F&M Engineering Services
Effective: [TBD — date not confirmed]

Privacy Policy

F&M Engineering Services — Gmail Automation

1. Overview

This Privacy Policy describes how F&M Engineering Services ("we", "us", "our") handles information when you use our Gmail automation service, accessed through our self-hosted n8n workflow platform at n8n.fmes.online (or the equivalent internal address).

This policy applies specifically to the Gmail automation feature. Our engineering calculators (timber and wind) run entirely in your browser and do not collect or transmit your data — see the homepage for details.

By connecting your Google account to our automation service, you acknowledge and agree to the practices described in this policy.

2. Information We Collect

2.1 Information You Provide

When you connect your Google account, you grant our application access to your Gmail data through Google's OAuth 2.0 system. The specific access scopes are determined by the Google OAuth consent screen and may include:

Gap: The exact OAuth scopes currently granted are not confirmed in this draft — verify against the active Google OAuth client configuration before publishing.

2.2 Information We Process Automatically

When you configure and run workflows, our system may process the following types of data from your Google account:

2.3 Information We Do Not Collect

3. How We Use Your Information

We use the information accessed through your Google account solely for the purposes you configure in your workflows, including:

We do not use your email content, attachments, or personal data for any purpose unrelated to the workflows you create and run.

4. Google API and Third-Party Access

4.1 Google API Limited Use

Our application uses Google APIs (Gmail, and potentially Calendar) pursuant to Google's API Terms of Service and the Google API User Data Policy. We commit to the Limited Use requirements, which prohibit using Google Workspace API data for:

4.2 Third-Party Services

Our n8n automation platform may connect to third-party services as part of your workflows. When you configure a workflow that sends data to a third-party service, that data is processed by the third party according to their own privacy policies. We are not responsible for third-party data handling.

Gap: The full list of third-party services your workflows connect to is not enumerated in this draft — update this section to list each integrated service before publishing.

5. AI and External Processing

Gap: This section requires confirmation. If any workflow step sends email content or personal data to an external AI provider (e.g., for summarization, classification, or generation), that must be disclosed here with the provider name, data types sent, and purpose. If no AI processing is used, state that explicitly.

As of this draft, we have not confirmed whether external AI providers are used. Do not publish this policy until this is verified.

6. Data Retention and Security

6.1 Retention

Data accessed through your Google account is retained only as long as needed to operate your workflows and for the period you configure in your workflow settings. Execution logs may be retained for troubleshooting purposes.

Gap: Specific retention periods for tokens, email data, execution logs, and backups are not yet defined — set explicit retention periods before publishing.

6.2 Security

Our n8n instance runs on a self-hosted server with the following measures:

Gap: The full security measures are not verified — confirm TLS configuration, access controls, backup encryption, and network isolation before claiming specific safeguards.

6.3 Token and Credential Handling

Google OAuth access tokens and refresh tokens are stored encrypted in our n8n instance. Tokens are used only to access your Google data on your behalf and are not shared with any other party.

6.4 Data Deletion

You may disconnect your Google account at any time from the n8n credential management screen. Disconnecting revokes our access to your Google data. Workflow execution logs stored on our server may persist until manually deleted or until retention policies are applied.

Gap: The procedure and timeframe for requesting deletion of stored logs and data is not defined — establish a deletion request process and response timeframe before publishing.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise these rights, contact us at the email address in Section 9. We will respond within a reasonable timeframe.

Gap: Formal data subject request procedure and statutory response timeframe are not defined — align with applicable privacy laws (e.g., Australian Privacy Act, GDPR if applicable) before publishing.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the policy page. The "Effective" date at the top of this document will be updated when changes are made.

9. Contact Us

F&M Engineering Services
Email: fmecc02@gmail.com
For privacy-related questions, concerns, or data requests.
⚠️ Gap Notes — Do Not Publish Until Resolved:
  • Legal operator name: The legal entity name behind "F&M Engineering Services" is not confirmed. The policy currently uses the trading name only.
  • Business address: A physical or mailing address is not provided. Privacy laws in some jurisdictions require this.
  • Effective date: Not confirmed. Replace [TBD] with the actual date before publishing.
  • OAuth scopes: The exact Google API scopes in use must be verified against the active OAuth client configuration.
  • Workflow data handling: Confirm which workflows read email content, access attachments, apply labels, send mail, or delete mail — and reflect that accurately.
  • Third-party services: Enumerate all external services integrated by your workflows.
  • AI processing: Confirm whether any external AI provider is used and, if so, disclose it. If not, state that explicitly.
  • Retention periods: Define explicit retention periods for tokens, email data, execution logs, and backups.
  • Data deletion procedure: Define the process and response timeframe for deletion requests.
  • Security measures: Verify TLS, access controls, backup encryption, and network isolation before claiming specific safeguards.
  • Applicable law: Determine which privacy law applies (e.g., Australian Privacy Act 1988, GDPR) and ensure the policy complies.