Is Smart Fields running on an Enterprise API with a BAA and/or DPA that prevents the need for each customer to get consent from each employee, patient, and parent before extracting employee data, patient data, student demographics, etc?
Question
Question
Does Smart Fields require individual consent before processing personal data or is it covered?
Answer
Laserfiche AI uses the OpenAI API enterprise license and has a DPA in place. For more details, please see our Laserfiche AI FAQ
In this situation, Laserfiche is rather data agnostic. Laserfiche operates as a data processor, aligning with the EU's "data controller" and the US's "service provider" designations. In this capacity, we process data on behalf of our customers. Our customers bear the sole responsibility for ensuring their use of the Laserfiche Cloud operating environment complies with all applicable data privacy and other relevant laws concerning the data they provide and utilize with AI tools or otherwise. This includes establishing the lawful basis for processing such data. For more information, please see Laserfiche's Data Processing Agreement (DPA) available in each Laserfiche Cloud admin's Cloud Account or via email, upon request, to privacy@laserfiche.com. Also, you may refer to Laserfiche's Privacy Notice available at www.laserfiche.com/legal/privacy.