IT Services Privacy Notice
This privacy notice describes the Aalto University policy on the personal data collected and processed by the Aalto University IT Services (ITS) in connection with the services it produces and the processes it executes.
| Purpose |
To enable service use, maintenance, administration, and information security |
| Legal Basis |
Consent, legitimate interest, public interest, legal obligation |
| Data Collected |
Log data, user data, and conversation data |
| Recipients |
Microsoft (platform provider and sub-processors) |
| Transfers |
Data processed within EU/EEA; transfers outside follow GDPR safeguards |
| Security |
Technical, organisational, and administrative measures in place |
| Retention |
Conversations: 6 months (from spring 2026); User data: 2 years of inactivity |
| Automated Decisions |
No automated decision-making or profiling |
(Supplementing the IT Services Privacy Notice)
Effective as of: 16.03.2026
This privacy notice supplements the IT Services Privacy Notice and describes how your personal data is processed by Aalto University when you use Aalto AI Assistant in accordance with its guidelines. Please note that Aalto AI Assistant is offered both as a chatbot and as an Application Programming Interface (API).
Purposes of processing your personal data:
Aalto AI Assistant does not utilise automated decision-making or profiling in the processing of personal data.
Legal bases for processing:
| Processing activity | Legal basis |
|
Data subject logging into Aalto AI Assistant (voluntary use) |
Consent of the data subject |
|
Conversation data submitted to the system |
Legitimate interest |
|
Log data |
Legitimate interest |
|
User data |
Legitimate interest, legal obligation |
|
Mandatory usage (e.g., in courses) |
Performance of a task carried out in the public interest, exercise of official authority, legal obligation, consent of the data subject |
|
Summarising survey results |
The original legal basis for data collection remains applicable |
The personal data processed can be categorised as follows:
Log data including:
User data including:
Conversation data including:
Chat with Aalto.fi:
Recipients who process your personal data:
Azure OpenAI-based language models (e.g., GPT models): The Aalto AI Assistant service is operated on Microsoft servers located in the EU/EEA area. However, user data is stored on Aalto's own servers.
The University's data protection policy is to exercise particular care if personal data is transferred outside the EU and European Economic Area (EEA) to countries that do not provide data protection in accordance with the EU General Data Protection Regulation (GDPR). Transfer of personal data outside the EU and EEA is carried out in accordance with the requirements of the GDPR using, for example, standard contractual clauses or other appropriate safeguards in accordance with the GDPR.
Local language models: If you use local language models, the data is hosted on Aalto's own on-premise servers.
Data security is important to Aalto University. Aalto University has implemented appropriate technical, organisational, and administrative security measures to protect all personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Aalto AI Assistant has undergone Aalto's detailed information security review process.
Your personal data is retained for as long as it is necessary for the purpose for which it is processed, or for as long as required by law and regulations.
User data: User information in the backend server is saved as long as the user remains active. After a period of 2 years without the user logging into Aalto AI Assistant, this data is deleted (including files and conversations).
Files and conversations: The user is responsible for backing up important conversations. During the spring of 2026, Aalto University will start automatically deleting conversations that are older than 6 months. Pinned conversations will not be deleted.
If the conversation is part of a document chat, deleting an individual conversation does not remove the uploaded files in the document chat; however, users can delete individual files or the document chat separately.
Log data: Log data is stored in accordance with Aalto's log management rules.
Aalto AI Assistant is being actively developed and new features are being added. As the service evolves, updates may be made to this privacy notice. The latest version is available on this page.
This privacy notice describes the Aalto University policy on the personal data collected and processed by the Aalto University IT Services (ITS) in connection with the services it produces and the processes it executes.