How Digital Onboarding uses your data

DOBI is the assistant built into the Digital Onboarding platform. Your marketing team can ask it, in ordinary language, to help draft and edit campaign content: emails, pages, and digital banking messages. This page explains what data DOBI uses, where that data goes, and the rules we hold ourselves to.

What actually gets sent when your team uses DOBI

When one of your users asks DOBI for help with campaign content, we send the AI provider only what it needs to do that job:

What is never sent

About the brand voice profile

We read the public copy on your home page once and build a short profile of how your institution sounds: word choices (for example, "members" versus "customers"), how formal or warm the writing is, and phrases worth mirroring. We store that short profile. We do not store a copy of your website, and we do not re-read your site on a schedule. The profile only updates if you change the address.

What about when DOBI helps build audiences?

A coming DOBI feature helps your team build audiences: the rules that decide who a campaign reaches. It is in internal testing now, and it will reach customers only after the same review this page describes. We are answering the question early because it is the natural one to ask: audiences are built from account holder attributes, so does DOBI see account holder data there?

No. When DOBI helps with an audience, it sees the rules your user is building (the categories, fields, and conditions in the editor) and the aggregate counts those rules produce, such as "2,400 contacts match." On request, it can look up lists your institution has already configured, like campaign names or survey questions. It never sees individual account holder records, and the counts are totals only: no rows, no samples, no examples drawn from real people. The promise at the top of this page, that DOBI never sees your account holders' personal information, applies to every DOBI feature, this one included.

Where your data goes, and for how long

DOBI's requests are processed by a leading commercial AI provider under a commercial agreement. That provider:

Are we violating anything by using this?"

his is the right question, and it is the question the feature was designed around. The obligations your institution carries for account holder data (your privacy policy, your regulatory obligations, your vendor management standards) are about your account holders' personal information. DOBI does not receive account holder personal information, so using DOBI does not send the data those obligations protect to any AI company. If you have any questions, please speak with your compliance team, or reach out to your CSM or customersuccess@digitalonboarding.com.

Two things remain true, and we want to say them plainly:

Our commitments to you

Where is this going

These commitments are a starting point, not a finish line. We are convening a customer advisory panel and intend to ratify a full set of AI operating principles together with the institutions we serve, so the rules are written with you, not just for you. If you would like a seat in that conversation, tell your customer success manager.

Questions? Contact your customer success manager, or ask us to walk your compliance or vendor management team through any of this directly.

Appendix: Draft operating principles for AI and your data

This is a working draft, deliberately unfinished. We intend to edit and ratify these principles together with our customer advisory panel, so the final version is written with the institutions we serve, not just for them. Each principle is stated as a promise, followed by how you can check that we are keeping it.

1. Personal information stays home.
No account holder or member personal information goes to any AI provider. Ever, under the features that exist today; and never in the future without your explicit agreement first.

How you can check: ask us for the data-flow documentation for any AI feature. We will show you exactly what is sent.

2. You hear about changes before they happen, not after.
If we materially change what data an AI feature sends or how that data is used, we tell you before the change takes effect. If a change would involve account holder personal information, telling you is not enough: it requires your agreement.

How you can check: every material change appears in our release communications before it ships.

3. Your data never trains AI models.
Our AI provider's commercial terms exclude customer inputs and outputs from model training. If we ever change providers, this principle travels with us: it is a requirement we select for, not a feature we hope for.

How you can check: ask for the relevant provider terms through your customer success manager.

4. Your data serves you, and only you.
One institution's data is never used in another institution's requests or results. If we ever propose an industry-insights capability built on aggregated, de-identified data, that proposal comes to this advisory panel first, with the de-identification standard spelled out, before anything is built or sold.

How you can check: this panel is the checkpoint. Nothing of that kind exists today.

5. People decide; AI drafts.
No AI in our platform sends, publishes, or takes action toward your account holders on its own. A person at your institution reviews and approves anything before it goes out.

How you can check: try it. There is no path in the product where AI output reaches an account holder without a human approving it.

6. Off by default, and you hold the switch.
AI features are off until your institution's own admin turns them on, user by user. Choosing not to use them never degrades the rest of the platform.

How you can check: the permission screen in your own settings.

7. Everywhere your data sits has a stated shelf life.
Every place AI-related data is held, by us or by our provider, has a stated retention period, and we publish those periods rather than making you ask.

How you can check: the retention table published alongside this document.

8. We support your compliance work; we never substitute for it.
Reviewing content for your regulatory requirements stays your team's responsibility, and we will never market AI output as compliance-checked when it is not. When your model risk, vendor management, or examiner review needs documentation, we provide it.

How you can check: ask. Documentation requests are part of the service, not a favor.