Skip to main content

Enterprise AI Policy

Last updated: 7 September 2026

Northdocs ApS entity registration (CVR) is pending. These policies describe how the service operates today and are intended for customer due diligence. For a countersigned DPA or negotiated terms, contact legal@northdocs.com.

How optional AI features work, what you can disable, and that production inference uses OVHcloud AI Endpoints from the EU app. Related: Security Overview · Architecture · Subprocessors & third-party suppliers.

1. Summary

Northdocs uses AI optionally. You can run a production redaction workflow with AI off (on-platform deterministic detectors only) or with AI on (semantic detection, speech-to-text, and assist features via OVHcloud AI Endpoints), controlled by an organization administrator.

When AI / ML detection is disabled for an organization, Northdocs does not send document content, detection text, Outlook compose snippets, clipboard text, or audio to any AI provider. That includes identity linking, cover summaries, Magic Redact validation, rule suggestions, Prompt Guard names, Outbound Guard names, and Conversation Redact speech-to-text. Audio-only Conversation Redact uploads then require a WebVTT or SubRip sidecar.

Customer inference uses OVHcloud AI Endpoints from the EU-hosted Northdocs application. Northdocs engineering environments may use OpenAI for development against test data only, never for customer inference. Organizations cannot select a different production AI vendor.

2. What AI is used for (when enabled)

When AI detection is enabled for the organization, Northdocs may call OVHcloud AI Endpoints from the EU app for:

  • Semantic named-entity recognition (for example names, organizations, addresses, and health-related phrases)
  • Magic Redact filter validation
  • Identity attribute linking assists
  • Review accept/skip suggestions
  • Case cover summaries
  • Sample-based detection rule suggestions
  • Prompt Guard name and organization detection (when the reviewer turns AI assist on)
  • Outbound Guard person and organization names on Outlook cloud scan (when the org policy allows AI names)
  • Conversation Redact speech-to-text for audio without a WebVTT or SubRip sidecar

3. AI providers

OVHcloud AI Endpoints (production): OpenAI-compatible inference hosted by OVHcloud in the EU, called over HTTPS from the EU-hosted Northdocs application. Document snippets used for detection stay on this EU path when AI is enabled.

OpenAI (Northdocs development only): used in engineering environments against test data. Vendor selection is environment-driven and fails closed, so it is not used for customer inference.

Deterministic detectors for structured identifiers (including email, phone, IBAN, CPR-style national IDs, VAT, payment cards, and similar pattern/checksum categories) run on Northdocs infrastructure and do not require an AI provider.

4. Customer controls

Administrators and reviewers retain control over AI use and disclosure readiness:

ControlWhereEffect
Disable AI / ML detectionSettings → OrganizationNo document content, detection text, Outlook snippets, clipboard text, or audio is sent to any AI provider for that organization
Human reviewReview / Fast TrackRequired before trustworthy external disclosure; AI never auto-exports packs
Fail-closed verifyApply pipelineBlocks download if sensitive strings survive anywhere a reviewer did not deliberately keep them, independent of whether AI was used
Subprocessors register/subprocessorsPublic Article 28 list of Northdocs-engaged suppliers
Outbound emailScaleway TEMDoes not include document files, filenames, extracted text, detections, or case contents. AI features must not draft or fill TEM messages with that payload.

5. Provider retention

Customer AI requests go to OVHcloud AI Endpoints from the EU-hosted application, under the OVHcloud DPA. Northdocs does not send customer inference to OpenAI or Mistral.

If your organization prefers not to send document content, Outlook snippets, clipboard text, or audio to an AI provider at all, disable AI / ML detection under Settings → Organization. Conversation Redact then accepts chats, captions, and recordings that already include a WebVTT or SubRip sidecar.

Questions: support@northdocs.com.

6. Recommended configurations

PostureConfiguration
AI offDisable AI / ML detection; use on-platform detectors, human review, and fail-closed verify. For Conversation Redact audio, include a caption sidecar.
AI on (EU)Enable AI; traffic uses OVHcloud AI Endpoints from the EU app; keep Fast Track review and verify before export

7. DPIA notes (short)

  • Purpose: assist detection and review of personal data in documents, chats, and (when enabled) meeting audio the customer uploads for redaction, and optional send-time name detection in Outlook.
  • Roles: the customer is controller (or acts for a controller); Northdocs is processor for customer documents under the DPA.
  • Transfer: when AI is on, document content, optional Outlook snippets, and optional audio for speech-to-text are processed by OVHcloud AI Endpoints in the EU under the OVHcloud DPA.
  • Mitigations: organization AI kill-switch (including speech-to-text), EU-hosted inference, fail-closed export verification, configurable retention, human review before disclosure, and no document payload in transactional email.

8. Contact

Policy and contracting: legal@northdocs.com. Privacy: privacy@northdocs.com. Sales diligence: sales@northdocs.com. AI questions: support@northdocs.com.

Related pages: Security Overview · Architecture · Subprocessors · DPA.