Policy
Data Processing and Security Policy
This policy explains how Brocklesby approaches data access, client systems, security and responsible automation delivery.
Last updated: 20 July 2026
Business: Brocklesby AI Ltd
Contact: max@brocklesby.ai
1. Purpose
Brocklesby may need to process business data to design, test and maintain automation systems. This policy explains the practical principles used to reduce unnecessary access and keep workflows controlled.
2. Least necessary access
Brocklesby aims to request only the access needed for the agreed workflow. Where possible, access should be limited to the specific inboxes, folders, sheets, forms, tools or accounts required.
Clients should avoid granting wider access than needed.
3. Separate accounts and permissions
Where tools allow it, clients should use separate user accounts, role-based permissions or limited access tokens. This makes access easier to monitor, change or revoke.
4. Sensitive information
Clients should not provide unnecessary sensitive personal data. Workflows involving sensitive information, regulated advice, legal, medical, financial or high-risk decisions should be scoped carefully and may require specialist review.
5. Human approval
AI can draft, label, summarise, prepare and route work. Important or judgement-heavy actions should keep human approval in the workflow. This is especially important for customer commitments, legal wording, financial decisions, complaints or unusual cases.
6. Testing before live use
Automations should be tested using realistic examples before live use. The client should review outputs and confirm the system is useful for the agreed workflow before monthly billing begins.
7. Third-party tools
Automations may use tools such as Gmail, Outlook, Google Sheets, Excel, Shopify, CRMs, Zapier, n8n, payment processors or other platforms. Each tool has its own security and privacy settings. Clients should review tool permissions before connecting them.
8. Data retention
Data should be kept only for as long as needed to build, test, support and maintain the agreed workflow or meet business and legal obligations. Retention arrangements can be agreed for specific projects where required.
9. Revoking access
Clients can request access removal when a project ends or where access is no longer needed. Depending on the setup, this may involve removing user permissions, deleting tokens, disabling workflows or changing API keys.
10. Incidents
If a data or security issue is suspected, Brocklesby and the client should work quickly to understand the issue, reduce risk, preserve relevant information and take appropriate next steps.
11. Contact
For data processing or security questions, contact max@brocklesby.ai.
Need a practical AI automation system?
No upfront setup cost. Brocklesby builds and tests the system first, then you only pay once it is working and useful.
Start Free Automation Audit