Brynqel Automata / Legal

Data Processing & Third-Party Integrations Policy

Last updated: September 21, 2026

This policy describes the operational handling of client information, permissions, AI providers, APIs and third-party systems used in approved automation projects.

1. Purpose and scope

This policy describes how Brynqel Automata approaches client information, system access and third-party integrations when delivering workflow automation and AI-assisted services. It supplements the Privacy Policy by focusing on project data and operational integrations.

2. Client instructions and approved scope

Data processing should be tied to the agreed automation purpose. Clients are responsible for identifying approved systems, users, data categories and business rules. Brynqel Automata should not be treated as authorized to connect additional systems or use client data for unrelated purposes solely because technical access is available.

3. Data minimization

Where practical, an automation should process only the fields reasonably necessary to complete the approved workflow. Planning may include removing unnecessary data fields, separating test data from live data and limiting the information sent to an AI provider or external system.

4. Credentials and access

Clients may be asked to create dedicated API keys, service accounts, tokens or limited user accounts where that improves control. Access should be limited to the permissions needed for the project. Clients should rotate, revoke or remove access when it is no longer required.

5. Third-party integrations

Integrations may include automation platforms, AI providers, email systems, customer-support systems, databases, spreadsheets, file-storage services, customer-management systems, APIs or other cloud tools. Each provider operates under its own terms, security practices, data locations and availability commitments.

6. AI-provider inputs and outputs

When an AI provider is part of a workflow, information submitted to the provider may include prompts, business context, structured fields or documents required for the task. The provider's retention and training settings depend on the selected product and configuration. Clients should approve the provider and the type of data sent to it.

7. Sensitive and regulated information

Clients should not connect highly sensitive, regulated or confidential information to a workflow unless the selected tools, contractual terms, security settings and business purpose have been reviewed for that use. A general automation project should not be assumed to satisfy sector-specific legal requirements.

8. Logs and diagnostic information

Workflow platforms may generate logs containing timestamps, task status, identifiers, error messages or portions of processed information. Logs can be useful for testing and troubleshooting but may also create additional data-retention considerations. Log settings should be reviewed where the processed information is sensitive.

9. Testing

Where appropriate, test or sample data should be used before a workflow is connected to live production data. If live data is necessary for testing, the client should understand and approve the systems and providers that will receive it.

10. Subprocessors and service providers

Cloud, communication, project-management, automation and AI providers can act as service providers or subprocessors in connection with a project. The exact providers vary by project. Formal subprocessor commitments, data-processing agreements or security schedules should be documented separately where a client requires them.

11. Retention and deletion

Project information may be retained for active service delivery, troubleshooting, business records and legal obligations. Client-controlled systems may retain information independently of Brynqel Automata. A request to delete project materials cannot automatically delete information held by an independent third-party provider or in backups controlled by that provider.

12. Security incidents and provider incidents

If a suspected security issue materially affects a project, the response may depend on which system is involved and who controls that system. Clients should maintain their own security and incident-response responsibilities for their accounts and data. Third-party providers remain responsible for incidents within their own infrastructure according to their terms and applicable law.

13. Client responsibilities

Clients are responsible for ensuring they have a lawful basis and appropriate authority to provide data for processing, for supplying accurate workflow rules, for reviewing permissions, and for determining whether notices, consents, contracts or internal approvals are required before information is routed to a third-party tool.

14. Changes to integrations

Third-party integrations can change after deployment. API versions, authentication, permissions, model behavior and platform limits may require workflow updates. Ongoing Support can be used for routine changes and optimization where separately agreed.

15. Data flow mapping

A project should identify the data source, each connected system, the fields passed between them and the expected destination. This map helps clients spot unnecessary transfers, confirm access rights and understand what a third-party provider may receive. When a new data source or destination is added, the flow should be reviewed before the workflow is expanded.

16. Decommissioning a workflow

When an automation is retired, the client and provider should determine which credentials, API keys, scheduled tasks, webhooks and provider accounts require removal or rotation. The client may also need to review logs, backups and retained records in systems that remain under its control. Deleting one connection does not necessarily erase information previously stored by other providers.

17. Cross-border processing

A selected software or AI provider may operate infrastructure in more than one location. The client should review provider documentation and contract terms where data residency or cross-border transfer restrictions matter. This policy does not promise a particular storage region for every third-party service; that requirement should be written into the scope before the integration is approved.

Contact information

EMAIL: systems@brynqelautomata.com

ADDRESS: 8301 E Prentice Ave, Greenwood Village, CO 80111

PHONE: +1 970 665 3358