Privacy Notice

What personal data we collect, why, how long we keep it, and your rights under UK GDPR.

  • Last updated 26 September 2026
  • UK GDPR
On this page

1. Introduction

This Privacy Notice explains how Leveld (“Leveld”, “we”, “us”) collects and uses personal data when you use the Leveld B2B agentic project-management platform (the “Service”).

It applies to the people who sign up to use Leveld directly — the authorised users of a customer organisation — and to the personal data of others that we process on a customer’s behalf when delivering the Service. For business customers, the controller- processor terms that govern processing on their behalf live in our Data Processing Agreement; this notice covers our direct relationship with you as an individual.

2. Contact details

Leveld is incorporated in England and Wales. You can reach us at:

Our Data Protection Officer is reachable at get@leveld.ai.

3. What we collect

We collect personal data in the following categories:

CategoryExamples
IdentificationName, job title, employee ID, profile picture.
ContactEmail address, phone number, postal address.
AccountUser ID, email magic-code authentication events, session identifiers, and security metadata. Leveld does not store a user password for beta sign-in.
Communication contentGmail message body, headers, attachments, and anything that customers or their authorised users submit through the active Gmail connector.
Project metadataRegister items, tags, assignments, dates, evidence references.
BehaviouralInterface events, accept / dismiss / edit signals, calibration telemetry that helps us measure how well the agent is working.
Product feedbackProduct-feedback messages, their category, and the Service route from which they were submitted.
Recommendation feedbackRecommendation scores and optional reasons supplied when we ask how likely you are to recommend Leveld.
TechnicalIP address and the approximate location (city, region and country) it indicates, looked up when you sign in; user-agent; device fingerprint (for high-risk actions only).
Account administrationWorkspace membership, role, and invitation status.

We work out the approximate location from your IP address with a location database we hold ourselves, so your IP address is not sent to a third party for this. We keep it with your sign-in records to help secure your account. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

4. Why we collect it

We use personal data to:

  • Deliver the Service: authenticate users by email magic code, ingest and extract work from the authorised Gmail account, surface drafts and register items, and send email when explicitly asked to.
  • Secure the Service: detect abuse, prevent fraud, maintain an audit log of high-risk actions, and respond to security incidents.
  • Improve the Service: Leveld reviews product-feedback messages, recommendation scores, and optional reasons to understand user experience and improve the Service. We also use aggregate, anonymised learnings from how the Service is used. Customer content is not used to train Leveld or provider models.
  • Meet our legal obligations: tax records, regulatory retention, responding to lawful requests.

5. Google user data

Connecting Gmail is optional and separate from signing in. This section sets out exactly what Leveld does with the data it receives from Google when you connect a mailbox.

5.1 What we ask Google for

Leveld requests two Gmail scopes, and no others. Both are shown to you on Google’s own consent screen before anything is granted:

ScopeWhat Google calls itWhat Leveld uses it for
gmail.readonlyView your email messages and settings.Reading the messages in the connected mailbox so Leveld can turn them into actions, decisions, risks and information, each cited back to the message it came from. It also registers and stops the notification channel that tells Leveld when new mail arrives.
gmail.composeManage drafts and send emails.Preparing a reply as a draft and sending it — only after you have read it and pressed send in Leveld.

Leveld also receives your Google account’s email address (through the openid and email scopes) so the mailbox can be bound to your Leveld account. Leveld does not use Google as a sign-in method, does not request calendar access, and cannot delete your mail: neither scope permits it.

5.2 What Leveld does with it

  • Reads message headers, bodies and attachments from the connected mailbox, and the change history that tells Leveld which messages are new.
  • Extracts work from them — actions, decisions, risks and information — each linked to its source message. This uses the AI model providers listed in our Sub-processor Register, which receive the message content needed for the task.
  • Writes nothing to your mailbox except a draft you asked for. Leveld never sends on its own: every outbound email is prepared as a draft and sent only when you press send.

5.3 How it is stored and secured

Message content is encrypted before it is stored, using AES-256-GCM with data keys held in a managed key service and bound to your workspace. The Google access and refresh tokens are encrypted the same way and are never written to logs. Access is limited to the workspace context you authorise, and hosting and storage regions are described in section 10.

5.4 Who else sees it

Only the sub-processors in our register, for the purposes recorded there — hosting and storage, AI inference, and the Gmail API itself. Execution traces sent to our AI-observability vendor are content-free: message, email and output text is removed before export. Leveld does not sell Google user data and does not share it with advertising or marketing brokers.

5.5 No AI training

Data received from Google Workspace scopes is not used to create, train, or improve a machine-learning or artificial-intelligence model, whether ours or a provider’s. Every AI request Leveld makes sets provider data collection to deny; the detail, including what a provider may retain under its own contract, is in our AI Transparency Statement.

5.6 Ending the connection and deleting the data

You can disconnect Gmail at any time from Settings → Connectors. Disconnecting revokes Leveld’s access token at Google and stops the mailbox notification channel, so no further data is received. You can also revoke Leveld from your Google Account’s permissions page; Leveld does not inhibit that. Message content already ingested follows the retention rules in section 8 — deleted within 30 days of account closure — and you can ask us to erase it sooner at get@leveld.ai.

To delete your Leveld account, use Settings → Account. Once you confirm with a code sent to your account email address, Leveld revokes its access at Google, erases your account, your projects and the messages it ingested, deletes your beta application, and emails you when your account data is gone. Stored message files become unreadable straight away; our storage keeps each one under a 30-day write-once lock from when it arrived, and Leveld erases the last copies when that lock ends. Deletion cannot be undone.

5.7 Limited Use

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

6. Lawful basis

We rely on the following lawful bases under UK GDPR Article 6:

6.1 Performance of a contract

For most processing required to deliver the Service to you or your employer (UK GDPR Art. 6(1)(b)).

6.2 Legitimate interests

For security, audit logging, fraud prevention, reviewing product and recommendation feedback, and improving the Service through that feedback and aggregate analytics (UK GDPR Art. 6(1)(f)). Our legitimate interests are running, securing, and improving the platform; we have weighed these against your rights and freedoms and consider them proportionate.

6.3 Legal obligation

For tax records, regulatory retention, and compliance with lawful requests (UK GDPR Art. 6(1)(c)).

6.4 Consent

For an optional feature only where we expressly ask for it. Consent is never inferred from use of the beta and can be withdrawn at any time (UK GDPR Art. 6(1)(a)).

7. Special categories of data

Leveld does not deliberately solicit special-category data (UK GDPR Art. 9) or data relating to criminal convictions and offences (Art. 10). However, because Leveld ingests authorised Gmail content, special-category data may appear incidentally in content that customers and their correspondents supply.

Where Leveld processes personal data on a customer’s behalf, the customer is the controller and is responsible for nominating the appropriate Art. 9(2) condition and any required Data Protection Act 2018 Schedule 1 Part 4 appropriate policy document. Leveld treats all ingested content as if it may contain special-category data for security-control purposes.

8. How long we keep it

We keep personal data only as long as we need it to deliver the Service, meet our legal obligations, or resolve disputes. Headline retention periods:

Data typeRetention
Account and contact dataFor the lifetime of your account, deleted within 30 days of account closure (subject to legal retention).
Gmail and product communication contentFor the lifetime of your account, deleted within 30 days of account closure.
Feedback and recommendation dataFor the lifetime of your account, deleted within 30 days of account closure.
Sign-in records (IP address, approximate location, user-agent)For the lifetime of your account, deleted within 30 days of account closure.
Audit-log entries (high-risk actions)1 year in hot storage plus 6 years in cold storage, for compliance and dispute resolution.
BackupsEncrypted backups expire under service-specific schedules. RDS automated backups are retained for seven days; deleted data ages out as those backups expire.
Tombstone records (proof of deletion)Retained indefinitely in minimal form (no personal content) so we can demonstrate compliance with deletion requests.

9. Who we share data with

Leveld engages third parties to deliver the Service. The complete register lives at /legal/sub-processors and we recommend reading it for full detail. In summary:

  • Sub-processors — vendors that process personal data on our instructions, under UK GDPR Art. 28 terms. These include the infrastructure, Gmail API, authentication, AI routing, durable-workflow, observability, AI-evaluation, incident-response, and customer-support vendors in that closed register.
  • Independent controllers — none receive personal data for beta payment collection. Beta access is free and Leveld does not collect payment details.

Email magic-code authentication is handled by WorkOS. Gmail connector authorisation is separate from sign-in. Connecting Gmail grants only the approved Gmail OAuth scopes to the product connector; it is not a Google social-login flow. Microsoft social login is also disabled for beta.

We do not sell personal data. We do not share personal data with advertising or marketing brokers.

10. International transfers

Leveld is established in the United Kingdom and pins data storage to UK and EU regions wherever possible. Where personal data is transferred outside the UK or the European Economic Area, we rely on one or more of:

  • UK or EU adequacy decisions for transfers to countries the UK or EU has determined offer adequate protection.
  • The EU-US Data Privacy Framework, together with the UK Extension, for transfers to certified US recipients.
  • The EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) plus the UK International Data Transfer Addendum for transfers to non-certified recipients.
  • A data protection test, using the “not materially lower” threshold introduced by the Data (Use and Access) Act 2025.

The per-vendor transfer mechanism is listed at /legal/sub-processors.

11. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Ask us to rectify data that is inaccurate or incomplete (the right to rectification).
  • Ask us to erase data (the right toerasure, also called the “right to be forgotten”) where we have no overriding lawful basis to retain it.
  • Ask us to restrict processing (the right to restriction) while we investigate an objection or correction.
  • Receive your data in a portable format (portability).
  • Object to processing we carry out on the basis of legitimate interests.
  • Withdraw consent at any time, where the lawful basis is consent.
  • Complain to the Information Commissioner’s Office at ico.org.uk.

Exercise any of these rights by emailing get@leveld.ai. You can also erase your account yourself from Settings → Account; section 5.6 explains what that deletes and when. We aim to respond within 30 days. Where Leveld is the processor on behalf of a customer (i.e. the data subject is not a direct Leveld user), we will forward the request to the customer and support their response.

12. Automated decision-making

Leveld is an assistant. The Service generates suggestions, drafts, and ranked lists, but a human user reviews and decides on every external action. Leveld does not make decisions about you that produce legal effects or similarly significant effects within the meaning of UK GDPR Art. 22 without human review.

13. Cookies

Leveld uses a small number of essential cookies and browser storage for authentication, session management, and CSRF protection. These are strictly necessary to deliver the Service and are always on. We do not set advertising or third-party tracking cookies.

One optional category exists: support chat cookies, which let our support widget load. Because it is not strictly necessary, we ask for your choice in a banner on your first visit and load nothing until you allow it. Rejecting is presented as prominently as allowing.

You can change that choice at any time: select Cookie preferences in the footer of leveld.ai and the banner returns with your current choice, ready to be changed. Withdrawing is as quick as giving consent, and takes effect immediately.

14. Changes to this notice

We may update this Privacy Notice from time to time. The “Last updated” date at the top of the page reflects the current revision. Material changes are notified to account-holders by email; non-material changes (typo fixes, link updates) are published silently.

15. Contact

For privacy questions or to exercise any of the rights listed above, contact our Data Protection Officer at get@leveld.ai. For commercial or legal questions, contact get@leveld.ai.

Last updated 26 September 2026. Contact get@leveld.ai for questions about this Privacy Notice.