Skip to main content

Xoxoday Responsible AI Policy Statement

Updated over 2 months ago

Purpose

This policy defines how Xoxoday designs, governs, and operates artificial intelligence (AI) capabilities in a manner that prioritizes data privacy, security, regulatory compliance, and enterprise control.

Guiding Principles

Xoxoday’s use of AI is governed by the following principles:

  1. Privacy by Design
    AI is architected with privacy embedded across data flows, processing layers, and governance mechanisms.

  2. Data Minimization
    AI processes only the minimum amount of data required to perform explicitly defined tasks.

  3. Enterprise Control and Accountability
    Organizations retain full control over whether and how AI is used within their environment.

Organizational Control Over AI Usage

Xoxoday provides organizations with explicit administrative controls to manage AI usage:

  • AI capabilities can be enabled or disabled at the organization level

  • When AI is disabled, no data is transmitted to AI systems

  • Disabling AI does not impact core platform functionality or data integrity

  • AI settings are configurable by authorized administrators only

This ensures that customers can align AI usage with internal policies, regulatory requirements, or risk tolerance.

Protection of Personal Data

  • All Personally Identifiable Information (PII) is removed or anonymized before any interaction with AI systems

  • Identifiers such as names, email addresses, employee IDs, and contact details are never shared with AI servers

  • AI systems operate solely on non-identifiable, sanitized, and context-only data

AI Model Usage and Data Retention

  • Customer data is not used to train public or shared AI models

  • AI interactions are transactional and non-retentive

  • No cross-tenant or cross-customer data sharing occurs

Aggregation and Insight Controls

  • AI-generated insights are delivered in aggregated or summarized formats

  • Individual-level profiling is explicitly avoided

  • Outputs are designed to minimize re-identification risk

Governance and Oversight

  • AI features operate under role-based access controls

  • Human oversight is maintained for all AI-assisted outputs

  • AI-generated content is subject to moderation and safety controls

Use of External AI Services

Where external AI frameworks are utilized:

  • Only anonymized, non-identifiable inputs are transmitted

  • Data sharing is purpose-limited and ephemeral

  • External AI services are evaluated against enterprise security and compliance standards

Compliance and Risk Alignment

Xoxoday’s Responsible AI practices align with enterprise expectations, including:

  • Privacy-by-design and least-privilege principles

  • Clear separation between operational data and AI processing

  • Audit-ready governance and documentation

Continuous Review

AI capabilities and controls are periodically reviewed to address evolving regulatory, security, and ethical requirements. New AI features undergo risk and governance assessment prior to release.

Policy Commitment

Xoxoday is committed to responsible AI innovation that enhances enterprise outcomes while preserving customer autonomy, data protection, and trust.

Need help? Reach out to your support team or [[email protected]](mailto:[email protected]).

Did this answer your question?