You own your data
Infrastructure code, prompts, generated artefacts and anything else you put into the platform remain yours. Using an AI feature doesn't transfer ownership of anything to Gabaltech or to the underlying model provider.
Your prompts remain private
Prompts and the context sent alongside them are used to serve your request and are not shared with other customers.
No training on your data without consent
We do not use customer prompts, source code or infrastructure data to train public AI models without your explicit, opt-in consent.
Minimal data collection
We send AI providers only what a given feature needs to function โ not your entire codebase or account history by default.
Data retention
AI interaction logs are retained only as long as needed for debugging, audit and abuse-prevention purposes, consistent with our general data retention practices.
Encryption
Data in transit to and from AI providers is encrypted (TLS). Stored logs and artefacts are encrypted at rest using AWS KMS, the same as the rest of the platform's data.
Regional processing where supported
Where our AI provider supports regional processing (for example, AWS Bedrock in eu-west-2), we default to keeping processing in-region rather than routing globally.
Compliance
Our data handling practices are designed to be consistent with UK GDPR principles โ data minimisation, purpose limitation, and a clear basis for processing.