Data Processing & Third-Party Integrations Policy
This policy describes the operational handling of client information, permissions, AI providers, APIs and third-party systems used in approved automation projects.
1. Purpose and scope
This policy describes how Brynqel Automata approaches client information, system access and third-party integrations when delivering workflow automation and AI-assisted services. It supplements the Privacy Policy by focusing on project data and operational integrations.
2. Client instructions and approved scope
Data processing should be tied to the agreed automation purpose. Clients are responsible for identifying approved systems, users, data categories and business rules. Brynqel Automata should not be treated as authorized to connect additional systems or use client data for unrelated purposes solely because technical access is available.
3. Data minimization
Where practical, an automation should process only the fields reasonably necessary to complete the approved workflow. Planning may include removing unnecessary data fields, separating test data from live data and limiting the information sent to an AI provider or external system.
4. Credentials and access
Clients may be asked to create dedicated API keys, service accounts, tokens or limited user accounts where that improves control. Access should be limited to the permissions needed for the project. Clients should rotate, revoke or remove access when it is no longer required.
5. Third-party integrations
Integrations may include automation platforms, AI providers, email systems, customer-support systems, databases, spreadsheets, file-storage services, customer-management systems, APIs or other cloud tools. Each provider operates under its own terms, security practices, data locations and availability commitments.
6. AI-provider inputs and outputs
When an AI provider is part of a workflow, information submitted to the provider may include prompts, business context, structured fields or documents required for the task. The provider's retention and training settings depend on the selected product and configuration. Clients should approve the provider and the type of data sent to it.
7. Sensitive and regulated information
Clients should not connect highly sensitive, regulated or confidential information to a workflow unless the selected tools, contractual terms, security settings and business purpose have been reviewed for that use. A general automation project should not be assumed to satisfy sector-specific legal requirements.
8. Logs and diagnostic information
Workflow platforms may generate logs containing timestamps, task status, identifiers, error messages or portions of processed information. Logs can be useful for testing and troubleshooting but may also create additional data-retention considerations. Log settings should be reviewed where the processed information is sensitive.
9. Testing
Where appropriate, test or sample data should be used before a workflow is connected to live production data. If live data is necessary for testing, the client should understand and approve the systems and providers that will receive it.
10. Subprocessors and service providers
Cloud, communication, project-management, automation and AI providers can act as service providers or subprocessors in connection with a project. The exact providers vary by project. Formal subprocessor commitments, data-processing agreements or security schedules should be documented separately where a client requires them.
11. Retention and deletion
Project information may be retained for active service delivery, troubleshooting, business records and legal obligations. Client-controlled systems may retain information independently of Brynqel Automata. A request to delete project materials cannot automatically delete information held by an independent third-party provider or in backups controlled by that provider.
12. Security incidents and provider incidents
If a suspected security issue materially affects a project, the response may depend on which system is involved and who controls that system. Clients should maintain their own security and incident-response responsibilities for their accounts and data. Third-party providers remain responsible for incidents within their own infrastructure according to their terms and applicable law.
13. Client responsibilities
Clients are responsible for ensuring they have a lawful basis and appropriate authority to provide data for processing, for supplying accurate workflow rules, for reviewing permissions, and for determining whether notices, consents, contracts or internal approvals are required before information is routed to a third-party tool.
14. Changes to integrations
Third-party integrations can change after deployment. API versions, authentication, permissions, model behavior and platform limits may require workflow updates. Ongoing Support can be used for routine changes and optimization where separately agreed.
15. Data flow mapping
A project should identify the data source, each connected system, the fields passed between them and the expected destination. This map helps clients spot unnecessary transfers, confirm access rights and understand what a third-party provider may receive. When a new data source or destination is added, the flow should be reviewed before the workflow is expanded.
16. Decommissioning a workflow
When an automation is retired, the client and provider should determine which credentials, API keys, scheduled tasks, webhooks and provider accounts require removal or rotation. The client may also need to review logs, backups and retained records in systems that remain under its control. Deleting one connection does not necessarily erase information previously stored by other providers.
17. Cross-border processing
A selected software or AI provider may operate infrastructure in more than one location. The client should review provider documentation and contract terms where data residency or cross-border transfer restrictions matter. This policy does not promise a particular storage region for every third-party service; that requirement should be written into the scope before the integration is approved.
EMAIL: systems@brynqelautomata.com
ADDRESS: 8301 E Prentice Ave, Greenwood Village, CO 80111
PHONE: +1 970 665 3358