TECNICODESK

AI Usage Policy

Owner: TECNICODESK

Effective Date: 2025-08-08 · Next Review: 2025-11-08 (Quarterly)

1) Purpose and Scope

This policy governs how employees, contractors, and subprocessors use AI systems (Microsoft Copilot for Microsoft 365, Google Gemini, and OpenAI ChatGPT, including API integrations) when handling internal data and client data. It applies to all devices, accounts, and workflows used for company business.

2) Definitions

3) Laws, Standards, and Contracts

We comply with applicable laws and frameworks where clients operate, including the Colorado Privacy Act and any contractual DPAs, BAAs, or SCCs. Client contracts prevail where stricter.

4) Data Classification

5) Allowed Use Matrix

Data class Gemini Workspace Gemini (Vertex AI) ChatGPT Enterprise or Team OpenAI API Personal or free AI tools
PublicAllowedAllowedAllowedAllowedNot for company work
InternalAllowedAllowedAllowedAllowedNot for company work
ConfidentialAllowed with redaction and approvalAllowed with project controlsAllowed with redaction and approvalAllowed with zero data retention and contract controlsNot for company work
Restricted (Sensitive)ProhibitedPermitted only under DPA or BAA, encryption, access controls, and project isolationProhibitedPermitted only with zero data retention, regional controls, and explicit client consentNot for company work

Redaction means removing PII, secrets, hostnames, tenant IDs, keys, or uniquely identifying context before prompt submission. Zero data retention is a vendor mode where prompts and outputs are not retained for logging.

6) Prohibited Content in Prompts

7) Client Consent and Disclosures

Use AI with client data only when one of the following is true:

  1. The MSA or SOW or DPA or BAA explicitly authorizes AI processing for defined purposes, or
  2. The client has provided written consent referencing this policy and the specific workflow.
Required SOW clause: Provider may use enterprise AI services (Microsoft Copilot for Microsoft 365, Google Gemini, and or OpenAI enterprise services) to assist with ticket triage, documentation, code generation, and analytics. Provider will not input credentials or unredacted regulated data into conversational interfaces. Where regulated or sensitive personal data is processed, Provider will use API based workflows with zero data retention and regional processing where available, and will ensure contractual protections with AI vendors at least equivalent to this Agreement. Provider will maintain human review of AI outputs and is responsible for final deliverables.

8) Data Residency and Cross Border Transfer

  • Prefer US data processing for US only clients and EU or EEA processing for EU clients.
  • Use vendor features to constrain regions where available (Vertex AI project regions, OpenAI regional endpoints if enabled).
  • Execute SCCs or relevant mechanisms for cross border transfers and keep a Record of Processing per client.

9) Prompt, Output, and Retention Rules

  • Default: retain only metadata (timestamp, user, purpose, tool) in our PSA or ITSM. Do not store full prompts or outputs that contain client data.
  • If tickets require retention of AI outputs, store them in the client record with the same classification as the source data.
  • All outputs must be fact checked and scanned for malware before use.
  • Outputs are drafts. Technicians validate before delivery.

10) Vendor Configuration

Gemini (Workspace and Google Cloud): Use paid enterprise offerings. Disable optional data sharing where available. For Vertex AI projects, enable governance controls (project isolation, IAM, logging, DLP) and configure regions.

OpenAI (ChatGPT Enterprise or Team and API): Use company owned accounts with SSO and role based access. For API workloads handling Confidential or Restricted data, enable Zero Data Retention for eligible endpoints and avoid logging payloads in application logs. Set organization wide data controls so prompts and outputs are not used for training.

Microsoft Copilot for Microsoft 365: Use tenant controls, label sensitivity, and restrict plugin or connector permissions according to least privilege. Review audit logs and activity explorer regularly.

Maintain a current Vendor Register with sub processors, regions, retention defaults, and security attestations.

11) Security Controls

  • Identity: SSO and MFA for all AI tools. Least privilege via groups.
  • Network: Allowlist official endpoints. Block unknown AI sites.
  • Data loss prevention: Enforce clipboard and attach controls and use DLP for web and email.
  • Redaction gateway: Prefer middleware that scrubs PII and secrets before API submission.
  • Prompt safety: Train staff to spot prompt injection and data exfiltration attempts.
  • Malware scanning: Scan AI generated files and scripts before use.
  • Logging: Centralize access logs and alert on anomalous use.

12) Human in the Loop and Quality

  • All AI outputs provided to clients require human review.
  • Technicians remain accountable for accuracy, licensing, and policy compliance.
  • For code or scripts, require peer review and testing in non production before deployment.

13) Incident Response

Treat unauthorized AI disclosure as a potential data incident. Steps: contain, preserve logs, assess data classes and jurisdictions, notify clients per contract or law, report to regulators if required, and update controls after a post mortem.

14) Training and Enforcement

  • Mandatory onboarding and annual refresher on this policy and vendor settings.
  • Quarterly spot checks of prompts and outputs for compliance.
  • Violations may result in access revocation and disciplinary action.

15) Exceptions

Exceptions must be approved by the Security or Privacy lead with justification, scope, compensating controls, and an expiration date.

Appendix C: Vendor Register (snapshot)

Vendor Product Use case Regions Default retention Training on data Contract
MicrosoftCopilot for Microsoft 365AI assistance in Microsoft 365 appsUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
GoogleGemini (Workspace)Drafts and Docs helpUS or EUAdmin setOff by defaultMSA and DPA
GoogleVertex AI or GeminiAPI workflowsProject regionConfigurableOff by defaultDPA and SCCs
OpenAIChatGPT Enterprise or TeamDrafts and helpUS or EUAbout 30 days (admin)Not used for trainingEnterprise terms
OpenAIAPIServer to serverEndpoint region0 to 30 days (ZDR)Not used for trainingDPA or SCCs
MicrosoftMicrosoft 365Productivity and collaborationUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
MicrosoftIntuneUEM or MDMUS tenant regionAdmin setN/AMicrosoft DPA
CloudflareEdge securityDNS, CDN, WAFGlobal edgeService defaultsN/ADPA and SCCs
HubSpotCRMLeads and formsUS tenantAdmin setN/ADPA and SCCs
FormspreeForms relayWeb form submissionsUSAdmin setN/ADPA
Monday.comProject managementTasks and usersUS tenantAdmin setN/ADPA and SCCs
AzureCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs
AWSCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs