1. Who is responsible
Innovative AI Solutions operates MXG Core AgentOS and is the controller for the processing described in this policy.
Privacy contact: contact.innovative.ai@gmail.com
2. Data we process
Depending on how you use the service, we may process:
- account details, such as your email address, role and company workspace;
- authentication and security data, such as session records, login events and audit information;
- content you provide, including campaign briefs, drafts, media references, review decisions and publication schedules;
- connected-channel data, such as a platform account identifier, display name, granted permissions and encrypted access or refresh credentials;
- technical data needed to operate and protect the service, such as request time, status, browser information and IP-derived security signals;
- publication results returned by a social platform, such as a post identifier, status or public post URL.
We do not ask you to place passwords, API keys or access tokens in chat or public content. Channel credentials must be entered only through the protected Config Vault.
3. Why we use data
- Provide the service: authenticate users, maintain workspaces, create and review content, connect selected channels and publish user-approved posts.
- Protect the service: prevent abuse, keep audit records, troubleshoot failures and enforce workspace isolation and approval controls.
- Meet legal obligations: respond to valid legal requests and maintain records where applicable law requires this.
- Improve reliability: understand technical errors and maintain the features users request.
4. Legal bases
Where the EU General Data Protection Regulation applies, we rely on:
- performance of a contract or steps requested before entering into a contract;
- our legitimate interests in operating, securing and improving the service, balanced against your rights;
- compliance with legal obligations; and
- consent where a specific integration or optional action requires it. You may withdraw consent, although this does not affect earlier lawful processing.
5. Meta, TikTok and other connected platforms
When an authorised user connects Instagram, Meta, TikTok or another supported platform, MXG Core AgentOS processes only the account and authorisation data needed for the permissions that user grants. Approved content and necessary media or metadata are sent to the selected platform only when the user requests or schedules publication.
Meta may send MXG Core a signed user-data deletion request. After its signature is verified, MXG Core removes the matching encrypted user credentials, connected account identity, provider-derived analytics and outstanding provider references. The requester receives a private confirmation code and status page. Invalid or unsigned requests cannot trigger deletion.
Connected platforms separately process data under their own terms and privacy policies. Removing a channel's credentials stops future AgentOS access, but does not automatically remove posts already published on that platform. Published content must also be managed on the relevant platform where necessary.
6. Sharing and international transfers
We share personal data only where needed with hosting, infrastructure, security and AI service providers acting under appropriate arrangements, with a social platform you choose to connect, or where disclosure is legally required. We do not sell personal data.
Some connected platforms or service providers may process data outside the European Economic Area. Where required, we use an applicable transfer mechanism and safeguards. A connected platform's own processing is also governed by its published terms and privacy information.
7. Retention
We keep personal data only for as long as needed for the purposes described above. Active workspace content and publication history are retained while the relevant workspace or account remains in use. Chat messages are normally retained for up to 90 days and uploaded attachments for up to 30 days, unless the operator changes those configured periods or a longer period is needed for security, legal obligations or claims.
Encrypted channel credentials are kept until they are replaced, removed by an authorised owner, or no longer needed. Security and audit records may be retained longer where necessary to protect the service and demonstrate authorised activity.
8. Security
We use measures designed to protect data, including encrypted credential storage, write-only secret fields, access controls, company and workspace isolation, human approval gates, rate limits and audit logging. No system is completely secure, so users should protect their account and report suspected misuse promptly.
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may also withdraw consent where processing relies on consent.
Send requests to contact.innovative.ai@gmail.com. We may need to verify your identity. You may also lodge a complaint with the Dutch Data Protection Authority or your local supervisory authority.
10. Children
MXG Core AgentOS is a business service and is not directed to children. Do not use the service to submit children's personal data unless you have a lawful basis and appropriate safeguards.
11. Changes
We may update this policy when the service or legal requirements change. We will publish the revised version here and update the date above. Material changes may also be communicated through the service.