This Privacy Policy describes how iAgentic ("we", "us") collects, uses, stores, protects and deletes information when you use our services. It forms part of our Terms of Service. Detail specific to the platforms we connect to is in section 12.
1. Scope and our role
This policy covers three kinds of information:
- Connected System data - data we access in a business system you authorise us to connect to, such as an accounting or operations platform.
- Service data - data generated by your use of the Services, such as conversation transcripts, approval decisions and audit records.
- Business data - your account, contact and billing details, and content you provide to us when we design and build an agent workforce for you.
For Connected System data and Service data we act only on your instructions and for no independent purpose of our own. Where you are the controller of that information, we act as your processor. Where you are yourself a processor acting for someone else, as an accounting firm does for its clients, we act as your sub-processor, and our obligations to you flow through to them. We act as controller only for our own business records, such as your billing and contact details and our security and audit logs.
2. What we access, and why
When you connect a business system, you authorise us, through that platform's own consent flow, to access the categories of data set out in section 12. We request the narrowest set of permissions that lets the Services do what you have engaged us to do, and we access only the data needed for that purpose.
We use that data only to provide the Services you have requested, for example answering questions about your data, running reconciliations and analyses, preparing reports, and preparing proposed changes for your approval, as configured for your engagement. We do not use it for advertising, and we do not sell it.
3. Changes to your records require your approval
Any operation that creates, modifies or deletes a record in a connected system happens only through a workflow that presents the exact proposed change to an authorised person for explicit approval. Nothing is written to your systems without that approval. This is described more fully in section 4 of our Terms of Service.
4. Where your data is processed, and which models see it
The Services run on IBM Cloud in the Toronto, Canada region (ca-tor), on the IBM watsonx Orchestrate platform.
Connected System data is processed only by language models hosted within the IBM watsonx Orchestrate environment in which the Services run. We do not route Connected System data to external model providers. We will not change this without first updating this policy and notifying active customers in advance of the change taking effect.
Separately from the Services' runtime, when we design and build an agent workforce for you we process content you provide to us for that purpose, such as discovery interview transcripts and requirements documents, using the third-party model providers identified in section 9. Connected System data is not used for this purpose. Those providers are engaged under terms that prohibit them from retaining your content or using it to train their models.
5. We never use one customer's data for another
We do not share your data with other customers. We do not use your data, connected, derived or aggregated, to serve, benchmark or inform any other customer. We do not use it to train or improve models, and we do not use it to build any shared knowledge base. Your data is scoped to your tenant and stays there.
6. Security
- Encryption in transit (HTTPS/TLS) and at rest.
- Connection credentials and access tokens are encrypted server-side using managed key-encryption services, and are never exposed in browsers, in URLs, or in logs.
- Least-privilege, tenant-scoped access; credentials are vaulted and not accessible to agents.
- Sensitive-data masking on values surfaced through the Services.
- Human approval gates on every data-modifying operation.
- Audit records of integration activity, as described in section 7.
Access by our people
iAgentic personnel have no standing access to your connected systems, your environment or your conversation transcripts. Our staff can see your data only where you have granted that access yourself, by adding a named person to your environment, or by sending us a transcript or extract for support purposes, and only for as long as you leave that access in place. Where you grant it, access is limited to the people and the purpose you have agreed, is subject to confidentiality obligations, and is recorded in the audit records described in section 7. We have no back-door or support account that bypasses this.
Only iAgentic employees are eligible for such access. We do not use contractors or subcontractors to build, operate or support the Services.
7. What our audit records contain
We keep an audit record of integration activity so that you and we can establish what happened and who authorised it. These records capture the event, not the contents of your records: the time of the operation, the person who approved it, the agent that performed it, the operation type, and the type and identifier of the record affected. They do not capture the values inside your records, no amounts, balances, names, descriptions or memo text. We do not log credentials or the contents of connected-system data anywhere.
8. How long we keep things
We keep each category of data only for as long as it serves the purpose it was collected for.
| What | How long we keep it | Why |
|---|---|---|
| Connection credentials (access and refresh tokens, connection identifiers) | For the life of the connection. When a disconnection is initiated through our service, we revoke the credentials at Intuit and delete them immediately. When a customer disconnects from within QuickBooks, Intuit revokes the credentials at that moment and they can no longer be used; Intuit does not notify us, so we learn of the disconnection on our next refresh attempt for that company, within one hour, and stop using the connection at that point. Any stored copy is inert from the moment of disconnection. | They have no purpose once the connection ends. |
| Cached connected-system records | While the connection is active, then 30 days after disconnection or termination. | So an accidental disconnection and reconnection does not lose your working context, and so we can answer questions about recent activity. |
| Conversation transcripts and interaction history | 12 months on a rolling basis while connected; then deleted on the same schedule as cached records after disconnection. | Service continuity, and a record of what was presented to you and approved. |
| Audit records (event data only, per section 7) | 7 years. | To evidence what was authorised and by whom, consistent with business-record retention norms in Canada. |
| Derived data (indexes, embeddings, summaries built from connected-system data) | Same schedule as cached records: deleted 30 days after disconnection. Never reused for another customer. | It has no purpose beyond serving you while you are connected. |
| Onboarding and design content you provide (transcripts, requirements) | Duration of the engagement plus 7 years. | It forms part of our business and professional records for the work we did for you. |
| Backups | 35 days on a rolling basis. Deletions propagate as backups rotate out. | So that a deletion is a real deletion. |
You may ask us to delete data we hold about your organisation at any time by contacting contact@iagentic.ca. We will action deletion requests within 30 days, subject to any legal retention requirement, and will tell you if anything must be retained and why.
9. Sub-processors
We engage a small number of service providers to operate the Services. This is the current list. We will give active customers at least 30 days' notice before adding a sub-processor that would process Connected System data. We do not engage contractors or subcontractors: all build, operation and support work is carried out by iAgentic employees.
Runtime, processing your connected business data
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| IBM (IBM Cloud, IBM watsonx Orchestrate) | Application hosting, storage, key management, and the platform on which our agents and their language models run. | Connected System data, service data, audit records. | Toronto, Canada (ca-tor) |
The language models that process your connected business data run inside the IBM watsonx Orchestrate environment above. No external model provider receives Connected System data.
Design and onboarding, processing content you give us to build with
These providers are used only when we design and build an agent workforce, on content you supply for that purpose. They do not receive Connected System data.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Anthropic | Generation of design and specification content during agent build. | Customer-provided onboarding content: discovery transcripts, requirements documents. | United States |
| Automated review and quality checking of generated design content. | Customer-provided onboarding content, as above. | United States |
Both are engaged under commercial API terms that prohibit retention of submitted content beyond what is needed to return a response, and prohibit its use for model training.
10. Your rights
Subject to applicable law, including PIPEDA in Canada, and the GDPR, CCPA/CPRA and LGPD where they apply to you, you may request access to, correction of, portability of, or deletion of personal information we hold, and may withdraw consent where processing is based on consent. Contact contact@iagentic.ca and we will respond within 30 days.
Where we hold personal information as a processor on behalf of a customer, we will refer your request to that customer and support them in responding to it.
11. Security incidents
If we become aware of a security incident affecting your data, we will notify you without undue delay and in any event within 72 hours of confirming it, along with what we know about its nature, scope and our response, and will notify regulators where required. To report a suspected vulnerability, contact contact@iagentic.ca.
12. Intuit QuickBooks Online
This section sets out the detail specific to our integration with Intuit QuickBooks Online. We connect through Intuit's published APIs using its OAuth 2.0 authorisation flow. QuickBooks Online is provided by Intuit and your use of it is governed by Intuit's own terms and privacy policy.
What we access
With your authorisation we access accounting data in your QuickBooks Online company, which may include company information and preferences; customers and vendors; invoices, bills, estimates and credit memos; payments, purchases and expenses; journal entries and transactions; items, products and services; the chart of accounts; and financial reports. We do not access QuickBooks Payments card data or payroll data.
That list mirrors the permission scope we request. The specific subset actually accessed in your deployment is determined by the agent configuration agreed for your engagement, and is limited to what those agents require to perform the functions you have commissioned.
Permissions we request
We request the QuickBooks Online Accounting scope
(com.intuit.quickbooks.accounting), the permission required to read your accounting
records and, subject to your approval of each change, to write to them. We do not request permissions
we do not use.
Reading and writing
All data movement happens through Intuit's APIs. Reading is automatic within the scope you authorised. Writing is not: any operation that would create, modify or delete a record in your QuickBooks company is presented to an authorised person as a specific proposed change and executed only once that person approves it.
Which models see your QuickBooks data
QuickBooks data is processed only by language models hosted within the IBM watsonx Orchestrate environment in Toronto, Canada, where the Services run. We do not send your QuickBooks data to external model providers, by API call or by any other means, and we do not provide any third party with access to it.
Connecting and disconnecting
You connect using the Connect to QuickBooks control, which is replaced by a Disconnect control once connected. You can disconnect at any time, either from within the Services or from the Apps area of QuickBooks Online; either way we call Intuit's revoke endpoint, the authorisation is withdrawn, and we can no longer make calls to your QuickBooks company. Signing out of the Services does not disconnect your QuickBooks company. You can reconnect at any time by repeating the authorisation flow.
How we handle QuickBooks data
- We do not export, save or store QuickBooks data for any purpose other than providing the Services to you.
- We do not provide third parties with access to your QuickBooks data, through external API calls or by any other means.
- We do not share one customer's QuickBooks data with another, and do not aggregate it across customers.
- We do not use QuickBooks data to train or improve models or any shared knowledge base.
- We do not log QuickBooks data or your credentials.
- Refresh tokens and company identifiers are encrypted at rest using managed key-encryption services, and are never exposed in the application interface, in URLs or in logs.
Design and onboarding materials
The materials you give us when we design and build your agents, such as discovery notes, requirements and process descriptions, are handled separately from your QuickBooks data and are processed as described in section 9. We do not put QuickBooks data into that design and build process. Where we need to understand the shape of your records we work from structure and field definitions rather than live records, and we ask that you do not send us QuickBooks exports, reports or screenshots for this purpose. The providers listed in section 9 therefore do not receive QuickBooks data.
Regulated services
The integration does not provide lending, insurance, investment or financial planning services and does not perform payments or money movement. It reads and, with your approval, writes bookkeeping records.
Retention and deletion for this integration follow the schedule in section 8.
13. Children
The Services are business tools and are not directed to children. We do not knowingly collect personal information from anyone under 16.
14. Changes to this policy
We may update this policy. The "Last updated" date reflects the current version, and material changes will be communicated to active customers in advance of taking effect. Prior versions are available on request.
15. Contact
iAgentic. contact@iagentic.ca. https://iagentic.ca. Ontario, Canada.