← Back

EC API Integrations Policy

02_legal_root/ec_api_integrations_policy.md

Employee Center API and Integrations Policy

No Raw Database Data Claim

For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.

This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.

Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policy URL: /legal/api-integrations-policy


1. Purpose

This API and Integrations Policy explains how Employee Center (“EC”) APIs, webhooks, service accounts, connected systems, imports, exports, automations, and third-party integrations may be used.

EC is a private operational platform owned by Quintin N. Mahan. EC may connect to internal systems, external systems, customer systems, vendor systems, network devices, phone systems, email systems, SMS/modem systems, and other approved integrations.

This policy is intended to protect EC, EC credentials, EC API endpoints, EC service accounts, EC integration data, EC logs, EC automation records, EC evidence-preservation records, EC legal records, and the EC Protected Materials.


2. Scope

This policy applies to:

This policy applies whether an integration is used by a user, administrator, service account, script, webhook, scheduled task, device, router, phone system, modem, automation engine, or third-party system.


3. Relationship to Other Policies

This policy works together with:

If this API and Integrations Policy conflicts with the Employee Center Terms and Conditions, the Terms and Conditions control unless Quintin N. Mahan signs a separate written agreement stating otherwise.

Nothing in this policy transfers ownership of EC, EC APIs, EC integrations, EC credentials, EC source code, EC integration records, EC logs, EC backups, or the EC Protected Materials.


4. Approved Integrations

EC may connect to approved systems, including:

Approval may be limited by purpose, credential, scope, endpoint, role, network, device, company, or time period.


5. Authorized API and Integration Use

APIs and integrations may be used only for authorized EC-related purposes.

Authorized purposes may include:


6. Prohibited API and Integration Use

Users, companies, service accounts, scripts, or third parties may not use APIs or integrations to:

Unauthorized access or use is prohibited.


7. Credentials, Keys, Tokens, and Secrets

API keys, OAuth tokens, webhook secrets, service-account credentials, database credentials, email credentials, device credentials, and other integration secrets are confidential EC-controlled materials.

Users and companies may not:

Credentials may be rotated, revoked, replaced, or disabled by Quintin N. Mahan for security, enforcement, preservation, or operational reasons.


8. Service Accounts

Service accounts may be used for EC-approved integrations, automations, background jobs, and system-to-system access.

Service accounts are not personal accounts.

Service accounts may be limited by:

Users may not use service accounts for personal access or to bypass user permissions.


9. Webhooks

EC may receive, process, store, verify, retry, and log webhook events.

Webhook records may include:

Users and systems may not send forged, misleading, replayed, malicious, excessive, or unauthorized webhook events.


10. Imports and Exports

EC may import and export data for authorized EC-related purposes.

Imports may include records from approved systems.

Exports may include authorized records, reports, backups, evidence packages, legal artifacts, or migration files.

Users may not use imports or exports to:


11. Logging and Audit

EC may log API and integration activity.

Logs may include:

Logs may be retained for security, troubleshooting, reporting, evidence, legal defense, evidence preservation and authorized transition support, and enforcement.


12. Rate Limits and Abuse Protection

EC may apply rate limits, throttling, quotas, request-size limits, timeout limits, retry limits, or other abuse protections.

EC may block, delay, reject, disable, or restrict API or integration activity that appears abusive, excessive, unauthorized, suspicious, broken, misconfigured, or harmful.


13. Third-Party System Terms

Third-party systems may have their own terms, policies, security controls, rate limits, data practices, audit logs, and restrictions.

Users and companies are responsible for complying with applicable third-party terms when using connected systems.

EC’s use of third-party systems does not transfer ownership of EC, EC integrations, EC-created records, EC-maintained records, EC-derived records, EC logs, EC certificates, EC backups, or the EC Protected Materials.


14. Zoho Email Integration

EC may use a Zoho email integration to send legal, acceptance, certificate, operational, support, or system notices.

For EC legal acceptance notices and certificate emails, the required envelope is:

FROM: support@crsabq.com
TO: mahanquintin@gmail.com

Acceptance and certificate emails are evidence notices to Quintin N. Mahan only unless Quintin N. Mahan configures otherwise.

Users do not receive acceptance/certificate emails by default.


15. Google and Voice Integrations

EC may connect to Google Workspace, Google Voice, Gmail, calendar systems, or related services for authorized EC-related purposes.

Such integrations may support:

Records imported from or linked with Google systems may become part of EC records and the EC Protected Materials to the maximum extent stated in the Terms.


16. Network and Device Integrations

EC may connect to network, router, firewall, UniFi, GL.iNet, Tailscale, phone, modem, caller ID, SMS, Raspberry Pi, or device-related systems.

Such integrations may support:

Users may not interfere with, spoof, disable, corrupt, overload, or misuse these integrations.


17. Automation Systems

EC may connect to automation systems, including approved scripts, scheduled jobs, Tasker, Shortcuts, SMS command systems, background workers, and webhook automations.

Automations may be logged and attributed to a user, service account, device, or system.

Users may not use automations to bypass approval, impersonate another user, create false records, delete records, export data without authorization, or interfere with EC operation.


18. Security Incidents

If an API, token, webhook, integration, or service account is suspected of misuse, compromise, leak, excessive activity, or unauthorized access, EC may:


19. Changes to Integrations

Quintin N. Mahan may add, remove, modify, restrict, disable, replace, or suspend EC APIs and integrations.

No user or company is entitled to continued access to any specific API, integration, webhook, export, service account, or automation unless a separate written agreement signed by Quintin N. Mahan states otherwise.


20. Changes to This Policy

Quintin N. Mahan may update this API and Integrations Policy by publishing a new active version in EC.

The current active version will be displayed through the Legal hub.

Older versions may remain stored in Postgres for audit, evidence, and historical review.


21. Contact / Owner

Employee Center is owned by Quintin N. Mahan.

Legal and policy documents are available from:

/legal

The current Terms and Conditions are available from:

/legal/terms-and-conditions

End of API and Integrations Policy.