Skip to main content
All CollectionsSecurity and Compliance
StrategyAI: Security & Compliance
StrategyAI: Security & Compliance

FAQ about the security and compliance of Quantive products

Neli Ivanova avatar
Written by Neli Ivanova
Updated over a week ago

At Quantive, we prioritize the protection of your data and ensure that all data-handling practices comply with applicable laws and regulations. This article explains how we manage data residency to maintain compliance with the General Data Protection Regulation (GDPR) and other relevant data protection standards.

Where is my data transmitted to?

Your data will not be transferred outside of Azure Data centers that Quantive uses. Unlike many other tech companies, we have invested in internal infrastructure that can provide AI capabilities while eliminating unnecessary data dissemination.

Are there any new companies that will be involved in the processing of my data (new 3rd party subprocessors)?

No. Strategy AI was built by leveraging Azure’s built-in AI capabilities without sending any of your data to 3rd parties outside of the existing data processing agreement you have with Quantive.

How is the data handled in terms of residency?

Quantive ensures customer data is protected and handled in compliance with all applicable laws, in total alignment with any existing data processing agreements.

Data processed by StrategyAI for customers deployed in Europe is transmitted to an AI instance in Europe, while data from US and Asian customers will be processed in the US. This makes StrategyAI automatically compliant with any data residency requirements you have had with Quantive. The AI instances are part of our infrastructure and are in scope for ISO 27001 and SOC 2 compliance audits.

Is StrategyAI GDPR compliant?

Enabling StrategyAI will not require more personal data from your employees and no data will be shared with additional 3rd parties. All provisions from the DPA between your company and Quantive will remain intact.

I am an EU customer - does that mean I have to sign Standard Contractual Clauses (SCC) with Quantive to ensure compliance with GDPR?

No. EU customers who are already hosting their application instance on our EU infrastructure will not require SCC as StrategyAI will be provided from the same region.

Is user data and input used to train the model to get better answers over time?

Users will get better answers over time but that doesn't mean models are trained from your data. To ensure that the output provided to users is relevant, we use the context of what they are trying to do, who they are (what the platform understands about them), what they are typically focused on, and their tone of voice. The richer this information in Quantive Results is, the more StrategyAI understands the user, and hence the better the recommendations through the context provided to the AI service on top of the use case.

Is data from our Quantive Results account used to improve the model or the service for other customers?

No. Data is not shared, nor reused from account to account. Suggestions and recommendations for an individual user are solely based on data within the Quantive Results account that the user belongs to as well as any additional documents that they provide.

Did this answer your question?