Security and trust

Security, privacy and direct API pulls

Datplan DataPull is designed for privacy-first API pulling: users authorise supported sources, choose the company or tenant, and pull provider data through the desktop app for local reporting workflows, dashboards and exports.

Where business data is used

Direct API pulls

Users connect authorised source accounts and run pulls from supported APIs. The product is designed around a simple workflow: choose source, choose company or tenant, click sync.

Local reporting workflow

Provider datasets are pulled through the desktop app for local storage, modelling, dashboards, exports, audit output and reconciliation review.

Not cloud-hosted analytics

Datplan is not positioned as a cloud data warehouse or cloud-hosted BI platform for customer provider datasets.

What Datplan online services handle

Datplan online services support the account and access layer needed to run a controlled source-access product. They may process account identifiers, sign-in claims, source access, tenant or account references, billing status, usage checks, run state and support controls.

Important boundary: online services are used to control access, billing status, usage checks and run state. They are not used to host customer dashboards as a cloud analytics service.

OAuth and source authorisation

Supported sources use browser-based provider authorisation where available. Users sign in with the provider, review the provider consent screen, and authorise access according to the provider's own permission model.

Device, backup and export responsibility

Because Datplan DataPull is designed around local reporting workflows, users remain responsible for device access, operating-system security, local backups, exported files, shared dashboards and any BI tools connected to exported outputs.

Protect the device

Use normal device controls such as account passwords, device encryption where available, access control and secure disposal of old devices.

Protect exports

CSV, JSON and BI-ready exports may contain business data. Store and share them according to your organisation's data-handling rules.

Review connected accounts

Review source-provider connections periodically and remove access that is no longer needed.

Support-safe diagnostics

Support should use app-generated diagnostic output where available. Users should avoid sending raw provider data, full local databases, access tokens, secrets, authorisation codes, private local file paths or screenshots containing sensitive client data unless Datplan specifically requests them through an agreed support route.

Third-party source boundaries

Datplan does not own or control third-party source providers. Source access is subject to provider API availability, rate limits, service availability, tenant or account allowances, provider terms and any provider allowance already consumed by other apps, automations or users.

Datplan pulls and presents source-provider data for reporting workflows but does not verify or guarantee the accuracy, completeness, timeliness, legality or suitability of third-party source data.