TECNICODESK

AI Usage Policy

Owner: TECNICODESK

Effective Date: 2025-08-08 · Next Review: 2025-11-08 (Quarterly)

In plain English

We use AI to help with internal work like ticket triage and drafting. We don’t paste secrets or regulated data into chat tools. When sensitive processing is needed, we use enterprise services with strict controls and where available zero-data-retention endpoints. AI outputs are drafts: a human reviews before anything goes to clients.

1) Purpose and Scope

This policy governs how employees, contractors, and subprocessors use AI systems (Microsoft Copilot for Microsoft 365, Google Gemini, and OpenAI ChatGPT, including API integrations) when handling internal data and client data. It applies to all devices, accounts, and workflows used for company business.

2) Definitions

3) Laws, Standards, and Contracts

We comply with applicable laws and frameworks where clients operate, including the Colorado Privacy Act and any contractual DPAs, BAAs, or SCCs. Client contracts prevail where stricter. We align our oversight with recognized guidance that emphasizes accountability and human review.

Accountability: The Security/Privacy lead owns this policy and performs an at-least annual review. We document AI risks, mitigations, and evidence of human oversight in our QA process.

Regulatory note (Colorado): We monitor Colorado SB24-205 (high-risk AI obligations) taking effect February 1, 2026, and will align where applicable.

4) Data Classification

5) Allowed Use Matrix

Data class Gemini Workspace Gemini (Vertex AI) ChatGPT Enterprise or Team OpenAI API Personal or free AI tools
PublicAllowedAllowedAllowedAllowedNot for company work
InternalAllowedAllowedAllowedAllowedNot for company work
ConfidentialAllowed with redaction and approvalAllowed with project controlsAllowed with redaction and approvalAllowed with zero-data-retention (ZDR) on eligible endpoints and contract controlsNot for company work
Restricted (Sensitive)ProhibitedPermitted only under DPA/BAA, encryption, access controls, and project isolationProhibitedPermitted only with ZDR on eligible endpoints, regional controls, and explicit client consentNot for company work

Redaction means removing PII, secrets, hostnames, tenant IDs, keys, or uniquely identifying context before prompt submission. Zero-data-retention is a vendor mode where prompts/outputs are not retained for logs.

6) Prohibited Content in Prompts

7) Client Consent and Disclosures

Use AI with client data only when one of the following is true:

  1. The MSA/SOW/DPA/BAA explicitly authorizes AI processing for defined purposes, or
  2. The client has provided written consent referencing this policy and the specific workflow.
Required SOW clause: Provider may use enterprise AI services (Microsoft Copilot for Microsoft 365, Google Gemini, and/or OpenAI enterprise services) to assist with ticket triage, documentation, code generation, and analytics. Provider will not input credentials or unredacted regulated data into conversational interfaces. Where regulated or sensitive personal data is processed, Provider will use API-based workflows with zero-data-retention (where available) and regional processing where available, and will ensure contractual protections with AI vendors at least equivalent to this Agreement. Provider will maintain human review of AI outputs and is responsible for final deliverables.

8) Data Residency and Cross-Border Transfer

  • Prefer US processing for US-only clients and EU/EEA processing for EU clients.
  • Use vendor features to constrain regions where available (e.g., Vertex AI project regions, OpenAI regional endpoints if enabled).
  • Execute SCCs or relevant mechanisms for cross-border transfers and keep a Record of Processing per client.

9) Prompt, Output, and Retention Rules

  • Default: retain only metadata (timestamp, user, purpose, tool) in our PSA/ITSM. Do not store full prompts/outputs that contain client data.
  • If tickets require retention of AI outputs, store them in the client record with the same classification as the source data.
  • All outputs must be fact-checked and scanned for malware before use.
  • Outputs are drafts. Technicians validate before delivery.

10) Vendor Configuration

OpenAI (ChatGPT Enterprise & API): Business data from ChatGPT Enterprise isn’t used for training. API inputs/outputs may be retained for up to ~30 days for abuse detection unless we request/enable Zero-Data-Retention (ZDR) on eligible endpoints.

Microsoft Copilot for Microsoft 365: Operates within Microsoft’s enterprise data boundaries and Microsoft Graph with tenant controls, auditing, and retention policies.

Gemini for Google Workspace: Enterprise controls/governance for Workspace tenants with confidentiality commitments and admin settings appropriate for business use.

We disable optional data sharing where offered, enforce SSO/MFA and least-privilege access, and maintain a current vendor register with regions, retention defaults, and security attestations.

11) Security Controls

12) Human in the Loop & Quality

  • All AI outputs provided to clients require human review.
  • Technicians remain accountable for accuracy, licensing, and policy compliance.
  • For code/scripts, require peer review and testing in non-production before deployment.

Accuracy & claims: AI can be wrong. We validate outputs and avoid marketing statements that overstate accuracy or safety.

13) Incident Response

Treat unauthorized AI disclosure as a potential data incident. Steps: contain, preserve logs, assess data classes/jurisdictions, notify clients per contract or law, report to regulators if required, and update controls after a post-mortem.

14) Training and Enforcement

  • Mandatory onboarding and annual refresher on this policy and vendor settings.
  • Quarterly spot checks of prompts and outputs for compliance.
  • Violations may result in access revocation and disciplinary action.

15) Exceptions

Exceptions must be approved by the Security or Privacy lead with justification, scope, compensating controls, and an expiration date.

Appendix C: Vendor Register (snapshot)

Vendor Product Use case Regions Default retention Training on data Contract
MicrosoftCopilot for Microsoft 365AI assistance in Microsoft 365 appsUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
GoogleGemini (Workspace)Drafts and Docs helpUS or EUAdmin setOff by defaultMSA and DPA
GoogleVertex AI or GeminiAPI workflowsProject regionConfigurableOff by defaultDPA and SCCs
OpenAIChatGPT Enterprise or TeamDrafts and helpUS or EUAbout 30 days (admin)Not used for trainingEnterprise terms
OpenAIAPIServer-to-serverEndpoint region0–30 days (ZDR)Not used for trainingDPA or SCCs
MicrosoftMicrosoft 365Productivity and collaborationUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
MicrosoftIntuneUEM/MDMUS tenant regionAdmin setN/AMicrosoft DPA
CloudflareEdge securityDNS, CDN, WAFGlobal edgeService defaultsN/ADPA and SCCs
HubSpotCRMLeads and formsUS tenantAdmin setN/ADPA and SCCs
FormspreeForms relayWeb form submissionsUSAdmin setN/ADPA
Monday.comProject managementTasks and usersUS tenantAdmin setN/ADPA and SCCs
AzureCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs
AWSCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs