DATA AND PRIVACY
What the product does
with your data.
Described from how Chief Agent actually behaves, not from what a policy would like to be true. Each of the statements below is enforced in the software and can be shown to you in the product.
How it behaves
Enforced, not promised.
The difference matters. A policy is a statement of intent; these are properties of the running system, and the ones about separation and the audit trail are enforced below the application, where the application cannot talk its way past them.
One company cannot read another
Separation is enforced by the database, not only by the application. Every company-owned table carries a row-level policy, and the account the product connects with cannot bypass it. A query that asks for another company’s rows returns nothing, whatever the code above intended.
What happens is recorded, and the record cannot be edited
Actions land in an append-only trail, hash-chained so that a removed or altered row shows as a break rather than as nothing. It holds who acted, what changed, when, and the reason where the action required one.
A company’s data sits with that company
Data residency is set per company rather than globally, so where your data lives is part of your arrangement rather than a platform-wide default you inherit.
Aadhaar is used for matching, and nothing else
Where an Aadhaar number is entered it is used to match a person to a record inside your own company. UBoss does not perform Aadhaar authentication and does not claim verified Aadhaar status. It is not identity evidence and no decision in the product treats it as such.
A photograph is optional, and it is not identity
An employee photograph is one of the things a company may add and is never required. It appears where a colleague’s name already appears, and nowhere else.
There is no public sign-up
A company exists in UBoss because somebody at UBoss provisioned it. Nobody can create a workspace holding your people’s data by filling in a form.
Not yet on this page
What a notice still needs.
This page describes the product. It is not a privacy notice under the DPDP Act or the GDPR, and it does not stand in for one — a notice has to carry facts about the company, and those are not written here because they would have to be invented.
- The legal entity that is the data fiduciary, and its registered address
- A named contact for data-protection and data-subject requests
- The list of sub-processors that handle personal data, including the model provider behind AI runs
- Retention periods, stated per kind of record
Until those are supplied by the company, this page is a description and not an undertaking. If you are evaluating Chief Agent and need the notice for procurement, ask and it will come from the company rather than from this website.