Privacy and security
How the private workspace handles information
Last updated: 19 August 2026. No Fries is operated from Auckland, New Zealand. This page covers the public managed IT website and assistant, verified service-scope access, and the private scoping, operator and service-desk workspaces.
Website assistant and prospect discovery
When you choose to message the No Fries website assistant, No Fries processes the conversation, a signed browser-session identifier, limited request and security metadata, and the business or contact details you provide. The signed browser cookie lasts for up to 30 days so the conversation can continue on the same browser. The assistant progressively stores structured facts, their source and known or unknown status, a rolling summary, suggested next action, and technical run metadata such as latency, model, token count and approximate cost. Simply loading the website does not create a prospect record; a record is created when a message is submitted.
The default structured preview uses deterministic application logic and is labelled as a preview. If the live model runtime is enabled, selected conversation context and the current message are sent from the No Fries backend to the OpenAI API to produce structured tool calls and a response. Model requests are configured not to store response objects in OpenAI. The OpenAI credential remains on the backend. Do not enter passwords, access tokens, recovery codes, payment data or raw security configuration; the application rejects common secret patterns before creating the conversation.
Email verification for the service scope
When you request the detailed managed IT scope, No Fries processes the email address you provide, a short-lived verification challenge, limited delivery and security metadata, and the time verification succeeds. The code and confirmation link expire after 15 minutes and can be used once. Verified browser access expires after 24 hours. The email is used to deliver and secure the requested scope and to record genuine interest; it does not by itself subscribe you to a marketing list.
Service-scope storage and providers
Verification challenges are stored in the application’s private Microsoft Azure storage, expire after 15 minutes and are deleted after successful use. Uncompleted challenge records follow the application storage-retention process. Only after successful confirmation, the verified email address and confirmation time are retained as an interest record. Resend is the intended transactional email provider for the verification message. Access cookies are signed, marked HttpOnly and Secure, and are not available to website JavaScript.
Website visitor tracking
The public managed IT overview does not load a third-party visitor-tracking script. Standard hosting and security logs may process limited request metadata such as IP address, time, requested path, browser type and response status to operate and protect the service. The website assistant creates its signed session only when the assistant is opened or messaged, as described above.
Information processed
Approved users may enter customer profiles, discovery answers, notes, evidence references, internal qualification, service recommendations, proposal drafts, and CRM handoff metadata. When an operator confirms a lifecycle-to-scoping handoff, known prospect facts may pre-populate equivalent scoped answers or appear as context notes; unknown answers remain visibly unknown. Microsoft identity details are used to determine tenant and role access. Limited audit records identify who performed material actions and when.
Storage and location
Production workspace data is stored in a private Microsoft Azure storage account configured for the application. The current operator-selected region is Australia East. Data is encrypted in transit using HTTPS and encrypted at rest by Azure Storage. Static application files do not contain a tenant service catalogue or customer records.
Tenant isolation and access
Microsoft sign-in is necessary but not sufficient. Backend checks restrict each request to an approved tenant and role. Tenant storage keys are derived server-side; browser requests cannot select a different tenant. Catalogue, customer, assessment, proposal, export, audit, and CRM routes require explicit capabilities.
Service catalogue and proprietary material
Uploaded service definitions and matching signals remain in authenticated tenant storage. They are not published in the public website or static JavaScript bundle. Authorised users can still see information required to perform their role, so contractual and organisational controls remain important.
CRM handoff
No Fries does not continuously read a CRM. The pilot integration is a user-initiated, one-way handoff of an approved proposal to a tenant-controlled endpoint. Endpoint details and credentials stay server-side. Production writes are disabled unless the operator explicitly enables them.
Retention, export, and deletion
The current default lifecycle policy makes raw prospect conversation messages eligible for removal after 90 days, abandoned unlinked prospect records eligible after 180 days, and detailed AI observability events eligible after 365 days. An authenticated administrator must preview the eligible records and explicitly run the retention job. Linked scoping or customer records and conversations awaiting human contact are excluded from automatic selection. The structured lifecycle summary may remain after raw messages are removed where the prospect is still linked or active.
Authenticated operators can export an individual lifecycle record and its related conversation, audit, AI activity, and correction data as JSON. Administrators can delete an unlinked lifecycle prospect after typing its exact name, or delete a sales-workspace customer and associated assessments, proposals, and recorded handoffs. A linked lifecycle record cannot be deleted until its scoping customer is deleted or unlinked. Minimal audit metadata may record that retention or deletion occurred without retaining the deleted content. Platform backups or recoverable storage versions may remain for the operator’s configured infrastructure-retention period. Proposal exports are available only to authenticated users with export permission.
Do not upload
Do not enter passwords, API keys, private keys, authentication tokens, credentials, raw security configurations, or other secrets. During an evaluation, use fictional or specifically approved customer information and only service material approved for the external pilot environment.
Subprocessors and service providers
Microsoft Azure and Microsoft Entra ID provide hosting, storage, and workspace authentication. Resend may provide transactional scope-verification email. OpenAI processes assistant requests only when the live model runtime is enabled; the labelled deterministic preview does not call OpenAI. A tenant-approved Microsoft Power Automate or Logic Apps flow may be used for CRM handoff once configured. No public subscription billing is active.
Incidents and requests
For an access, correction, export, deletion, privacy, or security request, email hello@nofries.nz. Do not include secrets in the email.