How does the AI of Sendsteps work?

How does the AI of Sendsteps work?

How Does the AI of Sendsteps Work?

Does Sendsteps Use ChatGPT or Its Own AI?

Sendsteps uses state-of-the-art AI language models provided by OpenAI, operated through Microsoft Azure. All AI processing is routed by default to Azure OpenAI in the European geography, so prompts and outputs are processed fully within the EU.

We do not operate our own foundational language model. Instead, Sendsteps has implemented its own secure orchestration and routing layer that connects directly to Microsoft Azure’s enterprise-grade AI infrastructure. This lets us combine GDPR-compliant EU processing, high performance, and enterprise security, without running our own LLM.

For European organizations, this setup is the standard and default: all storage and all AI processing stay in Europe. For customers in other continents, we can, on request, configure region-specific routing if legal or policy requirements demand it.


What Happens to My Data?

We treat your data with the highest possible level of security, privacy, and transparency.

1. Your request is securely routed by Sendsteps

When you enter a prompt (for example “Create a lesson on photosynthesis for Grade 8”), Sendsteps:

  • receives your prompt via our secure platform,

  • routes it through our EU-based orchestration layer,

  • forwards it to Azure OpenAI in the chosen European region.

We ensure EU-only routing as the default and use encrypted connections end-to-end.

2. Processing happens in Azure OpenAI in Europe only (by default)

All prompts and outputs are processed within Microsoft Azure’s European geography (for example West Europe / North Europe), as configured by Sendsteps. Azure may optimize internally between EU regions for performance, but:

  • data remains inside the EU geography,

  • prompts and responses are not sent outside Europe in the default configuration.

For European organizations this means: AI processing is fully EU-based.

3. No retention and no training on your data

Azure OpenAI in the enterprise / Foundry architecture:

  • does not store prompts or outputs after processing,

  • does not use your prompts or content to train models,

  • does not use your data for product improvement,

  • only processes your data to generate the response and then discards it.

Sendsteps follows the same principle for AI prompts: we only keep what is needed to show and edit your generated presentations in your account.

4. What Sendsteps stores (and where)

To let you edit, save, and reuse your content, Sendsteps stores:

  • the generated presentation content,

  • your edits and versions,

  • your account and subscription data.

All of this is stored exclusively in:

  • AWS EU-Central (Frankfurt, Germany).

We do not store data outside the EU for the standard setup.

5. Your data is not shared beyond essential processing partners

Your information is only sent to:

  • Sendsteps (platform, orchestration, storage),

  • Azure OpenAI in Europe (AI generation).

Your data is not shared with advertising partners, data brokers, or any other third parties.


Data Residency: Where Is My Data Processed?

Sendsteps Data Residency (Storage)

All Sendsteps platform data, including:

  • presentations and quizzes,

  • lesson content and interaction results,

  • account and subscription details,

is stored in:

  • AWS EU-Central (Frankfurt, Germany)
    on fully GDPR-compliant infrastructure.

AI Data Residency (Processing via Azure OpenAI Europe)

For AI processing, Sendsteps:

  • routes prompts and outputs to Azure OpenAI in the European geography,

  • ensures processing and generation only take place inside the EU,

  • benefits from Microsoft’s enterprise-grade security and compliance.

Azure OpenAI:

  • processes prompts and outputs within the configured EU region(s),

  • may route within the EU geography for performance, but not outside Europe,

  • does not retain your prompts or outputs,

  • does not train on your data.

Summary

  • 🔒 All Sendsteps storage = EU (AWS Frankfurt)

  • 🤖 All AI processing (default) = EU (Azure OpenAI Europe)

  • 🌍 No processing outside Europe by default, which satisfies strict EU data residency and GDPR requirements for European organizations.


Use Outside Europe and Other Continents (By Request)

By default, Sendsteps processes and stores all data for European organizations inside the EU.

For organizations outside Europe (for example in North America, Africa, or Oceania), or for multinationals with specific legal or compliance needs, we can configure custom region routing by request. Depending on availability and regulatory requirements, this can include:

  • processing in other geographic regions supported by the selected AI provider,

  • region-specific deployments for regulated sectors or institutions,

  • localized processing if required and technically feasible.

Not all providers or regions support the same configurations. We will advise on the options that are realistically possible for your organization.


Enterprise Option: Connect a Different LLM or Your Own LLM (By Request)

Sendsteps can also integrate with:

  • your own private LLM,

  • an LLM hosted in your own cloud environment,

  • or a different model provider of your choice.

We can connect to any LLM that exposes a secure API endpoint. The exact implementation, routing, and quality considerations will be discussed together during the integration process, so the setup fully meets your compliance and technical requirements.

Note: The quality and structure of the generated output depend on the model used. During onboarding, we work with enterprise clients to validate that their chosen LLM produces output suitable for Sendsteps' presentation workflows.



GDPR Compliance

Sendsteps is fully committed to GDPR compliance and privacy by design.

EU-only storage and processing (default for European organizations)

  • All stored data is located in AWS EU-Central (Frankfurt).

  • All AI inference is done via Azure OpenAI in the EU geography.

  • Sendsteps’ orchestration layer is also hosted in the EU.

Data minimization

We store only what is strictly necessary to:

  • create,

  • edit,

  • present,

  • and manage

your content and your account. We do not collect extra data for marketing profiling or unrelated purposes.

No AI training on customer data

Neither:

  • Sendsteps, nor

  • Azure OpenAI (in our configuration)

use your prompts, outputs, or content to train AI models.

Your data remains your data.

Retention control

  • Sendsteps keeps your presentations, quizzes, and related content only so you can access and use them in your account.

  • Azure OpenAI does not retain prompts or outputs.

  • For enterprise customers, retention periods and deletion policies can be refined in a Data Processing Agreement (DPA).

User rights

Under GDPR, you have the right to:

  • access your data,

  • correct your data,

  • request deletion (right to be forgotten),

  • restrict processing in certain cases.

You can exercise these rights by contacting our support team.

Security measures

We use:

  • industry-standard encryption (in transit and at rest),

  • strict access control and authentication,

  • logging and monitoring,

  • secure development and data-processing practices.

Security is an ongoing process, and we continuously improve our controls to match best practices.


Why Do We Use OpenAI (Azure) Instead of Our Own AI Model?

OpenAI’s models, hosted on Microsoft Azure, provide:

  • world-class language and reasoning capabilities,

  • strong enterprise security and compliance,

  • zero data retention in our configuration,

  • guaranteed EU processing for European organizations.

Training and operating our own large-scale LLM would:

  • reduce our ability to match this quality and pace of innovation,

  • introduce significant operational and security risks,

  • require huge ongoing investments in infrastructure and research.

By using Azure OpenAI and managing the orchestration ourselves, we can:

  • deliver the highest-quality AI-generated presentations and quizzes,

  • ensure GDPR and EU data-residency compliance,

  • focus on what we do best: building tools that save teachers and trainers time and improve learning outcomes.


Want to Know More?

If you have further questions about how Sendsteps uses AI or how your data is handled, please contact us:

📧 support@sendsteps.com

    • Related Articles

    • What safety/security regulations does Sendsteps adhere to? (ISO 27001)

      At Sendsteps we prioritize safeguarding personal information above all else. Data encryption experts work with us to ensure that all our databases are fully secured at all times. Read below for some of the security measures we take very seriously at ...
    • What are Sendsteps security standards?

      Sendsteps keeps your data as safe a possible. We employ the highest possible security standards. If you’re interested to learn everything about our security standards, please have a look at our security standards.
    • How does Sendsteps handle my privacy?

      Sendsteps keeps your data as secure as possible. We follow the GDPR regulations closely and have privacy as one or our core values. If you want to learn the specifics of how privacy is handled at Sendsteps be sure to visit our privacy statement ...
    • Is my data secure at Sendsteps?

      Sendsteps follows GDPR regulations closely and keeps your data as safe as possible. By employing the highest possible security standards we maintain a high level of (data) privacy. Your data is safe with us. If you want to learn more about how we ...
    • Enhanced Security Update: One-Time Code Login

      At Sendsteps, we prioritize the security of your account and the integrity of your data. As part of our commitment to providing the highest level of security, you will only be able to log in using a one-time code sent directly to your email inbox. ...