MOSS Privacy Policy
Effective Date: September 7, 2026
ERGO SYSTEMS LLC, a Florida limited liability company doing business through the MOSS platform ("MOSS," "ERGO SYSTEMS," "we," "us," or "our"), respects privacy and is committed to handling personal information responsibly.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with:
- the MOSS website;
- the MOSS software platform;
- MOSS AI Employees;
- MOSS applications and dashboards;
- APIs;
- integrations;
- communications;
- customer support;
- sales and marketing;
- and other products and services that link to this Privacy Policy,
collectively, the "Services."
This Privacy Policy also explains certain privacy rights and choices available to individuals.
MOSS is operated by:
ERGO SYSTEMS LLC
2125 Biscayne Blvd, STE 204 #20921
Miami, FL 33137
United States
Privacy and Legal Contact:
jorge@ergosystems.ai
1. SCOPE OF THIS PRIVACY POLICY
MOSS is primarily a business-to-business software platform.
Our customers are businesses that use MOSS to operate customer-facing and internal workflows through AI-powered software employees and related automation.
This Privacy Policy applies to personal information that MOSS processes in connection with:
- prospective customers;
- customers;
- customer employees and Authorized Users;
- website visitors;
- people communicating directly with MOSS;
- people whose information is processed through MOSS on behalf of a MOSS customer.
The role MOSS plays may differ depending on the circumstances.
1.1 Information MOSS Controls Directly
For information we collect for our own purposes, such as:
- account registration;
- billing;
- sales;
- website operation;
- customer support;
- security;
- product administration;
MOSS generally determines why and how the information is processed.
1.2 Information Processed on Behalf of Customers
A MOSS customer may provide or connect information relating to its own:
- customers;
- prospects;
- employees;
- technicians;
- vendors;
- contacts;
- business operations.
For this information, MOSS generally processes the information on behalf of the MOSS customer and according to the customer's configuration and instructions.
The MOSS customer is responsible for its relationship with the individuals whose information it provides to MOSS, including providing legally required privacy notices and obtaining required permissions or consent.
If you are an individual whose information was provided to MOSS by a business that uses MOSS, you may need to contact that business directly to exercise certain privacy rights.
2. INFORMATION WE COLLECT
The information we collect depends on how you interact with MOSS and which Services are used.
We may collect the following categories of information.
3. ACCOUNT AND CONTACT INFORMATION
We may collect:
- name;
- business name;
- job title;
- business role;
- email address;
- telephone number;
- mailing address;
- account identifiers;
- login information;
- authentication information;
- organization membership;
- account permissions;
- subscription information;
- support contact information.
4. BUSINESS INFORMATION
Customers may provide information about their businesses so MOSS can operate appropriately.
This may include:
- business name;
- business address;
- operating locations;
- service areas;
- business hours;
- holidays and closures;
- services offered;
- business policies;
- scheduling rules;
- dispatch rules;
- escalation rules;
- communication preferences;
- booking policies;
- cancellation and rescheduling rules;
- technician information;
- business procedures;
- pricing-related business information;
- customer-service policies;
- sales policies;
- operational information.
5. CUSTOMER AND PROSPECT INFORMATION
When a business uses MOSS to interact with its customers or prospects, MOSS may process information including:
- names;
- phone numbers;
- email addresses;
- service addresses;
- mailing addresses;
- customer identifiers;
- service requests;
- inquiries;
- appointment information;
- job information;
- estimates;
- service history;
- communication history;
- customer preferences;
- consent or communication-preference information;
- notes;
- relationship history;
- complaint or escalation information;
- payment or invoice status received from connected systems;
- other information necessary to perform the requested business workflow.
6. COMMUNICATIONS
MOSS may process communications sent, received, generated, or managed through the Services.
Depending on the features enabled, these may include:
- emails;
- text messages;
- customer inquiries;
- conversation threads;
- support communications;
- internal notes;
- AI-generated drafts;
- AI-generated responses;
- dispatch notifications;
- sales follow-ups;
- review requests;
- service reminders.
If voice functionality is enabled in the future, MOSS may also process:
- call metadata;
- audio;
- transcripts;
- call summaries;
- call outcomes;
subject to applicable laws, customer configuration, and required notices or consent.
7. KNOWLEDGE BASE AND DOCUMENT INFORMATION
Customers may provide business knowledge used by MOSS AI Employees.
This may include:
- knowledge articles;
- operating procedures;
- FAQs;
- service policies;
- employee instructions;
- sales guidance;
- dispatch guidance;
- customer-service procedures;
- uploaded documents;
- answers to knowledge gaps;
- internal business documentation.
Where semantic retrieval is enabled, MOSS may:
- extract text from supported documents;
- divide content into sections or chunks;
- generate mathematical representations known as embeddings;
- index content for retrieval;
- associate metadata and provenance with indexed content.
These processes are designed to help MOSS retrieve relevant business knowledge based on meaning and context.
8. INFORMATION FROM CONNECTED SERVICES
Customers may choose to connect third-party services to MOSS.
Depending on the integration, MOSS may receive or transmit information through services such as:
- Google Calendar;
- Microsoft Outlook Calendar;
- Gmail;
- Microsoft Outlook Mail;
- Jobber;
- QuickBooks Online;
- Google Business Profile;
- Twilio;
- Resend;
- other supported business systems.
The information MOSS receives depends on:
- the integration;
- the permissions granted;
- the customer's configuration;
- the functionality being used.
9. CALENDAR INFORMATION
Connected calendar information may include:
- calendar identifiers;
- calendar names;
- events;
- event times;
- availability;
- attendees;
- event descriptions;
- appointment information;
- event status;
- scheduling metadata.
MOSS uses calendar information to support functions such as:
- availability;
- scheduling;
- rescheduling;
- cancellation;
- dispatch;
- appointment coordination;
- conflict detection;
- calendar synchronization.
10. FIELD-SERVICE AND BUSINESS-SYSTEM INFORMATION
Connected field-service or operational platforms may provide information such as:
- customers;
- prospects;
- jobs;
- requests;
- visits;
- appointments;
- estimates;
- technicians;
- employees;
- assignments;
- services;
- job statuses;
- service history;
- operational identifiers.
MOSS uses this information to support authorized customer-service, sales, dispatch, relationship, scheduling, and operational workflows.
11. EMAIL INFORMATION
If a customer connects a Gmail or Microsoft Outlook mailbox, MOSS may process authorized mailbox information such as:
- email address;
- sender and recipient information;
- subject lines;
- message bodies;
- threads;
- timestamps;
- attachments;
- message identifiers;
- mailbox folders or labels;
- delivery and response metadata.
MOSS processes connected mailbox information only within the permissions granted by the customer and for functionality enabled by the customer.
12. ACCOUNTING INFORMATION
If a customer connects an accounting platform such as QuickBooks Online, MOSS may process authorized business information including:
- customer records;
- estimates;
- invoices;
- invoice status;
- payment status;
- balances;
- products or services;
- accounting identifiers;
- relevant business transaction information.
MOSS does not treat AI-generated assumptions as authoritative accounting information.
Where accounting information is used, authoritative state should come from the applicable accounting or transactional system.
13. GOOGLE BUSINESS PROFILE INFORMATION
If a customer connects Google Business Profile, MOSS may process authorized information including:
- business locations;
- business profile information;
- reviews;
- ratings;
- review responses;
- performance information;
- other information made available through supported Google Business Profile APIs.
14. PAYMENT AND BILLING INFORMATION
MOSS may collect information relating to subscriptions and billing, including:
- subscription plan;
- billing cadence;
- invoice history;
- payment status;
- transaction identifiers;
- billing contact information;
- payment-method metadata.
Payment-card or banking information may be processed directly by a third-party payment processor rather than stored directly by MOSS.
MOSS may receive limited payment information from the processor, such as:
- payment status;
- card type;
- last four digits;
- expiration information;
- transaction identifier.
15. TECHNICAL AND USAGE INFORMATION
When you use MOSS, we may automatically collect information such as:
- IP address;
- browser type;
- device type;
- operating system;
- application version;
- pages or screens viewed;
- timestamps;
- login activity;
- session information;
- referring pages;
- feature usage;
- integration usage;
- diagnostic information;
- error information;
- security events.
16. AI EMPLOYEE OPERATIONAL INFORMATION
MOSS may generate and retain structured information relating to the operation of AI Employees.
This may include:
- AI Employee identity;
- trigger or wake-up source;
- assigned objective;
- capabilities used;
- tasks completed;
- escalations;
- approvals;
- provider actions;
- outcomes;
- retries;
- failures;
- execution duration;
- model used;
- cost or usage metadata;
- external references;
- synchronization state;
- operational activity.
This information may be used for:
- providing Services;
- customer visibility;
- auditing;
- troubleshooting;
- reliability;
- safety;
- security;
- system improvement.
17. AI MODEL INFORMATION
MOSS may use third-party artificial intelligence or machine-learning providers to perform certain functions.
Information sent to an AI provider may include the minimum context reasonably necessary for the requested operation, such as:
- conversation context;
- relevant business knowledge;
- customer context;
- instructions;
- structured operational context.
MOSS is designed to avoid providing AI models with unnecessary:
- provider credentials;
- OAuth tokens;
- passwords;
- encryption keys;
- infrastructure secrets.
MOSS does not disclose hidden authentication credentials to AI Employees as business context.
18. SOURCES OF INFORMATION
We may obtain information:
Directly from you
For example when you:
- create an account;
- configure MOSS;
- communicate with us;
- purchase Services;
- upload content;
- request support.
From MOSS customers
Businesses using MOSS may provide information about:
- their customers;
- prospects;
- employees;
- technicians;
- vendors;
- business contacts.
From connected services
We may receive information from third-party systems a customer authorizes MOSS to access.
Automatically
We may collect technical, security, and usage information when Services are accessed.
From service providers
We may receive information from providers supporting:
- billing;
- authentication;
- hosting;
- analytics;
- communications;
- security;
- customer support.
From public or business sources
Where appropriate, we may obtain business contact or company information from publicly available or commercial business sources for legitimate business purposes.
19. HOW WE USE INFORMATION
We may use personal information for the following purposes.
20. PROVIDING THE SERVICES
We use information to:
- create and administer accounts;
- authenticate users;
- provide AI Employee functionality;
- operate customer-service workflows;
- operate sales workflows;
- operate dispatch workflows;
- operate relationship-management workflows;
- process communications;
- manage schedules;
- coordinate appointments;
- retrieve business knowledge;
- synchronize connected systems;
- execute customer-authorized workflows;
- display operational information.
21. AI-POWERED PROCESSING
We may use information to enable AI-powered functionality such as:
- understanding customer requests;
- generating responses;
- classifying intent;
- retrieving relevant knowledge;
- summarizing information;
- selecting appropriate capabilities;
- assisting with workflow execution;
- identifying escalation needs;
- generating communications.
AI-generated recommendations are not treated as authoritative substitutes for transactional systems where authoritative business data exists.
22. INTEGRATION AND SYNCHRONIZATION
We use information to:
- connect third-party systems;
- verify integration readiness;
- synchronize authorized information;
- reconcile differences among systems;
- maintain external identifiers;
- detect stale information;
- execute authorized provider actions;
- maintain appropriate operational context.
23. COMMUNICATIONS
We may use information to:
- send requested business communications;
- respond to customers;
- send scheduling communications;
- send operational notifications;
- send sales follow-ups;
- send review requests;
- send service reminders;
- provide customer support;
- provide account and security notices.
24. PRODUCT OPERATION AND IMPROVEMENT
We may use information to:
- operate MOSS;
- maintain reliability;
- troubleshoot errors;
- understand feature performance;
- improve workflows;
- improve user experience;
- develop new functionality;
- evaluate AI Employee performance;
- test system quality.
Where feasible and appropriate, we may use aggregated, anonymized, or de-identified information for analytics and product improvement.
25. SECURITY AND FRAUD PREVENTION
We may use information to:
- authenticate users;
- monitor access;
- detect security incidents;
- prevent fraud;
- prevent misuse;
- investigate suspicious activity;
- protect customers;
- enforce our agreements;
- maintain platform integrity.
26. LEGAL AND COMPLIANCE PURPOSES
We may process information to:
- comply with applicable law;
- respond to lawful legal process;
- protect our legal rights;
- investigate violations;
- comply with regulatory requirements;
- enforce contracts.
27. MARKETING
We may use business contact information to communicate about:
- MOSS products;
- product updates;
- events;
- demonstrations;
- educational content;
- offers.
Recipients may opt out of promotional email communications using the unsubscribe mechanism provided in the message or by contacting us.
Even if you opt out of marketing communications, we may continue sending:
- security notices;
- billing notices;
- service communications;
- account notices;
- other non-promotional communications.
28. HOW AI EMPLOYEES USE INFORMATION
MOSS AI Employees may use relevant authorized information to perform tasks.
Depending on the employee and customer configuration:
Customer Service
May use:
- customer information;
- conversation history;
- business policies;
- services;
- schedules;
- connected-system information;
- knowledge;
- appointment information.
Sales
May use:
- lead information;
- opportunity information;
- estimates;
- service information;
- customer history;
- sales policies;
- relevant financial or payment context;
- knowledge.
Dispatcher
May use:
- job information;
- appointment information;
- technician information;
- availability;
- calendars;
- service areas;
- scheduling policies;
- dispatch procedures.
Relationship
May use:
- customer history;
- completed service information;
- communication preferences;
- review information;
- service-due information;
- account status;
- relationship policies.
MOSS seeks to provide AI Employees with relevant context rather than indiscriminately exposing all available tenant data to every AI Employee.
29. AUTOMATED PROCESSING
Certain MOSS functionality may involve automated processing.
AI Employees may:
- classify requests;
- recommend actions;
- select authorized capabilities;
- generate communications;
- prioritize operational work;
- initiate configured workflows.
Consequential actions remain subject to the technical, business, authority, and approval controls configured within MOSS.
Customers are responsible for determining whether automated use is appropriate for their particular business, industry, and legal obligations.
30. HOW WE DISCLOSE INFORMATION
We may disclose personal information to the following categories of recipients.
31. SERVICE PROVIDERS
We may use service providers supporting:
- cloud infrastructure;
- databases;
- artificial intelligence;
- communications;
- email delivery;
- telephony;
- authentication;
- hosting;
- monitoring;
- security;
- analytics;
- billing;
- customer support.
These providers may process information on our behalf as necessary to provide their services to MOSS.
32. CUSTOMER-AUTHORIZED INTEGRATIONS
When a customer connects a third-party service, MOSS may exchange authorized information with that provider to perform requested functionality.
Examples may include:
- Google;
- Microsoft;
- Jobber;
- Intuit;
- Twilio;
- Resend;
- other supported integration providers.
Information exchanged is limited by:
- provider functionality;
- granted permissions;
- customer configuration;
- MOSS functionality.
33. MOSS CUSTOMERS
Where MOSS processes information on behalf of a business customer, authorized users of that business may have access to information processed in its MOSS tenant.
For example, a business may view:
- conversations;
- customers;
- appointments;
- AI Employee activity;
- jobs;
- escalations;
- operational records.
34. PROFESSIONAL ADVISORS
We may disclose information where reasonably necessary to:
- attorneys;
- accountants;
- auditors;
- insurers;
- financial advisors;
- other professional advisors.
35. LEGAL DISCLOSURES
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with law;
- respond to a subpoena, court order, or lawful request;
- protect the rights or safety of MOSS or others;
- investigate fraud or abuse;
- enforce agreements;
- protect the Services.
36. BUSINESS TRANSACTIONS
If ERGO SYSTEMS LLC is involved in:
- a merger;
- acquisition;
- financing;
- restructuring;
- bankruptcy;
- sale of assets;
- corporate transaction;
information may be disclosed to relevant parties as part of that transaction, subject to appropriate confidentiality and legal protections.
37. SALE OR SHARING OF PERSONAL INFORMATION
MOSS does not sell personal information for monetary consideration.
MOSS also does not use customer operational data for the purpose of selling individual profiles to data brokers.
MOSS does not intend to share Customer Data for cross-context behavioral advertising.
If MOSS's practices materially change in a manner that constitutes a "sale" or "sharing" under applicable privacy law, we will update this Privacy Policy and provide legally required choices before applying the changed practice.
38. TARGETED ADVERTISING
MOSS does not use Customer Data processed through the MOSS application to create advertising profiles for unrelated third-party advertising.
Our public website may use ordinary analytics or similar technologies to understand site usage.
If we later use technologies that constitute targeted advertising, sale, or sharing under applicable law, we will provide legally required notices and opt-out mechanisms.
39. AI TRAINING AND CUSTOMER DATA
MOSS may analyze system performance and interactions to improve the reliability, safety, and functionality of the Services.
MOSS does not sell Customer Data to AI model providers.
MOSS does not authorize third-party AI model providers to use Customer Data submitted through MOSS for their own independent advertising purposes.
Where MOSS uses external AI providers, information is provided for the purpose of delivering authorized MOSS functionality, subject to applicable provider agreements and data-processing controls.
MOSS may use:
- de-identified information;
- aggregated information;
- synthetic information;
- test data;
to evaluate and improve its systems.
40. DE-IDENTIFIED AND AGGREGATED INFORMATION
We may create information that cannot reasonably be used to identify an individual.
We may use and disclose aggregated or de-identified information for lawful purposes, including:
- analytics;
- benchmarking;
- security;
- product development;
- system evaluation;
- performance improvement.
Where required by law, we will maintain de-identified information in de-identified form and will not attempt to re-identify it except as permitted by law.
41. COOKIES AND SIMILAR TECHNOLOGIES
MOSS websites and applications may use:
- cookies;
- local storage;
- session storage;
- similar technologies.
These technologies may be used for:
- authentication;
- security;
- user preferences;
- session management;
- functionality;
- analytics.
You may be able to control cookies through your browser settings.
Disabling necessary cookies may prevent certain Services from functioning correctly.
42. DO NOT TRACK
Some browsers provide "Do Not Track" signals.
There is not currently a universally accepted standard for responding to all browser Do Not Track signals.
Where applicable law requires MOSS to recognize a legally binding universal opt-out mechanism, MOSS will honor such mechanisms to the extent they apply to our processing.
43. DATA RETENTION
We retain personal information for as long as reasonably necessary to:
- provide the Services;
- maintain customer accounts;
- fulfill contractual obligations;
- maintain security;
- resolve disputes;
- comply with law;
- maintain appropriate business records.
Retention periods may vary depending on:
- the type of information;
- customer configuration;
- contractual requirements;
- legal requirements;
- operational need.
When information is no longer required, we may:
- delete it;
- anonymize it;
- de-identify it;
- securely dispose of it.
Customer Data may also be subject to specific retention terms contained in an applicable agreement or Data Processing Addendum.
44. DELETION AND DISCONNECTED INTEGRATIONS
When an integration is disconnected, MOSS may:
- revoke or deactivate credentials;
- discontinue future synchronization;
- unregister integration resources where appropriate;
- stop using the provider for future operations.
Historical MOSS records may be retained when reasonably necessary for:
- audit;
- customer history;
- transaction integrity;
- security;
- legal compliance;
- operational records.
Disconnecting a provider does not necessarily delete all information previously synchronized from that provider.
45. KNOWLEDGE DELETION AND ARCHIVAL
When tenant knowledge is:
- deleted;
- archived;
- replaced;
- made unavailable;
MOSS may prevent that content from being used for future AI retrieval.
Technical copies may temporarily remain in:
- backups;
- logs;
- recovery systems;
until deleted according to normal retention processes.
46. SECURITY
MOSS uses administrative, technical, and organizational measures designed to protect personal information.
Depending on the system and risk, safeguards may include:
- access controls;
- tenant isolation;
- encryption;
- credential protection;
- authentication;
- logging;
- monitoring;
- network protections;
- provider-access controls;
- database-security controls;
- least-privilege access principles.
No online system can guarantee absolute security.
Customers are also responsible for:
- maintaining secure passwords;
- controlling user access;
- protecting connected accounts;
- promptly notifying MOSS of suspected unauthorized activity.
Security concerns may be reported to:
jorge@ergosystems.ai
47. DATA BREACH RESPONSE
If MOSS becomes aware of a security incident involving personal information, we will investigate and take steps reasonably appropriate to:
- contain the incident;
- assess its scope;
- protect affected systems;
- remediate vulnerabilities;
- provide legally required notifications.
Where MOSS processes information on behalf of a business customer, notification responsibilities may also be governed by contractual data-processing terms.
48. INTERNATIONAL DATA PROCESSING
MOSS is operated from the United States.
Personal information may be processed or stored in the United States or other jurisdictions in which MOSS or its service providers operate.
Privacy laws in those jurisdictions may differ from those in the individual's home jurisdiction.
Where legally required, MOSS will use appropriate mechanisms for international transfers of personal information.
49. CHILDREN
MOSS is a business software service and is not directed to children under 13.
We do not knowingly collect personal information directly from children under 13 through the MOSS website or account-registration process.
If we learn that we collected personal information directly from a child under 13 without legally required authorization, we will take appropriate steps to delete it.
If a MOSS customer processes information about minors through its own business operations, that customer is responsible for ensuring it has appropriate authority and complies with applicable law.
50. YOUR PRIVACY RIGHTS
Depending on where you live and the law that applies, you may have rights relating to your personal information.
These may include the right to:
- confirm whether we process your personal information;
- access personal information;
- obtain certain information about our processing;
- correct inaccurate personal information;
- delete personal information;
- obtain a portable copy of certain information;
- opt out of certain sales or sharing;
- opt out of targeted advertising;
- opt out of certain profiling or automated processing;
- limit certain uses of sensitive personal information;
- withdraw consent where processing depends on consent;
- appeal a denied privacy request;
- receive equal service and pricing when exercising privacy rights.
These rights are subject to applicable law, exceptions, and verification requirements.
51. HOW TO EXERCISE PRIVACY RIGHTS
To submit a privacy request, contact:
jorge@ergosystems.ai
or write to:
ERGO SYSTEMS LLC
2125 Biscayne Blvd, STE 204 #20921
Miami, FL 33137
United States
Please indicate that your request concerns privacy rights and provide enough information for us to understand and respond to the request.
We may need to verify your identity before fulfilling a request.
Verification may depend on:
- the nature of the request;
- the sensitivity of the information;
- the information we maintain.
We will not request more information than reasonably necessary to verify a request.
52. INFORMATION PROCESSED FOR A MOSS CUSTOMER
If your information is processed by MOSS on behalf of a business that uses MOSS, the business may be the party responsible for handling your privacy request.
For example, if you:
- scheduled service with a plumbing company;
- emailed a MOSS customer;
- communicated with a MOSS customer;
- received service from a MOSS customer;
and that company uses MOSS, you should generally direct privacy requests concerning that business relationship to the company itself.
MOSS will assist customers with legally required requests where required by contract or law.
53. AUTHORIZED AGENTS
Where applicable law permits an authorized agent to submit a privacy request on your behalf, we may require:
- evidence that the agent is authorized;
- identity verification;
- additional information permitted by law.
54. APPEALS
Where applicable law provides a right to appeal a denied privacy request, you may submit an appeal by emailing:
jorge@ergosystems.ai
Use the subject line:
Privacy Request Appeal
We will review the appeal according to applicable law.
55. NON-DISCRIMINATION
MOSS will not unlawfully discriminate against an individual for exercising applicable privacy rights.
Exercising privacy rights will not result in unlawful:
- denial of Services;
- differential pricing;
- retaliation;
- reduction in service quality.
Differences that are reasonably related to data required to provide a requested Service may apply where permitted by law.
56. CALIFORNIA PRIVACY RIGHTS
California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, where those laws apply.
These rights may include:
- the right to know;
- the right to access;
- the right to correct;
- the right to delete;
- the right to obtain information about categories of personal information collected;
- the right to obtain information about categories of sources;
- the right to obtain information about business purposes;
- the right to obtain information about categories of third parties;
- the right to opt out of sale or sharing;
- the right to limit certain uses of sensitive personal information;
- the right to non-discrimination.
MOSS does not sell personal information for monetary consideration and does not intend to share Customer Data for cross-context behavioral advertising.
57. CALIFORNIA CATEGORIES OF PERSONAL INFORMATION
During the preceding twelve months, depending on use of the Services, MOSS may have collected categories of personal information such as:
- identifiers;
- customer-record information;
- commercial information;
- internet or network activity;
- professional or employment information;
- geolocation information at a general or service-address level where provided;
- communications;
- inferences generated in connection with business workflows;
- sensitive information where a customer provides it and processing is necessary for authorized Services.
MOSS collects these categories from the sources described in this Privacy Policy and uses them for the purposes described in this Privacy Policy.
MOSS may disclose these categories to:
- service providers;
- contractors;
- integration providers;
- customer-authorized recipients;
- professional advisors;
- legal authorities where required.
58. SENSITIVE PERSONAL INFORMATION
MOSS does not seek to collect sensitive personal information unless necessary for legitimate Services or provided by a customer as part of its business operations.
Where sensitive information is processed, MOSS uses it for purposes reasonably necessary and proportionate to providing, securing, administering, or complying with applicable requirements for the Services, unless otherwise disclosed.
59. OTHER U.S. STATE PRIVACY RIGHTS
Residents of states with comprehensive privacy laws may have additional rights under applicable state law.
Depending on jurisdiction and applicability, these may include:
- access;
- correction;
- deletion;
- portability;
- opt-out rights;
- profiling rights;
- appeal rights.
MOSS will process valid requests according to the applicable law.
60. FLORIDA
ERGO SYSTEMS LLC is headquartered in Florida.
Where the Florida Digital Bill of Rights or other Florida privacy laws apply to particular processing, MOSS will comply with applicable requirements.
Nothing in this Privacy Policy is intended to represent that every Florida privacy statute applies to every MOSS activity or customer.
61. THIRD-PARTY WEBSITES AND SERVICES
The Services may contain links to or integrations with third-party services.
This Privacy Policy does not govern the independent privacy practices of third parties.
Customers should review the applicable third party's:
- privacy policy;
- terms;
- permissions;
- security practices.
62. THIRD-PARTY INTEGRATION PERMISSIONS
Connecting an integration does not give MOSS unrestricted access to the provider.
Access depends on:
- the permissions requested;
- the permissions granted;
- provider APIs;
- customer configuration;
- provider restrictions.
Customers can generally disconnect supported integrations through MOSS or the applicable provider.
63. GOOGLE USER DATA
Where MOSS accesses Google user data through authorized Google APIs, MOSS will use that information only to provide or improve user-facing functionality associated with the authorized connection and as otherwise permitted by applicable Google API policies.
MOSS will request only permissions reasonably required for the functionality being provided.
Google account credentials are not disclosed to MOSS merely because a customer authorizes OAuth access.
64. MICROSOFT USER DATA
Where MOSS accesses Microsoft user data through Microsoft Graph or related authorized APIs, MOSS uses that information according to:
- customer authorization;
- granted permissions;
- enabled MOSS functionality;
- applicable Microsoft platform requirements.
Mail and calendar capabilities may have separate permission and readiness requirements.
65. INTUIT / QUICKBOOKS DATA
Where a customer connects QuickBooks Online, MOSS processes authorized QuickBooks information for customer-requested functionality such as:
- customer context;
- estimates;
- invoices;
- payment state;
- service/product context;
- operational workflows.
MOSS does not treat model-generated guesses as canonical accounting data.
66. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
- changes to the Services;
- new integrations;
- changes in law;
- changes in privacy practices;
- operational or security developments.
When we make material changes, we will provide reasonable notice where required by law.
The updated Privacy Policy will identify its effective date.
Continued use of the Services after an updated policy becomes effective is subject to applicable law and contractual requirements.
67. CONTACT US
Questions, concerns, requests, or complaints regarding this Privacy Policy or MOSS privacy practices may be directed to:
ERGO SYSTEMS LLC
2125 Biscayne Blvd, STE 204 #20921
Miami, FL 33137
United States
Email: jorge@ergosystems.ai
68. PRIVACY COMMITMENT
MOSS is designed to help businesses give meaningful operational work to AI Employees while maintaining appropriate controls over business data and connected systems.
Our privacy approach is based on the following principles:
- collect and process information for legitimate purposes;
- give customers control over connected business systems;
- limit access according to tenant and capability;
- avoid unnecessary exposure of credentials and secrets;
- protect tenant boundaries;
- use authoritative systems for authoritative business facts;
- provide appropriate transparency into AI Employee actions;
- respect applicable privacy rights;
- maintain reasonable security safeguards.
ERGO SYSTEMS LLC is committed to evolving these practices as MOSS, privacy law, and AI technology continue to develop.