AI Solution Usage Policy

Effective Date: July 22, 2026

Purpose and Scope

This Usage Policy describes how our AI solutions process information, the intended purposes for which they may be used, and the responsibilities of customers when deploying our services. It applies to all AI-powered products, features, APIs, and services provided by the Company unless a product-specific policy or agreement states otherwise.

Intended Use

Our AI solutions are designed to assist users by analysing information, generating responses, summarizing content, extracting insights, classifying information, making recommendations, automating workflows, and supporting business processes. For more information, see below Section “Operational Processing”.

Our services are intended to support human decision-making and operational efficiency. Outputs generated by our AI solutions are advisory in nature and should not be considered definitive decisions or professional advice.

Responsible AI Use

We are committed to developing and operating AI systems that are lawful, transparent, secure, and trustworthy.

Our AI services are not designed or intended to:

  • perform automated decision-making that produces legal effects or similarly significant effects on individuals without appropriate human oversight;
  • profile individuals for employment, disciplinary, creditworthiness, insurance eligibility, or other decisions that materially affect a person's rights or opportunities;
  • conduct employee surveillance or behavioural monitoring;
  • generate decisions on behalf of customers where applicable law requires meaningful human review;
  • process personal data for advertising, marketing, or unrelated secondary purposes.

Customers are responsible for ensuring that appropriately qualified personnel review AI-generated outputs before they are used in decisions that could materially affect individuals.

Operational Processing

As part of providing the contracted services, we process customer data to perform operational AI and analytics functions necessary to deliver the service; this would include user prompts, uploaded content, application data, structured and unstructured data, conversation history and metadata necessary to provide the functionality requested by our Customer. Depending on the product, these functions may also include:

  • classification and categorization;
  • summarization;
  • information extraction;
  • semantic search and retrieval;
  • clustering;
  • recommendation generation;
  • workflow automation;
  • anomaly detection;
  • forecasting;
  • prioritization and routing;
  • knowledge discovery;
  • quality improvement;
  • service optimization;
  • reporting and operational analytics.

These activities are performed solely to provide, maintain, secure, improve, and support the contracted services, and only in accordance with the applicable agreement, Data Processing Agreement (where applicable), and the customer's documented instructions.

Customer Responsibilities

Customers are responsible for:

  • determining the lawful basis for processing any personal data submitted to the services;
  • obtaining any required notices, consents, or authorizations;
  • ensuring that submitted data is accurate and appropriate for the intended use;
  • implementing appropriate human oversight for decisions involving individuals;
  • validating AI-generated outputs before relying upon them in business, clinical, financial, legal, regulatory, or other high-impact contexts;
  • complying will all applicable law for their use of the product in their jurisdiction;
  • complying with industry-specific regulatory obligations applicable to their organization.

Processing of Personal Data

Where personal data is processed, we process such data on behalf of our customers and in accordance with applicable contractual commitments and applicable data protection laws. For further details of the processing of personal data in the context of the provision of the product, you can read our Data Processing Privacy Statement.

We process personal data as necessary to provide the requested services, maintain security, improve reliability, comply with legal obligations, and fulfil contractual commitments.

AI Model Improvement

Unless otherwise agreed in writing or explicitly disclosed for a particular service, customer prompts, uploaded content, and AI interactions are not used to train foundation models or improve generalized AI models.

Where product improvement activities are performed, they are conducted using appropriate technical and organizational safeguards and in accordance with applicable contractual commitments and data protection laws.

Compliance with Data Protection Laws

Our services are designed to support compliance with applicable privacy and data protection legislation, including, where applicable:

  • the General Data Protection Regulation (GDPR);
  • the UK GDPR and Data Protection Act 2018;
  • the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA);
  • the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
  • the EU AI Act; and
  • other applicable privacy, AI governance, and sector-specific regulations.

Customers remain responsible for configuring and using the services in a manner consistent with their own legal and regulatory obligations.

High-Risk and Regulated Use Cases

Our AI solutions may be deployed in regulated industries, including healthcare, banking, financial services, insurance, government, telecommunications, manufacturing, and critical infrastructure.

Where our services are used within regulated environments, customers are responsible for determining whether their intended use constitutes a regulated or high-risk AI use case under applicable law and for implementing any required governance, risk management, documentation, validation, human oversight, or regulatory controls.

Unless expressly documented otherwise, our services are not marketed or certified as autonomous decision-making systems for regulated activities.

Human Oversight

AI-generated outputs may contain inaccuracies, biases, omissions, or outdated information.

Customers should ensure that appropriately qualified individuals review outputs before they are relied upon for decisions involving legal rights, healthcare, financial services, insurance, employment, public services, safety, or other matters that may significantly affect individuals.

Accountability. Efficiency. 

We assign responsibility for the development, integration, and oversight of AI solution to designated team members. We consider ethical implications and compliance requirements in all AI-related activities. We evaluate the AI solution for effectiveness, efficiency, quality, value, and impact. Our goal is to deliver positive outcomes for our users, customers, and society, while minimizing any negative or unintended consequences. We instruct our team to make sure that AI is used responsibly and appropriately, in line with our mission, values, and the broader interests of society. 

Accuracy. 

We are committed to delivering AI solution that is accurate and reliable. However, we acknowledge that AI solutions are inherently non-deterministic and, as such, errors or unexpected outcomes may occur from time to time. AI-generated output may not always be accurate and may include mistakes or hallucinations; this is an inherent risk of using AI technologies. 

Security and Confidentiality

The safety and security of our AI solution is top priorities for us. We implement appropriate technical and organizational measures designed to protect customer information against unauthorized access, alteration, disclosure, or destruction, consistent with applicable legal requirements and our contractual commitments. We have obtained an ISO 27001, SOC2 type II, and ISO47001 certification. 

Third party AI tools

When using third-party AI tools, we conduct due diligence to ensure that such tools align with our governance and ethics principles. 

Prohibited Uses

Customers must not use our AI services to:

  • violate applicable laws or regulations;
  • infringe intellectual property or privacy rights;
  • generate or distribute unlawful, fraudulent, deceptive, or harmful content;
  • facilitate discrimination or unlawful profiling;
  • create or deploy AI systems intended to circumvent legal safeguards or human oversight; or
  • use the services in any manner prohibited by applicable agreements or law.