CODEXIS AI guide
FAQ
1. What is the data retention policy with OpenAI? Do you use the standard 30-day retention, or have you arranged Zero Data Retention?+
We currently use the standard 30-day data retention as part of abuse monitoring. We are currently negotiating the introduction of a Zero Data Retention regime.
2. Where does data processing physically take place within OpenAI? Does inference take place exclusively in the EU, or does data also travel outside the EU (e.g. to the USA)?+
We have a GDPR compliance agreement in place with OpenAI. By default, OpenAI uses global infrastructure, and it cannot be guaranteed that processing (inference) takes place exclusively in the EU. We are currently negotiating an "EU data residency" regime.
3. Who has access to the data during the 30-day retention period? Do OpenAI employees have access to it? Does OpenAI use further sub-processors?+
These aspects are governed by the GDPR agreement (DPA) with OpenAI. The document is available for download here.
4. Do you support sign-in via SSO connected to Microsoft Entra ID (Active Directory)?+
Yes, we can. We use Keycloak to ensure maximum security; Microsoft Entra ID can be used as an external IdP.