This notice describes the intended working model for client data. Final controls depend on the approved systems and engagement scope.
Client responsibility
Clients decide what information may be shared, identify sensitive or regulated data before work begins, provide lawful access, maintain appropriate backups, review consequential outputs, approve production use, and monitor deployed automations.
Access and separation
The client portal is designed to restrict client access to records belonging to their organization. Administrative privileges and service credentials are server-side. Row Level Security is applied to exposed database tables.
Third-party systems
Automations may depend on third-party platforms selected or approved by the client. Their availability, privacy practices, and security controls are outside Jason’s direct control. Credentials should use least privilege and be revoked when no longer needed.
Human review
AI-generated or automated outputs may be incomplete or incorrect. Appropriate human review is required for financial, legal, employment, safety, public, or otherwise consequential actions.
Incidents
Suspected unauthorized access or data exposure related to the service should be reported promptly to hello@automatemejay.com. The parties will cooperate on reasonable containment and investigation steps.