YOUNG/Governance & data
Governance & data

AI that operates in regulated
environments, with a clear data owner.

We run journeys in education, health, government and sports — sectors where data is sensitive and a wrong answer has consequences. This page describes how we handle data, models and decisions.

Principle
We don't take the data out of the company. We put intelligence inside it.
This is the architectural decision that everything else on this page follows from: the AI operates inside the client's systems, and the system of record stays where it already was.
Governance & data

The data behind this scene belongs to a family. Not to us.

We operate journeys in public service, health and education — where a wrong answer has consequences and the record belongs to the citizen. That is why the AI runs inside the client's systems, with an escalation path written before it goes live.

Who owns the data

The data belongs to the client. Always.

01

We operate inside your systems

The journey runs on the CRM, ERP and academic or clinical systems the organization already uses. SYNG does not become the system of record.

02

One client's data never serves another

Client data is not used to train or improve the solution of any other client. Each operation is isolated by project.

03

Declared purpose

Every project states what the data is for. A journey designed for enrollment is not silently reused for something else.

04

Minimum necessary access

The journey reads the fields it needs to answer, not the whole record. Scope of access is a project decision, never a default.

Model choice

The model is a project decision, not an article of faith.

We are model-agnostic on purpose. Which engine runs a journey depends on the regulation, the latency, the cost and the sensitivity of the case — and it can be replaced without redesigning the journey.

Regulation→Sensitivity→Latency and cost→Model choice→Journey unchanged

For cases that require it, the operation can be configured for local or sovereign deployment. Which configuration applies to a given project is defined in that project's contract.

Human in the loop

The AI runs the operation. It does not decide alone what it should not.

01

Escalation is designed, not improvised

Every playbook defines what the AI answers, what it confirms and what it hands to a person — with the trigger written down before it goes live.

02

In health, it organizes — it does not diagnose

Scheduling, reminders, exam follow-up and the communication between doctor, patient and caregiver. Clinical decisions stay with the professional.

03

In government, it informs and routes

The journey brings the service closer to the citizen. It does not replace an administrative act or a public servant's decision.

04

It is not a credit or eligibility engine

We do not position the operation as a decision engine for credit, benefit or eligibility. Where those decisions exist, they belong to the client's own rules.

Traceability

Every interaction leaves a trail. Every behaviour has an owner.

01

Versioned playbooks, not loose prompts

What the AI can say lives in a playbook with a version and an author, so a change in behaviour is a change someone made on purpose.

02

Reconstructable answers

It is possible to go back and see why the AI answered the way it did — which journey, which data, which rule.

03

Sampled human review

Real conversations are read by people, continuously, looking for what the AI should not have answered.

04

Fix the cause, not the symptom

Because behaviour is traceable to a playbook, a bad answer is corrected at the rule that produced it, for everyone.

LGPD

What we take on as data processor.

  • ●The client is the controller; YOUNG acts as processor of the personal data involved in the journey.
  • ●Purpose and legal basis are defined with the client and recorded in the data processing agreement.
  • ●The operation supports the exercise of data subject rights requested through the controller.
  • ●Retention and disposal follow each project's agreement, not an internal default.
  • ●Security incidents are reported to the controller so the legal deadlines can be met.

This section describes the standard design of our projects. Clauses, deadlines and legal bases are agreed case by case in the data processing agreement, and this text does not replace a privacy policy — which must be reviewed by counsel before publication.

The questions compliance asks

Answered here, so nobody has to wait for the second meeting.

01

Where is the data processed?

It depends on the project's design. When there is a residency or local deployment requirement, the operation is configured for it and that choice is recorded in the contract. Ask us for your project's configuration in writing — we will give it in writing.

02

Do you train models on our data?

No. Client data is not used to train or improve the solution of any other client.

03

Can the AI answer something wrong?

Yes — any AI can. That is why the answer is bounded by the playbook's scope, escalation to a person is designed in, and real conversations are reviewed by sampling. What cannot be answered safely is routed, not improvised.

04

Who is responsible if it fails?

Liability is set in the contract. Operationally, behaviour is traceable to the playbook that produced it, which is what lets us fix the cause instead of apologizing for the symptom.

05

Does the AI access the full record?

Only the fields the journey needs. Scope of access is defined per project and reviewed with the client's own security team.

06

Can we switch it off?

Yes. The journey runs on the client's systems, so turning off the AI operation does not take down the CRM and does not erase history.

07

Do you hold ISO 27001 or SOC 2?

We do not claim those certifications today, and we would rather say so than imply otherwise. What we do have is the architecture described on this page and the willingness to go through your security assessment. When a certification exists, the seal will appear here with its number.

Commitment
Anything we can't answer in writing, we don't claim.
If a question about data, model or responsibility is missing from this page, send it to us. The answer comes back in writing — and if it is a good question, it ends up on this page.