Purpose
This policy defines how Xoxoday designs, governs, and operates artificial intelligence (AI) capabilities in a manner that prioritizes data privacy, security, regulatory compliance, and enterprise control.
Guiding Principles
Xoxoday’s use of AI is governed by the following principles:
Privacy by Design
AI is architected with privacy embedded across data flows, processing layers, and governance mechanisms.Data Minimization
AI processes only the minimum amount of data required to perform explicitly defined tasks.Enterprise Control and Accountability
Organizations retain full control over whether and how AI is used within their environment.
Organizational Control Over AI Usage
Xoxoday provides organizations with explicit administrative controls to manage AI usage:
AI capabilities can be enabled or disabled at the organization level
When AI is disabled, no data is transmitted to AI systems
Disabling AI does not impact core platform functionality or data integrity
AI settings are configurable by authorized administrators only
This ensures that customers can align AI usage with internal policies, regulatory requirements, or risk tolerance.
Protection of Personal Data
All Personally Identifiable Information (PII) is removed or anonymized before any interaction with AI systems
Identifiers such as names, email addresses, employee IDs, and contact details are never shared with AI servers
AI systems operate solely on non-identifiable, sanitized, and context-only data
AI Model Usage and Data Retention
Customer data is not used to train public or shared AI models
AI interactions are transactional and non-retentive
No cross-tenant or cross-customer data sharing occurs
Aggregation and Insight Controls
AI-generated insights are delivered in aggregated or summarized formats
Individual-level profiling is explicitly avoided
Outputs are designed to minimize re-identification risk
Governance and Oversight
AI features operate under role-based access controls
Human oversight is maintained for all AI-assisted outputs
AI-generated content is subject to moderation and safety controls
Use of External AI Services
Where external AI frameworks are utilized:
Only anonymized, non-identifiable inputs are transmitted
Data sharing is purpose-limited and ephemeral
External AI services are evaluated against enterprise security and compliance standards
Compliance and Risk Alignment
Xoxoday’s Responsible AI practices align with enterprise expectations, including:
Privacy-by-design and least-privilege principles
Clear separation between operational data and AI processing
Audit-ready governance and documentation
Continuous Review
AI capabilities and controls are periodically reviewed to address evolving regulatory, security, and ethical requirements. New AI features undergo risk and governance assessment prior to release.
Policy Commitment
Xoxoday is committed to responsible AI innovation that enhances enterprise outcomes while preserving customer autonomy, data protection, and trust.
Need help? Reach out to your support team or [[email protected]](mailto:[email protected]).
