An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
Hi @Laurent Bouhnik - No retention maximum is published as far as I can find. For your deployment though, three things in the same two pages narrow that question considerably, and none of them are in the AI answer.
Data Zone Standard does not move the abuse monitoring store out of your geography. Worth pinning down, since Data Zone is where people expect a residency exception. From Data, privacy, and security:
For both Global and DataZone deployment types, any data stored at rest, such as uploaded data, and including the abuse monitoring data store created for Global and DataZone deployments, is stored in the customer-designated geography.
For your France Central resource, inference may be processed in any EU Member Nation, while the store itself stays in your designated geography. Only processing location varies.
Storage is the exception, not the default. The automated review that runs first stores nothing:
For automated review, customer's prompts and completions are not stored by the system or used to train the AI models or other systems.
Human review, and so the data store, only applies "when automated review doesn't meet applicable confidence thresholds in complex contexts or if automated review systems aren't available." Retention therefore covers a subset of a subset: content already flagged, that automated review could not resolve.
The access controls are documented even though the duration is not, which for a record of processing is usually the more useful half:
The human reviewers are authorized Microsoft employees who access the data via point wise queries using request IDs, Secure Access Workstations (SAWs), and Just-In-Time (JIT) request approval granted by team managers.
Point-wise query by request ID is the operative detail: retrieval of an already-flagged item, not browsing.
On your second question, the documentation does state the eligibility criteria. From Limited access for Foundry Models sold by Azure:
At this time, modified Guardrails (previously content filters) and/or modified abuse monitoring for Models sold by Azure are available only to customers and partners managed by a Microsoft account team or under an eligible program, and are subject to additional requirements.
Still restricted to managed customers or an eligible program, and "Some advanced Models sold by Azure may have more stringent criteria for turning off abuse monitoring." If you are not account-team managed, the linked form is not a route in on its own.
On the 30 day figure, it appears on neither Abuse monitoring nor the data privacy page, so I would not carry it into your assessment.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.