Data Handling · Plain language

How ChainSpark handles your data. Six statements. No legal jargon.

This page states, in plain language, how ChainSpark handles data in our engagements. The full legal terms are in the MSA. If there is any conflict between this page and the MSA, the MSA governs.

01
We work inside your environment. We do not take data out of it.
ChainSpark practitioners work within your organization's environment during the engagement. We do not extract, copy, or process your operational data on external systems. Discovery sessions are conducted under NDA from day one of the engagement relationship — before any access to your systems or data occurs.
02
You own everything produced during the engagement.
Foreground IP — every workflow, configuration, prompt, integration, and document produced specifically for your environment during an engagement — is yours. ChainSpark retains rights only to background IP: the methodologies, frameworks, and deployment patterns we bring to every engagement. This distinction is explicit in the MSA.
03
We do not sell, share, or use your data to train AI models.
Information you provide during discovery sessions, assessments, or engagements is used only to design and deliver the engagement. It is not shared with third parties, used in marketing, or used to train AI models. Your business information is yours.
04
The AI capabilities we deploy process data in your tenancy, not ours.
Every capability ChainSpark builds is deployed in your Microsoft 365 tenancy (or equivalent) — under your authentication model, your data governance policies, and your security controls. Your data does not leave your environment to reach the AI layer. Data residency is determined by your tenancy configuration, not by ChainSpark.
05
Assessment and audit information is confidential.
Information gathered during the Spark Audit or any pre-engagement assessment is treated as confidential. It is not shared externally, used in case studies, or referenced in marketing without your explicit written permission. If you request anonymized benchmarking against other organizations, we tell you what data we would use before we use it.
06
The MSA governs. This page summarizes it.
ChainSpark's Master Services Agreement contains the binding legal terms that govern data handling, IP ownership, confidentiality, and liability. The MSA is reviewed and agreed before any paid engagement begins. This page is a summary for readability — not a legal document. If there is any conflict between this page and the MSA, the MSA governs.
Common questions
Who is the data controller for data processed by the AI capabilities you build?
You are. ChainSpark builds capabilities that process data within your environment, under your governance controls. We act as a data processor during the build phase of the engagement — accessing your systems solely to configure and test the capability. Once deployed, the capability operates under your control entirely.
Do the AI models you use learn from our data?
The AI capabilities we build use large language models deployed through your tenancy. The configuration of data retention and model training is governed by the underlying platform provider's terms — typically Microsoft (for Copilot Studio deployments) or Anthropic (for Claude-based deployments). In both cases, enterprise agreements are available that explicitly prohibit the use of your data for model training. We document the applicable configuration in the governance pack for every deployment.
What happens to our data if the engagement ends?
The capabilities built for your environment continue to run in your environment after the engagement ends — they are yours. Any ChainSpark practitioner access to your systems is revoked at engagement close. Discovery notes and engagement documentation are retained by ChainSpark in accordance with the confidentiality terms in the MSA and applicable law.
Is ChainSpark CCPA or GDPR compliant?
ChainSpark's engagement practices are designed to support client compliance with applicable privacy regulations, including CCPA and GDPR. Whether a specific engagement satisfies a specific regulatory requirement is a determination your qualified legal and compliance advisors must make — we produce the documentation to make that determination straightforward.
The full legal terms
ChainSpark Master Services Agreement
The MSA contains the binding terms for every engagement — IP ownership, confidentiality, data rights, liability, and dispute resolution. Reviewed and agreed before the first paid engagement begins.
Read the MSA →