Westover Digital Development LLC
AI and Data Processing Notice
This Notice explains where Gemini is used, what it may process, what it cannot decide, and how human review remains authoritative.
1. Division of responsibility
Explain product workflows, summarize bounded records, extract proposed facts with citations, identify possible gaps or conflicts, and suggest next steps.
Unit conversions, stored-input calculations, matching, reconciliation, completeness checks, and reproducible report generation.
Whether evidence supports a fact, whether to accept or reject proposals, methodology selections, approvals, and external actions.
Ambiguous producer identity, exemptions, contractual responsibility, disputed classifications, and legal or regulatory interpretation.
2. Public Gemini assistant
The public assistant may process a user’s question, bounded Westover EPR product knowledge, public regulatory educational material, and security metadata. It does not have access to private customer workspaces, approve records, or provide customer-specific legal advice.
3. Authenticated workspace Gemini
Authenticated features may receive an organization-scoped, server-prepared status snapshot and selected knowledge relevant to the page or question. The server—not the browser or model—determines organization identity and eligible context. Responses are explanatory and read-only unless a separately authorized workflow explicitly creates unconfirmed proposals.
4. Document extraction and proposals
When an authorized user selects an eligible private source document, the service may send the permitted document content and bounded extraction instructions to Gemini through Google Cloud Vertex AI. Output must conform to a structured schema and may include proposed values, confidence, missing information, contradictions, and source citations.
Every result remains “Proposed by Gemini—unconfirmed.” Gemini cannot write directly into approved packaging records. An authorized human must compare the proposal with its cited source and accept, correct and accept, reject, or request clarification.
5. Information sent and information withheld
Depending on the authorized operation, processing may include:
- the user’s question or selected source document;
- bounded organization, workflow, page, or target-record context;
- controlled taxonomies and field definitions;
- instructions requiring citations, null values, and fail-closed behavior; and
- technical metadata needed to operate and secure the request.
The system is designed not to send passwords, service credentials, signed storage URLs, unrelated tenant records, private payment-card information, or authority to approve facts.
6. Provider data practices
Westover EPR uses managed Gemini models through Google Cloud Vertex AI. Google states that customer data is not used to train or fine-tune managed AI models without permission or instruction. Google may apply limited in-memory caching, abuse monitoring, safety controls, and other processing under applicable Google Cloud terms. Westover EPR does not promise “zero retention” unless the applicable Google Cloud configuration has been separately verified for the operation.
7. Auditability and retention
We may retain execution ID, organization, user, model, prompt and schema version, input and output hashes, timestamps, status, token usage, sanitized error information, citations, proposals, and human dispositions. These records support security, cost controls, reproducibility, evaluation, and accountability without requiring raw document content in ordinary application logs.
8. Limitations and reporting
AI can be incomplete, incorrect, outdated, or misleading—even when it produces a citation or confidence score. Users must independently verify material output. Missing information must remain missing; uncertainty must remain visible; and regulatory ambiguity must be escalated.
Report unsafe, unsupported, cross-tenant, or incorrect AI behavior to compliance@westoverepr.com. Include the execution reference where available, but do not send credentials or unnecessary Customer Data.