AI privacy and human review
2 min read
Understand bounded sanitized AI inputs, access checks and required human control.
ELUNIA builds a feature-specific, bounded input only after an authorized person requests AI assistance. The task remains linked to its organization, Property, requester and source record; access and entitlement are checked again during queued processing.
Data minimization
The input sanitizer removes HTML and control/format characters, redacts recognizable email addresses, phone-like values, booking/room/reference patterns and URLs, truncates each text value, and caps total input and comment count. ELUNIA deliberately omits Guest profiles, invitation tokens, internal notes, communication recipients/bodies and integration credentials.
This is risk reduction, not a promise that every unexpected personal detail in free text can always be recognized. Review and Response text is untrusted source content, and the organization must enable external AI processing under its own approved privacy basis.
Human control by workflow
- Survey translation produces a Draft; a person reviews and publishes it.
- Review reply assistance produces a Draft; a person may edit, approve, then separately publish it.
- Response analysis, Property summaries and Feedback Case summaries are advisory. They do not alter Survey metrics, assign work, change a case state or perform recovery.
- A Feedback Case response Draft is working text, not an automatically sent message.
Validated results and task evidence are stored with the AI run and are visible only through authorized tenant/Property scope. ELUNIA does not expose prompts, raw provider responses or internal processing identifiers in customer Help. Continue with AI task states and failures.