This page explains where oboloo uses artificial intelligence, what data is involved, the commitments we make and the controls you have. It is written for customers, their security and data protection teams, and suppliers who use the Supplier Portal.
Two features today. Both are listed here with the data involved, and new ones are added to this page when they launch.
Produces a plain-language summary of a record and its recent activity so you can get up to speed quickly. Available in Suppliers, Sourcing, Contracts and Savings.
Users on a Plus Plan or a 14-day Trial, with access to the recordLets you connect an AI assistant you already use (ChatGPT, Microsoft Copilot or Claude) so it can answer questions about your oboloo data.
Customers who choose to set it upAI is never used to approve or reject a supplier, award a sourcing event, approve a saving or make any other decision in oboloo. Those actions are always taken by a person in your organisation.
We add AI features over time. New features are listed here when they launch, with the same information as above.
Nothing leaves oboloo in the background. A record is sent when a user runs an AI feature on it, and only that record.
OpenAI (GPT models) and Anthropic (Claude models), through their APIs. We use one as the primary model and the other as a fallback if it is unavailable. Both are listed in Annex 3 of our Data Processing Agreement, and we give at least 30 days’ notice before adding or changing a provider, as set out in the DPA.
Both providers may retain API inputs and outputs for up to 30 days for abuse and safety monitoring, after which they are deleted.
Both providers process API requests on their global infrastructure, primarily in the United States.
Six commitments that apply to every AI feature in oboloo, today and as we add more.
We do not use Customer Data to train AI models, and we do not allow our providers to do so.
AI output is a summary or a draft for a person to review. No AI feature in oboloo makes a decision that has legal or similarly significant effects on anyone.
AI-generated content is labelled as such in the product.
We send only what the feature needs, only when it is used.
AI features run under the same access controls, encryption and monitoring as the rest of the platform. Your role and record-level permissions apply.
Provider, region and retention are published here and in the DPA, and we update this page when they change.
AI output can be wrong, incomplete or out of date. Review it before relying on it, particularly figures, dates and anything you will share with a supplier.
AI access sits inside the same role-based permissions you already use to run oboloo.
AI features are controlled through user roles and access rights (RBAC). Administrators decide which roles can use them and can remove access for some or all users. There is no separate organisation-wide switch.
A user can only summarise records they can already see.
AI features are not available in the Supplier Portal, and suppliers are not shown AI output about themselves.
If your organisation restricts the use of AI tools, remove the permission from your roles, or contact support@oboloo.app and we will help you set this up.
Our MCP server lets you connect an assistant you already use, such as ChatGPT, Microsoft Copilot or Claude, so it can read your oboloo data in response to your questions. Before you do:
It runs under your account with that provider. The provider’s terms, retention and training policies apply to anything the assistant reads. oboloo is not responsible for how the provider handles it.
The connection uses an API key tied to a named user, so the assistant can only see what that user can see. Use a key with the least access you need and revoke it when it is no longer required.
Your organisation’s own AI policy should cover this. Many organisations restrict which assistants may be connected to business systems.
Setup guides are in the Help Centre at help.oboloo.com under AI & MCP Server.
AI providers are sub-processors under our DPA, and AI features are covered by the same controls as everything else.
AI providers are sub-processors under our Data Processing Agreement. Processing is on your instructions, and the DPA’s security, breach notification and deletion commitments apply.
oboloo does not carry out solely automated decision-making that produces legal or similarly significant effects.
Our AI features are productivity tools (summaries and assistance) and are not used for any purpose listed as high-risk. We label AI-generated content and keep our position under review as guidance develops.
oboloo staff use AI tools only under our internal AI use policy: approved tools, business accounts, and no customer data in personal or unapproved tools.
AI features are covered by the same penetration testing, access controls and monitoring described at oboloo.com/data-and-security.
The ten questions we are asked most often, answered. We answer full questionnaires on request.
Version 1.0 · October 2026 — first published.