AI & data protection at narratiQ
How we protect your manuscripts – technically, contractually, and legally.
No AI training with your data
narratiQ uses the OpenAI business API – not the ChatGPT app. The difference is crucial: with private ChatGPT accounts, inputs can be used to train new models by default. For the business API, OpenAI contractually excludes this.
OpenAI states in its data protection commitments for business customers:
"We do not train our models on your business data by default."
– OpenAI Enterprise Privacy
This means: No manuscript you analyze through narratiQ feeds into the training of GPT models or other AI systems.
Where your data is processed
We are transparent about what happens where: the narratiQ application runs in Frankfurt (EU). For data storage and AI processing we use specialized US providers – secured by data processing agreements and EU Standard Contractual Clauses (Art. 46 GDPR).
All subprocessors are disclosed in our DPA. Processing thus meets the GDPR requirements for data processing agreements (Art. 28) and third-country transfers (Art. 44 et seq.).
- Application hosted in Frankfurt (EU)
- Third-country transfers secured by EU Standard Contractual Clauses
- DPA under Art. 28 GDPR, all subprocessors disclosed
Deletion and data subject rights
OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring and deletes them afterwards, unless legally required to retain them. Your manuscripts and analyses at narratiQ remain until you delete them – and are deleted at the end of the contract at the latest. Additionally, data subjects (authors) have the following GDPR rights at any time:
- Right to erasure (Art. 17 GDPR) – immediate deletion on request
- Right of access (Art. 15 GDPR) – what data is stored
- Right to data portability (Art. 20 GDPR) – export of own data
These rights can be exercised at any time through the publisher or directly with us.
Roles and responsibilities
Under the GDPR, roles are clearly defined:
Publisher
Data controller (Art. 4 No. 7 GDPR) – decides on processing
narratiQ
Data processor (Art. 28 GDPR) – processes on behalf of the publisher
Author
Data subject – has GDPR rights regarding their own data
Every publisher receives a data processing agreement (DPA) under Art. 28 GDPR that governs all details.
AI processing in detail
narratiQ uses the OpenAI API for business customers – separate from the ChatGPT consumer world. The platform provides:
- SOC 2 Type 2 audited security controls
- Encryption: AES-256 at rest, TLS 1.2+ in transit
- Data Processing Addendum (DPA) with EU Standard Contractual Clauses
At OpenAI, access to stored API data is limited to authorized employees for support, abuse monitoring and legal obligations.
Complete OpenAI data protection documentationSummary
Not a marketing promise – implemented technically and committed contractually.
- No AI training with your manuscripts (contractually committed)
- Clear contracts: DPA + EU Standard Contractual Clauses, subprocessors disclosed
- AI processing data deleted after 30 days at the latest + GDPR right to erasure
- Data processing agreement (DPA) for every publisher
- SOC 2 Type 2 audited AI infrastructure, AES-256 + TLS