GenAI Usage Policy

Last updated 2024-10-22

1. Purpose

This policy ensures that Within Intelligence, Inc. (“Within”) usage of GenAI models protects the security and confidentiality of customer data while also delivering stability and scalability.

Within offers GenAI-based features through a number of software vendors (each, a “GenAI Provider”) such as Microsoft and OpenAI.

Regardless of the GenAI Provider, your data will not be used as training data for current or future AI models.

2. Our GenAI Providers

a. Microsoft

Microsoft Corporation (“Microsoft”) is a U.S. technology company that develops and sells a variety of enterprise and consumer technology products. WIthin has conducted a privacy and security assessment of Microsoft to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Microsoft Azure is available here.

b. OpenAI

OpenAI, L.P. (“OpenAI”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of OpenAI to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at OpenAI is available here.

c. Google

Google LLC (“Google”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of Google to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Google is available here.

d. Anthropic

Anthropic PBC (“Anthropic”) is a U.S. company that conducts research and deployment of artificial intelligence models. Within has conducted a privacy and security assessment of Anthropic to verify its policies and procedures are appropriate for access to customer data. More information about security and privacy at Anthropic is available here.

3. How Within Uses GenAI Models

Within uses GenAI models to enhance its core NLP platform for automating document workflows. In addition to improving the speed and accuracy of the existing Within features, it powers generation of new AI-powered features within Within such as Chat, Search and many others. GenAI Providers may perform the following activities with respect to data:

  • Processing document data to perform extractions
  • Matching data between checklist items
  • Compute embeddings from document data
  • Interact with users in a chat interface
  • Other activities in accordance with the agreement between your organization and Within

4. Personal Data Processing

Within sends document data to GenAI Providers for processing. In addition, Within may send other field values from third party systems (such as Salesforce) if your use case requires it. This may include the following categories of personal data:

  • First and last name
  • Contact information (telephone number & email address)
  • Company, position
  • Other personal data your organization asks Within to process

All GenAI providers will process personal data in the United States.

All GenAI Providers will process personal data according to the respective data processing agreement (DPA) in place between that company and Within, which fully comply with General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

5. Model Training

No GenAI Provider will use your organization’s data as training data for any GenAI models.

  • Microsoft data usage policy can be found here.
  • OpenAI data usage policy can be found here.
  • Anthropic data usage policy can be found here.
  • Google data usage policy can be found here.

6. Data Retention

Any data processed by a GenAI Provider will be deleted.

Within has negotiated and defined zero data retention policies with its GenAI Providers.

  • Microsoft data usage policy can be found here.
  • OpenAI data usage policy can be found here.
  • Anthropic data usage policy can be found here.
  • Google data usage policy can be found here.

7. Certifications and Additional Protections

Microsoft Azure is SOC 1 Type 2, SOC 2 Type 2, ISO 27001 and SOC 3 certified, amongst other certifications listed here.

OpenAI is SOC 2 Type 2 certified.

Google is SOC 1 Type 2, SOC 2 Type 2 and SOC 3 certified, amongst other certifications.

Within has non-disclosure and data processing agreements in place with all GenAI Providers.