Data Policy
This Data Policy explains how we handle the business data your organization stores in its appsforwork.ai workspace — the records, files, and content that flow through the tools we build and host for you. For personal information about individual users, see our Privacy Policy.
Last updated: September 4, 2026
Your data is yours
Your organization owns the data it stores in the service. We process it only to provide, secure, and support the tools your organization has engaged us to build. We claim no ownership of it, we do not sell it, and we do not use it to train public AI models.
Workspace isolation and access control
The service is multi-tenant: every record is bound to the organization that owns it, and every read and write is checked against that boundary on the server. Within a workspace, role-based access controls determine what each user can see and do. Our staff access customer data only to build, operate, and support the service.
Encryption
Data is encrypted in transit using TLS and at rest on our storage infrastructure. Credentials for third-party integrations that tools connect to are stored server-side and never returned in full to the browser.
AI processing
When a tool uses an AI feature, the relevant content is sent to a third-party AI model provider to produce the result, then returned to your workspace. Our provider agreements do not permit the use of your content to train their publicly available models. AI usage is metered per tool, and your organization can see and control its AI spend from within the service.
Where data lives
The service runs on established cloud infrastructure providers in the United States — application hosting, a managed database service, and cloud file storage. Files intended for end users (such as documents a tool presents for download) are served from cloud storage; links to them should be treated as accessible to anyone who has the link.
Backups and availability
Databases are backed up automatically by our managed database provider. Backups exist for disaster recovery — restoring individual records on request may not always be possible. We work to keep the service continuously available but do not guarantee uninterrupted operation; planned maintenance is scheduled to minimize disruption.
Audit logging
The service records user and system activity — sign-ins, page views, data changes, and automated jobs — to support security review, troubleshooting, and accountability within your workspace.
Export and deletion
Your organization can export its data at any time — tools provide export features, and we will assist with bulk exports on request. When an engagement ends, we will return or delete your organization's data on request and remove it from active systems within 90 days, except where the law requires us to retain it. Data in backups ages out on the backup retention schedule.
Incident response
If we become aware of a security incident affecting your organization's data, we will notify you without undue delay, describe what happened and what data was involved, and keep you informed as we investigate and remediate.
Subprocessors
We use a small set of infrastructure and AI providers to deliver the service, each engaged under terms consistent with this policy. A current list is available on request.
Questions about this document? Contact us at info@agileconsulting.info.