Legal

Privacy Policy and AI Use Policy

For customers and prospective customers. Effective January 1, 2026. Last updated June 1, 2026.

This Privacy Policy and AI Use Policy (the "Policy") explains how SMART INSTINCT ("SMART INSTINCT," "we," "us," or "our") collects, uses, handles, stores, accesses, processes, shares, deletes, and protects information when we provide onboarding, IT support, help desk, managed services, system configuration, workflow support, and related technology services (the "Services") to our business clients.

It also describes how we use artificial intelligence ("AI") tools and AI agents in connection with client onboarding and IT support. This Policy is written for SMART INSTINCT's customers and prospective customers. It is intended to be transparent and practical, not a substitute for the specific terms of any signed service agreement. Where this Policy and a signed agreement conflict, the signed agreement controls.

1. Purpose and Scope

This Policy applies to SMART INSTINCT's collection, use, handling, storage, access, processing, sharing, deletion, and protection of client data in the course of providing the Services. It also applies to SMART INSTINCT's use of AI tools, automation, and AI agents in connection with client onboarding and IT support.

This Policy is directed to SMART INSTINCT's customers and prospective customers. It is not an offer or a contract, and it does not create rights beyond those agreed in a signed engagement. If you are evaluating SMART INSTINCT, this Policy is meant to help you understand how we work with your information before you engage us.

2. Types of Information We May Access or Process

To provide the Services, SMART INSTINCT may access or process the following categories of information, depending on what each customer engages us to do and what the customer chooses to share:

SMART INSTINCT accesses information for the purpose of delivering the Services, not for unrelated purposes. The amount and type of information we access depends on the scope of each engagement.

3. Customer Shared Folder Access

As part of the Services, a customer may grant SMART INSTINCT access to a customer-designated shared folder, drive, workspace, ticketing folder, or similar location. We use this access to provide onboarding, support, implementation, documentation, troubleshooting, and related services.

If you are unsure whether something belongs in the shared folder, ask us first. It is easier to avoid placing high-risk data than to remediate it later.

4. AI Use Policy (AI Tools and AI Agents)

This section is SMART INSTINCT's standalone AI Use Policy. It explains how and when we use AI in connection with the Services.

4.1 What We Use AI For

SMART INSTINCT may use AI tools, automation, scripts, and AI agents to assist with reviewing customer-provided help desk files, onboarding materials, technical notes, support tickets, configuration documents, and other files you voluntarily share with us. AI may be used for:

4.2 Limits on AI Agents

We place clear limits on what our AI agents do:

4.3 Human Review and Judgment

AI outputs are reviewed as appropriate before SMART INSTINCT relies on them for customer-facing work. AI should not be treated as a substitute for professional judgment, cybersecurity review, legal advice, or final technical approval. AI tools can make mistakes, and we do not promise that AI output will always be accurate or complete. A qualified person remains responsible for decisions about your environment.

5. Data Retention and Deletion

  • General retention period. SMART INSTINCT generally deletes or securely disposes of customer data within one year after the data is no longer needed for the Services, unless a different retention period is required by law, contract, a dispute or legal hold, a security investigation, a backup cycle, or another legitimate business need.
  • Business records. SMART INSTINCT may retain limited business records, invoices, service history, audit logs, security records, and communications as needed for legal, tax, accounting, operational, or dispute-resolution purposes.
  • Backups. Customer data contained in backups may persist for a limited period until those backups are overwritten or deleted in the ordinary course.
  • Deletion requests. Customers may request deletion of customer-provided files, subject to legal, contractual, security, and operational limitations (see Section 15).

6. Security Safeguards

SMART INSTINCT uses commercially reasonable safeguards appropriate to a small professional services business. These may include:

  • Access controls and the principle of least privilege;
  • Use of password managers for credential handling;
  • Multi-factor authentication (MFA) where available;
  • Encryption where appropriate;
  • Secure file-sharing methods;
  • Limiting internal access to those who need it;
  • Logging or documentation of support activity where practical;
  • Vendor review for major service providers;
  • Secure disposal of data; and
  • Confidentiality obligations for personnel.

No method of transmission, storage, or processing is perfectly secure. SMART INSTINCT does not guarantee that its safeguards will prevent every unauthorized access or incident, but we work to apply reasonable, practical protections.

7. Client Responsibilities

Effective and secure Services depend on shared responsibility. Customers are responsible for:

  • Providing accurate onboarding information;
  • Authorizing SMART INSTINCT's access to relevant systems, folders, and tools;
  • Managing their own internal users and permissions;
  • Not placing unnecessary sensitive information in shared folders;
  • Maintaining their own backups unless backup services are expressly included in the engagement;
  • Reviewing and approving material system changes; and
  • Complying with the laws that apply to their own business and data.

8. API Access

  • Authorized use. SMART INSTINCT may use APIs or integrations to perform authorized Services.
  • Scope of access. API access may include public endpoints, customer-authorized endpoints, GitHub repositories, software tools, cloud services, ticketing platforms, CRM systems, or similar business systems.
  • Purpose limitation. SMART INSTINCT will use API access only for authorized service purposes.
  • Customer control. The customer remains responsible for granting, limiting, monitoring, and revoking API permissions, unless SMART INSTINCT is expressly engaged to help manage those permissions.

9. Confidentiality

SMART INSTINCT treats customer business information as confidential. This includes business and technical information, support records, credentials, architecture diagrams, code repositories, documentation, configurations, and other non-public information you share with us in connection with the Services.

SMART INSTINCT will use such information only to provide the Services and will not disclose it to third parties except: (a) to SMART INSTINCT personnel and service providers who need it to deliver the Services and are bound by confidentiality obligations; (b) as authorized by the customer; or (c) as required by law. These obligations are in addition to any separate non-disclosure agreement (NDA) between the parties.

10. Service Provider and Vendor Use

To provide the Services, SMART INSTINCT may use third-party tools and providers, such as hosting providers, AI providers, ticketing systems, cloud services, communication tools, and productivity platforms. SMART INSTINCT uses commercially reasonable care in selecting and using these providers. We do not control how these third parties operate their own systems, and their services are governed by their own terms.

11. No Sale of Customer Data

SMART INSTINCT does not sell customer data.

12. Legal Compliance

SMART INSTINCT aims to handle customer data responsibly and in accordance with applicable laws governing how we provide the Services. SMART INSTINCT does not represent that it is compliant with every privacy or data protection law, and this Policy is not a certification of compliance with any particular legal framework.

If you handle regulated or sensitive data, such as data subject to HIPAA, PCI DSS, GLBA, education-records laws (e.g., FERPA), government data, export-controlled data, or other sensitive regulated information, please notify SMART INSTINCT before sharing that data with us. This allows the parties to establish appropriate written terms (such as a Business Associate Agreement or Data Processing Agreement) before such data is shared.

13. Security Incident Response

  • Investigation. SMART INSTINCT will investigate suspected unauthorized access to, disclosure of, or misuse of customer data that comes to our attention.
  • Notification. SMART INSTINCT will notify affected customers as legally or contractually required.

SMART INSTINCT does not commit to a fixed notification deadline in this Policy. Specific notification timelines, if any, will be governed by a separate signed agreement. Our goal is to act promptly and reasonably under the circumstances.

14. Limitations

  • SMART INSTINCT is not responsible for data that a customer shares unnecessarily or incorrectly.
  • SMART INSTINCT does not control the customer's own systems unless specifically contracted to manage them.
  • SMART INSTINCT's AI tools do not independently access customer systems.
  • Customer approval may be required before SMART INSTINCT makes material changes.

15. Customer Rights and Requests

Customers may request to access, correct, delete, restrict the processing of, or receive a return of customer-provided files. To make a request, contact SMART INSTINCT using the details in Section 17. We will respond within a reasonable time.

All requests are subject to legal, contractual, operational, and security limitations. For example, we may need to retain certain records to comply with law, resolve disputes, or maintain security, and some data may persist in backups until overwritten in the ordinary course.

16. Policy Updates

SMART INSTINCT may update this Policy from time to time to reflect changes in our Services, tools, or practices, or for legal or operational reasons. When we make material changes, we will update the "Last updated" date above and make the current version available to customers. Continued use of the Services after an update means the updated Policy applies going forward.

17. Contact Us

Questions about this Policy or requests under it can be directed to:

SMART INSTINCT

Email: email@smartinstinct.com

Phone: 800-969-4803

Web: smartinstinct.com