Legal
AI Data Use Statement
Last updated: 30 June 2026
This AI Data Use Statement explains, in plain English, how SyftOS uses artificial intelligence and customer data to provide digital worker, workflow and automation functionality. It should be read alongside the SyftOS Terms of Service, Privacy Notice, Data Processing Agreement and Sub-processor List.
1. Purpose
This AI Data Use Statement explains how SyftOS uses artificial intelligence, machine learning models and related processing to provide the SyftOS platform.
SyftOS is operated by Techshift Digital Ltd, company number 15218025, registered office 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH.
For most content processed within a customer workspace, Techshift acts as processor on the customer’s behalf (see the Data Processing Agreement). For account, billing, support and website data, Techshift acts as controller (see the Privacy Notice). The aim of this document is to make SyftOS AI processing clear, practical and transparent for customers, users, design partners and prospective customers.
2. Plain-English summary
| Question | SyftOS position |
|---|---|
| Does SyftOS use AI? | Yes. SyftOS uses AI models to power digital workers, workflows, summaries, drafts, analysis, classification and recommendations. |
| Does SyftOS replace human approval? | No. SyftOS is designed around governed actions and human approval, especially where actions affect external systems or customer data. |
| Does Techshift train its own models on customer workspace content? | No. Techshift Digital Ltd does not use customer workspace content to train Techshift-owned models. |
| Do the AI providers train their models on our data? | No. The AI providers process data under their standard API terms, which do not use data submitted through their APIs to train their models. |
| Can third-party AI providers process customer data? | Yes, where needed to provide the service. The exact provider and processing depends on the feature and configuration. |
| Are AI outputs guaranteed to be accurate? | No. AI outputs may be incomplete, incorrect or unsuitable. Customers remain responsible for reviewing and using outputs. |
| Can customers choose what data to connect? | Yes. Customers control which integrations, documents, workflows and data sources they connect or configure within SyftOS. |
3. How SyftOS uses AI
SyftOS may use AI to help customers create, configure, run and manage digital workers, workflows, departments, assistants and governed actions.
AI functionality may be used for:
- summarising messages, documents, tickets, tasks, customer records or other connected data;
- classifying, routing, prioritising or extracting information;
- drafting messages, reports, replies, notes, content or proposed updates;
- analysing business information, workflows, integration data or customer-provided context;
- generating recommendations, proposed actions or next steps;
- supporting digital workers and workflow steps;
- assisting with configuration, onboarding, documentation or product usage.
SyftOS supports human users and is not a substitute for human responsibility for business decisions. It is not designed to act without human oversight.
4. Data that may be processed by AI
The data processed by AI depends on how the customer configures SyftOS, which integrations are connected, which workflows are run and which digital workers are enabled.
AI processing may include:
- prompts and instructions entered by users or configured in workflows;
- workspace configuration, agent configuration and workflow context;
- uploaded documents, excerpts or extracted content;
- connected integration data selected for a workflow, such as messages, tasks, tickets, CRM records, email content, documents or finance records;
- previous workflow outputs, summaries, approvals, rejections or audit context where relevant;
- technical metadata needed to provide, monitor, secure or improve the service.
SyftOS sends only the data reasonably needed for the relevant workflow, digital worker or feature. Customers should avoid connecting or submitting unnecessary sensitive data.
5. Third-party AI model providers
SyftOS uses third-party AI model providers to process prompts, context, documents, connected data and outputs where required to provide AI functionality.
| Provider | Use in SyftOS |
|---|---|
| Anthropic | Default AI model provider for workflows, summaries, drafting, analysis, classification, digital worker outputs and assistant functionality. |
| OpenAI | Optional models, plus embeddings (retrieval), web search and voice (speech-to-text / text-to-speech) where enabled. |
The providers used may change over time as SyftOS evolves or as model capability, cost, security or availability change. The current providers, their processing locations and the applicable transfer safeguards are set out in the SyftOS Sub-processor List, and Techshift will give advance notice of new or replacement providers in accordance with the Data Processing Agreement.
These providers process data under their standard API terms, which do not use data submitted through their APIs to train their models. Where a provider offers it, SyftOS can be configured to request zero data retention for a tenant.
Where the web search feature is enabled, the search query (which may include workspace content) is sent to the search provider and used to retrieve results from external sources on the internet. The relevant recipients and safeguards are set out in the SyftOS Sub-processor List and Privacy Notice.
6. Model training and customer data
Techshift Digital Ltd does not use customer workspace content to train, fine-tune or develop Techshift-owned models.
Where SyftOS uses third-party AI model providers, the provider processes submitted data under its standard API terms; for the current providers, data submitted through their APIs is not used to train the providers’ models. Provider data retention, security and any zero-retention options are as set out in the provider’s terms and the SyftOS Sub-processor List.
Any feature that builds memory, summaries, document context or retrieval indexes (see section 7) operates within your workspace to improve continuity and usefulness for you. It does not involve training Techshift-owned models, or the providers’ models, on your content.
7. Prompts, outputs, logs, memory and audit records
SyftOS may store prompts, instructions, workflow inputs, workflow outputs, approvals, rejections, run metadata, audit events and related records so that customers can understand what happened, review decisions, debug workflows and maintain governance.
Depending on the customer configuration, SyftOS may also maintain memory, summaries, document context or knowledge retrieval indexes to improve the usefulness and continuity of digital workers and workflows. As noted above, these features operate within your workspace and do not train any models on your content.
Audit records may be retained for governance, security, accountability, contractual and evidential purposes. SyftOS maintains an append-only, tamper-evident audit trail, so customers should not assume audit records can be freely edited or removed.
8. Human approval and governed actions
SyftOS is designed around governed automation. Where an AI-generated action may affect external systems or customer data, the action is approval-gated unless the customer has explicitly configured permitted automation.
Examples of approval-gated actions include sending messages, updating records, creating tasks, changing CRM data, posting to collaboration tools, triggering finance workflows, modifying project management systems or taking actions in connected third-party tools.
Customers remain responsible for reviewing AI outputs, checking proposed actions and deciding whether to approve, reject, edit or use them.
SyftOS is not designed to be used to take decisions that produce legal effects concerning an individual, or that similarly significantly affect them, based solely on automated processing without meaningful human involvement. Where a customer configures automated workflows, the customer is responsible for ensuring any automated decision-making complies with data protection law, including Article 22 of the UK GDPR and the provision of human review where required. SyftOS should not be used as the sole decision-maker for legal, financial, medical, employment, regulatory, safety-critical or other high-risk decisions unless a suitable written agreement, human oversight process and risk assessment are in place.
9. Connected integrations
Customers may connect third-party systems to SyftOS, such as Slack, Google Workspace, Microsoft 365, GitHub, Jira, Teamwork, HubSpot, Stripe, Xero or other supported tools.
When a customer connects an integration, SyftOS may read, process, analyse, summarise, draft, propose actions or take approved actions using data from that connected system.
Customers are responsible for ensuring they have authority to connect each third-party system, grant permissions, process the data and allow SyftOS to perform the configured workflows.
The data sent to AI models may include excerpts, records, messages, files, metadata or summaries from connected integrations where needed for the relevant workflow.
10. Sensitive and high-risk data
Customers should be careful when using SyftOS with sensitive, confidential, regulated, special category or high-risk data.
Unless expressly agreed in writing, customers should not use SyftOS to process:
- special category personal data or criminal offence data where this has not been assessed;
- medical, clinical, diagnosis or treatment data;
- children’s data or safeguarding information;
- financial, legal, employment, insurance, credit or regulatory decisions without appropriate human review;
- secrets, credentials, passwords, private keys or unnecessary authentication tokens;
- data that the customer does not have permission to process or disclose to SyftOS.
If a customer needs to process sensitive or regulated data through SyftOS, this should be discussed and documented before use.
11. International processing
SyftOS’s core application and data are hosted in the United Kingdom. AI model providers and certain operational providers may process data in the United States or other jurisdictions, depending on the provider, customer configuration and feature used.
Where personal data is transferred internationally, those transfers are handled under appropriate safeguards (such as the UK Addendum to the EU Standard Contractual Clauses) in accordance with the SyftOS Data Processing Agreement and applicable data protection law. The SyftOS Sub-processor List sets out each provider’s location and transfer safeguard.
12. Security and access
SyftOS uses technical and organisational measures designed to protect customer data and AI processing. These include tenant isolation, role-based access controls, approval controls, append-only audit logs, encrypted storage of integration secrets, access restrictions and monitoring. Further detail is set out in the SyftOS Security and Trust Statement.
Access to customer data by Techshift Digital Ltd personnel is limited to what is reasonably necessary for support, security, maintenance, troubleshooting, onboarding, compliance or providing the service.
Customers should configure users, roles, integrations and permissions carefully and should remove access when users leave or no longer require access.
13. Customer responsibilities
Customers are responsible for:
- checking AI outputs before relying on them;
- approving, rejecting or editing proposed actions where approval is required;
- ensuring connected systems and data sources are authorised;
- configuring workflows, agents, permissions and integrations appropriately;
- avoiding unnecessary sensitive or high-risk data;
- ensuring their own privacy notices, policies and contracts cover their use of SyftOS;
- training their users to understand the limits of AI-generated outputs.
14. Changes to AI providers or processing
Techshift Digital Ltd may update the AI providers, models, processing methods, safety controls, integrations or data handling processes used by SyftOS from time to time.
Where a change materially affects customer data processing, Techshift Digital Ltd will update the relevant documentation and provide notice where required by the Terms of Service, Data Processing Agreement or applicable law.
15. Questions and contact
Questions about this AI Data Use Statement can be sent to privacy@syftos.com (interim fallback: mathew@techshift.digital).
16. Legal entity details
| Item | Details |
|---|---|
| Legal company name | Techshift Digital Ltd |
| Company number | 15218025 |
| Registered office | 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH |
| Registered in | England and Wales |
| Product | SyftOS |
| Website | https://syftos.com |