AI at oboloo

AI that summarises. People decide.

This page explains where oboloo uses artificial intelligence, what data is involved, the commitments we make and the controls you have. It is written for customers, their security and data protection teams, and suppliers who use the Supplier Portal.

Supplier record Your data Only on request OpenAI Primary model Anthropic Fallback model AI SUMMARY Reviewed by a person in your organisation Never used for training Deleted within 30 days
Where we use it

Where oboloo uses AI.

Two features today. Both are listed here with the data involved, and new ones are added to this page when they launch.

AI summaries

Produces a plain-language summary of a record and its recent activity so you can get up to speed quickly. Available in Suppliers, Sourcing, Contracts and Savings.

Users on a Plus Plan or a 14-day Trial, with access to the record
MCP server

Lets you connect an AI assistant you already use (ChatGPT, Microsoft Copilot or Claude) so it can answer questions about your oboloo data.

Customers who choose to set it up

AI never makes the decision.

AI is never used to approve or reject a supplier, award a sourcing event, approve a saving or make any other decision in oboloo. Those actions are always taken by a person in your organisation.

Security questionnaire answers

We add AI features over time. New features are listed here when they launch, with the same information as above.

Data

What we send, and what we do not.

Nothing leaves oboloo in the background. A record is sent when a user runs an AI feature on it, and only that record.

Sent to the provider
What we send
  • Only on request.Data is sent to an AI provider only when a user runs an AI feature, and only the content of the record that feature needs. We do not send your database to a provider in bulk or in the background.
  • What is sent.The text fields, notes and activity of the record being summarised and, where the feature uses them, the documents attached to it.
Never leaves oboloo
What we do not
  • What is not sent.Your login credentials, payment details, or any record the user does not have permission to see.
  • Training.Neither OpenAI nor Anthropic uses data sent through their APIs to train their models, and we do not opt in to data sharing with either.
Providers

OpenAI (GPT models) and Anthropic (Claude models), through their APIs. We use one as the primary model and the other as a fallback if it is unavailable. Both are listed in Annex 3 of our Data Processing Agreement, and we give at least 30 days’ notice before adding or changing a provider, as set out in the DPA.

Retention

Both providers may retain API inputs and outputs for up to 30 days for abuse and safety monitoring, after which they are deleted.

Where

Both providers process API requests on their global infrastructure, primarily in the United States.

Commitments

What we promise.

Six commitments that apply to every AI feature in oboloo, today and as we add more.

No training on your data

We do not use Customer Data to train AI models, and we do not allow our providers to do so.

People decide

AI output is a summary or a draft for a person to review. No AI feature in oboloo makes a decision that has legal or similarly significant effects on anyone.

Clearly labelled

AI-generated content is labelled as such in the product.

Minimum data

We send only what the feature needs, only when it is used.

Same security

AI features run under the same access controls, encryption and monitoring as the rest of the platform. Your role and record-level permissions apply.

Transparency

Provider, region and retention are published here and in the DPA, and we update this page when they change.

Check before you act.

AI output can be wrong, incomplete or out of date. Review it before relying on it, particularly figures, dates and anything you will share with a supplier.

How we keep data safe
Your controls

You decide who uses it.

AI access sits inside the same role-based permissions you already use to run oboloo.

Who can use it

AI features are controlled through user roles and access rights (RBAC). Administrators decide which roles can use them and can remove access for some or all users. There is no separate organisation-wide switch.

Permissions apply

A user can only summarise records they can already see.

Suppliers

AI features are not available in the Supplier Portal, and suppliers are not shown AI output about themselves.

Your own policy

If your organisation restricts the use of AI tools, remove the permission from your roles, or contact support@oboloo.app and we will help you set this up.

Bring your own assistant

Connecting your own AI assistant (MCP server).

Our MCP server lets you connect an assistant you already use, such as ChatGPT, Microsoft Copilot or Claude, so it can read your oboloo data in response to your questions. Before you do:

  • It runs under your account with that provider. The provider’s terms, retention and training policies apply to anything the assistant reads. oboloo is not responsible for how the provider handles it.

  • The connection uses an API key tied to a named user, so the assistant can only see what that user can see. Use a key with the least access you need and revoke it when it is no longer required.

  • Your organisation’s own AI policy should cover this. Many organisations restrict which assistants may be connected to business systems.

  • Setup guides are in the Help Centre at help.oboloo.com under AI & MCP Server.

Your assistant → oboloo MCP server Your assistant ChatGPT · Copilot · Claude Your account, your provider oboloo MCP server API key tied to a named user Least access. Revoke any time. THE ASSISTANT SEES ONLY WHAT THAT USER SEES Suppliers and contracts in their remit Readable by the assistant Records outside their permissions Never returned The Supplier Portal No AI features at all
Security and compliance

Where this sits in our compliance.

AI providers are sub-processors under our DPA, and AI features are covered by the same controls as everything else.

01
Data protection

AI providers are sub-processors under our Data Processing Agreement. Processing is on your instructions, and the DPA’s security, breach notification and deletion commitments apply.

02
UK GDPR Article 22

oboloo does not carry out solely automated decision-making that produces legal or similarly significant effects.

03
EU AI Act

Our AI features are productivity tools (summaries and assistance) and are not used for any purpose listed as high-risk. We label AI-generated content and keep our position under review as guidance develops.

04
Internal use

oboloo staff use AI tools only under our internal AI use policy: approved tools, business accounts, and no customer data in personal or unapproved tools.

05
Security

AI features are covered by the same penetration testing, access controls and monitoring described at oboloo.com/data-and-security.

Quick answers

For your security questionnaire.

The ten questions we are asked most often, answered. We answer full questionnaires on request.

Yes. AI summaries for users on a Plus Plan or a 14-day Trial, and optionally an assistant you connect yourself through our MCP server.
OpenAI (GPT models) and Anthropic (Claude models), through their APIs, one as primary and one as fallback. Both are listed in Annex 3 of our DPA.
No. Neither provider trains on API data, and oboloo does not opt in to data sharing.
On the providers’ global infrastructure, primarily in the United States.
Up to 30 days for abuse and safety monitoring, then deleted. Never used for training.
Yes, per user or per role through RBAC. There is no single organisation-wide switch.
Yes. All decisions are taken by your users. AI output is labelled and is a draft for review.
No.
None.
Only the record a user asks to summarise, at the moment they ask. Nothing in bulk or in the background.
Questions about AI at oboloo?
Email support@oboloo.app with the subject line “AI”. We answer security questionnaires on request.

Version 1.0 · October 2026 — first published.