Personal data, security, and privacy for genAI features

PII handling and governance for Medallia Experience Cloud generative AI features

Important: The following content is provided for informational and educational purposes only and does not constitute a legally binding guarantee, representation, or warranty regarding Medallia's' processing or protection of personally identifiable information (PII).

Actual legal commitments, data privacy obligations, and technical guarantees are defined exclusively in each customer's executed Master Services Agreement (MSA) and GenAI Addendum. Users must refer to their specific GenAI Addendum for legally binding guarantees and contractually enforceable terms.

Personally identifiable information (PII) is generally split into two categories:
  • Direct identifiers like full name, personal email address, social security number, or physical address
  • Indirect identifiers like zip codes, job titles, birthdays, IP addresses, or combinations of data that might allow for the identification of a specific individual
Medallia Experience Cloud processes and stores both types. This includes Experience Cloud's generative AI features.

Generative AI governance, data scope, and access controls

Medallia customers are responsible for the identification of PII data fields and setting up sensitive data rules to meet PII standards. PII data fields in Experience Cloud are governed primarily by role-based access control (RBAC). If a user's role can access a PII field, that field may be present in the data provided to genAI LLM models unless that field is explicitly redacted by sensitive data rules (SDR), or if the feature implements placeholder substitution (for example, Smart Response).

GenAI features analyze customer feedback signals including survey responses, transcripts, and social comments, along with contextual metadata. They do not evaluate individual employee performance.

Customer data is never shared across tenant boundaries or accessed by other customer programs. Third-party foundational models do not receive customer data for general model training or updates. No data is harvested from unethical sources, copyrighted material, or unapproved web scraping.

Infrastructure complies with enterprise security certifications including ISO 27001, ISO 27701, and SOC 2 / SSAE 16 Type II. GenAI features are categorized as "Limited Risk" under the EU AI Act, supported by transparency controls and ongoing oversight by Medallia's internal cross-functional AI Moderation Council.

Platform security and infrastructure

Data processing occurs in isolated environments designed to prevent unauthorized external access or data leakage. Tenant segregation is maintained through dedicated, logically isolated database instances. All data, including PII, is encrypted in transit using secure protocols (HTTPS, SFTP, PGP) and encrypted at rest.

Customer data and generated AI results remain stored at rest within the customer's designated primary hosting region. GenAI inference is executed on Medallia co-located regional GPU farms or enterprise public cloud infrastructure (for example, AWS Bedrock).

Model training, fine-tuning, and data persistence

Pre-training alters the underlying foundational LLM weights, whereas fine-tuning adapts a pre-trained model for specific domain tasks using only de-identified data.

Medallia does not pre-train foundational LLMs on customer data. Medallia's selective model fine-tuning (for example, Intelligent Summaries) or classic ML model training uses strictly de-identified, aggregated datasets stripped of personal data fields.

Customers can opt out of having their de-identified data used for shared model fine-tuning, though customer-specific features (for example, GenAI themes) still require localized data processing to function.

Data transmitted to LLMs during real-time inference is used solely to generate the immediate output and does not persist within the model. Contractual limits with LLM providers ensure data is not retained or used for third-party-provider model training.

GenAI feature PII masking and data handling

GenAI featurePre-LLM data maskingPII field behaviorGDPR deletion
Insights AssistantYes. Operates on reporting data that is subject to sensitive data rules and field masking.Subject to role-based access and sensitive data rules. PII that is not subject to sensitive data rules can be passed to the LLM if the user has access. PII is a permitted input when identifying entities such as unit and unit groups (for example, employee, manager) specific to the end user's request.Yes. AI platform query traces are deleted 15 days after a conversation is initiated to comply with GDPR regulations. Additionally, conversation history becomes read-only 15 days after a conversation is initiated.
Intelligent Summaries for conversational dataNo. Full unmasked transcripts are sent to the LLM, even when transcripts are masked in the UI.N/AYes. LLM output is stored in the associated record, and it is deleted if the record is deleted subject to a GDPR request.
Intelligent Summaries for Text AnalyticsYes. When data masking is enabled and configured through sensitive data rules, these rules are applied before LLM processing.Subject to role-based access and sensitive data rules. PII that is not subject to sensitive data rules can be passed to the LLM if the user has access. Summarized data and exports preserve masking from sensitive data rules.Transient processing. LLM output is deleted 15 days after creation.
Root Cause AssistYes. Operates on reporting data that is typically masked prior to the point that it is processed by Root Cause Assist.Out of scope. Root Cause Assist works with aggregated reporting data, not raw unstructured text. PII in Text Analytics tags may be present, but this is atypical.Transient processing. LLM output is deleted 15 days after creation.
Smart ResponsePartial. Certain PII fields are masked. Comment fields with sensitive data rules applied are masked; other comment text is sent verbatim.Customer name and employee signature details (like name, email, and phone number) are masked before LLM processing and added back in by Experience Cloud after processing. Other free-text PII in comments is sent if not anonymized or masked. Smart Response requires human review and approval prior to sending.Yes. LLM output is stored in the associated record, and it is deleted if the record is deleted subject to a GDPR request.
Smart Topic BuilderYes. Inherits tagpool field selection, so an admin actively controls which fields the feature can access. Sensitive data rules are applied to comment data before that data is processed.Output is generated from aggregated data but includes example comments. These examples respect sensitive data rules but may contain PII.Yes. Topic discovery proposals, including example comments, are deleted after 15 days. When Experience Cloud records are deleted, example comments used for topic audit are deleted with the records and are no longer available in Topic Builder.
Themes with generative AIYes. Sensitive data rules are applied prior to all Themes processing, both inference and training.Subject to role-based access and sensitive data rules. PII that is not subject to sensitive data rules can be passed to the LLM if the user has access. A subset of Themes with GenAI data may be stored in training sets. These examples respect sensitive data rules but may contain PII.Yes. Storage respects right-to-be-forgotten for customer-specific datasets, and records removed from Experience Cloud are removed from Themes training sets.