Privacy Policy
Last updated: 2026-07-30
Data residency
All customer data is hosted in Microsoft Azure, Canada Central (with Canada East for disaster recovery). Data does not leave Canada.
What we store
Workflow definitions, runs, agent decisions (prompt, model, reasoning, cost), human approvals, connector configuration (secret references only — never secret values), and an append-only audit log. Each record is scoped to your tenant and is not accessible to other tenants.
Encryption
Encrypted at rest with customer-managed keys (Azure Key Vault) and in transit with TLS 1.2+. Secrets are held in Azure Key Vault and accessed via managed identity.
AI processing
Agent decisions may send prompts to Azure OpenAI within our Canadian tenant. Microsoft does not use this data to train models. PII is redacted before prompts are sent, per your tenant configuration.
Access & deletion
You may request export or deletion of your tenant data by contacting your account representative. The audit log is append-only and retained for compliance.
Authentication
Sign-in is handled by Microsoft Entra ID; we do not store your password.