Artificial Intelligence in Perfony: Transparency, Data, and Control

Perfony lets you use certain artificial intelligence features and connect Perfony to third-party AI assistants, including Claude and Microsoft 365 Copilot.

This page clearly explains when artificial intelligence is used, what data may be shared, with which service provider, and what controls remain available to your organization and its users.

This approach is consistent with, among other things, the European Artificial Intelligence Regulation (“AI Act”), the General Data Protection Regulation (“GDPR”), and Perfony’s security and privacy commitments.

The following table summarizes how data is processed in connection with Perfony’s AI features:

 

AI Function Who triggers it Accessible Data Who is in charge Training Customer Audit
Claude Connector When the user makes a request in Claude Only the Perfony data that the user is already authorized to access and that is necessary to fulfill their request Anthropic / Claude, via the Perfony connector Not by default for Anthropic’s business plans. Terms may vary depending on the plan and the settings of the Claude account being used. Organization-wide activation + individual authorization. Revocable access
Microsoft 365 Copilot Agent When the user makes a request in Copilot Only the Perfony data that the user is authorized to access and that is necessary to fulfill their request Microsoft 365 Copilot, with access to Perfony via the agent/connector No. Microsoft states that the work-related data, prompts, and responses from Microsoft 365 Copilot are not used to train the foundation models. Activation controlled by the organization. The user’s Perfony rights remain in effect
AI Features Built into Perfony Perfony, when a previously enabled AI feature is used or executed Data required for the feature: metrics, progress, deadlines, and, as applicable, certain text elements Perfony, with Microsoft Azure as its technology provider No. The data transmitted to the Azure service used by Perfony is not used to train foundation models without authorization or explicit instructions. Features that can be disabled by the administrator, either globally or on a per-scope basis

 

In any case, the use of AI does not alter the access rights defined in Perfony: a connected assistant can only access information that the user in question is authorized to access.

When content is generated or suggested by artificial intelligence in Perfony, the user is notified. The results produced by AI are intended as a guide and must be verified before any decision or action requiring human validation is taken.

Three Different Uses of Artificial Intelligence

Perfony distinguishes between three scenarios:

  • The Claude Connector

The user asks Claude questions and, when prompted, allows Claude to access certain information from their Perfony environment.

  • The Microsoft 365 Copilot agent

The user asks Microsoft 365 Copilot a question, and Copilot may request information from Perfony to view or update the information that the user is authorized to access.

  • AI Features Built into Perfony

Perfony uses an artificial intelligence service hosted on Microsoft Azure to generate certain analyses or recommendations directly within Perfony.

These three scenarios involve different data flows and responsibilities.

Connect Claude to Perfony

How does the connector work?

The connector allows a user to grant Claude access to certain Perfony features.

Its activation is based on two levels of control:

    • The connector must be authorized for the organization;
    • Each user must then log in and authorize their own account.
    • When a user queries Claude, Claude can call the Perfony connector to obtain the information needed to fulfill the request.

The connector does not grant Claude any more rights than those available to users in Perfony.

The rules regarding rights and privacy set forth in Perfony therefore continue to apply.

Depending on the features available in the connector, the relevant information may include, among other things, files, meetings, tasks, or other content to which the user has access.

 

Who initiates the treatment?

It is the user, not Claude. Perfony does not automatically send the account content to Claude. The data is returned in response to requests made by Claude following an interaction initiated by the user.

 

What happens to the data sent to Claude?

The processing performed in Claude depends on the Anthropic plan used by the user or their organization and the settings associated with that plan.

For Anthropic’s enterprise offerings, Anthropic states that inputs and outputs are not used by default to train its models.

However, retention policies may vary depending on the Claude plan used and the organization’s settings. In particular, conversations saved in Claude may be retained in the account history until they are deleted, in accordance with the terms applicable to the relevant plan.

The use of Claude is therefore also subject to the contractual terms, settings, and privacy policy applicable to the Anthropic account being used.

 

How do I disable access?

Access can be disabled at the organizational level when this option is available, and the user can revoke the permission granted to Claude.

Using Perfony from Microsoft 365 Copilot

How does the Perfony agent work?

The Perfony agent enables Microsoft 365 Copilot to interact with Perfony at the user’s request.

When a user submits a request in Copilot, the agent can call Perfony using that user’s identity and permissions.

The access rights rules defined in Perfony remain in effect.

The agent therefore does not allow a user to access information that they would not normally have access to in Perfony.

 

Who performs the AI processing?

The query is interpreted and the response is generated within the user’s Microsoft 365 Copilot environment.

The Perfony agent essentially allows Copilot to query or, when the feature supports it, update authorized Perfony data.

Perfony does not, solely as a result of this request, trigger a second artificial intelligence processing step on the data returned to Copilot.

 

Does Microsoft use this data to train its models?

According to the Microsoft documentation for Microsoft 365 Copilot, the prompts, responses, and business data used in Microsoft 365 Copilot are not used to train the foundation models.

Copilot interactions can be retained in the organization’s Microsoft 365 environment and are subject to the retention, security, and compliance policies defined by the organization, including through Microsoft Purview.

Use of Copilot remains subject to the organization’s contractual terms and Microsoft 365 settings.

 

AI features built directly into Perfony

Some Perfony features use artificial intelligence models hosted on Microsoft Azure.

Unlike the Claude and Copilot connectors, processing here is triggered by a Perfony feature that has been previously enabled for the organization or the relevant scope.

This may include recommendations or analyses designed to facilitate the management of cases and action plans.

What data is used?

Perfony follows a data minimization principle: only the information necessary to generate the analysis or recommendation is sent to the AI service.

Depending on the feature, this information may include, among other things:

    • monitoring indicators;
    • the number of actions;
    • progress reports;
    • deadlines;
    • certain headings or text elements necessary for analysis.

The exact scope depends on the feature being used.

 

Is the data used to train the models?

No.

According to the terms and conditions applicable to the Microsoft Azure service used by Perfony, prompts, responses, and customer data transmitted to the service are not used to train or improve foundation models without explicit authorization or instruction.

The data transmitted is not made available to other users of the service.

 

Where is the data processed?

Perfony prioritizes services and configurations that allow data to be processed within the European Economic Area whenever this option is available and compatible with the feature being used.

However, the exact location of the processing depends on the service, the model, and the type of Azure deployment used.

Microsoft may also implement automated mechanisms to detect misuse. In certain cases specified by Microsoft, reported content may be subject to further review in accordance with the Terms of Service.

 

The Principles Applied by Perfony

For its artificial intelligence features and AI connectors, Perfony applies the following principles:

Transparency
Users must be able to tell when a feature relies on artificial intelligence or allows information to be sent to an AI assistant.

Control: AI connectors and features may be subject to prior activation by the organization and, where applicable, to the user’s consent or authorization.

Respect for Perfony Rights
An assistant connected to Perfony does not automatically have additional rights. The user’s permissions remain in effect.

Data Minimization
For AI processing performed directly by Perfony, only the data necessary to perform the feature is transmitted to the relevant service.

Separation of Environments
Perfony does not make one customer’s data available to another customer.

Human Supervision
Content, analyses, recommendations, summaries, decisions, or actions proposed by artificial intelligence may contain errors or inaccuracies. They are intended to assist the user and must be verified before any use that requires a decision or action.

Maintain control over artificial intelligence

The use of generative AI does not change the confidentiality rules that apply to your organization’s information.

In particular, users must take care not to share confidential, personal, or sensitive information with an external assistant when their organization does not authorize such use.

Organization administrators determine which AI features and connectors are made available to their users in accordance with their own security, privacy, and AI usage policies.

Regulatory Framework

The features described on this page are designed with particular consideration for:

    • Regulation (EU) 2024/1689 on artificial intelligence (“AI Act”), particularly its requirements regarding transparency and control of AI;
    • Regulation (EU) 2016/679 (“GDPR”) when the processing involves personal data;
    • the contractual obligations applicable to service providers and subcontractors used by Perfony;
    • Perfony’s security and data protection policies.

The AI Act and the GDPR pursue complementary objectives: the AI Act regulates, in particular, the design, provision, and use of artificial intelligence systems, while the GDPR continues to apply when these systems process personal data.

 

read more…

The documentation for each connector explains how it works and how to activate it.

The terms of service applicable to third-party services can also be found in the documentation provided by Microsoft and Anthropic.

If you have any questions regarding security, privacy, or data processing by Perfony’s AI features, you may contact Perfony as described in our privacy policy.

 

Last updated: September 2026.

Comment pouvons-nous vous aider ? Une question sur Perfony, une démo à réserver, ou envie de créer votre espace ?