Trust & Governance

Privacy Policy

DRAFTPending legal & deployment review•Version: 1.1•Controller: ZTICOM Tech Ltd

This is a draft policy pending legal and deployment review — it does not create binding commitments. This website itself renders specification content and client-side simulations only; no business actions are executed here, and contact requests are handled via email. For the data handling posture see the Trust Center.

Training Exclusion (Target)

Design intent: customer prompts, embeddings, and documents are not used to train third-party foundation models — subject to the exact provider contract.

Tenant Isolation (Target)

Design intent: customer data partitioned by PostgreSQL Row-Level Security (RLS) and tenant-scoped access boundaries.

Data Sovereignty (Roadmap)

Planned regional hosting options (e.g. EU/US) — no region is currently offered or deployment-verified.

1. Introduction & Scope

This Privacy Policy outlines how ZTICOM Tech Ltd ("WorkAgent OS", "we", "us", or "our") collects, processes, stores, and protects data when enterprises and authorized users utilize the WorkAgent OS execution platform, APIs, agent runtimes, and developer consoles.

WorkAgent OS is intended to operate as a Data Processor under GDPR and a Service Provider under CCPA/CPRA once deployed under an executed agreement, processing customer enterprise data in accordance with documented instructions and policies. The platform is not yet generally available; this draft describes the target posture.

2. Categories of Data Processed

  • Account & Identity Metadata: Name, work email address, corporate identity provider (IdP) attributes, enterprise tenant ID, and RBAC/ABAC role assignments.
  • Execution Context Data: User task instructions, conversational context, retrieved document chunks from integrated systems (e.g. Google Drive, Jira), and calendar/meeting metadata necessary for agent execution.
  • Audit & Telemetry Records (planned): SHA-256 canonical action hashes, human approval records, OpenTelemetry trace spans, execution latency, and token consumption metrics.
  • Connector Credentials (planned): OAuth access tokens and API keys intended to be stored exclusively in encrypted secret management vaults, never exposed to LLM context windows.
  • Website Contact Data (actual): the only data this website itself handles is the content of email inquiries you send to us via the mailto contact link.

3. Third-Party Foundation Model Inference

WorkAgent OS is designed to connect to foundation models (such as Anthropic Claude, OpenAI, DeepSeek, and Google Gemini) via stateless inference APIs. Provider retention and training terms depend on the exact provider contract and deployment; no specific ZDR or training-exclusion agreement is asserted as executed. Intended handling:

  • Target: prompts and model outputs are not retained by foundation model providers under the selected enterprise terms.
  • Target: customer data is not used for base model training or model improvement.
  • Data in transit is intended to be secured via TLS encryption.

4. Data Retention & Deletion

Retention and deletion schedules are defined per data class (conversations, memory, vectors, tool outputs, audit, traces, approvals, credentials, backups) and require an approved deployment policy agreed with the customer — no fixed durations are published. Tenant data deletion is intended to be triggerable by contacting our security engineering team.

5. Security & International Transfers

WorkAgent OS specifies administrative, physical, and technical safeguards including encryption of data at rest and in transit. Cross-border transfer mechanisms (such as EU Standard Contractual Clauses or UK IDTAs) are intended to be established per deployment — no active signed SCCs are asserted.

6. Inquiries & Data Protection Officer

For privacy inquiries, DPA requests, or to exercise your rights under GDPR/CCPA, please contact our data protection team:

ZTICOM Tech Ltd — Privacy & Security Office