AI Data Handling
Home»AI Data Handling
How AI fits into the architecture
AI automation is one step inside a controlled workflow, not an open channel to a customer's data. This page explains that architecture directly, without overstating what any AI provider's terms guarantee.
The data flow
- Customer data
- BMaiKR application / workflow
- Controlled retrieval / context
- AI model, when required
- Response / action
- Controlled system
What this means in practice
- AI models are not automatically given unrestricted access to a customer’s full database.
- Customer information is minimized before it reaches a model — only what a specific task requires is supplied.
- Sensitive information is handled according to the customer’s configured architecture, not a one-size-fits-all rule.
- The AI provider used for a given service is documented so a customer knows which provider processes their data.
- Data retention and model-training policies vary by provider and must be verified against that provider’s own terms — BMaiKR does not assume a provider never trains on submitted data unless that provider’s terms confirm it.
AI processing modes
Which mode applies is a configuration decision made per project, documented as part of that engagement.
Controlled external AI
A third-party AI provider processes minimized, task-specific context supplied by the application layer.
EU-hosted / private model
Where a project requires it, a model can be deployed on EU-hosted infrastructure rather than a third-party API.
Customer-approved AI provider
A customer specifies which AI provider is acceptable for their workload, and the integration is built to that constraint.
No external AI
For workloads where no external AI processing is appropriate, automation is built without an AI step.
