AOT Jason Privacy Policy

Effective Date: October 6, 2026

Atlantic Office Technologies (“AOT,” “we,” “our,” or “us”) operates AOT Jason (“Jason”), an internal technology and automation platform used to support authorized AOT business operations.

This Privacy Policy explains how information is accessed, processed, protected, and disclosed when Jason is used or connected to third-party services.

1. Scope

Jason is primarily an internal business application intended for authorized AOT personnel.

Jason may connect to business systems operated by AOT or third-party providers, including QuickBooks Online and other approved business, accounting, security, and information technology platforms.

This policy applies to information processed through Jason.

2. Information We May Process

Depending on the authorized function being performed, Jason may process information such as:

Account and Identity Information

  • User name

  • Business email address

  • Organization or company affiliation

  • Authentication and authorization identifiers

  • Role and access information

Business and Operational Information

  • Support ticket information

  • Device and system information

  • Customer and vendor business information

  • Procurement information

  • Operational records

  • Audit and security metadata

QuickBooks Online Information

When an authorized AOT QuickBooks Online company is connected, Jason may access accounting information such as:

  • Company information

  • Chart of accounts

  • Vendor records

  • Customer records

  • Invoices

  • Bills

  • Profit and Loss reports

  • Balance Sheet reports

Jason's initial production QuickBooks integration is read-only.

Jason does not initially create, modify, delete, or post QuickBooks transactions.

Jason does not request QuickBooks Payments API access as part of this integration.

3. How We Use Information

Information processed by Jason may be used to:

  • Provide requested business information

  • Assist with accounting and reconciliation workflows

  • Support authorized IT and managed-service operations

  • Verify invoices, bills, vendors, customers, and financial records

  • Assist with procurement and billing processes

  • Diagnose technical or operational issues

  • Enforce identity and authorization controls

  • Maintain audit and security records

  • Detect and investigate security incidents

  • Improve authorized AOT operational workflows

  • Comply with legal, regulatory, or contractual obligations

We do not use QuickBooks information for advertising.

4. QuickBooks and Intuit Authorization

Jason connects to QuickBooks Online using Intuit's OAuth 2.0 authorization process.

AOT does not require users to provide QuickBooks passwords to Jason.

The QuickBooks integration requests only the Intuit permissions required for approved functionality.

The initial production integration requests the QuickBooks Accounting scope only and does not request the QuickBooks Payments scope.

Access to an AOT QuickBooks company must be explicitly authorized through Intuit.

5. Credentials and OAuth Tokens

Application credentials and OAuth secrets are treated as protected security information.

Production Intuit application credentials are stored in AOT's controlled secret-management system.

Production QuickBooks OAuth token information is stored separately from development and sandbox credentials.

Production OAuth token payloads are protected using application-layer AES-256-GCM encryption, with the encryption key maintained separately in AOT's protected secret-management system.

Credentials, Client Secrets, access tokens, refresh tokens, and encryption keys are not intended to be stored in source code, ordinary application logs, chat conversations, or user-facing responses.

6. Data Storage and Retention

Jason is designed to minimize unnecessary persistence of information obtained from connected systems.

QuickBooks API response bodies are not stored in Jason's standard connector or orchestration event logs.

Operational systems may retain limited metadata needed for security, reliability, troubleshooting, authorization, and auditing, such as:

  • Which capability was requested

  • The provider used

  • Request timing

  • Success or failure status

  • Authorization decisions

  • Correlation identifiers

OAuth connection information is retained while the integration remains authorized and operational.

Information is retained only for legitimate business, security, contractual, or legal purposes and may be deleted or deactivated when no longer required.

7. Information Sharing

AOT does not sell QuickBooks data or personal information obtained through Jason.

Information may be disclosed only when appropriate for legitimate business purposes, including to:

  • Authorized AOT personnel

  • Service providers supporting AOT's technology infrastructure

  • Third-party platforms necessary to perform an authorized integration

  • Legal, regulatory, governmental, or law-enforcement authorities when disclosure is required by applicable law

  • Professional advisors when reasonably necessary for legal, accounting, security, or compliance purposes

Third-party providers are subject to their respective contractual, security, and privacy obligations.

8. Data Access and Authorization

Access to information through Jason is restricted through technical and organizational controls.

Jason may evaluate factors including:

  • User identity

  • Organization

  • Approved capabilities

  • Permission level

  • Requested operation

  • Required approvals

  • Connection to the underlying system

Access to a connected system does not automatically grant a Jason user access to all information in that system.

9. Security

AOT maintains administrative and technical safeguards intended to protect information processed through Jason.

These safeguards may include:

  • Restricted system access

  • Multi-factor authentication where applicable

  • Role- and capability-based authorization

  • Secret-management systems

  • Encrypted production OAuth token storage

  • Network and system access controls

  • Security monitoring

  • Audit logging

  • Software and dependency management

  • Controlled deployment and change-management processes

  • Separation of development and production credentials

No information system can guarantee absolute security, and AOT continually evaluates its safeguards based on operational risk.

10. Development and Production Separation

QuickBooks development and production integrations are maintained as separate trust environments.

Jason uses separate:

  • Intuit application credentials

  • Secret-management identities

  • OAuth authorization records

  • OAuth token databases

  • Callback paths

  • Deployment activation profiles

Production access is not automatically granted because sandbox or development access exists.

11. Third-Party Platforms

Jason may interact with third-party platforms.

Information processed by those services is also subject to their privacy policies and terms.

For QuickBooks Online integrations, Intuit independently controls the QuickBooks platform and its OAuth authorization process.

12. Data Rights and Requests

Individuals may contact AOT regarding questions about personal information processed through Jason, including requests for access, correction, or deletion where applicable under law.

Because Jason primarily processes business information as part of AOT's internal operations, certain information may be retained when required for contractual, financial, security, audit, or legal purposes.

Requests may be directed to:

support@teamaot.com

AOT may need to verify the identity and authority of the person making a request before acting on it.

13. Children

Jason is a business application and is not intended for use by children.

We do not knowingly design Jason to collect personal information from children.

14. Changes to This Policy

AOT may update this Privacy Policy as Jason, its integrations, applicable laws, or AOT's business practices change.

The current version will be posted at this URL and will identify its effective date.

15. Contact Us

Questions about this Privacy Policy or Jason's handling of information may be directed to:

Atlantic Office Technologies
1202 W Little Creek Rd

Norfolk VA, 23505
Email: support@teamaot.com
Website: https://www.atlanticofficetechnologies.com