Overview
This Policy describes how TLJ Tech Systems and Development, LLC handles information in connection with the Cockpit AI application. The Application is installed in your Bitrix24 account and is made up of drivers, which are enabled per account: Atlas (results dashboard, targets and ranking), Pulso (pipeline analysis and forecast), Zelo (record quality and CRM structure creation), Lumi (follow-up priorities and reports through chat), Mira (satisfaction surveys) and Mike (marketing lead reading). Each driver only processes data when it is enabled and in use in your account.
You — the owner of the Bitrix24 account — are the controller of the CRM data. TLJ Apps acts as a processor: it handles that data on your behalf, following the configuration you set in the Application.
Data the Application Processes
| Data | Purpose | Retention |
|---|---|---|
| Deals, leads, contacts, companies, activities, tasks and stage history from your Bitrix24 | Build dashboards, ranking, targets, forecast, priorities and the drivers' reports | Read on demand. Computed results are cached for minutes or hours; daily reports for a few days |
| Account users: identifier, name, department, time zone and whether they are an administrator | Identify who is using the Application, apply permissions and attribute results to the right person | The user link and their role in the Application are kept for as long as the Application is installed |
| Duplicate index (Zelo driver): normalized phone, e-mail and name of contacts and companies, with the record identifier | Find duplicate records and repeated data without re-reading the whole CRM on every query | For as long as the driver is in use; rebuilt on each scan and deleted together with the organization |
| Satisfaction surveys (Mira driver): campaigns, sends and answers — score, comment and the respondent identification you associated | Run the survey, compute the index and show results | For as long as the campaign exists; deleted when you delete the campaign or request deletion |
| Open Channel conversations and calls logged in Bitrix24 | Count conversations, response time and unanswered conversations | Only the aggregated numbers from the last scan are kept. Conversation text is not stored |
| Messages you exchange with the drivers through the Bitrix24 chat or the Application screen | Answer the question and keep the thread of the conversation | Short memory, about 30 minutes. Support and feature requests are recorded so we can act on them |
| Record of what was delivered and changed: priorities sent to each person, merged records, created structures | Measure whether priorities were acted on and allow changes to be reviewed or undone | 45 to 90 days, depending on the type of record |
| Bitrix24 access and refresh tokens | Read and write in your account, including in scheduled routines | For as long as the Application is installed |
| Settings, targets, driver licenses and each user's screen preferences | Make the Application work the way you configured it | For as long as the Application is installed |
Artificial Intelligence
Several features of the Application use language models run on Cloudflare's infrastructure (Workers AI): dashboard summaries and readings, the drivers' chat answers, the drafting of CRM structure plans and lead rating. To produce an answer, the Application sends the model the slice of data needed for that question — for example, deal titles and values, owner names, stages and counts.
- According to Cloudflare's documentation, content sent to Workers AI is not used to train models or to improve Cloudflare or third-party services.
- We do not use your data to train models of our own.
- Artificial intelligence answers are suggestions produced by a statistical model, which can be wrong. Check figures and conclusions before making relevant decisions.
- Actions that change your CRM as a result of a conversation with a driver ask for confirmation before they run.
What the Application Writes to Your Bitrix24
Cockpit AI is not read-only. Depending on the drivers enabled and the configuration you make, it can:
- Send messages through the Bitrix24 chat, via the drivers' bots, to the people you designate.
- Merge duplicate records, fix phones and e-mails and delete custom fields, when an authorized user triggers those actions or sets them to run automatically.
- Create pipelines, smart processes, stages and fields, after a user reviews and confirms the plan.
- Reassign deals, complete tasks and write comments or fields on cards, when requested.
- Send satisfaction surveys to your customers through the channels you configure.
What We Do Not Do
- We do not sell, rent or transfer data to third parties.
- We do not use your data or your customers' data for our own advertising or for other customers.
- We do not keep a copy of your CRM. What we store is listed in the table above.
- We do not mix data from different accounts: each installation has its data separated by organization.
- We do not use tracking cookies or third-party pixels in the Application screens.
Where Data Lives
The Application runs on Cloudflare's network (Cloudflare Workers), which also holds tokens, cache and short-lived records. Settings, the duplicate index and survey data live in a PostgreSQL database managed by Supabase. Traffic is always encrypted in transit (HTTPS/TLS).
Third-Party Services
- Bitrix24: source of the data and destination of the changes made by the Application.
- Cloudflare: hosting, short-lived storage and artificial intelligence inference (Workers AI).
- Supabase: database for settings, the duplicate index and surveys.
Your Rights
Because CRM data lives in your Bitrix24, data subject requests for access, correction or deletion are fulfilled by you, directly in the CRM. For what is under our custody — tokens, settings, the duplicate index and survey data — you may request access or deletion at any time at contato@tlj.net.br. The Brazilian LGPD (Law 13.709/2018) and, where applicable, the GDPR apply.
Data Deletion
Uninstalling the Application from your Bitrix24 account invalidates the tokens and stops the scheduled routines. To also erase the settings, the duplicate index and the survey data we hold, write to our contact — we respond within 30 days. The changes the Application made to your CRM remain in your account, under your control.
Security
All calls use HTTPS. Every request made from the Application screen is checked against your Bitrix24 account before any response, and events received from Bitrix24 are validated before being processed. What each person sees respects their role in the Application, and actions that change the CRM triggered from the screen use the permission of the very user who triggered them; the scheduled routines you turn on use the Application's access. Tokens are kept in restricted storage, reachable only by the Application.
Changes to This Policy
We may update this Policy to reflect changes in the Application or in applicable law. The update date at the top of this page indicates the current version.
Contact
Privacy questions: contato@tlj.net.br — TLJ Tech Systems and Development, LLC.
