Skip to content

An OMO project / AIAPI

Map the data before the integration.

Questions to resolve before sending customer data through AIAPI: roles, upstream route, location, retention, agreements and access controls.

Who decides the purpose?

If you build a customer-facing application, your organization decides what to collect and why. AIAPI and upstream services participate in the processing chain. Their legal roles must be assessed for the actual service and contract, not inferred from the label “API”.

Questions for a regulated or confidential workload

Email [email protected] before sending such data. Describe the categories, volume, intended model and the requirements you need confirmed. Do not include actual sensitive records in the initial enquiry.

  • Which upstream route and processing locations apply?
  • Which records are stored, for what purpose and for how long?
  • What terms apply to model training, diagnostics and human access?
  • Is a processing agreement, transfer safeguard or separate approval required?
  • How will you handle access, correction, deletion and an incident?

Send the minimum necessary

Remove unrelated identifiers and use synthetic examples during development. Separate production and test keys. Restrict access to logs and avoid copying complete prompts into tickets or analytics.

This information page is not a signed data-processing agreement or a provider/subprocessor register. Confirm the required terms before a use case that depends on them.