LLM Data Tenancy Policy
At Dramatify, the security, privacy, and sovereignty of your data are fundamental. As an EU-based company, we are fully committed to complying with the General Data Protection Regulation (GDPR) and all applicable EU data protection and information security laws. This policy outlines how Dramatify manages Large Language Model (LLM) usage to ensure that customer data, content, and intellectual property remain secure, confidential, and under your control.
1. Data Sovereignty & EU Compliance
All LLM-related services at Dramatify are hosted and processed exclusively within the European Union.
We adhere to the following legal and technical requirements:
- GDPR compliance, including data minimisation, purpose limitation, and user consent.
- EU-based data residency to ensure that no data is transferred outside the European Economic Area (EEA) without explicit legal safeguards.
- LLM data protection practices aligned with ISO 27001, SOC 2, and Microsoft’s EU Data Boundary commitments.
2. Microsoft Azure EU Tenancy
Dramatify’s AI-powered features, including those using LLMs, are built on Microsoft Azure’s OpenAI services.
Key safeguards include:
- All prompts, inputs, and outputs are processed within a dedicated EU-based Azure instance.
- No customer data is stored or used for training by OpenAI or Microsoft.
- Azure enforces logical separation of customer data using multi-layered security architecture.
- All data is encrypted both in transit and at rest, adhering to industry best practices.
3. Optional Private Azure Tenancy for Customers
For enterprise and broadcast clients with additional security or regulatory requirements, Dramatify supports integration with your private Microsoft Azure tenancy.
Benefits include:
- Complete control over where and how your data is processed.
- Dedicated compute, storage, and security controls within your organisation’s own Azure environment.
- Seamless integration with Dramatify’s AI workflows, while maintaining 100% data isolation from Dramatify’s infrastructure.
4. No Data Retention or Training
Dramatify does not retain or cache any LLM-related input or output beyond the active user session unless explicitly stored by the user within their project. Additionally:
- No LLM interactions are logged or reviewed by Microsoft, OpenAI, or Dramatify for model training or product development.
- All interactions with the LLM are transient unless explicitly saved as part of a project within the Dramatify platform.
5. Customer Responsibilities
Customers are responsible for:
- Ensuring that input data shared with Dramatify’s AI tools complies with internal and external data handling policies.
- Managing access and permissions appropriately within their own Azure tenancy (if using private tenancy integration).
- Not entering sensitive personal data unless necessary for the intended production workflow.
- Adhering to MS Azure Content Safety policy.
6. Updates and Transparency
We continuously monitor regulatory developments, Microsoft Azure service changes, and industry best practices to maintain the highest standards.
Policy changes will be communicated in advance on this page.
Contact and Questions
For more information or to initiate a private Azure tenancy integration, please contact: [email protected]