Hi Boss home

Privacy notice

LEVER CONSULTANCY LTD, trading as Hi Boss · Version 2026-09-07.2 · 7 September 2026

Who is responsible

LEVER CONSULTANCY LTD, trading as Hi Boss, company 12434213, 6 Rose Joan Mews, London, England, NW6 1DQ, is the controller for account administration, security, usage and support data. Contact Daniel Lever at lever.daniel@gmail.com for privacy requests. For meeting content and connected knowledge processed on a business customer’s instructions, that customer is normally the controller and we act as processor. Your meeting organiser can identify the relevant customer.

Data and sources

We receive sign-in identity, name, email, company, profile choices, acceptance records, invitations and usage records from you, your sign-in provider or administrator. If connected, Google supplies authorised calendar metadata and selected Drive content. Meeting participants provide speech, names and conversation content via the meeting provider. We process audio, transcripts, AI responses, summaries, actions and technical events. Uploaded documents and photographs may contain information about other people. Support submissions and reported meeting feedback are visible to the service owner.

Purposes and lawful bases

We use account and service data to deliver our contract with individual business subscribers and comply with legal obligations where applicable. For organisation representatives, security, service diagnostics and responding to enquiries we rely on legitimate interests in operating and protecting the service, taking account of your rights. We do not sell personal data or use meeting content for advertising. Customers determine and document the lawful basis for their meeting and knowledge processing. We do not make solely automated decisions producing legal or similarly significant effects about individuals.

Who can access data

Your account scopes private content. Company administrators see team identities, membership and usage budgets; your explicit company-sharing choices can make knowledge available to other approved company members. The global operator can access information necessary for support, administration, security and lawful requests. This is not an end-to-end encrypted service in which the operator cannot access data. Service providers process data as described in our subprocessor notice. Meeting participants hear the AI’s spoken responses, so choose sources appropriate for everyone present.

Audio and retention

Hi Boss does not retain meeting audio or video in its own storage. Live audio is processed through Recall.ai and OpenAI. Our current Recall bot configuration uses its documented zero-recording-retention setting with low-latency transcription. This does not cover all provider operational logs or OpenAI processing. Provider retention and operational logs are separate from our application storage. Transcript text, summaries and conversation diagnostics have a 30-day access window; physical cleanup runs in bounded batches across accounts when approved users use the platform, with daily checks and retries on later activity. If there is no platform activity or cleanup fails, records may remain stored longer. The operator can also run cleanup from Admin; there is no connected unattended scheduler. Saved actions, profiles, sources and usage records remain until deleted or account closure. Security, legal-hold and provider backup retention can differ. This is not a promise of zero retention across providers.

Deletion and export

Use Settings to export account records or request account deletion, Knowledge to remove sources and the transcript controls to remove retained conversation records. Keep any export secure. Source deletion and account deletion attempt applicable provider cleanup; failures are surfaced rather than reported as completed. Removing company access cannot erase copies already obtained by others. Contact us for meeting-content requests not covered by self-service controls. We may retain the minimum records required by law or to establish, exercise or defend legal claims and will explain applicable restrictions.

International processing and security

Providers may process information outside the UK. We must use applicable adequacy decisions or contractual safeguards, such as the UK IDTA or UK Addendum where required, and assess transfers before introducing new processing. Contact us for available transfer information. Provider agreements and location settings require ongoing verification; we do not offer a UK-only data-residency guarantee. Application controls include authenticated workspaces, scoped queries, meeting tokens and encryption of Google credentials. Cloudflare documents automatic encryption at rest for the D1 database and R2 object storage used by Hi Boss. These are provider-managed keys, not customer-managed end-to-end encryption. No service is completely secure and we do not claim SOC 2 or ISO 27001 certification.

Training and providers

We do not train Hi Boss models on your meeting content or connected knowledge. OpenAI states that API inputs and outputs are not used for model training unless the API customer opts in. That statement does not mean the API retains no data. We do not authorise optional training-data sharing for customer content. Provider processing, safety logs and stored knowledge indexes remain subject to the applicable service settings and agreements.

Your rights and complaints

Depending on the processing and applicable law, you can request access, correction, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent where consent is used. Contact lever.daniel@gmail.com. We may reasonably verify identity and normally respond within one month; lawful extensions will be explained. For customer-controlled meeting content, contact the organiser or contact us so we can help route the request. You can complain to the Information Commissioner’s Office at ico.org.uk. You do not have to contact us before doing so.

Cookies and changes

Hi Boss uses essential sign-in/session technologies and local browser preferences to operate the service. It does not intentionally add advertising trackers. Hosting and sign-in providers operate their own services and notices. Any future optional analytics requiring consent will need a separate choice. Material changes to this notice will be highlighted in the platform. Keep children’s and highly sensitive or regulated data out of the beta.

Contact us