1. Scope and contract priority
A signed MSA, SOW, BAA, or DPA controls where it conflicts with this summary. The Data Processing Agreement governs Client Data processed on your instructions; the Privacy Policy describes Website Data and account data.
These commitments apply when Bitscaled processes Client Data through an AI feature within the contracted service scope. They do not authorize new processing, change your access permissions, or permit protected health information without a signed BAA.
2. No foundation-model training
Bitscaled does not use Client Data, including customer infrastructure data, telemetry, and source code, to train foundation models. We process that data only on documented client instructions to deliver the agreed services. Operational prompt and tool logs are not used to train public foundation models.
Model-provider processing must stay within the agreed instructions and applicable provider terms. A provider selection alone does not establish a no-training contract for every product, account tier, endpoint, or customer-supplied credential.
3. Provider and feature scope
AI prompts and relevant context may be sent to the model provider configured for a feature. The subprocessor directory describes providers and when they are used. Customer-configured integrations and credentials also require review of the customer's agreement with that provider.
- Agree the feature, provider, permitted data categories, processing locations, and retention requirements before submitting regulated or sensitive Client Data.
- Do not include secrets, payment-card data, or PHI unless the specific workflow is contracted and the required safeguards and agreements are in place.
- Review AI output before relying on it. AI processing remains subject to the same company permissions and authorized service scope as the underlying workflow.
4. Operational retention and zero-retention requirements
No training and zero retention are separate commitments. Features may retain saved conversations, workflow inputs and outputs, prompts, tool metadata, and audit records to provide the service, investigate errors, enforce permissions, and prevent abuse. Retention follows the applicable feature settings, Privacy Policy, and signed agreement.
Bitscaled does not provide a universal zero-retention guarantee. A zero-retention commitment requires a signed agreement identifying the feature, provider and endpoint, data covered, provider approval and configuration, and any operational or legal exceptions. Confirm those conditions before sending data that requires zero retention.
Return and deletion of Client Data follow the DPA. Backups, security records, and legally required records may remain for their applicable retention periods; deleting a visible conversation does not promise immediate deletion of every retained copy.
5. Enterprise review
Contact legal@bitscaled.tech to document your AI processing requirements in the DPA or SOW. See Data Security and Tenant Boundaries for the controls that support authorized access.