PII
Personally identifiable information — a class of content that belongs outside assistant scope.
TL;DR
Personally identifiable information subject to KVKK/GDPR.
Quick facts
- Category
- AI & knowledge management
- Product tie-in
- KobiGPT RAG platform
- Related
- See compare and tools pages
- Locale
- TR and EN site
Why teams choose KobiGPT
- Understand terms before evaluating vendors.
- Link concepts to KobiGPT features (RAG, Kobi Kredi).
- Share glossary links with procurement and legal.
- Explore assistant use cases next.
Product facts
- Ücretsiz plan
- 100 doküman · 2 departman · 120 Kobi/ay(PLAN_CONFIG)
- Starter
- 1000 doküman · 5 departman · 1000 Kobi/ay(PLAN_CONFIG)
- Pro
- 12500 doküman · 25 departman · 12500 Kobi/ay(PLAN_CONFIG)
Why personal data should stay out of scope
Personal data is any information making a natural person identified or identifiable. Names, identity numbers, contact details, HR records, and health data all qualify; health data is additionally treated as a special category.
When a file containing personal data is attached to an assistant, that data is indexed and can be surfaced as a source in a query result. Trying to protect it with an access rule is more fragile than never attaching the file.
The strongest protection therefore sits at setup: files containing personal data are not brought into any assistant’s scope. A file that is not attached can never appear as a source.
Places that get overlooked
The main document may be clean while its attachments are not. Sample forms at the end of procedure documents can carry real names; meeting minutes include attendee lists; contract templates may have been filled in with real customer details.
The second overlooked place is scanned paperwork. When an image-based PDF goes through text extraction, the identity details inside it enter the index too; being an image is not protection.
A quick review before upload is therefore far cheaper than selective deletion afterwards. This step should not be skipped, especially during bulk uploads.
When a deletion request arrives
A deletion request requires removing the data from two places: the source document store and the vector index. Doing only one leaves the data reachable.
That operation needs testing. After taking a document out of scope, query the same content; if an answer still comes back, index removal is not working.
Never indexing personal data in the first place makes this operation unnecessary and is the safest approach. Consult your legal adviser for compliance assessment; this page is not legal advice.
FAQ
What is PII in practice?
Personally identifiable information subject to KVKK/GDPR.
Does KobiGPT use this?
See product docs and feature pages for implementation details.
More reading?
Visit our blog and FAQ.
Accuracy disclaimer?
Educational content; verify for compliance decisions.
Can we attach files containing personal data?
Not advised. The strongest protection is keeping those files out of every assistant’s scope; an unattached file cannot appear as a source.
Do scanned documents carry risk?
Yes. Image content that goes through text extraction also enters the index; being an image is not protection.
Comparison
| Feature | KobiGPT | Alternative |
|---|---|---|
| SME focus | Yes | N/A |
| Citations | When using RAG | N/A |
| Glossary depth | Growing | N/A |
| Tools | Interactive | N/A |