Fault reports may contain contact data, location information and internal operating details. Before a pilot, operators should understand how customer data is separated, who may access it and how long it is retained.
Tenant separation is one control
OUTAG3 associates cases with a tenant and limits queries to that context. Roles and permissions are intended to restrict which people within the operator team can view or change data. These controls reduce the risk of unintended mixing, but they do not make a system immune to every failure or attack.
Questions to include in due diligence
Operators should clarify at least:
- Which data is collected during intake?
- Which roles can access cases and configuration?
- Which retention and deletion periods apply?
- Which processing agreements and subprocessors are relevant?
- How are access and security incidents logged and handled?
- Which integrations transfer data to other systems?
The answers depend on the specific pilot configuration. Product information can support the review, but it does not replace individual legal or security assessment.
AI does not move the responsibility boundary
AI structures and classifies reports within the intended workflow. The operator team makes the decision about refunds, callbacks, field work and closure. Sensitive information should only be collected when it is needed for the case.
The product overview describes the process-level data flow. The glossary explains tenant and triage, and the FAQ covers privacy and retention. Roles and periods can be scoped before a pilot request.