Will institutional data be processed through a third party or subprocessor that also uses AI?
Explanation
Example Responses
Example Response 1
Yes, institutional data will be processed through two third-party services that utilize AI Our customer support platform, Zendesk, uses AI for ticket routing and sentiment analysis on support communications Additionally, our cloud storage provider, Box, uses AI for content classification and search functionality For both services, we have Data Processing Agreements (DPAs) in place that restrict AI usage to specific operational purposes and prohibit using institutional data for training their general AI models We conduct annual reviews of these vendors' AI practices and have implemented data minimization techniques to limit exposure of sensitive information to these systems.
Example Response 2
No, we do not currently utilize any third parties or subprocessors that employ AI technologies to process institutional data Our primary data processors are AWS for infrastructure hosting and Salesforce for CRM functionality, and we have confirmed with both vendors that the specific services we use do not employ AI processing on our institutional data Our contracts with these vendors explicitly prohibit the use of our data for AI training or other purposes beyond direct service provision We review this stance annually as part of our vendor management program to ensure continued compliance.
Example Response 3
We are currently unable to provide complete assurance that institutional data will not be processed by AI systems at third parties While our primary application is hosted on Microsoft Azure, which does offer AI capabilities, we have not implemented technical controls to prevent Azure's AI systems from potentially accessing our data Additionally, our analytics provider, Google Analytics, has recently introduced AI features that may analyze institutional data for insights We are in the process of conducting a review of all our vendors to identify AI usage and implement appropriate contractual safeguards, but this work is not yet complete We expect to have full visibility and appropriate controls in place within the next 6 months.
Context
- Tab
- Privacy
- Category
- Privacy and AI

