Protecting data in AI-enabled services
At Zensai, protecting customer and personal data is a fundamental part of how we develop and operate AI-enabled services.
We design AI capabilities to align with our security, privacy, and compliance commitments, helping customers benefit from AI while maintaining control over their data. AI-enabled services operate within the same data protection framework that governs our products and services.
Privacy by design
Privacy considerations are integrated throughout the design, development, and operation of our AI-enabled services.
Before introducing new AI capabilities, we evaluate privacy requirements, assess potential risks, and implement appropriate safeguards to help ensure responsible handling of data throughout the AI lifecycle.
How AI uses data
AI-enabled features may process customer-provided content to generate outputs such as summaries, recommendations, suggestions, insights, or other AI-assisted functionality.
This processing only occurs for the purpose of providing the requested AI service and supporting the functionality selected by the customer.
We seek to minimize the amount of data processed and use only the information necessary to deliver the intended AI capability.
Customer data isn't used for model training
Zensai uses Microsoft Azure OpenAI Service to support certain AI-enabled capabilities.
Customer data, prompts, source content, and AI-generated outputs aren't used by Zensai to train AI models. Microsoft doesn't use customer content processed through Azure OpenAI Service to improve or train foundation models provided through the service.
Data storage and processing
Data processed by AI-enabled services is hosted and processed within Microsoft's enterprise cloud infrastructure.
The processing location depends on the region selected for the customer's environment and service deployment - the specific location of these data centers is determined by the region chosen during the installation process.
To read more about Zensai data storage, see this article.
Zensai applies the same security and operational controls that govern the rest of our cloud services.
Where is AI data processed?
The data processing centers for AI aren't the same as the Zensai (Learn365, Perform365, and Engage365) regional data centers, even though both are housed within Microsoft Azure. User prompts are processed in specific regions, according to the mapping in the following table.
| Zensai region in Azure | Corresponding AI region in Azure |
| North Europe | West Europe |
| UK South | UK South |
| German West Central | German West Central |
| Switzerland North | Switzerland North |
|
Central US US Gov Virginia |
East US |
| Australia East | Australia East |
| Japan East | Japan East |
| Canada Central | Canada East |
Personal data protection
Where AI-enabled services process personal data, we apply appropriate technical and organizational measures to help protect confidentiality, integrity, and availability.
These measures may include:
- Access controls and authentication
- Encryption in transit and at rest
- Security monitoring and logging
- Data minimization practices
- Secure development and operational processes.
Our privacy program supports compliance with applicable data protection obligations and recognized privacy management practices.
Human control and transparency
Our AI capabilities are designed to support people, not replace them.
Users remain responsible for reviewing AI-generated outputs and determining how they're. We strive to provide transparency about when AI is used, how data is processed, and what controls are available to customers.
Customer choice and control
Customers remain in control of how AI-enabled capabilities are used within their environment.
Depending on the product and feature, admins may choose whether AI functionality is enabled and may control how users access AI-powered capabilities. AI-generated suggestions and outputs typically require user review before being applied.
Individual rights
We're committed to respecting applicable privacy and data protection rights.
Requests relating to personal data, including access, correction, deletion, or other applicable rights, are managed through our established privacy processes and in accordance with applicable legislation.
For additional information, please refer to our Privacy Policy and Data Processing Agreement on the Zensai website.
Additional information
For more information about AI technologies, governance, security, and responsible AI practices, see the following articles:
- Responsible AI principles
- AI governance and oversight
- AI security
- AI technology and architecture
- AI data usage and model training
- Frequently asked questions