Security and GDPR
Safe AI use
Data Processing Agreement
The Data Processing Agreement (DPA) is established to comply with the requirements of the GDPR and other relevant privacy legislation for business services.
Sub-processors
The processing agreement governs the list of sub-processors that fall under the data processing of AI-Public. Other vendors or internal administrative systems are not included here, as they fall outside the scope of processing in AI-Public.
Privacy at BFL and Stability AI
Black Forest Labs (BFL/FLUX) and Stability AI are image providers, but not subprocessors of AI-Public. They do not receive personal data from AI-Public. This is technically enforced in the backend.
Setting Permissions
AI-Public security works based on roles with permissions.
View History
AI-Public offers the possibility to set per role whether the chat history of users or employees is visible. This can be configured in the admin section under Permissions.
Retention Periods
AI-Public offers the ability to set retention periods per collection. A collection is a set of similar data. For example, there is a "Organizations" collection and a "Chats" collection.
Leaving the App
When a person temporarily leaves the app, it is advisable to set the account to inactive.
Database Structure
Each customer receives a separate database within AI-Public in Google Cloud. Custom security rules can be set on this database, and the administrator can set read and write permissions per role.
Server Security
Personal data used within the application are stored on servers within the European Economic Area.