Data Governance

Where your data lives, and who can touch it.

A plain-English account of how David handles your data: what an AI model sees, what never leaves your control, whether any of it trains a model, and how to keep it all inside the UK or EU.

The big 3 questions

Is our data used to train AI models?

No

David only works with AI companies whose contracts forbid training on your data. Any provider that won't commit to that, or that sits in a jurisdiction with weak data-protection law, is not offered.

Can anyone outside our control access it?

No

Every customer runs on its own separate, walled-off setup, so your data is never mixed with anyone else's, and your files are encrypted. Passwords and keys are never shown to the AI. To do a task, the AI is given the request plus the information it needs, sent only for as long as the task takes, to a company barred from training on it.

What settings apply across every platform?

One baseline

The same floor across every connected model: no training on your data, a signed Data Processing Agreement, and the option to keep processing inside the UK or EU.

Where your data is processed

Choose where your data is processed

The point where your data reaches an AI can be locked to a region: your administrator chooses UK, EU, or US in David's settings and can change it at any time. Whichever you choose, your administrators decide which models users may run, and a supporting vendor can be excluded on request.

Recommended where US processing is acceptable

United States

Storage and processing run in the US, where every model we offer is available.

The widest model choice. Every provider we engage by default is vetted against the same floor: no training on your data and data-processing terms in place, with zero data retention by default on several providers and available on request for the rest (see the table below). Choose this where your data-processing requirements allow US processing.

United Kingdom

Hosting and AI model requests stay in London. Supporting features that process elsewhere are listed on the sub-processor page.

For organisations whose obligations require UK-only processing. A focused set of models (the ones available in the UK): strong coverage across the main types, though not every model.

European Union

Processing stays within the EU (Ireland, Germany, France and other EU countries), never sent outside it.

The full, latest set of models, kept within the EU. Broader choice than UK-only.

The detail

Every provider, assessed

David isn't tied to a single AI company; it runs the best model for each job. Each provider is assessed on the questions a data-protection review actually asks. "Retention" is how long the provider itself keeps a request after answering it: "zero retention by default" means nothing is kept once the response is returned; "deleted within 30 days" means the provider holds it for abuse monitoring and then deletes it, with a zero-retention arrangement available on request. Which providers are engaged follows the models your administrators enable.

ProviderTrains on dataRetentionDPA / GDPRUK / EU residency
Amazon Web Services (AWS Bedrock)Claude + open models, via AWSNoZero retention by defaultSingle AWS DPAUK or EULondon for UK-only, or kept within the EU.
Google (Vertex AI)GeminiNoNot stored; 24-hour in-memory cache, abuse logging can be switched offYes (Cloud DPA)EU, UK for some modelsKept within the EU, and in the UK (London) for some Gemini models.
Anthropicfirst-party APINoDeleted within 30 days; zero retention by agreementYesNo direct UK/EUUS-based; for UK/EU we run Claude through AWS Bedrock (above).
OpenAIbusiness / API tierNoDeleted within 30 days; zero retention on approvalYesEU availableEU storage and processing available on the EU option.
Groqfast inferenceNoNot retained by default; zero-retention setting availableYesUS onlyUS-based; no UK/EU option today.
Fireworks AIopen-weight modelsNoZero retention by defaultYes (DPA, SOC 2)US onlyUS-based; no standard UK/EU option.
Meta PlatformsNot in standard configurationMuse SparkNo (standard tier)Nothing stored at our request; zero retention on request to MetaDeveloper terms; DPA under reviewUS onlyUS-based; no region controls published.
xAINot in standard configurationGrokNo (API)30-day abuse audit; zero retention by agreementYes (published DPA, SCCs)US defaultEU endpoint by agreement.
Self-hosted (Ollama)open models on our infraNoNever leaves the hostN/A, no third partyYour regionRuns entirely in-tenant, on our own infrastructure.

The data boundary

What reaches an AI model, and what never does

Everything is stored in infrastructure isolated to your organisation, in your chosen region. This is what is, and isn't, sent to an AI model to do the work.

Never sent to a model

  • Your passwords and integration keys
  • Used only behind the scenes to connect David to your tools

When David uses one of your connected tools, the sign-in happens behind the scenes. The AI is never shown those keys.

Sent to the model, as needed

  • The task being worked on
  • Relevant conversation history and organisational knowledge
  • The content of documents you ask David to work with
  • Results from the tools David runs

Sent securely, only for as long as the task takes, to a company barred from training on it, and (if you choose) kept inside your country or region. Only what the task needs is sent, never your whole data set.

See the Security page for infrastructure and compliance detail, or the Privacy Policy. Our Data Processing Agreement and sub-processor list are published, with a change log.