Data Handling & Security Notice

How FenestraGPT handles and protects business and technical information.

FENESTRA DATA HANDLING AND SECURITY NOTICE Effective Date: August 30, 2026 Fenestra may process business and technical information to provide its services. 1. Data Minimization Fenestra aims to collect and use information reasonably necessary for the requested service, operation, security, and legal compliance. 2. Customer-Controlled Information Customers should avoid submitting unnecessary sensitive information. Customers are responsible for ensuring they have authority to provide business, employee, contractor, supplier, customer, and other third-party information. 3. AI Processing Information provided to Fenestra may be processed using AI technologies where appropriate to perform analysis, design, recommendations, and related work. 4. Access Access to customer information should be limited to authorized personnel, systems, affiliates, and service providers with a legitimate need related to delivery, operation, security, or legal obligations. 5. Security Controls Fenestra uses reasonable administrative, technical, and operational measures designed to reduce risks of unauthorized access, loss, misuse, alteration, or disclosure. No system can be guaranteed completely secure. 6. Cloud and On-Premises Deployment Client CompanyGPT environments may be designed for cloud or on-premises deployment depending on the engagement, customer requirements, convenience, control, and long-term operational considerations. Deployment terms, responsibilities, infrastructure ownership, access controls, backup arrangements, and ongoing maintenance responsibilities should be defined in the applicable implementation agreement. 7. Third-Party Infrastructure Fenestra may depend on third-party providers for hosting, AI processing, payment services, communications, or other infrastructure. Such providers operate under their own terms, security controls, and service conditions. 8. Incident Handling Where Fenestra becomes aware of a material security incident affecting information under its control, Fenestra will respond in accordance with applicable obligations and reasonable incident-response practices. 9. Retention and Deletion Data may be retained as reasonably necessary for service delivery, records, security, fraud prevention, contractual obligations, dispute resolution, and applicable law. 10. Contact Questions regarding data handling or security may be sent to contact@fenestragpt.com.