Data and security
Agree how your data is handled before the build.
Every workflow has its own data requirements. These are the practical questions to settle when scoping your project: what information is needed, where it goes, who can access it and what happens at handover. Our privacy notice separately explains how this website handles enquiries and Snapshot requests.
- Data a workflow touches
- An email workflow may need message text, sender details and attachments. A document workflow may need invoice fields, file names and records from your business software. The project scope identifies the fields needed for the task and which information should stay out of the workflow.
- Processing and storage
- Keeping files in Microsoft 365 or Google Workspace does not mean they stay there throughout processing. An automation or AI service may receive a copy, and execution logs may retain one. The design needs to identify each destination, storage location and copy before live data is connected.
- AI and automation providers
- The provider list depends on the agreed workflow. BrisAI’s demonstrations use tools including n8n, Microsoft 365 and OpenAI; these are examples, not a fixed stack for every client. Provider terms, model-training settings, retention and any international transfers are part of choosing the configuration.
- Processing responsibilities
- Before a workflow uses personal data, the project needs clear responsibilities for the client, BrisAI and any service providers. Where BrisAI processes personal data on your behalf, a written data processing agreement is required. The agreement and supplier arrangements belong in the project setup, alongside the scope.
- Retention and deletion
- Retention needs to cover source files, extracted records, workflow logs and backups separately. The project plan should specify what is kept, for how long, who can delete it and which copies expire under a provider’s own rules. There is no single retention period that suits every client workflow.
- Access and handover
- Client workflows are designed to run on accounts you control, with access limited to the agreed task. Handover includes documentation of the connected accounts and permissions, who manages credentials and how BrisAI’s access is removed or continued under an agreed support arrangement.
- Testing with business data
- Start with sample or anonymised records wherever practical. Decide which actions need approval, test the workflow against agreed examples and check how errors are surfaced before enabling it for live business use. Financial approvals and uncertain decisions stay with your team.
- Raising a concern
- Contact Art at hello@brisai.co.uk with the workflow name, what happened and when. For a suspected access or data issue, avoid sending passwords or confidential documents in the first message; describe the concern so the next steps can be discussed.
For the requirements around processing personal data on a client’s behalf, see the ICO’s guidance on controller–processor contracts.