Privacy notice
This notice covers the MSP AI Gateway at mspai.acidni.net, including its plugin for ChatGPT, Codex and
other AI assistants. Acidni's general privacy policy also applies. Where the two
differ for this service, this notice is the more specific one.
What the gateway does
It lets a managed service provider (MSP) and its clients use AI assistants with the business systems their organisation has connected. Those systems include ticketing, remote monitoring, documentation and accounting. The gateway sits between the assistant and those systems. It checks who is asking and what their role allows, then passes on the request.
What we store
- Organisation records. The organisation's name, a contact email address, and the Microsoft Entra directory ID or Google Workspace domain its staff sign in with.
- People and roles. The email addresses administrators grant roles to, and the name, email address and directory identifier from your Microsoft or Google sign-in. We never receive your Microsoft or Google password.
- Connector credentials. Administrators enter these (API keys, for example) on a secure form on this site, never in an AI chat. They are encrypted at rest and can be written but never read back out: not by staff through the console, and not by an AI assistant. Credentials for systems inside a customer's own network stay on that customer's gateway and are not sent to us.
- Audit records. For every request: who made it, which tool, when, whether it was allowed, and summary figures such as a record count and the time taken. Audit records do not contain the content of requests or results.
- Operational logs. Faults the gateway itself hits, so they can be fixed.
- Billing. Subscription status. Card payments are handled by Stripe and we never see card numbers.
Site analytics
The web pages on this site use Microsoft Clarity and Google Analytics to understand how they are used: which pages are visited, where people click and scroll, and (Clarity only) recordings of those interactions. On every page, text typed into a form field is masked. On the console, approval and chat pages the whole page is masked in Clarity recordings, so none of their text is captured. Pages whose address carries a one-time link or sign-in details, such as credential set-up links and the sign-in consent page, load neither tool. Google Analytics receives page paths without their query strings, and Google signals and ad personalisation are turned off. Both tools set cookies to recognise a returning browser; Microsoft and Google process this data under their privacy statements (Microsoft, Google). Requests an AI assistant makes to the gateway are not tracked by either tool.
What we do not store
We do not store your conversations with your AI assistant. The gateway relays data between your systems and the assistant you are using, at your request. It does not keep a general copy of that data. Features your organisation turns on that exist to keep work, such as handoffs between technicians and ticket analytics, keep what they need inside your organisation's tenant.
AI assistants
When you use the gateway from an AI assistant, whatever the gateway returns is sent to that assistant's provider (for example OpenAI or Anthropic). It is then handled under your agreement with that provider. Administrators decide which systems, and which operations on them, each role may use. Actions that change data can be set to wait for an administrator's approval.
Separation between organisations
Each organisation's records, credentials and audit trail are kept to that organisation. One MSP cannot see another's, and a client's staff see only what their MSP has made available to them.
Where it runs
The gateway runs on Microsoft Azure. Its data is encrypted in transit and at rest.
Your choices
- Administrators can remove credentials, users and organisations, and can sign every AI session for a person out at once.
- You can disconnect the plugin from your AI assistant at any time. Your organisation's administrator can revoke access from the gateway's side.
- To request a copy or deletion of information about you, email privacy@acidni.net. If your MSP administers your account, you can also ask them.
Contact
Acidni LLC · privacy@acidni.net · support