QAAIFY

AI Use Policy

Draft — requires legal review before publishing

Internal note (remove before publishing to customers)

Effective date: [PLACEHOLDER] · Version 0.1 (draft)

1. General provisions

This Policy sets out the rules for using AI features in the QAAIFY Platform: evaluating the quality of tickets, generating explanations, coaching suggestions, knowledge-base support, compliance support, analytics, and other tasks permitted within the Platform.

2. Principles of AI use

  • AI is used as a decision-support tool, not as a final professional, legal, or HR arbiter.
  • AI results may contain errors, inaccuracies, incompleteness, or outdated assumptions.
  • The Client must independently verify AI results before using them in processes that have legal, disciplinary, financial, or other significant consequences.
  • If an AI result affects an employee or another individual, the Client must ensure human review wherever required by law or the Client's internal policy.

3. Permitted use

AI features may be used for analyzing tickets, generating internal recommendations, preparing reports, improving processes, identifying knowledge-base gaps, and auxiliary automation, without automatically executing data-changing actions that require confirmation by an authorized person.

4. Prohibited use

It is prohibited to use AI features for:

  • unlawful activity, fraud, discrimination, or violation of third-party rights;
  • creating or distributing harmful content;
  • circumventing technical limitations, deliberate prompt injection attacks, or other model abuse;
  • using AI results as the sole basis for decisions with significant consequences without human review, where not permitted by law.

5. Third-party AI providers

The Platform works with the AI provider chosen by the Client (OpenAI, Anthropic, or Google Gemini) — the Client connects its own API key. Such a provider processes data under its own terms and policies. The Client independently verifies the AI provider's suitability for its needs and the lawfulness of transferring data to that provider.

6. Sensitive data and masking

The Platform applies automated masking of sensitive data (card numbers, CVV, phone numbers, passwords, access tokens) in ticket text before it is sent to the AI provider. The Client must not submit to the AI data whose processing is prohibited by law or by the Client's internal policy.

7. Human oversight and traceability

The Platform retains the technical data necessary to reproduce an AI evaluation and review its history: the prompt version, the AI provider and model, and the human-review status. Where the functionality allows for human confirmation, correction, or appeal, the Client is responsible for the final decision. The AI copilot does not execute data-changing actions automatically — it only proposes them, and execution follows only after explicit confirmation by an authorized person of the Client.

8. Use of AI results

The Client acknowledges that AI results are auxiliary and must be assessed in the context of the data, processes, and human oversight. The Provider does not guarantee that AI results will be error-free or fit for any particular purpose.

9. Disclosing AI interactions to the Client's own customers

The Platform itself does not communicate directly with the Client's end customers — it only evaluates the quality of already-completed tickets. If the Client itself uses an AI agent or chatbot to communicate with its own customers, the obligation to disclose that fact (for example, under Article 50 of the EU AI Act) rests with the Client, not with the Provider.

10. Data used for model training

The Provider does not use Client Content to train, fine-tune, or otherwise improve its own AI models or the general-purpose models of third-party providers.

11. Changes to this Policy

The Provider may update this Policy by publishing a new version on the Site. Continued use of the AI features after the new version takes effect constitutes acceptance of it, unless otherwise contrary to law.

See also Terms of Use, Privacy Policy, DPA and Trust Center.