Clients deploy their own AI models within Boring OS, we maintain logical separation and access controls to ensure data isolation between tenants.
Cookies and Tracking Technologies
Our website and Services use cookies and similar technologies. We categorize these as:
- Strictly Necessary Cookies: Required for platform functionality, authentication, and security. These cannot be disabled.
- Analytical Cookies: Used to understand how users interact with our website and Services, helping us improve performance and user experience.
- Functional Cookies: Used to remember your preferences and provide enhanced features.
We do not use cookies for advertising or behavioral profiling. You may manage cookie preferences through your browser settings.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your Personal Data:
Rights Under GDPR (EEA/UK)
- Right of access: Obtain confirmation of and access to your Personal Data
- Right to rectification: Correct inaccurate or incomplete Personal Data
- Right to erasure: Request deletion of your Personal Data in certain circumstances
- Right to restriction: Restrict processing of your Personal Data
- Right to data portability: Receive your Personal Data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: Where processing is based on consent, withdraw at any time
- Right to lodge a complaint: File a complaint with a supervisory authority
Rights Under CCPA/CPRA (California)
- Right to know: What Personal Data we collect, use, disclose, and sell
- Right to delete: Request deletion of Personal Data
- Right to correct: Request correction of inaccurate Personal Data
- Right to opt-out: Opt out of the sale or sharing of Personal Data (note: we do not sell Personal Data)
- Right to non-discrimination: Equal service regardless of exercising privacy rights
Rights Under PDPA (Singapore)
- Right of access: Access your Personal Data held by us
- Right to correction: Correct errors in your Personal Data
- Right to withdraw consent: Withdraw consent for collection, use, or disclosure
- Right to data portability: Request data in a commonly used format
Rights Under APA (Australia)
- Right to access: Access your personal information
- Right to correction: Request correction of personal information
- Right to complain: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
To exercise any of these rights, please contact us at privacy@boringworkflows.ai. We will respond within the timeframe required by applicable law (generally 30 days). If you are an End User of a Client, we may refer your request to the relevant Client as the data controller.
AI Processing and Automated Decision-Making
Our Services use artificial intelligence and machine learning to automate workflows, process natural language, and orchestrate actions across enterprise systems. Specifically:
- AI Agent Processing: Our AI agents process data from integrated systems to execute workflows, generate insights, and facilitate decision-making. Agents operate within governed access policies set by Clients.
- Natural Language Processing: We process text and voice inputs to understand user intent and translate it into system actions.
- Third-Party AI Models: We may process data through third-party AI model providers (such as Anthropic and OpenAI). Data sent to these providers is subject to our data processing agreements with them and is not used to train their general-purpose models.
- Customer-Provided Models: Where Clients deploy their own AI models, data processing is subject to the Client's own policies and our platform security controls.
We do not use Personal Data for fully automated decision-making that produces legal or similarly significant effects without human oversight, unless explicitly agreed with the Client and with appropriate safeguards in place.
You have the right to request information about the logic involved in automated processing and, where applicable, to request human review of automated decisions.
Data Controller and Processor Roles
In most cases, our Clients are the data controllers and Boring Workflows acts as a data processor (or service provider under CCPA). This means:
- Clients determine the purposes and means of processing Personal Data
- Boring Workflows processes Personal Data only on the Client's documented instructions
- We enter into Data Processing Agreements (DPAs) with Clients that govern our processing obligations
Where we collect data directly (e.g., website visitors or prospective clients), we act as the data controller.
Children's Privacy
Our Services are designed for enterprise use and are not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child, we will take steps to delete it promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will provide notice of material changes by posting the updated Policy on our website and, where appropriate, notifying Clients directly. The "Last Updated" date at the top of this Policy indicates when it was most recently revised.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us at:
BORING WORKFLOWS PTE. LTD.
Data Protection Contact
Email: privacy@boringworkflows.ai
Address: 380 Jalan Besar #06-02, Arc 380, Singapore 209000
For complaints regarding our handling of Personal Data, you may also contact the relevant supervisory authority in your jurisdiction, including the Personal Data Protection Commission (PDPC) in Singapore, the relevant Data Protection Authority in the EU/UK, the California Attorney General, or the Office of the Australian Information Commissioner (OAIC).
Make Your Boring Workflows AI-Native
Built by a team that has lived inside telco systems