Privacy notice
Operational draft · effective upon public launch
Information this site records
The workflow engineering assessment records information you deliberately submit, including contact and organization details, role and decision authority, workflow purpose, affected functions, steps and exceptions, applications and interfaces, volume, labor and error estimates, existing automation, access and API readiness, data sensitivity, approval controls, target environment, availability and recovery expectations, security requirements, ownership, constraints, timeline, investment range, desired results, acceptance evidence, consent, and technical request metadata.
Purpose and operating use
Information is used to evaluate build/no-build fit, route the request, define the initial engineering boundary, prepare a response, protect the channel, preserve an auditable business record, and create a governed engagement only if both parties later agree in writing. Task-relevant in-house workflows may classify or summarize the record for the authorized Automation Office; production access and engineering conclusions still require accountable human review.
Confidentiality and intellectual property
You retain ownership of your pre-existing information and intellectual property. Submission grants only the limited permission required to evaluate and respond to the request. Ghost Atlas does not sell submitted assessment information or authorize its use to train a public or general-purpose model. Initial submission is not a substitute for a confidentiality or data-processing agreement where one is required.
Protected-data boundary
Do not submit passwords, tokens, certificates, production secrets, regulated records, customer datasets, classified or export-controlled information, source code, security vulnerabilities, or third-party intellectual property you are not authorized to disclose. Protected technical evidence enters only after an accepted access, custody, retention, and disposal plan.
Access, service providers, and retention
Access is limited to the founder, authorized Estate functions, and task-relevant infrastructure or service providers operating under the applicable business configuration. Final legal entity, jurisdiction, retention schedule, subprocessor register, international-transfer terms, notice address, and deletion procedure must be completed with counsel before custom-domain public launch.