Privacy
What we do with personal data, on this website and inside the product. In plain words, and with the gaps marked.
Updated
Who is responsible
Boreon Industries LLC publishes this website and provides Boreon. Our full identification is in the legal notice.
For any privacy question, and to exercise any right described here, write to privacy@boreon.com.
This website
This site exists to describe the product. It does not exist to profile you, and it is built that way rather than promising it.
- No analytics, first-party or third-party. Nothing counts you.
- No advertising, no retargeting, no tracking pixels.
- No content delivery network, no external fonts, no embedded third-party scripts. Everything the page loads comes from this site.
- One cookie, and it remembers which language you read in. The cookie policy sets it out in full.
The web server that serves these pages keeps operational logs, as every web server does. Those logs exist to keep the site running and secure, not to build a profile.
Those logs are kept only while they are useful for that purpose and are not used to build a profile of you, combined with anything else, or sold. This site sets no analytics and no advertising cookie, so there is nothing here that follows you to another site.
Who is the controller, and when we are not
This is the distinction that matters most, and the answer depends on which edition you run.
- Boreon Cloud
- You are the controller for the data you bring. Boreon is your processor and acts on your instructions. The data processing addendum sets out those terms.
- Boreon Server
- The software runs in infrastructure you control, and your content never reaches us. Boreon is not a processor of it, because there is nothing for us to process. You are the controller and the operator both.
- This website, and talking to us
- Boreon is the controller for the small amount of personal data involved in publishing this site and in corresponding with you.
Everything below describes the hosted edition unless it says otherwise. On the self-hosted edition the same software behaves the same way, but the machine belongs to you.
What the product holds about a user
A user account in the hosted edition holds very little, and each item earns its place:
- Identity
- An email address, a role, and whether the account is active.
- Password
- Never the password. A hash of it, computed with scrypt at N=2^17, which is deliberately slow and memory-hungry so that a stolen file is worth very little.
- Second factor
- The secret your authenticator tool uses, encrypted at rest.
- Sessions
- Enough to expire a session on time and to end every live session the moment an administrator disables an account or resets a factor.
- Administrative actions
- Who changed what, and when. Passwords, hashes and second-factor secrets are never written to that log.
- AI usage, if AI is switched on
- Calls, tokens in and out, which model answered, and an estimated cost, per person, so that a conversation about AI spend can be a conversation about numbers.
If you use the Agent, your conversation is kept for you so that it survives moving between applications. It is stored per user and encrypted at rest, and no other user reaches it.
Credentials never reach your browser
Tableau personal access tokens and warehouse credentials are handled server-side and held for the session only. Nothing about them is sent to the browser, and the page you are looking at has never seen one.
Where a credential is deliberately kept for automation, it goes into an encrypted vault and is never shown again after it is saved. On the self-hosted edition, your organisation holds the secret that keys that vault, so Boreon could not read it even in principle.
Warehouse connections are read-only by construction. Salesforce Data 360, Snowflake Horizon Catalog and Databricks Unity Catalog are reached with a read-only credential you issue, the connectors contain no write method at all, and whatever your own warehouse role cannot see, Boreon cannot see either.
The same applies to Tableau. You sign in with your own token, and your own permissions come with you. We inherit what your Tableau environment already grants you. We never widen it.
AI is optional, on your key, and never in a write path
Every application in the suite produces its complete result without AI. That is the default, and leaving it there means no prompt reaches a model provider at all.
Switch AI on and it runs on the provider key you supply, with the provider you chose, under the contract you hold with them. Boreon supplies no key and keeps no shared pool, so what happens to a prompt after it leaves is governed by your agreement with your provider, not by ours.
Point that key at your own OpenAI-compatible endpoint, including a proxy inside your own network, and a prompt travels only as far as a machine you operate.
The AI reads, explains and drafts. It has no write path. Anything that would change something arrives as an approve-to-run card and goes into the same governed gate a person would use, with the same signature and dual-control rules. A person always decides.
Where the Agent queries data, the query is recorded, successes and refusals alike, and no returned cell is ever written to that record. The row count is the only shape kept.
What the AI will and will not say, and the three independent layers that enforce it, are set out in full in the AI safety and content standards.
Where your data is processed
Boreon Cloud runs on dedicated Infomaniak infrastructure in Geneva, Switzerland, behind a web application firewall. There is no United States hyperscaler anywhere in the serving path.
Your data sits under Swiss data protection law. For a European buyer that is usually the first question and occasionally the only one, so it is worth saying plainly.
Data leaves that footprint in exactly one case: you switch AI on and choose a provider outside Switzerland. That is your choice, made per run, and you can avoid it entirely by leaving AI off or by pointing it at your own endpoint.
Any certification our hosting provider holds is theirs, not ours. Boreon itself holds no audited certification, and this site never implies one.
Boreon Cloud runs in Geneva and your data stays there. The one case where personal data leaves that footprint is if you switch AI on and choose a provider outside Switzerland, which is your decision and is described above. Where a transfer does occur under a signed agreement, the mechanism that covers it is set out in that agreement.
How long anything is kept
A retention period is a promise that something is actually deleted on a schedule. We would rather leave these blank until they are decided than publish a number nobody is keeping.
- Account records: for as long as the subscription they belong to is live, and after that for as long as we are required to keep them.
- The administrative audit log: for as long as the deployment it records is live, because an audit trail that is pruned is not an audit trail.
- AI usage records: for as long as they are needed to account for what was spent on your own key.
- Correspondence: for as long as the matter it concerns is open.
Credentials held for a session are gone when the session is. That one is not a policy, it is how the software is built.
Your rights, and how to use them
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Write to privacy@boreon.com and say what you want.
One thing worth knowing first. If you use Boreon because your employer bought it, your employer is the controller for that data and we act on their instructions. Ask them first. If you ask us, we will pass the request to them and tell you we have.
You can also complain to a supervisory authority. That right is yours wherever you live or work, and you can raise it with the data protection authority for that place. We would rather you came to us first, at privacy@boreon.com, but you are not required to.
Changes to this notice
The date at the top of this document is the date it last changed. When something material changes, we change this page rather than quietly changing the practice.
Privacy questions, requests and corrections all go to privacy@boreon.com.