Confidentiality, NDAs and AI disclosure
Fire Pixel works inside advertising accounts, analytics, call records and CRMs. That access can reveal commercially sensitive and personal data. This page explains the default safeguards and where AI is involved.
This page is a public commitment, not a signed standalone non-disclosure agreement. Our terms include mutual confidentiality. We will also sign a reasonable mutual NDA before account access where a client requires one. The signed proposal, NDA and data processing terms for an engagement take precedence over this summary.
Confidentiality by default
We treat non-public account data, credentials, CRM records, call recordings and transcripts, pricing, customer data, strategies, reports and business plans as confidential.
Access is limited to people and providers who need it for the agreed work. We do not publish a client's name, account screenshots, results or case study without prior written permission. We use account-level access and password managers where the platform supports them rather than asking a client to send passwords in email or chat.
Information may be disclosed where the client authorises it, where a provider needs it to deliver the agreed service under appropriate terms, or where disclosure is required by law. At the end of an engagement, access is removed and client data is returned or deleted according to the contract, applicable retention duties and the client's instructions.
How we use AI
AI is used as an assistant, not as the accountable decision-maker. Typical uses include drafting and checking code, proposing bulk account changes, producing a first-pass analysis, classifying calls or leads against an agreed rubric, and helping draft or illustrate website content.
Material client deliverables and proposed advertising-account changes are reviewed by a person before they are delivered or applied. Advertising account changes are not left to a general-purpose AI agent to approve for itself. Lead or call classification is tested against later CRM outcomes and can be overridden. We document the model, data fields, retention position and human review step for any client workflow that processes personal or confidential data.
We minimise what is sent to an AI provider. Credentials and secrets are not placed in prompts. Client data is not used for an unrelated case study or marketing example. If a project needs an external model to process client data, that use and the relevant provider are agreed as part of the implementation and covered by the appropriate controller, processor and transfer terms.
How data is routed
The route depends on the work and the data involved. The implementation record names the actual systems, region, retention and access controls rather than relying on a general claim that everything is either local or in the cloud.
| Data or work | Default boundary | External processing | Human control |
|---|---|---|---|
| Public research, website code and public page evidence | Local tools or a bounded public scanner where practical | Only where the task requires an external provider | Published or delivered output is reviewed |
| Aggregated advertising and analytics metrics | Client account, client-owned BigQuery project or the agreed reporting system | Project-specific and documented | I approve account decisions |
| CRM rows and customer data | Minimum fields needed for the agreed workflow | Named provider only where agreed | Overrides and reconciliation remain available |
| Call audio and transcripts | Agreed call provider and classification route | Provider, retention and transfer position documented per project | A labelled sample and later CRM outcomes are used for QA |
| Credentials and secrets | Account-level access and password management | Never placed in prompts | Access is revoked when it is no longer needed |
Predictive ecommerce models are treated as a separate documented data use. The training table, target, features, outcome window, validation result, model version and every outbound destination are recorded. Where BigQuery ML is used, training and batch scoring remain in the client-owned BigQuery project. Customer-level scores are not sent to Klaviyo or an advertising platform without the agreed purpose, required consent, platform eligibility and client approval.
Clients can ask for the current provider and subprocessor list, request an alternative route, or decline a proposed external model. If that changes what can be delivered, the effect is agreed before the workflow is built.
AI on this website
The text, code and some abstract illustrations on this website were produced with AI assistance. The current release received automated tests, visual checks, an AI-assisted primary-source fact-check and Ben Luong's editorial review. Fire Pixel remains the publisher and responsible for the version kept live. AI-assisted checking does not make the content infallible, so dated platform claims link to primary sources and corrections are welcome.
Any customer-facing chatbot supplied by Fire Pixel identifies itself as AI at the start of the interaction. A person remains available for handoff. This supports the transparency duty for systems that interact directly with people under Article 50 of the EU AI Act, which applies from 2 August 2026.
Data protection and project documents
Our privacy policy covers this website. For client work involving personal data, roles and instructions are recorded in the proposal or a data processing agreement. The implementation record identifies the systems used, data sent, purpose, retention, access and any international transfer safeguards. A client can request an NDA, data processing agreement or current subprocessor list before sharing account data.
Primary sources
- EU AI Act, Article 50
- European Commission guidance on AI transparency
- Irish Data Protection Commission: transparency
- Irish Data Protection Commission: controller and processor relationships
Questions, corrections or an NDA request: [email protected].
Last updated: 30 August 2026.