Your data, in Europe, for exactly as long as you say
Where it runs, what is kept, what leaves and how to be rid of it. None of the answers below are a policy we intend to write. Each one is a setting or a line of code you can be shown.
You set the window, and the window is enforced
Each customer company chooses how long a conversation and everything pulled into it are kept. When the window passes, a daily job deletes the conversation with its tool calls and its tool results. Not archived, not anonymised.
Days a conversation is kept
1 day – 365 days
- Conversations
One day to a year, set by your company
Your administrators set it on the company's AI settings page, and the change is audited. Fourteen days is only the value it starts at.
- What goes with them
The tool calls and the rows they returned
A conversation is not only its messages. The queries it ran and the records those queries brought back are deleted with it, because that is where your ledger data actually sits.
- Knowledge
A separate setting, and off by default
Business terms and memories are not conversations; a definition that is still true should not expire because a chat did. Left alone they live until the loop retires them as superseded, denied or stale. Set a number of days and they are deleted on that window too, and you are warned first that still-true terms will go.
Nothing in this path leaves Europe
Not as a commitment to be audited later. As the only configuration the system has.
Application and database
A European region
The API and the database it writes to run in a European cloud region, and the web app is served from the same place. Nothing about the deployment reaches outside the EU.
The models
France
The models are hosted in France. A request reaches them, produces the answer, and is dropped: the provider keeps no copy of the prompt, no copy of the records inside it, and nothing that could be retrieved, inspected or handed over afterwards. Inference is the whole of the arrangement. There is no account somewhere with your conversations sitting in it.
Files and exports
European object storage
Uploads, generated CSV, XLSX and PDF files, and report snapshots are stored encrypted in European object storage, reachable only through the portal's own access rules.
The knowledge index
Our own index, in Europe
Approved knowledge entries, and only approved ones, are embedded into a vector store we run ourselves. Nothing pending, denied or superseded is ever indexed.
What actually goes to a model, and what does not
The honest version, because the difference matters more than the hosting does.
- What is sent
The question, the conversation, and the rows this turn needed
A tool result is part of the next request, so the records a query returned do reach the model. That is what makes the answer real, and it is bounded: a result too large to carry back is reduced to a handful of rows and a note saying so.
- What is not
Your database, and anything the question did not reach for
There is no copy of your Business Central tenant anywhere in the platform. Every read is made when the question is asked, through your own connection, and nothing is synchronised into a training set.
- Training
Your data does not train a model
The models are hosted, and nothing of yours is used to train or fine-tune one: not your conversations, not the records a query returned, not the files you upload.
- At the provider
Nothing of yours is held between turns
No prompt cache, no stored conversation, no per-customer state on their side. Every turn arrives complete, is answered, and leaves nothing behind, which is why the full context is sent again each time rather than referenced from something they kept.
Send this page to your DPO
Then bring the questions it does not answer. We would rather have that conversation before a contract than after one.
Or write to us at hello@uni4c.ai