Data Governance
Where your data lives, and who can touch it.
A plain-English account of how David handles your data: what an AI model sees, what never leaves your control, whether any of it trains a model, and how to keep it all inside the UK or EU.
The big 3 questions
Is our data used to train AI models?
No
David only works with AI companies whose contracts forbid training on your data. Any provider that won't commit to that, or that sits in a jurisdiction with weak data-protection law, is not offered.
Can anyone outside our control access it?
No
Every customer runs on its own separate, walled-off setup, so your data is never mixed with anyone else's, and your files are encrypted. Passwords and keys are never shown to the AI. To do a task, the AI is given the request plus the information it needs, sent only for as long as the task takes, to a company barred from training on it.
What settings apply across every platform?
One baseline
The same floor across every connected model: no training on your data, a signed Data Processing Agreement, and the option to keep processing inside the UK or EU.
Where your data is processed
Keep it in the UK, the EU, or allow US
The point where your data reaches an AI can be locked to a region. Pick the option that fits your obligations; the detailed provider breakdown is below.
Recommended for UK
United Kingdom
Storage and processing both stay in London. Your data never leaves the UK.
A focused set of models (the ones available in the UK). Strong coverage across the main types, though not every model.
European Union
Processing stays within the EU (Ireland, Germany, France and other EU countries), never sent outside it.
The full, latest set of models, kept within the EU. Broader choice than UK-only.
United States
Storage and processing run in the US, where the widest range of models is available.
The broadest model choice, including models offered only in the US, but data is processed outside the UK and EU. Used only where US processing is acceptable.
The detail
Every provider, assessed
David isn't tied to a single AI company; it runs the best model for each job. Each provider is assessed on the questions a data-protection review actually asks.
| Provider | Trains on data | Retention | DPA / GDPR | UK / EU residency |
|---|---|---|---|---|
| AWS BedrockClaude + open models, via AWS | No | Zero-retention default | Single AWS DPA | UK or EULondon for UK-only, or kept within the EU. |
| Google Vertex AIGemini | No | Configurable | Yes (Cloud DPA) | EU, UK for some modelsKept within the EU, and in the UK (London) for some Gemini models. |
| Anthropic (Claude)first-party API | No | ≤30 days, can keep none | Yes | No direct UK/EUUS-based; for UK/EU we run Claude through AWS Bedrock (above). |
| OpenAIbusiness / API tier | No | ≤30 days, can keep none | Yes | EU availableEU storage and processing available on the EU option. |
| Groqfast inference | No | Can keep none | Yes | US onlyUS-based; no UK/EU option today. |
| Fireworksopen-weight models | No | Zero-retention default | Yes (DPA, SOC 2) | US onlyUS-based; no standard UK/EU option. |
| Self-hosted (Ollama)open models on our infra | No | Never leaves the host | N/A, no third party | Your regionRuns entirely in-tenant, on our own infrastructure. |
The data boundary
What reaches an AI model, and what never does
Everything is stored in infrastructure isolated to your organisation, in your chosen region. This is what is, and isn't, sent to an AI model to do the work.
Never sent to a model
- Your passwords and integration keys
- Used only behind the scenes to connect David to your tools
When David uses one of your connected tools, the sign-in happens behind the scenes. The AI is never shown those keys.
Sent to the model, as needed
- The task being worked on
- Relevant conversation history and organisational knowledge
- The content of documents you ask David to work with
- Results from the tools David runs
Sent securely, only for as long as the task takes, to a company barred from training on it, and (if you choose) kept inside your country or region. Only what the task needs is sent, never your whole data set.
See the Security page for infrastructure and compliance detail, or the Privacy Policy. Our full DPA and sub-processor list are available on request.