AOT Jason Privacy Policy
Effective Date: October 6, 2026
Atlantic Office Technologies (“AOT,” “we,” “our,” or “us”) operates AOT Jason (“Jason”), an internal technology and automation platform used to support authorized AOT business operations.
This Privacy Policy explains how information is accessed, processed, protected, and disclosed when Jason is used or connected to third-party services.
1. Scope
Jason is primarily an internal business application intended for authorized AOT personnel.
Jason may connect to business systems operated by AOT or third-party providers, including QuickBooks Online and other approved business, accounting, security, and information technology platforms.
This policy applies to information processed through Jason.
2. Information We May Process
Depending on the authorized function being performed, Jason may process information such as:
Account and Identity Information
User name
Business email address
Organization or company affiliation
Authentication and authorization identifiers
Role and access information
Business and Operational Information
Support ticket information
Device and system information
Customer and vendor business information
Procurement information
Operational records
Audit and security metadata
QuickBooks Online Information
When an authorized AOT QuickBooks Online company is connected, Jason may access accounting information such as:
Company information
Chart of accounts
Vendor records
Customer records
Invoices
Bills
Profit and Loss reports
Balance Sheet reports
Jason's initial production QuickBooks integration is read-only.
Jason does not initially create, modify, delete, or post QuickBooks transactions.
Jason does not request QuickBooks Payments API access as part of this integration.
3. How We Use Information
Information processed by Jason may be used to:
Provide requested business information
Assist with accounting and reconciliation workflows
Support authorized IT and managed-service operations
Verify invoices, bills, vendors, customers, and financial records
Assist with procurement and billing processes
Diagnose technical or operational issues
Enforce identity and authorization controls
Maintain audit and security records
Detect and investigate security incidents
Improve authorized AOT operational workflows
Comply with legal, regulatory, or contractual obligations
We do not use QuickBooks information for advertising.
4. QuickBooks and Intuit Authorization
Jason connects to QuickBooks Online using Intuit's OAuth 2.0 authorization process.
AOT does not require users to provide QuickBooks passwords to Jason.
The QuickBooks integration requests only the Intuit permissions required for approved functionality.
The initial production integration requests the QuickBooks Accounting scope only and does not request the QuickBooks Payments scope.
Access to an AOT QuickBooks company must be explicitly authorized through Intuit.
5. Credentials and OAuth Tokens
Application credentials and OAuth secrets are treated as protected security information.
Production Intuit application credentials are stored in AOT's controlled secret-management system.
Production QuickBooks OAuth token information is stored separately from development and sandbox credentials.
Production OAuth token payloads are protected using application-layer AES-256-GCM encryption, with the encryption key maintained separately in AOT's protected secret-management system.
Credentials, Client Secrets, access tokens, refresh tokens, and encryption keys are not intended to be stored in source code, ordinary application logs, chat conversations, or user-facing responses.
6. Data Storage and Retention
Jason is designed to minimize unnecessary persistence of information obtained from connected systems.
QuickBooks API response bodies are not stored in Jason's standard connector or orchestration event logs.
Operational systems may retain limited metadata needed for security, reliability, troubleshooting, authorization, and auditing, such as:
Which capability was requested
The provider used
Request timing
Success or failure status
Authorization decisions
Correlation identifiers
OAuth connection information is retained while the integration remains authorized and operational.
Information is retained only for legitimate business, security, contractual, or legal purposes and may be deleted or deactivated when no longer required.
7. Information Sharing
AOT does not sell QuickBooks data or personal information obtained through Jason.
Information may be disclosed only when appropriate for legitimate business purposes, including to:
Authorized AOT personnel
Service providers supporting AOT's technology infrastructure
Third-party platforms necessary to perform an authorized integration
Legal, regulatory, governmental, or law-enforcement authorities when disclosure is required by applicable law
Professional advisors when reasonably necessary for legal, accounting, security, or compliance purposes
Third-party providers are subject to their respective contractual, security, and privacy obligations.
8. Data Access and Authorization
Access to information through Jason is restricted through technical and organizational controls.
Jason may evaluate factors including:
User identity
Organization
Approved capabilities
Permission level
Requested operation
Required approvals
Connection to the underlying system
Access to a connected system does not automatically grant a Jason user access to all information in that system.
9. Security
AOT maintains administrative and technical safeguards intended to protect information processed through Jason.
These safeguards may include:
Restricted system access
Multi-factor authentication where applicable
Role- and capability-based authorization
Secret-management systems
Encrypted production OAuth token storage
Network and system access controls
Security monitoring
Audit logging
Software and dependency management
Controlled deployment and change-management processes
Separation of development and production credentials
No information system can guarantee absolute security, and AOT continually evaluates its safeguards based on operational risk.
10. Development and Production Separation
QuickBooks development and production integrations are maintained as separate trust environments.
Jason uses separate:
Intuit application credentials
Secret-management identities
OAuth authorization records
OAuth token databases
Callback paths
Deployment activation profiles
Production access is not automatically granted because sandbox or development access exists.
11. Third-Party Platforms
Jason may interact with third-party platforms.
Information processed by those services is also subject to their privacy policies and terms.
For QuickBooks Online integrations, Intuit independently controls the QuickBooks platform and its OAuth authorization process.
12. Data Rights and Requests
Individuals may contact AOT regarding questions about personal information processed through Jason, including requests for access, correction, or deletion where applicable under law.
Because Jason primarily processes business information as part of AOT's internal operations, certain information may be retained when required for contractual, financial, security, audit, or legal purposes.
Requests may be directed to:
support@teamaot.com
AOT may need to verify the identity and authority of the person making a request before acting on it.
13. Children
Jason is a business application and is not intended for use by children.
We do not knowingly design Jason to collect personal information from children.
14. Changes to This Policy
AOT may update this Privacy Policy as Jason, its integrations, applicable laws, or AOT's business practices change.
The current version will be posted at this URL and will identify its effective date.
15. Contact Us
Questions about this Privacy Policy or Jason's handling of information may be directed to:
Atlantic Office Technologies
1202 W Little Creek Rd
Norfolk VA, 23505
Email: support@teamaot.com
Website: https://www.atlanticofficetechnologies.com