GenAI Usage Policy
Last updated 2024-10-22
1. Purpose
This policy ensures that Within Intelligence, Inc. (“Within”) usage of GenAI models protects the security and confidentiality of customer data while also delivering stability and scalability.
Within offers GenAI-based features through a number of software vendors (each, a “GenAI Provider”) such as Microsoft and OpenAI.
Regardless of the GenAI Provider, your data will not be used as training data for current or future AI models.
2. Our GenAI Providers
a. Microsoft
Microsoft Corporation (“Microsoft”) is a U.S. technology company that develops and sells a variety of enterprise and consumer technology products. WIthin has conducted a privacy and security assessment of Microsoft to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Microsoft Azure is available here.
b. OpenAI
OpenAI, L.P. (“OpenAI”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of OpenAI to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at OpenAI is available here.
c. Google
Google LLC (“Google”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of Google to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Google is available here.
d. Anthropic
Anthropic PBC (“Anthropic”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of Anthropic to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Anthropic is available here.
3. How Within Uses GenAI Models
Within uses GenAI models to enhance its core NLP platform for automating document workflows. In addition to improving the speed and accuracy of the existing Within features, it powers generation of new AI-powered features within Within such as Chat, Search and many others. GenAI Providers may perform the following activities with respect to data:
- Processing document data to perform extractions
- Matching data between checklist items
- Compute embeddings from document data
- Interact with users in a chat interface
- Other activities in accordance with the agreement between your organization and Within
4. Personal Data Processing
Within sends document data to GenAI Providers for processing. In addition, Within may send other field values from third party systems (such as Salesforce) if your use case requires it. This may include the following categories of personal data:
- First and last name
- Contact information (telephone number & email address)
- Company, position
- Other personal data your organization asks Within to process
All GenAI providers will process personal data in the United States.
All GenAI Providers will process personal data according to the respective data processing agreement (DPA) in place between that company and Within, which fully comply with General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
5. Model Training
No GenAI Provider will use your organization’s data as training data for any GenAI models.
- Microsoft data usage policy can be found here.
- OpenAI data usage policy can be found here.
- Anthropic data usage policy can be found here.
- Google data usage policy can be found here.
6. Data Retention
Any data processed by a GenAI Provider will be deleted.
Within has negotiated and defined zero data retention policies with its GenAI Providers.
- Microsoft data usage policy can be found here.
- OpenAI data usage policy can be found here.
- Anthropic data usage policy can be found here.
- Google data usage policy can be found here.
7. Certifications and Additional Protections
Microsoft Azure is SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and SOC 3 certified, amongst other certifications listed here.
OpenAI is SOC 2 Type 2 certified.
Google is SOC 1 Type 2, SOC 2 Type 2 and SOC 3 certified, amongst other certifications.
Within has non-disclosure and data processing agreements in place with all GenAI Providers.