1. About Straden and this policy
This Privacy Policy explains how Straden collects, uses, discloses, retains, and protects personal information when it designs and operates AI-powered workflow agents and related services for business clients.
“Straden,” “we,” “us,” and “our” mean Jamal Muckett-Sobers, a sole proprietor operating as Straden in Ontario, Canada. Jamal Muckett-Sobers is Straden's designated privacy contact and is accountable for Straden's compliance with applicable privacy law. Privacy questions, requests, withdrawals of consent, and complaints may be sent to straden.agency@gmail.com or mailed to 9601 Valhalla Inn Road, Toronto, Ontario M9B 0V2, Canada.
For information processed through a client's connected business systems, that client generally determines why the information is processed and Straden processes it to provide the contracted services. Straden remains independently accountable for information it controls for relationship administration, service security, legal compliance, and any analytics Straden determines to conduct. Questions about a client's own privacy practices should be directed to that client.
2. Information we may process
The information depends on the workflow a client authorizes. It may include:
- business contact and account information, including names, email addresses, roles, and organization details;
- project and operational information contained in emails, attachments, Google Drive files, task records, and related communications;
- customer, supplier, and transaction information;
- QuickBooks Online information, such as customers, vendors, estimates, invoices, payment status, project or job references, and related accounting records;
- OAuth connection identifiers, access credentials or tokens, and technical information needed to maintain authorized integrations;
- agent instructions, workflow inputs, outputs, approval decisions, error records, and operational logs;
- website or inquiry information that a person chooses to submit to Straden.
Straden does not intentionally request more information than is reasonably needed for an authorized workflow. Clients are responsible for deciding what information may be connected to or submitted through the services.
3. Why we access and use information
We use information only for purposes connected to providing, securing, maintaining, and improving the services the client has requested, including to:
- authenticate users and connect authorized Google Workspace and QuickBooks Online accounts;
- read, organize, summarize, match, create, update, or route business records as configured in an approved workflow;
- prepare drafts, surface exceptions, track project or payment status, and request human review or approval;
- operate agent memory and workflow state needed to maintain context;
- troubleshoot failures, prevent misuse, support users, and maintain service reliability;
- meet legal, accounting, contractual, and platform obligations; and
- respond to inquiries and administer the client relationship.
Connected business systems. A Straden workflow may have read and write access to connected applications when that access is authorized by the client and needed for the approved workflow. Access varies by deployment and may include Google Workspace, QuickBooks Online, project-management systems, customer systems, communications tools, and other business applications. QuickBooks Online access begins only after an authorized user completes Intuit's OAuth consent process.
Google Workspace API data
Straden's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Straden accesses Google Workspace data only to provide or improve the authorized, user-facing workflow features for the connected business. Depending on the approved workflow, this may include reading and processing Gmail messages, threads, attachments, and mailbox history; sending replies and updating message state; finding, reading, creating, filing, moving, and sharing records in a configured Google Drive; and reading, creating, or updating operational Google Sheets.
We transfer Google Workspace data only to service providers needed to operate those authorized features, with the connected user's or client's consent; for security purposes; to comply with applicable law; or as part of a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent. We do not sell Google Workspace data or use it for advertising, creditworthiness or lending, cross-client or industry analytics, or to create, train, or improve a generalized machine-learning or artificial-intelligence model. When an authorized workflow uses an AI provider, the provider processes the minimum relevant Google Workspace data only to deliver that workflow's user-facing feature and is not authorized to use it to train a generalized model.
Humans do not read Google Workspace data unless the user has explicitly agreed to review of specific messages, files, or other records; access is necessary for security or legal compliance; or the data has been aggregated and anonymized for permitted internal operations. The retention, deletion, disconnection, and request procedures in sections 8 through 10 apply to Google Workspace data.
Consent and other lawful authority
Where consent is required, Straden or the relevant client will seek consent in a form appropriate to the sensitivity of the information and the nature of the processing. Straden may also process information where permitted or required by law. An individual may withdraw consent to Straden's processing at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent Straden or the client from continuing an affected workflow or service, but does not invalidate processing completed before withdrawal.
Accuracy
Straden and its clients take reasonable steps to keep information accurate, complete, and current for its intended use. Clients and users should keep source-system information accurate and promptly report material errors in agent outputs or connected records.
4. How AI is used
Some workflows send relevant information to an AI provider so the agent can classify, extract, summarize, draft, reason about, or route work. AI output may be incomplete or incorrect and may be subject to human review depending on the configured workflow.
Depending on the workflow, Straden may use services from OpenAI, Anthropic, Google, xAI, locally operated language models, or other suitable AI providers. Provider selection may change based on capability, availability, client requirements, and risk. Provider categories and material processing considerations are disclosed through the client agreement, deployment documentation, or another notice appropriate to the sensitivity of the information. A materially different provider or purpose may require additional notice or consent.
Whether a provider retains inputs or uses them to improve its models depends on the provider, service tier, and account configuration. Straden does not authorize providers to use client information for advertising and seeks business configurations appropriate to the workflow, but does not claim a no-training or zero-retention setting unless it has been verified for that deployment. For Google Workspace API data, the more specific commitments in section 3 control, including the prohibition on training generalized models. “Locally operated” describes a model run in infrastructure selected for that deployment and does not necessarily mean the information remains in the client's physical location or country.
5. Service providers and disclosures
We may disclose information to service providers that help deliver the services, subject to their applicable terms and the configuration of the client deployment. Current categories include:
- Railway, for application hosting;
- Supabase, for operational data storage and related database services;
- Google, when a client connects Google Workspace services;
- Intuit, when a client connects QuickBooks Online; and
- AI service providers, when an authorized workflow requires AI processing.
We may also disclose information where required by law, to protect rights or safety, in connection with a business transaction, or with the client's or individual's direction or consent.
Straden does not sell personal information and does not transfer ownership of client data or client intellectual property to itself. Except for Google Workspace API data, which is excluded from this use by section 3, Straden may create and own statistics, benchmarks, and industry insights derived from information that has been anonymized and aggregated so that it does not identify, and cannot reasonably be used to identify, a client, individual, or confidential business information. Straden owns the resulting generalized analysis and insights, not the underlying client data.
A client may opt out of future use of its information for cross-business or industry analysis by contacting Straden or as provided in its service agreement. An opt-out does not require Straden to remove information from statistics or insights that were already rendered anonymous and aggregated. Straden does not disclose one client's identifiable or reasonably re-identifiable information to another client or use identifiable information to train another client's agents without express written authorization.
6. International processing
Our service providers may process or store information outside Ontario or Canada, including in regions selected through Railway, Supabase, connected applications, and AI providers. Straden remains accountable under applicable Canadian privacy law for personal information under its control that is transferred to a service provider for processing. Straden uses contractual or other measures intended to require a level of protection comparable to that required of Straden.
When information is processed in another country, it may be accessible to courts, law-enforcement bodies, national-security authorities, or other lawful authorities under that country's laws. The exact locations depend on the provider and configuration used for the client deployment.
7. Security
We use administrative, technical, and organizational safeguards that we consider reasonable in light of the sensitivity, amount, format, and use of the information, and require appropriate handling by personnel and service providers. We do not claim a certification or specific security control unless it has been independently verified.
Straden assesses and responds to suspected breaches of security safeguards, including by containing and investigating the incident, working with affected service providers, addressing the cause, and documenting the response. Where required by applicable law, Straden will notify affected individuals and report the breach to the appropriate regulator. No internet transmission, storage system, or AI service can be guaranteed completely secure.
Clients and users must protect their credentials, limit integrations and permissions appropriately, and promptly tell us about suspected unauthorized access.
8. Retention and deletion
We retain information only as long as reasonably needed for the authorized services, client instructions, legitimate business purposes, dispute resolution, security, backup recovery, and legal or contractual obligations. Different records may be retained for different periods.
An automated process deletes temporary workflow information in systems controlled by Straden within 90 days when that information has not been designated as long-term agent memory, subject to verified backup cycles, legal holds, security needs, and the exceptions described below. Information intentionally saved to long-term agent memory is retained only while needed for the authorized purpose or until the client instructs Straden to delete it, subject to applicable law and contractual obligations.
Provider backups, logs, and recovery copies may follow the deletion cycles of Railway, Supabase, connected applications, and other service providers. Some information may also be retained where law, security, dispute resolution, accounting, or a binding obligation requires it. Information used to make a decision about an individual may be retained long enough to allow the individual to exercise applicable access and correction rights. Straden does not claim immediate deletion from every provider backup.
9. Connected applications and disconnection
Many connected applications use OAuth or a similar authorization process. A user with appropriate authority may disconnect a connected application through available Straden controls, through the connected application's own controls, or by contacting Straden. Where the application supports token revocation, disconnection revokes or invalidates the applicable authorization tokens and prevents new access through that connection. Signing out of a Straden service does not necessarily disconnect an application.
Disconnecting does not automatically delete information already lawfully processed or stored by Straden. To request export or deletion, contact us using the details below. Application-specific requirements, including Intuit's requirements for QuickBooks Online, continue to apply.
10. Access, correction, deletion, and questions
Subject to legal exceptions and the role of the relevant business client, an individual may request information about the existence, use, and disclosure of personal information under Straden's control, obtain access to it, and challenge its accuracy or completeness. We may need to verify identity and authority before acting. If access is refused, Straden will explain the reason where legally permitted.
Where appropriate, Straden will correct information, record an unresolved disagreement, and notify relevant third parties. If the information was provided through a Straden client, we may direct the request to that client or assist the client in responding.
Privacy questions, access or correction requests, withdrawals of consent, deletion requests, and complaints may be sent to Jamal Muckett-Sobers, operating as Straden, at straden.agency@gmail.com or 9601 Valhalla Inn Road, Toronto, Ontario M9B 0V2, Canada. We will review and respond within the time required by applicable law. If you are not satisfied after giving Straden an opportunity to address your concern, you may contact the Office of the Privacy Commissioner of Canada.
11. Changes to this policy
We may update this policy as our services, providers, or legal obligations change. We will post the revised policy and its effective date on this page. Where required, we will provide additional notice or obtain consent.