AI & data protection at narratiQ

How we protect your manuscripts – technically, contractually, and legally.

No AI training with your data

narratiQ uses the OpenAI business API – not the ChatGPT app. The difference is crucial: with private ChatGPT accounts, inputs can be used to train new models by default. For the business API, OpenAI contractually excludes this.

OpenAI states in its data protection commitments for business customers:

"We do not train our models on your business data by default."

OpenAI Enterprise Privacy

This means: No manuscript you analyze through narratiQ feeds into the training of GPT models or other AI systems.

Where your data is processed

We are transparent about what happens where: the narratiQ application runs in Frankfurt (EU). For data storage and AI processing we use specialized US providers – secured by data processing agreements and EU Standard Contractual Clauses (Art. 46 GDPR).

All subprocessors are disclosed in our DPA. Processing thus meets the GDPR requirements for data processing agreements (Art. 28) and third-country transfers (Art. 44 et seq.).

  • Application hosted in Frankfurt (EU)
  • Third-country transfers secured by EU Standard Contractual Clauses
  • DPA under Art. 28 GDPR, all subprocessors disclosed

Deletion and data subject rights

OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring and deletes them afterwards, unless legally required to retain them. Your manuscripts and analyses at narratiQ remain until you delete them – and are deleted at the end of the contract at the latest. Additionally, data subjects (authors) have the following GDPR rights at any time:

  • Right to erasure (Art. 17 GDPR) – immediate deletion on request
  • Right of access (Art. 15 GDPR) – what data is stored
  • Right to data portability (Art. 20 GDPR) – export of own data

These rights can be exercised at any time through the publisher or directly with us.

Roles and responsibilities

Under the GDPR, roles are clearly defined:

Publisher

Data controller (Art. 4 No. 7 GDPR) – decides on processing

narratiQ

Data processor (Art. 28 GDPR) – processes on behalf of the publisher

Author

Data subject – has GDPR rights regarding their own data

Every publisher receives a data processing agreement (DPA) under Art. 28 GDPR that governs all details.

AI processing in detail

narratiQ uses the OpenAI API for business customers – separate from the ChatGPT consumer world. The platform provides:

  • SOC 2 Type 2 audited security controls
  • Encryption: AES-256 at rest, TLS 1.2+ in transit
  • Data Processing Addendum (DPA) with EU Standard Contractual Clauses

At OpenAI, access to stored API data is limited to authorized employees for support, abuse monitoring and legal obligations.

Complete OpenAI data protection documentation

Summary

Not a marketing promise – implemented technically and committed contractually.

  • No AI training with your manuscripts (contractually committed)
  • Clear contracts: DPA + EU Standard Contractual Clauses, subprocessors disclosed
  • AI processing data deleted after 30 days at the latest + GDPR right to erasure
  • Data processing agreement (DPA) for every publisher
  • SOC 2 Type 2 audited AI infrastructure, AES-256 + TLS

Cookie settings

We use cookies to analyze website usage (Google Analytics). You can decide whether you want to allow this. Learn more