Privacy & Data Handling
Cannon Automation Works applies purpose limitation, minimum necessary access, and accountable oversight to the information used in automated workflows.
Purpose limitation
Client information should be collected, accessed, processed, and retained only for defined business purposes associated with the requested service or engagement. Data should not be repurposed beyond the agreed scope without appropriate authorization.
Minimum necessary access
Automations should use the minimum permissions and information reasonably necessary to perform their approved function. Administrative, financial, identity, infrastructure, production, and customer credentials should be segregated wherever practical.
Human oversight
Automated workflows should include appropriate review, exception handling, logging, and escalation for outcomes that may materially affect clients, finances, security, contractual commitments, privacy, legal obligations, or reputation.
Third-party systems
Some services may rely on third-party platforms, APIs, cloud services, payment systems, or AI providers. Applicable terms, privacy requirements, client permissions, data-location considerations, and technical safeguards should be evaluated before sensitive information is introduced into those systems.
Retention and deletion
Retention requirements should be established according to the applicable engagement, operational need, legal obligations, records-management requirements, and any client-specific retention or deletion instructions.
Governed automation. Accountable execution.
Questions about these terms may be directed to automation@cannonco.net.