redictiveIT Gateway — Privacy Policy
Effective Date: 2026-07-17 Publisher: predictiveIT, 600 N Willow Ave 2nd floor, Tampa, FL 33606 Applies to: the predictiveIT Gateway (the “App”), an internal integration service. This Policy is specific to the App. It supplements — and does not replace — the predictiveIT website Privacy Policy, which continues to govern data collected through predictiveit.com and related public marketing channels.
1. Who this Policy is about
The App is used only by predictiveIT employees, contractors, and authorized service accounts. There are no external users, customer sign-ups, or public-facing endpoints beyond those needed to authenticate authorized staff. This Policy describes how the App handles the data flowing through it during authorized internal use.
2. Data the App accesses
The App does not itself collect data from you directly. Instead, when an authorized staff member issues a request through an authenticated MCP client, the App retrieves data on demand from third-party business systems under predictiveIT’s existing integrations, including:
| Source | Categories of data retrieved |
|---|---|
| Intuit QuickBooks Online | Company profile; customers and contacts; invoices and their line items; bills and their line items; payments; purchase orders; profit & loss and aged receivables reports; chart of accounts. Payroll data is intentionally not requested (scope excluded). |
| Autotask (Datto) | Service tickets, notes, and time entries; companies and contacts; resources (staff); contracts; configuration items; opportunities and quotes; knowledgebase articles. |
| IT Glue | Organizations, documents, configuration items, and structured records. Passwords and other secret fields are automatically redacted before leaving the App; the /passwords endpoint is never accessed. |
| Microsoft Entra ID (in progress) | User identity attributes needed to authenticate staff and enforce role-based access. |
For each request, the App retrieves the minimum data required to answer the request. No wholesale replication of any upstream data store is performed.
3. How the data is used
The App is used exclusively to help predictiveIT staff perform legitimate business functions, including:
- Investigating service tickets and delivering support
- Reconciling financial records and preparing executive reporting
- Reviewing contract and opportunity data for account management
- Producing internal dashboards and KPI reports
Data retrieved through the App is used only for these internal business purposes. It is not sold, rented, licensed, or otherwise disclosed to third parties. It is not used for advertising, profiling of individuals, or any secondary purpose.
4. Sharing
We do not share upstream data with any third party except:
- Cloud AI providers — When you interact with the App through an MCP client backed by a cloud AI service (for example, OpenAI, Anthropic, or Microsoft Copilot), the tool-call responses returned by the App transit through that provider so the AI can incorporate them into its reply to you. Each of these providers is governed by its own privacy notice and enterprise data-handling terms. No data is retained by these providers for training or improvement of their services under the enterprise agreements predictiveIT uses.
- Infrastructure providers — Cloudflare (transport-layer only, terminated at Cloudflare’s edge under HTTPS then re-encrypted to origin over Cloudflare Tunnel) and Microsoft Azure (identity provider for staff sign-in). These providers process metadata (request URLs, timing, source IPs) for delivery and security but not the content of App responses.
- Legal obligations — If required by court order, subpoena, or applicable law, we may disclose data as legally compelled, and only to the extent so compelled.
5. Storage and retention
The App is stateless with respect to upstream data — it does not persist copies of your QuickBooks Online records, Autotask tickets, or IT Glue documents. Data is retrieved for each request and released from memory after the response is delivered.
The App maintains an audit log in a PostgreSQL database on predictiveIT’s private infrastructure. Each entry records the authenticated caller, the timestamp, the tool name, the caller’s IP address, and — for write operations only — a JSON snapshot of the arguments supplied. Read operations record only metadata (never the response body). The audit log is retained for twelve (12) months to support security monitoring, incident response, and compliance review, then automatically pruned.
The App also maintains an OAuth refresh-token file for its QuickBooks Online integration. This file contains no customer data; it holds only the credential material needed for the App to authenticate to Intuit on predictiveIT’s behalf. File permissions restrict it to a single system account, and it is excluded from all backups that leave predictiveIT’s premises.
6. Security
- All external traffic to the App is over HTTPS/TLS. The App’s public endpoint at
gateway.predictiveit.aiis fronted by Cloudflare Tunnel; there is no direct inbound network exposure to the origin host. - Every request must present a valid bearer key or Microsoft Entra identity token; anonymous access is rejected.
- Role-based access controls limit each authenticated caller to the tools their role requires.
- All access, authentication attempts (including failed attempts), and administrative operations are recorded in the audit log described above.
- Upstream credentials (Intuit OAuth secrets, Autotask API keys, IT Glue API keys, etc.) are stored only in restricted-permission files on the App’s host and are never returned to clients.
- Automated redaction of sensitive fields (passwords, API keys, private keys) is applied to IT Glue responses before they leave the App.
- The App’s log formatter is specifically hardened to prevent leaking upstream authentication headers or refresh tokens into logs, even in the event of an upstream error.
7. Third-party services and their privacy notices
Because the App draws data from third parties, their own privacy practices apply to that data at its source:
- Intuit — https://www.intuit.com/privacy/statement/
- Datto (Autotask) — https://www.datto.com/privacy-policy
- IT Glue (Kaseya) — https://www.kaseya.com/legal/privacy-policy/
- Microsoft — https://privacy.microsoft.com/
- Anthropic (Claude) — https://www.anthropic.com/legal/privacy
- OpenAI (ChatGPT) — https://openai.com/policies/privacy-policy
Data returned from any of these systems is subject to that provider’s terms in addition to this Policy.
8. Data-subject and account-owner rights
QuickBooks Online account owner. predictiveIT is the QuickBooks Online account owner for its own books. At any time, the account owner may revoke the App’s access to QuickBooks Online through the “My Apps” area of the Intuit QuickBooks Online console. Revocation is effective immediately at Intuit; the App’s cached OAuth refresh token becomes invalid on the next use.
Individual users. Data about individuals accessible through the App (staff usernames, contact records, ticket contents) is data predictiveIT already holds in its business systems for the purposes disclosed in each contract with the individual or their employer. The App does not create new individual profiles or perform automated decision-making about individuals. Requests to access, correct, or delete individual information should be directed to the source system’s controller — in most cases, predictiveIT (as data controller of its Autotask, IT Glue, and QBO tenants) at info@predictiveIT.com.
9. Data hosted in the United States
The App runs on predictiveIT-controlled infrastructure located in the United States. Upstream services (Intuit, Datto, Kaseya, Microsoft) each host data in regions defined by their own agreements with predictiveIT.
10. Children
The App is an internal business tool. It is not directed to, marketed to, or intended for use by children under 13, and predictiveIT does not knowingly permit any use of the App by children.
11. Changes to this Policy
predictiveIT may update this Policy from time to time. Updates take effect on the date shown at the top of this document. Material changes will be communicated to staff through predictiveIT’s internal channels.
12. Contact
Questions, concerns, or requests related to this Policy or the App’s handling of data should be directed to:
predictiveIT 3433 Lithia Pinecrest Rd. Ste 359 Valrico, FL. 33596 info@predictiveIT.com 813-514-8600