Skip to main content

Allin Data Security and Privacy FAQ

Frequently asked questions about how Allin handles guest data, including data retention, encryption, OpenAI's data policies, and your ownership of customer data.

Summary: Allin is built with data security and privacy at its core. Guest data is stored in secure, compliant databases, and transient data passed to OpenAI is not retained or used for model training. This article answers common questions about how your data is protected.

Permissions Required: No specific permissions required.

Key Points

  1. All guest data is stored in secure, compliant databases in line with your Data Processing Agreement (DPA).

  2. Data passed to OpenAI is transient β€” it is not retained by OpenAI and cannot be used for model training.

  3. Your data is never used to train models for other brands. Each property's Allin configuration is unique.

  4. All data transmission uses HTTPS SHA256 with RSA and TLS 1.3 encryption.

  5. If you have specific security or compliance questions not covered here, contact your Alliants team.


Common Questions

Q: Is guest data stored securely?

A: Yes. All guest data is stored in secure, compliant databases in line with existing best practices and the Data Processing Agreement (DPA) between Alliants and your organisation.

Q: Does OpenAI retain or use our data for training?

A: No. Transient data passed through to OpenAI's API is expressly not retained by OpenAI and cannot be used for model training purposes.

Q: Is our data used to train models for other brands?

A: No. Your data is not used by Alliants for training models for use with other brands. Allin responses are uniquely tailored for each property and brand.

Q: How is data transmitted securely?

A: Allin uses robust encryption standards including HTTPS SHA256 with RSA and TLS 1.3, ensuring secure data exchanges between the application and OpenAI's infrastructure.

Q: What is Allin's data retention policy?

A: Allin operates on a non-retentive data policy. Data is transient in nature β€” it originates from the AXP database and is reformatted for OpenAI API interactions without internal storage by the AI layer.

Q: How is the system monitored?

A: Allin integrates with AWS CloudWatch for logging application timeouts and errors. Sensitive information is withheld from logs, and only essential data is logged for monitoring purposes. The DevOps team performs regular log analyses for security oversight and proactive troubleshooting.

Q: Are security audits performed?

A: Yes. The Customer Operations team carries out periodic security evaluations to proactively identify and address potential system vulnerabilities.

Q: Who owns the data processed through Allin?

A: You do. Alliants acknowledges that customers maintain full ownership of their data processed via Allin through OpenAI's APIs. Processing protocols are strictly aligned with the terms in your Service Level Agreement and Privacy Policy.

Q: Do I need to add a disclaimer for guests?

A: It is your responsibility to ensure you add any necessary disclaimers to your front-end applications for guests. Alliants can advise on best practices if needed.

Q: Where can I find more information about privacy policies?

A: Review the Alliants' Privacy Notice and OpenAI's Privacy Policy for comprehensive details.

Did this answer your question?