Skip to content
TECNICODESK

AI Usage Policy

Owner: Tecnico Desk LLC

Effective Date: 2025-08-01 · Last Updated: 2026-08-12 · Next Review: 2026-11-10 (90 days)

In plain English

We use AI to help with internal work like ticket triage and drafting. We do not paste secrets or regulated data into chat tools. We use business-grade AI services, including approved OpenAI business services and Anthropic Claude business services where contractual privacy controls apply, with enterprise controls. We also use Microsoft Copilot for Microsoft 365, in a narrower role: assistance inside the Microsoft 365 apps we already work in, rather than general drafting and analysis. AI outputs are drafts and a human reviews before anything goes to clients.

The same applies to this website. The Tecnico Desk team does the research and analysis behind the articles, guides, and service pages, and we use AI to help with drafting, grammar, and spelling. A person decides what we publish, checks the security and compliance claims against the original sources, reviews every page before it goes live, and is accountable for what appears here.

Vendor commitment: OpenAI, Anthropic, and Microsoft state that their business services do not use customer prompts, responses, or tenant data to train foundation models without permission. These are vendor commitments, not Tecnico Desk's own guarantee.

AI and the Content on This Site

We think you should know how the writing on this site is made, so here it is plainly. The Tecnico Desk team does the research. We read vendor advisories from companies like Microsoft and Cisco, regulator and agency publications such as CISA bulletins, FTC and IRS guidance, and state bar opinions, and we draw on the patterns we see across the security reviews and support work we do for clients. Our team chooses the topics, based on the questions clients actually ask us. We then use business-grade AI tools to help put that research into words: drafting, structure, clarity, grammar, and spelling. That assistance covers drafting, not only proofreading, and we would rather say so than have you assume otherwise.

What stays with a person:

What we do not do: we do not use AI to invent client outcomes, testimonials, statistics, or security findings; we do not present AI output as independent research; and we do not publish AI-generated technical guidance that no one has verified.

If you ever find something on this site that is wrong, tell us at info@tecnicodesk.com and we will correct it.

How Tecnico Desk Uses AI

Tecnico Desk may use approved business AI tools to support documentation, summaries, checklists, report drafting, internal planning, service workflows, awareness content, and organizing security findings.

AI may assist with work, but it does not replace human judgment. Client-facing deliverables, security recommendations, and material security actions require human review before delivery or action.

Use of Guardz AI-Assisted Security Features

Tecnico Desk may use Guardz as part of its managed security service. Guardz includes AI-assisted security capabilities that may help analyze security alerts, correlate activity across users, devices, email, cloud services, and identities, summarize incidents, prioritize risk, support phishing investigations, and recommend remediation steps.

Guardz AI-assisted features are used as part of a security workflow, not as a replacement for human review by Tecnico Desk. Tecnico Desk reviews security findings, client-facing recommendations, and material remediation actions before delivery or action, unless a specific automated containment workflow has been separately approved and documented with the client.

Tecnico Desk does not represent Guardz AI features as a guarantee of breach prevention, complete phishing prevention, legal compliance, or full incident response replacement.

Client Data and AI Tools

Vendor AI Commitments

Tecnico Desk may rely on vendor AI features provided by approved business platforms, including security platforms, Microsoft business services, approved OpenAI business services, and Anthropic Claude business services where contractual privacy controls apply.

Tecnico Desk reviews vendor privacy, security, and data-use commitments before using AI-assisted features in client workflows. Vendor commitments are made by the vendor and are not Tecnico Desk's own guarantee of vendor model-training practices or vendor configurations.

What AI Does Not Do

1) Purpose and Scope

This policy governs how employees, contractors, and subprocessors use AI systems (approved OpenAI business services, Anthropic Claude business services, Microsoft Copilot for Microsoft 365, and the OpenAI and Claude APIs where contractual privacy controls apply) when handling internal data and client data. It applies to all devices, accounts, and workflows used for company business.

2) Definitions

3) Laws, Standards, and Contracts

We comply with applicable laws and frameworks where clients operate, including the Colorado Privacy Act and any contractual DPAs, BAAs, or SCCs. Client contracts prevail where stricter. We align our oversight with recognized guidance that emphasizes accountability and human review.

Accountability: The Security or Privacy lead owns this policy and performs an at-least annual review. We document AI risks, mitigations, and evidence of human oversight in our QA process.

Regulatory note (Colorado): Colorado SB24-205, as delayed by SB25B-004, has requirements scheduled for June 30, 2026. Tecnico Desk monitors Colorado AG rulemaking and aligns where applicable.

4) Data Classification

5) Allowed Use Matrix

Data class Approved OpenAI business services OpenAI API Anthropic Claude business services Claude API Microsoft Copilot for Microsoft 365 Personal or free AI tools
PublicAllowedAllowedAllowedAllowedAllowedNot for company work
InternalAllowedAllowedAllowedAllowedAllowedNot for company work
ConfidentialAllowed with redaction and approvalAllowed with zero-data-retention (ZDR) where contractually enabled on eligible endpoints, plus contract controlsAllowed with redaction and approvalAllowed with ZDR where contractually enabled, plus contract controlsAllowed inside the tenant, on data the user may already access. Outputs are not copied into other AI tools.Not for company work
Restricted (Sensitive)ProhibitedPermitted only with ZDR where contractually enabled on eligible endpoints, regional controls, and explicit client consentProhibitedPermitted only with ZDR where contractually enabled, a BAA where PHI is involved, and explicit client consentProhibitedNot for company work

Redaction means removing PII, secrets, hostnames, tenant IDs, keys, or uniquely identifying context before prompt submission. Zero-data-retention is a vendor mode where prompts and outputs are not retained for logs.

6) Prohibited Content in Prompts

7) Client Consent and Disclosures

Use AI with client data only when one of the following is true:

  1. The MSA/SOW/DPA/BAA explicitly authorizes AI processing for defined purposes, or
  2. The client has provided written consent referencing this policy and the specific workflow.
Required SOW clause: Provider may use enterprise AI services (approved OpenAI business services, Anthropic Claude business services, and Microsoft Copilot for Microsoft 365, where contractual privacy controls apply) to assist with ticket triage, documentation, code generation, and analytics. Provider will not input credentials or unredacted regulated data into conversational interfaces. Where regulated or sensitive personal data is processed, Provider will use API-based workflows with zero-data-retention where contractually enabled on eligible endpoints, regional processing where available and approved, and will ensure contractual protections with AI vendors at least equivalent to this Agreement. Provider will maintain human review of AI outputs and is responsible for final deliverables.

8) Data Residency and Cross-Border Transfer

  • Prefer US processing for US-only clients and EU/EEA processing for EU clients.
  • Use vendor features to constrain regions where available (for example Vertex AI project regions, OpenAI regional endpoints if enabled).
  • Execute SCCs or relevant mechanisms for cross-border transfers and keep a Record of Processing per client.

9) Prompt, Output, and Retention Rules

  • Default: retain only metadata (timestamp, user, purpose, tool) in our PSA/ITSM. Do not store full prompts or outputs that contain client data.
  • If tickets require retention of AI outputs, store them in the client record with the same classification as the source data.
  • All outputs must be fact-checked and scanned for malware before use.
  • Outputs are drafts. Technicians validate before delivery.

10) Vendor Configuration

OpenAI business services: Tecnico Desk uses approved OpenAI business services where contractual privacy controls apply. We rely on the contractually applicable privacy and data-use commitments for the specific OpenAI business plan in use, and we still avoid entering credentials, secrets, or unredacted regulated data into conversational interfaces.

OpenAI API: API inputs and outputs may be retained for abuse monitoring unless zero-data-retention is enabled. Tecnico Desk uses zero-data-retention where contractually enabled on eligible endpoints, and uses regional controls where available and approved for sensitive workflows.

Microsoft Copilot for Microsoft 365: Operates within Microsoft's enterprise data boundaries and Microsoft Graph with tenant controls, auditing, and retention policies. Microsoft commits that Microsoft 365 Copilot business services do not use customer prompts, responses, or tenant data to train foundation models without permission. This is a vendor commitment, not a Tecnico Desk guarantee.

Anthropic Claude: Anthropic states that it does not train its models on customer content submitted through its commercial services, that Claude API conversation content is not retained by default, and that zero-data-retention arrangements and a BAA are available to eligible commercial customers. These are vendor commitments, not a Tecnico Desk guarantee.

We disable optional data sharing where offered, enforce SSO/MFA and least-privilege access, and maintain a current vendor register with regions, retention defaults, and security attestations.

11) Security Controls

12) Human in the Loop and Quality

  • All AI outputs provided to clients require human review.
  • Technicians remain accountable for accuracy, licensing, and policy compliance.
  • For code/scripts, require peer review and testing in non-production before deployment.

Accuracy and claims: AI can be wrong. We validate outputs and avoid marketing statements that overstate accuracy or safety.

13) Incident Response

Treat unauthorized AI disclosure as a potential data incident. Steps: contain, preserve logs, assess data classes/jurisdictions, notify clients per contract or law, report to regulators if required, and update controls after a post-mortem.

14) Training and Enforcement

  • Mandatory onboarding and annual refresher on this policy and vendor settings.
  • Quarterly spot checks of prompts and outputs for compliance.
  • Violations may result in access revocation and disciplinary action.

15) Exceptions

Exceptions must be approved by the Security or Privacy lead with justification, scope, compensating controls, and an expiration date.

16) Automated Decisionmaking

Tecnico Desk does not use AI or automated decisionmaking technology to make final decisions about employment, lending, housing, education, healthcare, insurance, legal services, account access, pricing, eligibility, or other legally significant decisions.

If that changes, Tecnico Desk will review the workflow, document risks and controls, provide required notices, maintain human review, and honor applicable opt-out, access, appeal, and correction rights.

17) Automated Containment and Security Actions

Some security platforms may support automated containment actions, such as quarantining malicious email, revoking suspicious sessions, escalating confirmed threats, or generating recommended remediation steps.

Tecnico Desk enables, configures, and reviews these workflows based on client scope, risk level, vendor capability, and documented authorization. AI-assisted recommendations do not replace Tecnico Desk judgment or client-approved security procedures.

AI tools may not independently:

Security actions of this kind require human review and human authorization within the agreed change-control process, unless a specific automated containment workflow has been separately approved and documented with the client.

18) AI Privacy Change Notice

Tecnico Desk will not retroactively expand the use of client or consumer data for AI training or new AI purposes through quiet privacy-policy changes. Material AI data-use changes require updated notice and, where required, client approval or consent.

19) AI-Use Boundaries

Appendix C: Vendor Register (snapshot)

Vendor Product Use case Regions Default retention Training on data Contract
MicrosoftCopilot for Microsoft 365AI assistance in Microsoft 365 appsUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
AnthropicClaude business servicesDrafts and internal assistancePer business planPer business plan and admin configurationNot used for training under commercial termsCommercial terms and DPA
AnthropicClaude APIServer-to-serverEndpoint regionNot retained by default; ZDR where contractually enabledNot used for training under commercial termsDPA and SCCs
OpenAIApproved OpenAI business servicesDrafts and internal assistancePer business planPer business plan and admin configurationPer applicable business-plan privacy commitmentsPer business plan terms
OpenAIAPIServer-to-serverEndpoint region0 to 30 days (ZDR where contractually enabled on eligible endpoints)Per applicable API privacy commitmentsDPA or SCCs
MicrosoftMicrosoft 365Productivity and collaborationUS tenant regionAdmin setNot used for training outside tenantMicrosoft DPA
MicrosoftIntuneUEM/MDMUS tenant regionAdmin setN/AMicrosoft DPA
CloudflareEdge securityDNS, CDN, WAFGlobal edgeService defaultsN/ADPA and SCCs
HubSpotCRMLeads and formsUS tenantAdmin setN/ADPA and SCCs
FormspreeForms relayWeb form submissionsUSAdmin setN/ADPA
Monday.comProject managementTasks and usersUS tenantAdmin setN/ADPA and SCCs
AzureCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs
AWSCloud infrastructureInternal systemsUS regionsAdmin setN/ADPA and SCCs