DPOia is the artificial intelligence of the DPO Privacy platform. This page describes what it does, which providers it uses, what is sent and what is stored. Each piece of information was verified on the platform itself.
This is a courtesy translation. In case of any discrepancy, the Portuguese version prevails.
What DPOia does
Suggests answers when filling in the personal data inventory (RoPA).
Helps draft the description of a processing activity.
Extracts information from attachments and interview transcripts into the form.
Reviews the compliance of the inventory and points out inconsistencies.
Answers questions from the DPO in a support chat.
What it does not do
It does not save anything without a person's acceptance: every suggestion is reviewed before it enters the record.
It does not make decisions about data subjects.
Write requests made by external AI agents through the API remain pending until approved by an administrator or the DPO.
When it is used
It comes turned off. The organization contracts the feature and decides whether to enable it.
In the RoPA form, each person turns on the assistance whenever they want, and the choice applies only in that browser.
The features are restricted to the DPO, administration, management and analysis profiles; the extraction of attachments and transcripts, to the DPO and the administrator.
The chat and the suggestions have a monthly usage limit per organization.
Sending to the provider only happens when someone triggers a feature.
AI providers
OpenAI, L.L.C. (United States) is the default provider, with the gpt-4o-mini model.
Anthropic, PBC (United States) is used when the organization chooses it.
The organization may use its own access key to the provider.
The reference search always converts texts into vectors through OpenAI, even when the organization chooses Anthropic.
What is sent to the provider
Suggestions and review: process data and the context the organization has registered. Before sending, CPF (Brazilian individual taxpayer number), email, phone number, credentials and names identified by a label (such as "titular:") are masked.
Chat: the message and the latest messages of the conversation, with CPF, email and phone number masked. Platform information consulted to answer is sent as it is.
Extraction from attachments and transcripts: the full text of the document, without masking. We recommend not attaching personal data that is not necessary.
What is stored
Summary log of conversations (short excerpts, already masked): configured to be deleted after 90 days.
Interview transcripts: 30 days by default, a period the organization can adjust between 1 and 365 days.
Context attached to an activity: configured to be deleted after 30 days.
Drafts: 24 hours (voice and document) or 7 days (assistants).
AI memories: for the period the organization defines.
Decisions on suggestions (acceptance, adjustment or rejection): kept as the organization's audit trail.
AI Governance
Those who use DPOia are also accountable for it
The organization that uses DPOia can register it in its own AI inventory, in the AI Governance module, which is included in all plans. The record arrives already filled in with the information on this page and goes into review: the risk classification, the owners and the approval remain with the organization.
For information on the platform's security, see the Security page. For information on the processing of personal data by DPO Privacy, see the Privacy Policy.