← Creative Engine Automations

Privacy Policy

Effective date: 5 October 2026

This Privacy Policy explains how Creative Engine Automations processes information in connection with its private automation infrastructure and associated business workflows.

Creative Engine Automations is private workflow automation infrastructure. It is not offered as a public software-as-a-service platform.

1. Information we may process

Creative Engine Automations may process information that is reasonably necessary to perform authorized business and automation functions. Depending on the workflow, this may include business records, files, workflow configuration data, order information, customer enquiries, fulfillment information, contact information, and related operational data.

Where personal information is involved, this may include information such as a person's name, email address, order details, communication history, delivery or transaction-related information, or other information necessary for the relevant business purpose.

2. Google services and Google user data

Creative Engine Automations may connect to authorized Google services, including Google Drive and Google Sheets, in order to perform automation and business workflows.

Depending on the permissions granted, these workflows may read, create, copy, update, organize, or otherwise process authorized files, folders, spreadsheets, and related data where required to perform the requested workflow.

Information obtained through Google APIs is used only for authorized application functionality and legitimate operational purposes associated with the relevant workflows.

Creative Engine Automations' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How information is used

Information may be processed where necessary for purposes including:

4. Customer and order information

During normal business operations, information relating to customers, orders, enquiries, fulfillment, communications, or other business records may pass through or be temporarily stored in authorized services such as Google Sheets or Google Drive.

Creative Engine Automations follows a data-minimisation approach. Personal information is accessed, processed, transferred, or stored only to the extent reasonably necessary for the relevant operational purpose. The system is not intended to collect unrelated personal information.

5. Marketing communications

Personal information may be used to send marketing communications only where the recipient has provided the required consent or where another lawful basis permits such communications under applicable law.

Contact information used for consented marketing may pass through or be temporarily stored in authorized business systems, including Google services, where necessary for workflow processing, record-keeping, or backup purposes.

Data obtained through Google APIs is not sold, used to create unrelated advertising profiles, or provided to unrelated third parties for their own advertising purposes.

6. Data minimisation and purpose limitation

Creative Engine Automations is designed to process only information reasonably necessary for a defined business or automation purpose. Personal information is not intentionally collected merely because it is available from a connected service.

Processing is limited to relevant operational purposes and applicable legal obligations.

7. Storage, backups, and retention

Information may be stored or temporarily retained where necessary to execute workflows, maintain business records, provide operational continuity, troubleshoot errors, or create appropriate backups.

Personal information is retained only for as long as reasonably necessary for the purpose for which it is processed, subject to applicable legal, accounting, contractual, security, and operational requirements.

OAuth credentials or authorization tokens used to connect services may be securely retained while an integration remains active. Access may be revoked through the relevant service provider, including through Google Account authorization settings where applicable.

8. Sharing and service providers

Information may be processed by service providers or business systems where this is necessary to provide infrastructure, hosting, order processing, fulfillment, communications, automation, storage, security, or other legitimate business functions.

Personal information is not sold. Information is not shared with unrelated third parties for their independent marketing purposes.

Information may also be disclosed where required by applicable law, regulation, legal process, or a valid request from a competent authority.

9. Data protection and security

Reasonable technical and organisational measures are used to protect personal and business information against unauthorized access, loss, misuse, alteration, or disclosure.

Access to systems and integrations is limited according to operational requirements, and connected services are authorized using appropriate authentication mechanisms.

10. Data protection law and GDPR

Personal information is handled in accordance with applicable privacy and data protection laws, including the EU General Data Protection Regulation (GDPR) where applicable.

Principles including data minimisation, purpose limitation, appropriate retention, security, and lawful processing are applied where required.

11. International processing

Some infrastructure or third-party service providers may process information in countries other than the country in which the individual is located. Where applicable, appropriate safeguards required by data protection law are used for international transfers of personal data.

12. Privacy rights

Depending on applicable law and the circumstances of the processing, individuals may have rights relating to their personal information, including rights to request access, correction, deletion, restriction, or portability of their data, and to object to certain processing.

Where processing is based on consent, consent may be withdrawn where applicable. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

Individuals may also have the right to lodge a complaint with the applicable data protection supervisory authority.

13. Google authorization

Access granted to Creative Engine Automations through Google OAuth can be reviewed or revoked through the user's Google Account security and third-party connection settings.

14. Children

Creative Engine Automations is business automation infrastructure and is not designed or intended as a service directed to children.

15. Changes to this policy

This Privacy Policy may be updated when business operations, connected services, legal requirements, or data-processing practices change. The effective date displayed at the top of this page will be updated when material changes are made.

16. Contact

Questions, privacy requests, or enquiries regarding the handling of personal information can be sent to:

Creative Engine Automations
Email: creativeengineautomations@gmail.com