Security and GDPR
Safe AI use
Data Processing Agreement
The Data Processing Agreement (DPA) is designed to comply with the requirements of the GDPR and other relevant privacy legislation for business services.
Sub-processors
The data processing agreement governs the list of sub-processors that fall within the data processing of AI-Corporate. Other vendors or internal administrative systems are not included here, as they fall outside the scope of processing in AI-Corporate.
Privacy with BFL and Stability AI
Black Forest Labs (BFL/FLUX) and Stability AI are image providers, but not subprocessors of AI-Corporate. They do not receive personal data from AI-Corporate. This is technically enforced in the backend.
Setting Permissions
AI-Corporate security works based on roles with permissions.
View History
AI-Corporate offers the ability to set per role whether the chat history of users or employees is visible. This can be configured in the admin section under Permissions.
Retention Periods
AI-Corporate offers the possibility to set retention periods per collection. A collection is a set of similar data. For example, there is a collection of "Organizations" and a collection of "Chats".
Leaving the App
When a person temporarily leaves the app, it is advisable to set the account to inactive.
Database Structure
Each customer receives a separate database in Google Cloud within AI-Corporate. Security rules can be set up on this database, and the administrator can set read and write permissions for each role.
Server Security
Personal data used within the application is stored on servers within the European Economic Area.