Data Governance
Where your data lives, and who can touch it.
A plain-English account of how David handles your data: what an AI model sees, what never leaves your control, whether any of it trains a model, and how to keep it all inside the UK or EU.
The big 3 questions
Is our data used to train AI models?
No
David only works with AI companies whose contracts forbid training on your data. Any provider that won't commit to that, or that sits in a jurisdiction with weak data-protection law, is not offered.
Can anyone outside our control access it?
No
Every customer runs on its own separate, walled-off setup, so your data is never mixed with anyone else's, and your files are encrypted. Passwords and keys are never shown to the AI. To do a task, the AI is given the request plus the information it needs, sent only for as long as the task takes, to a company barred from training on it.
What settings apply across every platform?
One baseline
The same floor across every connected model: no training on your data, a signed Data Processing Agreement, and the option to keep processing inside the UK or EU.
Where your data is processed
Choose where your data is processed
The point where your data reaches an AI can be locked to a region: your administrator chooses UK, EU, or US in David's settings and can change it at any time. Whichever you choose, your administrators decide which models users may run, and a supporting vendor can be excluded on request.
Recommended where US processing is acceptable
United States
Storage and processing run in the US, where every model we offer is available.
The widest model choice. Every provider we engage by default is vetted against the same floor: no training on your data and data-processing terms in place, with zero data retention by default on several providers and available on request for the rest (see the table below). Choose this where your data-processing requirements allow US processing.
United Kingdom
Hosting and AI model requests stay in London. Supporting features that process elsewhere are listed on the sub-processor page.
For organisations whose obligations require UK-only processing. A focused set of models (the ones available in the UK): strong coverage across the main types, though not every model.
European Union
Processing stays within the EU (Ireland, Germany, France and other EU countries), never sent outside it.
The full, latest set of models, kept within the EU. Broader choice than UK-only.
The detail
Every provider, assessed
David isn't tied to a single AI company; it runs the best model for each job. Each provider is assessed on the questions a data-protection review actually asks. "Retention" is how long the provider itself keeps a request after answering it: "zero retention by default" means nothing is kept once the response is returned; "deleted within 30 days" means the provider holds it for abuse monitoring and then deletes it, with a zero-retention arrangement available on request. Which providers are engaged follows the models your administrators enable.
| Provider | Trains on data | Retention | DPA / GDPR | UK / EU residency |
|---|---|---|---|---|
| Amazon Web Services (AWS Bedrock)Claude + open models, via AWS | No | Zero retention by default | Single AWS DPA | UK or EULondon for UK-only, or kept within the EU. |
| Google (Vertex AI)Gemini | No | Not stored; 24-hour in-memory cache, abuse logging can be switched off | Yes (Cloud DPA) | EU, UK for some modelsKept within the EU, and in the UK (London) for some Gemini models. |
| Anthropicfirst-party API | No | Deleted within 30 days; zero retention by agreement | Yes | No direct UK/EUUS-based; for UK/EU we run Claude through AWS Bedrock (above). |
| OpenAIbusiness / API tier | No | Deleted within 30 days; zero retention on approval | Yes | EU availableEU storage and processing available on the EU option. |
| Groqfast inference | No | Not retained by default; zero-retention setting available | Yes | US onlyUS-based; no UK/EU option today. |
| Fireworks AIopen-weight models | No | Zero retention by default | Yes (DPA, SOC 2) | US onlyUS-based; no standard UK/EU option. |
| Meta PlatformsNot in standard configurationMuse Spark | No (standard tier) | Nothing stored at our request; zero retention on request to Meta | Developer terms; DPA under review | US onlyUS-based; no region controls published. |
| xAINot in standard configurationGrok | No (API) | 30-day abuse audit; zero retention by agreement | Yes (published DPA, SCCs) | US defaultEU endpoint by agreement. |
| Self-hosted (Ollama)open models on our infra | No | Never leaves the host | N/A, no third party | Your regionRuns entirely in-tenant, on our own infrastructure. |
The data boundary
What reaches an AI model, and what never does
Everything is stored in infrastructure isolated to your organisation, in your chosen region. This is what is, and isn't, sent to an AI model to do the work.
Never sent to a model
- Your passwords and integration keys
- Used only behind the scenes to connect David to your tools
When David uses one of your connected tools, the sign-in happens behind the scenes. The AI is never shown those keys.
Sent to the model, as needed
- The task being worked on
- Relevant conversation history and organisational knowledge
- The content of documents you ask David to work with
- Results from the tools David runs
Sent securely, only for as long as the task takes, to a company barred from training on it, and (if you choose) kept inside your country or region. Only what the task needs is sent, never your whole data set.
See the Security page for infrastructure and compliance detail, or the Privacy Policy. Our Data Processing Agreement and sub-processor list are published, with a change log.