← Back to Home

AI Governance Policy

SentientPro AI Governance Policy

Last updated: July 21, 2026

1. Purpose and Scope

This AI Governance Policy describes how SentientPro, Inc. ("SentientPro") selects, uses, and oversees artificial intelligence technologies in the delivery of its Services. It applies to all AI processing performed by or on behalf of SentientPro, including processing carried out by third-party AI providers acting as subprocessors.

This Policy supplements, and should be read together with, the SentientPro Terms of Service, Privacy Policy, and Data Processing Addendum ("DPA"). In case of conflict, the DPA prevails.

2. Governance Principles

SentientPro's use of AI is guided by the following principles:

  • Purpose limitation. AI processing is used solely to provide and improve the Services requested by the Customer. Customer Data is never used for unrelated purposes.
  • No training on Customer Data. Customer Data is not used to train generalized AI models — by SentientPro or by its AI providers — without explicit Customer opt-in.
  • Data minimization. Only the data necessary for a given AI feature is transmitted to an AI provider, and only for the duration of the request.
  • Human oversight. AI outputs are assistive. Summaries, action items, drafts, and classifications produced by AI are presented to users for review and can be edited or discarded; they do not trigger irreversible actions autonomously.
  • Transparency. The AI providers we use, and the categories of data they process, are disclosed in this Policy and in the SentientPro Subprocessor List.
  • Accountability. A named owner within SentientPro is responsible for this Policy and for reviewing AI providers, controls, and data flows.

3. AI Providers

SentientPro uses OpenAI (OpenAI, L.L.C.) as its external AI provider. All external AI requests are made through the OpenAI API platform, which is governed by OpenAI's business terms — not its consumer products. Under those terms:

  • Data submitted through the OpenAI API is not used to train or improve OpenAI's models. Organization-level data-sharing options are disabled on SentientPro's OpenAI account.
  • OpenAI may retain API inputs and outputs for a maximum of 30 days solely for abuse and misuse monitoring, after which they are deleted. SentientPro does not use OpenAI features that persist customer content beyond this window (no hosted file storage, assistants, or stateful conversation storage on OpenAI infrastructure).
  • A data processing agreement is in place with OpenAI covering GDPR and other applicable Data Protection Laws.
  • OpenAI maintains SOC 2 Type 2 attestation and encrypts data in transit (TLS 1.2+) and at rest (AES-256).

SentientPro's own AI orchestration and application logic run on Microsoft Azure infrastructure. SentientPro is transitioning its primary hosting region from the United States to the European Union during 2026; OpenAI API processing takes place in the United States, protected by the transfer safeguards described in the DPA. A current list of all subprocessors, including AI providers, is maintained in the SentientPro Subprocessor List.

4. Data Processed by AI Features

Depending on the features a Customer uses, the following categories of Customer Data may be processed by AI:

  • Meeting and call audio, submitted for transcription;
  • Meeting transcripts, processed to generate summaries, action items, insights, and classifications;
  • Email and message content, where the Customer uses AI-assisted drafting features;
  • Text queries and prompts submitted by users to AI-assisted features.

All AI requests are made server-to-server from SentientPro's infrastructure. End-user browsers never communicate directly with AI providers, and AI provider credentials are never exposed to clients.

5. Security Controls

AI processing is subject to the same safeguards as the rest of the Services, including:

  • Encryption in transit for all AI provider communications;
  • AI provider credentials stored in managed secret storage, scoped to the minimum required permissions, and rotated periodically;
  • Access to AI provider accounts restricted to authorized personnel, protected by single sign-on and multi-factor authentication;
  • Usage monitoring and spend limits on AI provider accounts to detect anomalous activity.

6. Evaluating and Adding AI Providers

Before engaging a new AI provider, SentientPro assesses: the provider's training and retention policies for API data; availability of a data processing agreement and appropriate international transfer mechanisms; the provider's security certifications; and whether the intended use meets the principles in Section 2. New AI providers are added to the Subprocessor List and notified to Customers in accordance with the DPA.

7. Limitations of AI Outputs

AI-generated content (including transcriptions, summaries, and drafts) may contain errors or omissions. Customers are responsible for reviewing AI outputs before relying on or acting upon them, as set out in the Terms of Service and DPA.

8. Review

This Policy is reviewed at least annually, and additionally upon any material change to SentientPro's AI providers or AI processing activities.

9. Contact

For questions about this Policy or SentientPro's use of AI:

© 2026 SentientPro, Inc. All rights reserved.