1. Who we are and what this policy covers
Pakkawork provides a control plane between AI agents and provider APIs. This policy covers the public website, Pakkawork workspaces, MCP and REST requests, provider connections, approval workflows, verification, incident records, support requests, and the signed evidence ledger.
For privacy questions or requests, contact admin@pakkawork.com. This policy does not replace the privacy terms of a provider API, identity provider, or other service you choose to connect.
2. Data we process
Account and workspace data may include a name, email address, authentication identifiers, workspace membership, role, and security events needed to operate access controls.
Governance data may include registered agent and operator identities, policy configuration, risk ceilings, immutable contract identifiers and hashes, approval decisions, execution status, verification results, compensation status, incidents, and signed ledger entries.
Connection data includes provider and scope metadata plus OAuth credentials. Provider credentials are stored server-side using envelope encryption; agent API keys are shown once and retained only as sha256 hashes.
Authorized action inputs can include Gmail recipient addresses, subject lines and message content; Calendar event details; Drive file metadata or content; spreadsheet values; and document content. Pakkawork processes only inputs supplied for an action that the user or workspace has authorized.
3. Content minimisation and redaction
Pakkawork minimises Google user data in approval metadata, provider results, incidents, and signed ledger evidence. Message bodies, file contents, document content, and cell values are redacted from those evidence surfaces and are not used to train models or for advertising.
An authorized action payload must remain available while it waits for policy evaluation, human approval, and asynchronous execution. For Gmail send, that payload can contain a base64url-encoded MIME message with recipients, subject, and body. It is stored in the tenant-isolated operational warrant record, available only to authorized service components and workspace access controls, and cleared after a terminal action reaches the workspace retention cutoff.
Pakkawork does not read a Gmail mailbox when only gmail.send is granted. Send-only execution uses Google's send response as an acknowledgement and labels the result as unchecked rather than requesting a mailbox read scope.
4. Why we use data
We process data to authenticate people and agents, maintain tenant isolation, resolve contracts, discover tools, compute risk, apply policy, route approvals, execute authorised calls, verify outcomes, support rollback and replay, maintain reliability controls, and preserve signed evidence.
We also use limited technical and support data to secure, troubleshoot, maintain, and improve the service, and to meet obligations that apply to Pakkawork.
5. Automated processing and human decisions
Risk and policy outcomes are computed from the resolved contract, API shape, request arguments, identity, and workspace configuration. High-risk actions can be held for out-of-band human approval; critical actions require two distinct approvers under the implemented safety floor.
Pakkawork does not use provider message bodies, file contents, or cell values to train a model. Its enforcement path is deterministic and runs outside the agent prompt.
6. Google API data and Limited Use
Pakkawork's public connection flow is limited to Gmail, Calendar, Drive, Sheets, and Docs in minimal mode. It may request openid and your primary account email for identity; gmail.send to send messages you authorize; calendar.events to manage events; drive.file for files created or opened with Pakkawork; spreadsheets for authorized spreadsheet actions; and documents for authorized document actions. Restricted mailbox-wide and Drive-wide modes are disabled.
Pakkawork's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy. Google user data is used only to provide or improve the user-facing connected features, security, and reliability; it is not sold, used for advertising, or used to train general-purpose models.
Google receives the API calls a user or workspace authorizes. Pakkawork uses infrastructure, database, authentication, communications, and operational vendors only as needed to provide and secure the service, subject to appropriate access controls and contractual obligations.
7. Retention and security
Operational warrant payloads are cleared after 7 days on Developer and 90 days on Team once actions reach a terminal state; Enterprise retention is defined for that deployment. Content-minimised signed control events may be retained longer to preserve security and ledger integrity. Account, security, support, incident, and legally required records may follow different periods based on operational need and applicable obligations.
Implemented safeguards include tenant isolation, row-level controls, AES-256-GCM envelope encryption for provider secrets, hash-only agent keys, PKCE and single-use OAuth state, host allowlists, SSRF containment, and an Ed25519-signed sha256 ledger chain.
No system is risk-free. Report a suspected security issue to admin@pakkawork.com without including active secrets in the message.
8. Your choices and rights
Workspace administrators can revoke a Google connection from the Apps page. You can also remove Pakkawork from Google Account permissions at https://myaccount.google.com/permissions. To request deletion of account data or retained Google action payloads, send a request from the email associated with your account to admin@pakkawork.com.
Depending on applicable law, you may also be able to request access, correction, restriction, portability, or object to particular processing. Pakkawork may need to verify identity and may retain content-minimised records where security, fraud prevention, legal, or ledger-integrity requirements prevent immediate deletion.