Where your AI data goes: your provider, a DPA, and zero data retention.

8 min read·For engineers & IT teams·Updated Aug 2026

Every AI feature has the same uncomfortable property: to do its job, it sends your data to a model someone else runs. Two questions matter: where does that data go, and who may keep it? For our managed AI tier, the answer comes down to the provider, a data processing agreement (DPA), and zero data retention (ZDR). Here is what those safeguards do, how Anthropic, Mistral, and OpenAI differ, and how to choose.

The common foundation

A DPA: what they're allowed to do with your data

A data processing agreement (DPA, sometimes called a data processing addendum) is the contract that governs how a provider handles personal data on your behalf. Under GDPR it's the Article 28 agreement between a controller (us, deciding what happens to the data) and a processor (the AI provider, acting on our instructions). It's what lets you put a provider in your sub-processor list and stand behind that choice.

A real DPA binds the provider to a specific list:

  • Process only on instructions. They use your data to do the task you asked for, and nothing else.
  • No training on your data. Your inputs and outputs don't get folded into the next model version. On all three of our providers' APIs (Anthropic, Mistral, and OpenAI), that's contractual.
  • Security and breach duties. Defined technical measures, and an obligation to tell you when something goes wrong.
  • Sub-processor control. They can't quietly pass your data to a fourth party without the same duties flowing down.

We hold a DPA with every managed provider. But a DPA governs permission and obligation; it does not, by itself, mean the provider retains no data.

The retention layer

Zero data retention: making sure there's nothing to keep

Even a provider with a clean DPA and a no-training promise usually keeps your inputs and outputs for a short window, for abuse monitoring and debugging (a limited retention window, then deletion). That window is reasonable, and for most products it's fine. For a security register it's still some number of days of other people's findings sitting on a system we don't run, which is exposure to a breach, a legal demand, or an insider slip.

Zero data retention (ZDR) turns that window off. With ZDR on, the provider doesn't store or log your inputs or outputs beyond what it needs to generate the response. On our managed tier, Anthropic and Mistral carry ZDR; OpenAI does not. The provider sections below explain the other trade-offs, including processing location.

The key distinction

A DPA and ZDR are not the same thing

A DPA governs how your data is handled while it exists. ZDR minimises whether it exists at all. One is about conduct; the other is about retention.

DPAZero data retention
What it controlsHow your data is handled while it existsWhether your data is kept at all
The question it answersWhat are they allowed and required to do?Is anything stored after the response?
On its ownBound by contract, but data still sits ~30 daysNothing stored, but no contractual handle on conduct
Covers model trainingYes, no-training is a DPA clauseIndirectly: nothing is retained to train on later
On our managed tierIn force with all three providers (Anthropic, Mistral, OpenAI)Enabled on Anthropic (US) and Mistral (EU)

A DPA without ZDR still leaves data in a retention window. ZDR without a DPA gives you no contractual handle on how data is treated in flight. For sensitive findings, you want both.

The Epic Handshake meme: two muscular arms clasping hands, the grip labelled 'Your Data', the left arm 'DPA' and the right arm 'ZDR'.
DPA and ZDR, the muscles of data protection.
The one-liner

A DPA is the rules for the room. ZDR is not leaving anything in the room after you walk out. The three providers below give you a DPA; our managed Anthropic and Mistral accounts also carry ZDR.

Your options · the default

Anthropic: the default, for the sharpest output

Anthropic (Claude) is the default because on our own workload it is simply the sharpest: richer findings, tighter risk reasoning, and it follows instructions far more reliably than the alternatives.

Where it goes, and the terms. Requests are processed by Anthropic in the United States. They are covered by our DPA (every conduct guarantee in the list above) and Anthropic does not train on data submitted through its API.

It now carries ZDR too. Anthropic approved Zero Data Retention on our account, so inputs and outputs are not retained beyond generating the response. The remaining distinction is location: Anthropic processing is still in the US.

Pick Anthropic when

You want our sharpest output with DPA + ZDR protection and US processing fits your requirements. It's the default, so there is nothing to switch on.

Your options · EU residency

Mistral: the EU-residency option, with ZDR

Mistral is the EU-residency choice. A French company, models served from EU data centres, GDPR-native. If your findings must stay inside the EU, this is the one-click switch in Account settings, with the same features and output that trails Anthropic a little.

Its edge is retention. We hold both a DPA and a zero-data-retention agreement with Mistral. ZDR is not part of Mistral's standard terms. We asked for it, they approved it, and it is enabled on our account today. We don't store your prompts on our side, and Mistral doesn't store them on theirs.

A note on semantic matching

When enabled, semantic matching sends observation text to Mistral's stateless embeddings endpoint under the same ZDR agreement — on every plan and regardless of the provider used for generation. The resulting vectors are encrypted under your organisation's key in our EU-hosted database; switching semantic matching off deletes them. Read more in how we build with AI.

Pick Mistral when EU data residency or a zero-retention guarantee is non-negotiable (a regulated sector, GDPR-sensitive data, a customer commitment) and you can accept output a notch below the default. Your organisation owner flips it under Account → AI Integrations, and it takes effect on the next AI call.

Your options · the GPT alternative

OpenAI: the GPT option, without ZDR

OpenAI is the GPT choice — the option for organisations that standardise on OpenAI or simply prefer GPT's style. It runs on the GPT-5.6 family (Terra for the writing you read, Luna for bulk background work), and like the other two it is a one-click switch in Account settings.

Where it goes, and the terms. Requests are processed by OpenAI in the United States, covered by our DPA (every conduct guarantee in the list above), and OpenAI does not train on data submitted through its API.

OpenAI does not carry ZDR on our account. OpenAI's standard terms keep a limited retention window for abuse monitoring. If “nothing kept” is the requirement, choose Anthropic or Mistral.

Pick OpenAI when

Your organisation already standardises on OpenAI, or you prefer GPT-5.6's output for your findings, and US processing under a DPA (with no training on your data, but without ZDR) fits your risk appetite.

Choosing

Which one should you pick?

The common floor is the same whichever you pick: every managed call runs under a DPA (conduct), with no training on your data, and stateless on our side (no memory here). On top of that floor you pick the axis that matters most to you. Anthropic for the sharpest output, processed in the US with ZDR; Mistral for EU residency plus zero data retention, so your findings stay in the EU with nothing kept afterwards; or OpenAI when GPT is your house standard — US processing under a DPA, but without ZDR. Choose by the constraint you cannot compromise, and change it later in one click.

The honest trade-off

This is a genuine choice, not a default we are quietly nudging you away from. Anthropic wins on output with ZDR, Mistral adds EU residency to ZDR, and OpenAI is there when GPT is what your organisation runs on. And if you'd rather not run under our AI contract at all, you can bring your own key (OpenAI, Anthropic, or Mistral) and every generative AI call runs under your account and your terms instead of ours. Semantic-matching embeddings remain on a separate platform-managed Mistral path when enabled.

Takeaways

What to ask your own AI provider

You don't need our stack to use any of this. The questions travel. Next time you put a provider in front of real data, work down this list:

  • Where is it physically processed? Region decides which laws can reach your data. EU residency is a real differentiator, not a checkbox.
  • Is there a DPA, and is it actually in force? Some are incorporated by reference (live the moment you accept the terms); others need a signature or an admin-console click. Confirm which, don't assume.
  • Do they train on your data? On a paid API tier this is usually no by default, but verify it, and check there isn't a free-tier or labs exception that flips it back on.
  • What's the default retention, and can you get it to zero? Ask for the retention window, and whether ZDR is available on your plan.
  • Does ZDR cover the endpoints you actually call? It often applies only to stateless requests, not to agents, batch jobs, or stored conversations. Match it to your real usage.
  • Are you stateless on your own side too? Provider-side ZDR does nothing if you're quietly keeping prompt history yourself.