AI data protection and security FAQ
Answers to common questions about data protection, retention and the use of OpenAI models in CODEXIS AI.
1. What is the data retention policy with OpenAI? Do you use the standard 30-day retention, or have you arranged Zero Data Retention?+
We have Zero Data Retention (ZDR) arranged with OpenAI, so neither API requests nor responses are stored. The standard 30-day retention used for abuse monitoring does not apply to our requests.
2. Where does data processing physically take place within OpenAI? Does inference take place exclusively in the EU, or does data also travel outside the EU (e.g. to the USA)?+
We have a GDPR compliance agreement in place with OpenAI. By default, OpenAI uses global infrastructure, so processing (inference) also takes place outside the EU (transfer under SCC). For OpenAI models you can enable EU data residency in the Data processing setting; queries are then processed in the EU and do not leave it. The choice is yours and you can change it at any time.
3. Who has access to the data on OpenAI’s side? Do OpenAI employees have access to it? Does OpenAI use further sub-processors?+
These aspects are governed by the GDPR agreement (DPA) with OpenAI. The document is available for download here.
4. Do you support sign-in via SSO connected to Microsoft Entra ID (Active Directory)?+
Yes, we can. We use Keycloak to ensure maximum security; Microsoft Entra ID can be used as an external IdP.