Security & Data Handling for Managed AI

This page explains how Pfitztech handles access and data for its remote Managed AI services. It is written for the IT person or owner evaluating us. If you need more detail, we complete security questionnaires on request.

Access

  • Least privilege. We connect through OAuth apps, service accounts or API keys that your IT person creates and scopes to specific mailboxes, folders and apps. We never ask for user passwords.
  • You hold the off switch. Access can be revoked at any time from your own admin console.
  • Read first. New workflows start read-only and in shadow mode. Write access is added only where a workflow needs it, such as creating draft invoices.

Human approval

Anything sent to a customer, posted publicly or touching money stays a draft until a named person on your team approves it. Approval rules are written into your onboarding document.

Data handling

  • Each client is isolated, with separate credentials, data, logs and test sets.
  • We keep only what a workflow needs, for the retention period in your agreement, and delete client data when the service ends.
  • AI model providers are used under business API terms that do not train on customer data.
  • Every action an agent takes is logged with time, system and approval status, and summarized in your weekly report.

Agreements

DocumentWhat it covers
Master services agreementScope, service levels, term and liability
Data processing agreementYour data, our obligations, retention, breach notification, and the list of subprocessors and processing locations
Onboarding recordEvery system connected, the access granted, and who approves drafts

Canadian clients are covered under PIPEDA and applicable provincial law. For clients in other jurisdictions, we agree on data processing terms that fit your requirements, such as GDPR standard contractual clauses, before any access is granted.

Frequently asked questions

Do you train AI models on our data?

No. We use AI model providers under business API terms that do not use customer data for training, and we never use one client’s data for another client.

Can our IT person revoke access?

Yes, at any time, from your own Microsoft 365, Google Workspace, accounting or CRM admin console. Revoking access stops the service immediately.

Do you store our emails?

Only what a workflow needs, for as long as it needs it. Retention periods are set in your data processing agreement, and data is deleted when the service ends.

Are you SOC 2 certified?

Not at this time. We publish our practices here, answer security questionnaires, and sign a data processing agreement with every client.

Back to the Managed AI Office Desk

Pfitztech Contracting Ltd. · Kelowna, British Columbia, Canada · 250-575-5721 · pfitztech@gmail.com

Pfitztech Electrical & Data is a trade name of Pfitztech Contracting Ltd.
Licensed Electrical Contractor · Technical Safety BC Contractor Licence LEL0203920