Pansophy AI Inc. is committed to protecting the privacy of your data. This Policy explains what data we collect, how we use it, and the controls you have over it. All data processed by the Second Opinion is stored and processed exclusively within the Microsoft Azure cloud infrastructure.

1. Information We Collect

Account and Identity Data

When you access the Software through Microsoft Teams, we receive your Microsoft Azure Active Directory / Entra ID identity information, including your name, email address, and tenant identifier. This information is used solely to authenticate your session and operate the Software.

Uploaded Documents

You submit documents to the Software for behavioral analysis. Supported file types are PDF, DOCX, TXT, and VTT (Microsoft Teams meeting transcripts). The uploaded file and the text extracted from it are held in session state during the active session and are discarded at session close. They are not written to persistent storage at any point.

Prior to analysis, extracted text is processed through Microsoft Azure AI Language to identify and redact personally identifiable information (PII), including names, email addresses, and phone numbers. The PII-redacted text is what reaches the scoring engine and the language model. The original un-redacted extracted text does not leave the PII-scrubbing step and is discarded at session close along with the uploaded file.

Derived Analytical Outputs

The Software produces numeric trait scores and a written narrative from the PII-redacted text. These derived outputs are retained by Pansophy AI past session close, as described in Section 6. They describe language patterns and do not contain the source text.

Usage Data

We collect session metadata used for product support and operations: session identifiers, timestamps, and word counts after PII scrubbing.

Support Communications

If you contact us for support, we collect the information you provide in that communication.

2. How We Use Information

We use the information we collect to:

We do not use your data to train third-party AI models. Customer data submitted to the Azure OpenAI Service is not used to train, retrain, or fine-tune any Microsoft or OpenAI model; this is contractually enforced by the Azure OpenAI Service terms.

3. How We Process Your Content

Processing Pipeline

Content submitted to the Software passes through a deterministic pipeline inside the Microsoft Azure tenant:

  1. The file is received through the Microsoft Teams bot channel and held in session state.
  2. Text is extracted from the uploaded file (by Azure AI Document Intelligence for PDF and DOCX, or by direct reader for TXT and VTT).
  3. Extracted text is passed to Microsoft Azure AI Language for PII detection and redaction. Detected PII is replaced with placeholder tokens.
  4. The PII-redacted text is passed to the behavioral scoring engine, which produces numeric trait scores.
  5. The scores and the PII-redacted text are passed to Azure OpenAI Service, which generates a written narrative.
  6. The narrative is returned to you in Microsoft Teams. The user may request rewrites of the narrative within the active session, which reuse the cached scores and PII-redacted text.
  7. At session close, the uploaded file, the extracted text, and the PII-redacted text are discarded. The derived trait scores and the written narrative are retained by Pansophy AI as described in Section 6.

What Is Retained and What Is Not

Pansophy AI applies a split retention model. Content you submitted (the uploaded file, the extracted text, the PII-redacted version of that text) is discarded at session close and is not written to persistent storage at any point. Content Pansophy AI produced from your submission (the trait scores and the written narrative) is retained by Pansophy AI past session close, for the purposes described in Section 6.

A session ends when you explicitly close it, when you submit a new document for analysis, or after thirty (30) minutes of inactivity.

4. Demographic Data: What We Do Not Collect or Infer

Pansophy AI does not collect, process, or infer any demographic information about the subjects of uploaded content. This is an affirmative architectural design principle, not a policy limitation.

The behavioral analysis engine receives only anonymized word patterns. It has no access to and makes no inference about:

The analysis methodology counts and categorizes word usage patterns using a validated psycholinguistic lexicon. It does not know who wrote or spoke those words. No demographic inference is performed at any stage of processing: not during PII scrubbing, not during scoring, and not during narrative generation.

This architecture means Pansophy AI cannot build demographic profiles, cannot use proxy variables to infer protected characteristics, and cannot produce outputs that vary based on the identity of the speaker rather than the content of their language.

5. Data Storage and Residency

All data processed by Second Opinion remains within Microsoft Azure's United States data centers. Specifically, the product is deployed in the Azure East US 2 region, and no customer data is transmitted to infrastructure outside Microsoft Azure.

Second Opinion is currently available to Microsoft 365 tenants based in the United States, United Kingdom, Canada, Australia, New Zealand, and Singapore. Eligibility is enforced at the Microsoft AppSource listing level.

6. Data Retention

Pansophy AI applies a split retention model. Content that you submitted (and anything derived from it that could reconstruct the source) is discarded at session close. Content that Pansophy AI produced from your submission, as its own work product, is retained.

Discarded at Session Close

None of these are written to persistent storage at any point. They exist only in session state and are purged when the session ends.

Retained by Pansophy AI

These derived outputs are retained for legal defensibility, model refinement, and ordinary business operations. They describe language patterns rather than containing the source text, and PII was removed upstream of their creation.

Account Data

Session Close Triggers

A session ends when you explicitly close it, when you submit a new document for analysis, or after thirty (30) minutes of inactivity.

Deletion Requests

You may request deletion of data associated with your account at any time by contacting privacy@pansophyai.com. Valid requests are processed within seven (7) business days. Uploaded files and extracted text are not subject to deletion requests because they are already discarded at session close.

7. Data Sharing and Subprocessors

We do not sell, rent, or share your personal data with third parties for marketing or commercial purposes.

We share data only in the following limited circumstances:

All subprocessors operate under written agreements requiring them to process data solely on our behalf and under our instruction, and within the Microsoft Azure sovereignty boundary in the United States.

8. Security

Pansophy AI implements the following technical and organizational security measures:

While we implement industry-standard security measures, no system can guarantee absolute security. In the event of a data breach that affects your personal data, we will notify you and applicable regulatory authorities as required by law.

9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

To exercise any of these rights, contact us at support@pansophyai.com. We will respond to valid requests within thirty (30) days. We may require verification of your identity before processing requests.

10. Consent Responsibility

Important: You are solely responsible for obtaining any required consent from individuals whose words are contained in documents you submit to the Software for analysis. Pansophy AI does not obtain consent directly from the subjects of submitted documents. By submitting a document, you represent and warrant that you have obtained all necessary consents under applicable law.

11. Children's Privacy

The Software is designed for professional use. It is not directed at individuals under the age of 18. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us immediately at privacy@pansophyai.com.

12. International Users

The Software is operated from the United States and is currently available to Microsoft 365 tenants based in the United States, United Kingdom, Canada, Australia, New Zealand, and Singapore. All data processing occurs within the Azure East US 2 region regardless of the tenant's location. Eligibility is enforced at the Microsoft AppSource listing level.

If you access the Software from any of these supported regions, your data will be processed in the United States, subject to US law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated Policy at this URL with an updated effective date. For material changes, we will provide notice through the Software or by email. Your continued use of the Software after the effective date of any update constitutes your acceptance of the revised Policy.

14. Contact

For privacy inquiries, data subject requests, or to report a privacy concern:

Pansophy AI Inc.

privacy@pansophyai.com

pansophyai.com