All policies

Legal

Responsible AI Policy

BEEVELOPE

RESPONSIBLE AI & AI GOVERNANCE POLICY

Effective Date: 5 September 2026

PART I

INTRODUCTION, PURPOSE, SCOPE, DEFINITIONS AND GOVERNING PRINCIPLES

1. Introduction

1.1 Welcome to the Responsible AI & AI Governance Policy (”AI Policy”) of Beevelope (”Company”, “we”, “our” or “us”).

This AI Policy establishes the principles, governance framework and operational standards governing the design, development, deployment, operation and continuous improvement of the artificial intelligence (”AI”) capabilities incorporated into the Company’s software-as-a-service platform, websites, application programming interfaces (”APIs”), integrations, automation tools and related services (collectively, the “Services”).

1.2Artificial intelligence is central to the Company’s mission of enabling businesses to automate workflows, improve productivity, enhance customer engagement and support data-driven decision-making. The Company is committed to ensuring that AI technologies are developed and deployed responsibly, ethically and in accordance with Applicable Laws.

1.3 This AI Policy reflects the Company’s commitment to trustworthy AI by promoting transparency, accountability, fairness, privacy, security, human oversight and responsible innovation throughout the AI lifecycle.

2. Purpose

The purpose of this AI Policy is to:

(a) establish the Company’s AI governance framework;

(b) promote the responsible and ethical use of AI technologies;

(c) define the responsibilities of the Company and its Customers regarding AI-enabled Services;

(d) support compliance with Applicable Laws and recognised AI governance principles;

(e) encourage transparency and appropriate human oversight in AI-assisted decision-making;

(f) reduce risks associated with AI systems;

(g) protect Customers, Users and other stakeholders from foreseeable misuse of AI; and

(h) foster trust, accountability and responsible innovation in the development and use of AI-powered Services.

3. Scope

This AI Policy applies to all AI-powered functionalities, products and Services provided by the Company, including but not limited to:

(a) AI-assisted content generation;

(b) AI-generated emails and communications;

(c) AI-powered campaign recommendations;

(d) workflow automation;

(e) predictive analytics;

(f) lead scoring and prioritization;

(g) summarization;

(h) classification;

(i) natural language processing;

(j) intelligent search;

(k) AI-powered reporting and analytics;

(l) conversational AI features;

(m) APIs providing AI functionality; and

(n) future AI-enabled products or services introduced by the Company.

4. Applicability

This AI Policy applies to:

(a) Customers;

(b) Users;

(c) administrators;

(d) Authorized Representatives;

(e) employees;

(f) contractors;

(g) Affiliates;

(h) Authorised Sub-processors involved in AI Processing; and

(i) any other person accessing or using AI-powered Services provided by the Company.

All such persons are expected to comply with this AI Policy, the Terms of Service and Applicable Laws.

5. Relationship with Other Documents

This AI Policy should be read together with the Company’s:

(a) Terms of Service;

(b) Privacy Policy;

(c) Data Processing Agreement;

(d) Information Security Policy;

(e) Service Level Agreement;

(f) API and Integration Terms;

(g) AI Services and Responsible AI Schedule;

(h) Cookie Policy; and

(i) other applicable policies or contractual documents.

In the event of any inconsistency concerning Personal Data Processing, the Privacy Policy, Data Processing Agreement and Applicable Privacy Laws shall prevail to the extent of such inconsistency.

6. Definitions

For the purposes of this AI Policy:

“Artificial Intelligence” or “AI” means computational systems capable of generating content, making predictions, producing recommendations, classifying information, automating workflows or performing other intelligent functions using machine learning, large language models, natural language processing or similar technologies.

“AI Model” means any statistical, machine learning, deep learning, large language model or other computational model used to provide AI-powered functionality.

“AI Input” means any prompt, instruction, document, communication, dataset, Customer Data or other information submitted to an AI-powered Service.

“AI Output” means any text, recommendation, summary, classification, prediction, analysis, workflow, communication or other content generated by an AI-powered Service.

“Customer”, “Personal Data”, “Processing”, “Services”, “User” and “Applicable Laws” shall have the meanings assigned to them in the Terms of Service unless otherwise defined herein.

7. AI Governance Principles

The Company’s AI governance programme is guided by the following principles:

(a) Lawfulness – AI shall be developed and deployed in accordance with Applicable Laws.

(b) Human Oversight – AI is intended to assist human decision-making and not replace appropriate human judgment.

(c) Transparency – Users should be informed when interacting with AI-powered functionality where appropriate.

(d) Accountability – The Company maintains governance processes designed to oversee the responsible development and operation of AI-enabled Services.

(e) Fairness – The Company endeavours to reduce unjustified bias and promote equitable treatment in AI-assisted processes.

(f) Privacy – AI Processing shall respect privacy rights and applicable data protection requirements.

(g) Security – AI systems shall be supported by appropriate technical and organizational safeguards designed to protect Customer Data and maintain system integrity.

(h) Reliability – AI-enabled Services should be designed to operate consistently and be subject to ongoing monitoring and improvement.

(i) Continuous Improvement – AI technologies shall be periodically reviewed and enhanced to improve performance, safety, compliance and user experience.

8. Commitment to Responsible AI

The Company is committed to developing and operating AI-enabled Services in a manner that:

(a) respects human rights;

(b) promotes responsible innovation;

(c) encourages meaningful human oversight;

(d) supports trustworthy business decision-making;

(e) protects confidential information;

(f) safeguards Personal Data;

(g) mitigates reasonably foreseeable AI-related risks; and

(h) complies with evolving legal, ethical and regulatory expectations relating to artificial intelligence.

The Company recognises that AI technologies continue to evolve and shall periodically review this AI Policy to reflect technological advancements, emerging risks, regulatory developments and recognised industry best practices.

9. Nature of AI Services

The Company’s AI-powered Services are intended to assist Users by generating content, recommendations, analyses and workflow automation.

AI-generated Outputs are designed to support, rather than replace, professional judgment. Customers and Users remain responsible for reviewing, validating and approving AI Outputs before relying upon them for business, legal, financial or operational purposes.

10. Acceptance of this AI Policy

By accessing or using AI-powered Services provided by the Company, Customers and Users acknowledge that they have read, understood and agree to comply with this AI Policy together with the Terms of Service and other applicable policies governing the Services.

Where Applicable Laws require additional notices or consents relating to AI Processing, such notices or consents shall be provided separately.

PART II

AI GOVERNANCE FRAMEWORK, HUMAN OVERSIGHT, ACCOUNTABILITY, TRANSPARENCY AND RISK MANAGEMENT

11. AI Governance Framework

11.1The Company shall maintain an AI governance framework designed to promote the responsible design, development, deployment, operation and continuous improvement of AI-powered Services.

11.2The AI governance framework shall be proportionate to the nature, scale and complexity of the Company’s AI systems and shall be reviewed periodically to reflect:

(a) technological developments;

(b) regulatory changes;

(c) evolving industry standards;

(d) operational experience;

(e) identified risks; and

(f) customer feedback.

11.3The governance framework is intended to ensure that AI systems operate in a manner that is lawful, reliable, transparent, secure and aligned with the Company’s ethical commitments.

12. Accountability

12.1The Company remains responsible for the governance and operation of AI-powered Services developed or provided by it.

12.2The Company shall establish appropriate internal governance processes for:

(a) oversight of AI systems;

(b) risk assessment;

(c) policy implementation;

(d) operational monitoring;

(e) compliance management; and

(f) continuous improvement.

12.3Customers remain responsible for their own business decisions, communications and actions taken based upon AI Outputs.

13. Human Oversight

13.1The Company believes that AI should support human decision-making rather than replace meaningful human judgment.

13.2Accordingly, AI-powered Services are designed to assist Users by providing recommendations, analyses, automation and draft content.

13.3Customers and Users are expected to exercise appropriate human review before:

(a) sending AI-generated communications;

(b) making commercial decisions;

(c) relying upon AI-generated recommendations;

(d) publishing AI-generated content;

(e) entering contractual commitments; or

(f) taking actions capable of producing legal, financial or significant business consequences.

13.4The Company does not represent that AI Outputs should be relied upon without independent review.

14. Transparency

14.1The Company is committed to promoting transparency regarding the use of AI within the Platform.

14.2Where appropriate, Users shall be informed that particular functionality is AI-assisted or AI-generated.

14.3The Company shall endeavour to provide information regarding:

(a) the intended purpose of AI functionality i.e. AI Email drafting; subject/ body generation; personalization; follow-up sequencing; lead scoring; reply sentiment/ intent classification; AI presentation- deck generation; multi provider AI contact enrichment, etc;

(b) the general capabilities of AI features;

(c) known limitations;

(d) expected user responsibilities; and

(e) applicable safeguards.

14.4The Company may publish documentation describing AI functionality without disclosing confidential information, proprietary algorithms or trade secrets.

15. Explainability

15.1The Company recognises the importance of enabling Users to understand the role played by AI in generating Outputs.

15.2Where reasonably practicable, the Company shall endeavour to provide explanations regarding:

(a) the intended purpose of AI functionality;

(b) the nature of AI-generated Outputs;

(c) factors influencing recommendations;

(d) expected limitations; and

(e) appropriate human oversight.

15.3Nothing contained in this AI Policy requires the Company to disclose confidential information, proprietary algorithms, model architecture, source code or trade secrets.

16. Risk-Based Approach

16.1The Company adopts a risk-based approach to AI governance.

16.2The level of governance applied to AI functionality may vary depending upon factors including:

(a) intended use;

(b) complexity;

(c) potential impact on individuals;

(d) security considerations;

(e) legal obligations;

(f) sensitivity of processed information; and

(g) reasonably foreseeable risks.

16.3Higher-risk AI functionality may be subject to enhanced governance, testing and monitoring.

17. AI Lifecycle Management

The Company seeks to implement governance throughout the lifecycle of AI-enabled Services, including:

(a) planning;

(b) design;

(c) development;

(d) testing;

(e) deployment;

(f) monitoring;

(g) maintenance;

(h) improvement; and

(i) retirement of AI functionality where appropriate.

18. Continuous Monitoring

The Company may monitor AI-powered Services for purposes including:

(a) identifying operational issues;

(b) improving reliability;

(c) detecting abnormal behaviour;

(d) reducing reasonably foreseeable risks;

(e) improving performance;

(f) enhancing customer experience; and

(g) complying with Applicable Laws.

Monitoring shall be conducted in accordance with the Privacy Policy and Applicable Laws.

19. AI Performance Evaluation

The Company may periodically evaluate AI functionality using appropriate performance indicators, including:

(a) reliability;

(b) consistency;

(c) operational effectiveness;

(d) user feedback;

(e) error trends;

(f) security observations; and

(g) other appropriate evaluation criteria.

Such evaluations are intended to support continuous improvement rather than guarantee specific performance outcomes.

20. Documentation and Governance Records

The Company may maintain documentation relating to AI governance, including:

(a) governance policies;

(b) operational procedures;

(c) risk assessments;

(d) testing activities;

(e) monitoring activities;

(f) incident records;

(g) model updates; and

(h) compliance activities.

Such documentation may be maintained to demonstrate responsible AI governance, facilitate internal oversight and support compliance with Applicable Laws.

21. Independent Review

Where appropriate for the nature of the AI functionality or where required by Applicable Laws, the Company may conduct or commission internal or external reviews of aspects of its AI governance programme.

Any such review shall not be interpreted as creating a guarantee that AI systems are free from error or risk.

22. Governance Review and Updates

The Company shall periodically review this AI Governance Framework to ensure that it remains appropriate in light of:

(a) technological developments;

(b) changes in Applicable Laws;

(c) recognised industry standards;

(d) operational experience;

(e) customer feedback;

(f) security developments; and

(g) emerging AI risks.

Material changes may be reflected in updated versions of this AI Policy or related governance documentation.

PART III

AI SERVICES, AI INPUTS, AI OUTPUTS, CUSTOMER RESPONSIBILITIES AND AI LIMITATIONS

23. AI Services

23.1The Company provides AI-powered Services designed to assist Customers and Users in improving business productivity, communication, workflow automation, sales engagement and operational efficiency.

23.2AI Services may include, without limitation:

(a) AI-generated email drafting;

(b) personalised communication recommendations;

(c) campaign optimisation;

(d) workflow automation;

(e) lead scoring and prioritisation;

(f) intelligent search;

(g) summarisation;

(h) natural language processing;

(i) predictive analytics;

(j) classification;

(k) reporting and business insights;

(l) conversational AI; and

(m) any future AI-enabled functionality introduced by the Company.

23.3The Company may introduce, modify or discontinue AI features from time to time in accordance with the Terms of Service.

24. AI Inputs

24.1Customers and Users may submit prompts, instructions, documents, communications, datasets, CRM information, campaign details, templates or other information (”AI Inputs”) for processing through AI-powered Services.

24.2Customers remain solely responsible for ensuring that AI Inputs:

(a) are accurate;

(b) are lawful;

(c) do not infringe the rights of any third party;

(d) comply with Applicable Laws;

(e) comply with the Terms of Service; and

(f) may lawfully be processed through the Services.

24.3Customers should avoid submitting confidential, sensitive or regulated information to AI Services unless such Processing is authorised under applicable contractual arrangements and Applicable Laws.

25. AI Outputs

25.1AI-powered Services generate content, recommendations, analyses and other materials (”AI Outputs”) based on AI Inputs and computational models.

25.2AI Outputs are generated using probabilistic technologies and may not always be:

(a) accurate;

(b) complete;

(c) current;

(d) unique;

(e) legally compliant;

(f) suitable for a particular purpose; or

(g) free from factual or contextual errors.

25.3AI Outputs should be treated as decision-support material rather than definitive professional advice.

26. Human Review

26.1Customers and Users shall exercise appropriate human judgment before relying upon AI Outputs.

26.2Human review is strongly recommended before:

(a) sending customer communications;

(b) publishing content;

(c) executing marketing campaigns;

(d) entering legal obligations;

(e) making financial decisions;

(f) communicating with regulators;

(g) taking employment-related decisions; or

(h) making decisions that could materially affect individuals or businesses.

26.3The Company does not guarantee that AI Outputs are suitable for use without independent verification.

27. Customer Responsibilities

Customers remain solely responsible for:

(a) reviewing AI Outputs;

(b) verifying factual accuracy;

(c) ensuring legal compliance;

(d) confirming commercial suitability;

(e) exercising appropriate business judgment;

(f) maintaining adequate human oversight;

(g) complying with Applicable Laws; and

(h) using AI Services responsibly.

The Company does not assume responsibility for decisions made by Customers based upon AI Outputs.

28. AI Limitations

Customers acknowledge that AI technologies have inherent limitations.

Accordingly, AI Outputs may:

(a) contain factual inaccuracies;

(b) omit relevant information;

(c) misinterpret AI Inputs;

(d) generate incomplete responses;

(e) reflect limitations of training data;

(f) produce inconsistent outputs for similar inputs;

(g) fail to understand context; or

(h) otherwise produce results requiring human verification.

The Company continually seeks to improve AI performance but cannot eliminate all limitations inherent in AI technologies.

29. Hallucinations and Incorrect Outputs

29.1AI systems may occasionally generate information that appears plausible but is inaccurate, misleading or unsupported (”hallucinations”).

29.2Customers shall independently verify AI-generated factual statements before relying upon them.

29.3The Company shall not be responsible for losses resulting from reliance upon AI Outputs without appropriate human review.

30. Prohibited Reliance

Unless expressly stated otherwise in writing, AI Outputs should not be relied upon as a substitute for:

(a) legal advice;

(b) medical advice;

(c) accounting advice;

(d) tax advice;

(e) financial or investment advice;

(f) engineering advice;

(g) regulatory compliance advice; or

(h) any other professional advice requiring qualified human expertise.

Users should consult appropriately qualified professionals where specialised advice is required.

31. Ownership of AI Inputs and AI Outputs

31.1Ownership of AI Inputs remains with the Customer or the party lawfully entitled to such information.

31.2Ownership and licensing of AI Outputs shall be governed by the Terms of Service and any applicable Enterprise Agreement.

31.3Nothing in this AI Policy transfers ownership of the Company’s AI models, algorithms, software, prompts, methodologies, datasets, documentation or other intellectual property.

32. AI Model Updates

The Company may update, improve, retrain, replace or modify AI models to:

(a) improve performance;

(b) enhance reliability;

(c) improve security;

(d) comply with Applicable Laws;

(e) support new functionality;

(f) improve user experience; or

(g) address operational requirements.

Customers acknowledge that AI Outputs may change over time as AI models evolve.

33. Availability of AI Services

AI-powered functionality may be modified, suspended or discontinued where reasonably necessary due to:

(a) maintenance;

(b) security concerns;

(c) legal requirements;

(d) operational improvements;

(e) third-party service availability;

(f) infrastructure changes; or

(g) technological developments.

The Company shall use commercially reasonable efforts to minimise disruption but does not guarantee uninterrupted availability of AI Services.

34. Feedback and Continuous Improvement

Customers may voluntarily provide feedback regarding AI functionality.

The Company may use such feedback to improve AI models, user experience and operational performance, subject to the Terms of Service, Privacy Policy and Applicable Laws.

Submission of feedback does not create any obligation upon the Company to implement requested changes.

PART IV

ACCEPTABLE USE OF AI SERVICES AND PROHIBITED ACTIVITIES

35. General Principle

35.1The Company’s AI-powered Services are intended to be used solely for lawful, ethical and responsible business purposes.

35.2Customers and Users shall use AI Services in a manner that respects Applicable Laws, contractual obligations, intellectual property rights, privacy rights, human dignity and recognised principles of responsible artificial intelligence.

35.3Customers remain solely responsible for all AI Inputs submitted to the Services and for any actions taken based upon AI Outputs.

36. Compliance with Applicable Laws

Customers shall ensure that their use of AI Services complies with all Applicable Laws, including laws relating to:

(a) privacy and data protection;

(b) intellectual property;

(c) consumer protection;

(d) electronic communications;

(e) anti-spam requirements;

(f) competition laws;

(g) export controls;

(h) sanctions;

(i) anti-corruption; and

(j) employment and human rights.

37. Fraudulent and Deceptive Activities

Customers shall not use AI Services to:

(a) commit fraud;

(b) facilitate identity theft;

(c) impersonate another individual or organisation;

(d) create forged or misleading documents;

(e) deceive customers regarding the identity of the sender;

(f) misrepresent AI-generated content as independently verified where such representation would be misleading; or

(g) otherwise engage in deceptive commercial practices.

38. Spam and Unsolicited Communications

AI Services shall not be used to:

(a) send unsolicited commercial communications in violation of Applicable Laws;

(b) generate spam;

(c) bypass anti-spam mechanisms;

(d) automate unlawful mass communications;

(e) harvest email addresses unlawfully; or

(f) otherwise violate applicable electronic communication regulations.

Customers remain responsible for ensuring that all communications generated or distributed using the Platform comply with applicable anti-spam legislation.

39. Harmful, Illegal and Offensive Content

Customers shall not use AI Services to generate, distribute or facilitate content that:

(a) violates Applicable Laws;

(b) promotes terrorism or violent extremism;

(c) incites violence;

(d) constitutes child sexual abuse material or exploits children;

(e) promotes human trafficking;

(f) facilitates organised criminal activity;

(g) unlawfully discriminates against protected individuals or groups;

(h) constitutes unlawful harassment; or

(i) is otherwise prohibited under the Terms of Service.

40. Intellectual Property

Customers shall not knowingly use AI Services to:

(a) infringe copyrights;

(b) infringe trademarks;

(c) misappropriate trade secrets;

(d) violate patent rights;

(e) remove or alter copyright notices;

(f) reproduce protected works without appropriate authorisation; or

(g) otherwise infringe the intellectual property rights of any person.

Customers remain responsible for ensuring that AI Inputs submitted to the Platform may lawfully be processed.

41. Privacy and Personal Data

Customers shall not use AI Services to:

(a) Process Personal Data unlawfully;

(b) submit Personal Data without an appropriate lawful basis;

(c) intentionally disclose confidential Personal Data to unauthorised persons;

(d) circumvent privacy protections;

(e) attempt to identify anonymised information unlawfully; or

(f) otherwise violate Applicable Privacy Laws.

The Processing of Personal Data through AI Services remains subject to the Privacy Policy, the Data Processing Agreement and Applicable Privacy Laws.

42. Cybersecurity and Malicious Activities

Customers shall not use AI Services to:

(a) develop malicious software;

(b) facilitate cyberattacks;

(c) compromise computer systems;

(d) distribute malware;

(e) conduct phishing campaigns;

(f) steal credentials;

(g) bypass security controls;

(h) exploit software vulnerabilities;

(i) interfere with the integrity or availability of the Platform; or

(j) engage in any unlawful cybersecurity activity.

43. Manipulation and Misinformation

Customers shall not knowingly use AI Services to:

(a) generate false information intended to deceive;

(b) manipulate elections or democratic processes unlawfully;

(c) create fabricated evidence;

(d) spread malicious misinformation;

(e) impersonate public authorities;

(f) manipulate financial markets unlawfully; or

(g) otherwise undermine public trust through deceptive AI-generated content.

44. Deepfakes and Synthetic Media

AI Services shall not be used to create or distribute synthetic media intended to:

(a) impersonate identifiable individuals without lawful authority;

(b) commit fraud;

(c) facilitate extortion;

(d) damage another person’s reputation unlawfully;

(e) mislead the public regarding factual events; or

(f) otherwise violate Applicable Laws.

Where AI-generated content could reasonably be mistaken for authentic human-created content, Customers are encouraged to provide appropriate disclosure where required by Applicable Laws or industry standards.

45. High-Risk Decisions

Unless expressly authorised by the Company in writing, AI Services should not be used as the sole basis for decisions concerning:

(a) employment;

(b) recruitment;

(c) promotion;

(d) dismissal;

(e) credit decisions;

(f) insurance eligibility;

(g) medical diagnosis or treatment;

(h) legal determinations;

(i) law enforcement actions; or

(j) other decisions producing legal or similarly significant effects on individuals.

Meaningful human review should always accompany such decisions.

46. Reverse Engineering and AI Abuse

Customers shall not:

(a) attempt to extract AI models;

(b) reverse engineer proprietary AI systems;

(c) circumvent technical safeguards;

(d) probe AI models for confidential information;

(e) conduct model extraction attacks;

(f) intentionally manipulate AI systems to produce harmful outputs;

(g) interfere with AI safety mechanisms; or

(h) otherwise misuse the Company’s AI technology.

47. Reporting Misuse

Customers are encouraged to promptly report suspected misuse of AI Services, security concerns or policy violations through the Company’s designated reporting channels.

The Company may investigate reports and take appropriate action consistent with Applicable Laws and the Terms of Service.

48. Enforcement

Where the Company reasonably believes that AI Services are being used in violation of this AI Policy, the Terms of Service or Applicable Laws, the Company may, subject to Applicable Laws and contractual obligations:

(a) issue warnings;

(b) require corrective action;

(c) suspend or restrict access to AI functionality;

(d) remove or disable AI-generated content where appropriate;

(e) terminate access to the Services;

(f) cooperate with competent governmental authorities; and

(g) take any other lawful action reasonably necessary to protect the Platform, Customers or third parties.

Nothing in this Policy limits any additional contractual or legal remedies available to the Company.

PART V

AI DATA GOVERNANCE, DATA QUALITY, CONFIDENTIALITY AND MODEL MANAGEMENT

49. General Principles

49.1The Company recognises that responsible AI depends upon sound data governance, appropriate security safeguards and responsible management of AI models throughout their lifecycle.

49.2The Company shall implement commercially reasonable governance measures designed to ensure that AI-enabled Processing is conducted lawfully, fairly, transparently and securely.

49.3AI systems shall Process information only for legitimate business purposes consistent with this AI Policy, the Privacy Policy, the Terms of Service, the Data Processing Agreement and Applicable Laws.

50. AI Data Governance

The Company shall maintain governance processes intended to promote:

(a) lawful Processing of information;

(b) data quality;

(c) confidentiality;

(d) integrity;

(e) accountability;

(f) security;

(g) appropriate retention practices;

(h) responsible model governance; and

(i) continuous improvement.

51. Customer Data

51.1Customers retain ownership of all Customer Data submitted to the Platform.

51.2The Company Processes Customer Data solely for purposes authorised under the applicable contractual arrangements and Applicable Laws.

51.3The Company shall not claim ownership of Customer Data merely because such data is Processed using AI-powered Services.

52. AI Inputs

Customers are responsible for ensuring that AI Inputs:

(a) are accurate;

(b) have been lawfully collected;

(c) may lawfully be Processed;

(d) do not infringe intellectual property rights;

(e) do not violate confidentiality obligations; and

(f) comply with Applicable Laws.

Customers should avoid submitting information that is unnecessary for the requested AI functionality.

53. Data Quality

The quality of AI Outputs depends substantially upon the quality of AI Inputs.

Accordingly:

(a) Customers are encouraged to provide accurate and relevant information;

(b) incomplete or inaccurate AI Inputs may result in inaccurate AI Outputs;

(c) AI-generated content should always be independently reviewed before use; and

(d) the Company does not warrant that AI Outputs derived from inaccurate AI Inputs will be reliable.

54. Confidentiality

54.1The Company shall implement commercially reasonable measures designed to preserve the confidentiality of Customer Data Processed through AI Services.

54.2Access to Customer Data shall be restricted to authorised personnel, authorised Subprocessors and systems requiring such access for legitimate operational purposes.

54.3Individuals authorised to access Customer Data shall be subject to appropriate confidentiality obligations.

55. Privacy Protection

Where AI Services Process Personal Data, such Processing shall be conducted in accordance with:

(a) the Privacy Policy;

(b) the Data Processing Agreement;

(c) the Terms of Service; and

(d) Applicable Privacy Laws.

Nothing contained in this AI Policy limits the rights available to Data Subjects under Applicable Privacy Laws.

56. AI Model Governance

The Company shall maintain governance procedures relating to AI models, including where appropriate:

(a) model evaluation;

(b) model version management;

(c) testing before deployment;

(d) monitoring of operational performance;

(e) documentation of material model updates;

(f) periodic review of model performance; and

(g) retirement or replacement of models where appropriate.

57. AI Model Improvement

57.1The Company may improve AI functionality through research, testing, operational monitoring and product development.

57.2 Where Customer Data or Personal Data is used in connection with model improvement, such Processing shall occur only where permitted by Applicable Laws, the applicable contractual arrangements or valid Customer instructions.

57.3The Company shall not use Customer Data for AI model training in a manner inconsistent with its contractual commitments or Applicable Privacy Laws.

58. Third-Party AI Providers

The Company may utilise AI technologies provided by carefully selected third-party providers.

Before engaging such providers, the Company shall use commercially reasonable efforts to ensure that they are subject to appropriate contractual obligations relating to:

(a) confidentiality;

(b) information security;

(c) data protection;

(d) lawful Processing;

(e) operational reliability; and

(f) compliance with Applicable Laws.

The Company remains responsible for managing such providers to the extent required under its contractual and legal obligations.

59. Data Minimisation

The Company endeavours to Process only the information reasonably necessary to provide the requested AI functionality.

Customers are encouraged to avoid submitting excessive, irrelevant or unnecessary information through AI-powered Services.

60. Retention of AI Data

AI Inputs, AI Outputs and associated operational records may be retained only for so long as reasonably necessary to:

(a) provide the Services;

(b) improve system performance where contractually and legally permitted;

(c) maintain Platform security;

(d) investigate operational issues;

(e) comply with Applicable Laws;

(f) resolve disputes; and

(g) fulfil contractual obligations.

Retention practices remain subject to the Privacy Policy and the Company’s applicable retention schedules.

61. Cross-Border Processing

AI-enabled Processing may occur across multiple jurisdictions where necessary to provide the Services.

Where Personal Data is transferred internationally, the Company shall implement appropriate safeguards consistent with Applicable Privacy Laws, the Privacy Policy and the Data Processing Agreement.

62. Security of AI Systems

The Company shall implement commercially reasonable administrative, technical and organisational measures designed to protect AI systems against:

(a) unauthorised access;

(b) unauthorised modification;

(c) model manipulation;

(d) data corruption;

(e) malicious attacks;

(f) operational disruption; and

(g) other reasonably foreseeable cybersecurity threats.

Nothing in this AI Policy guarantees absolute protection against all cybersecurity risks.

63. Continuous Governance

The Company shall periodically review its AI data governance programme in light of:

(a) technological developments;

(b) evolving AI capabilities;

(c) regulatory developments;

(d) recognised industry standards;

(e) customer feedback;

(f) operational experience; and

(g) emerging risks.

Appropriate improvements may be implemented where reasonably necessary to maintain responsible AI governance.

PART VI

AI RISK MANAGEMENT, FAIRNESS, BIAS MITIGATION, TESTING AND CONTINUOUS MONITORING

64. General Principles

64.1The Company recognises that artificial intelligence technologies may present legal, operational, ethical, security and commercial risks if not appropriately governed.

64.2Accordingly, the Company adopts a risk-based approach designed to identify, assess, mitigate, monitor and manage reasonably foreseeable AI-related risks throughout the lifecycle of AI-enabled Services.

64.3The Company’s risk management programme is intended to support the development and operation of AI systems that are lawful, reliable, secure, transparent and accountable.

65. AI Risk Management Framework

The Company shall maintain an AI risk management framework appropriate to the nature, scale and complexity of its AI-powered Services.

The framework may include:

(a) identification of AI-related risks;

(b) assessment of potential impacts;

(c) implementation of mitigation measures;

(d) ongoing operational monitoring;

(e) periodic review;

(f) governance oversight; and

(g) continuous improvement.

66. Risk Identification

The Company may identify and evaluate risks relating to:

(a) reliability;

(b) accuracy;

(c) security;

(d) privacy;

(e) bias;

(f) discrimination;

(g) misuse of AI;

(h) regulatory compliance;

(i) operational resilience;

(j) cybersecurity threats;

(k) intellectual property; and

(l) other reasonably foreseeable risks associated with AI-enabled Services.

67. Risk Assessment

Where appropriate, identified AI risks may be evaluated having regard to factors including:

(a) likelihood of occurrence;

(b) potential severity of impact;

(c) affected stakeholders;

(d) legal implications;

(e) technical feasibility of mitigation;

(f) operational consequences;

(g) availability of human oversight; and

(h) overall business context.

The level of governance applied may vary depending upon the assessed level of risk.

68. Risk Mitigation

Where reasonably practicable, the Company shall implement measures designed to reduce identified AI-related risks, including:

(a) technical safeguards;

(b) human oversight;

(c) security controls;

(d) access restrictions;

(e) monitoring procedures;

(f) operational policies;

(g) testing protocols; and

(h) user guidance.

The Company recognises that AI-related risks cannot be eliminated entirely and therefore seeks to reduce such risks to commercially reasonable levels.

69. Fairness

The Company endeavours to develop and operate AI-enabled Services in a manner that promotes fairness and equitable treatment.

Accordingly, the Company seeks, where reasonably practicable, to:

(a) avoid arbitrary discrimination;

(b) reduce unjustified bias;

(c) encourage objective AI-assisted decision support;

(d) support consistent operational outcomes; and

(e) promote responsible business use of AI.

The Company does not warrant that AI systems will be entirely free from bias, as such limitations may be inherent in current AI technologies.

70. Bias Mitigation

The Company may implement reasonable measures intended to identify and reduce unjustified bias in AI systems, including:

(a) periodic review of AI Outputs;

(b) operational testing;

(c) evaluation of user feedback;

(d) monitoring of model behaviour;

(e) review of identified anomalies;

(f) improvement of prompts and workflows; and

(g) refinement of governance procedures.

Customers remain responsible for independently reviewing AI Outputs before relying upon them.

71. Testing and Validation

Prior to deployment of material AI functionality, the Company may undertake testing and validation activities appropriate to the nature of the relevant AI system.

Such activities may include:

(a) functional testing;

(b) performance testing;

(c) security testing;

(d) reliability assessments;

(e) operational validation;

(f) compatibility testing;

(g) prompt evaluation; and

(h) quality assurance procedures.

Testing is intended to improve system performance and does not constitute a guarantee that AI Outputs will always be accurate or error-free.

72. Continuous Monitoring

The Company may continuously monitor AI-enabled Services for purposes including:

(a) identifying operational issues;

(b) improving reliability;

(c) detecting abnormal behaviour;

(d) identifying security concerns;

(e) evaluating customer feedback;

(f) improving model performance;

(g) supporting compliance; and

(h) enhancing user experience.

Monitoring activities shall be conducted in accordance with Applicable Laws and the Privacy Policy.

73. AI Incident Management

The Company shall maintain procedures for identifying, investigating and responding to significant AI-related incidents that may affect the integrity, security or lawful operation of AI-powered Services.

Such procedures may include:

(a) incident identification;

(b) technical investigation;

(c) containment measures;

(d) remediation activities;

(e) root cause analysis;

(f) documentation; and

(g) continuous improvement.

Where required by Applicable Laws or contractual obligations, affected Customers shall be notified of relevant incidents within appropriate timeframes.

74. Continuous Improvement

The Company recognises that responsible AI governance requires continual evaluation and improvement. Accordingly, AI systems, governance processes and operational safeguards may be reviewed periodically to:

(a) improve reliability;

(b) enhance safety;

(c) strengthen security;

(d) improve user experience;

(e) address emerging risks;

(f) comply with evolving legal requirements;

(g) improve transparency; and

(h) incorporate technological advancements.

75. Customer Participation

Customers are encouraged to assist the Company in improving AI-enabled Services by:

(a) reporting inaccuracies;

(b) identifying unexpected behaviour;

(c) reporting security concerns;

(d) providing operational feedback;

(e) identifying potential bias; and

(f) suggesting improvements.

The Company may consider such feedback as part of its continuous improvement programme but is not obligated to implement any specific recommendation.

76. Governance Reviews

The Company’s AI governance programme shall be reviewed periodically to determine whether existing governance measures remain appropriate in light of:

(a) technological developments;

(b) recognised industry standards;

(c) operational experience;

(d) evolving customer expectations;

(e) regulatory developments;

(f) emerging AI risks; and

(g) internal governance objectives.

Where appropriate, governance measures may be revised to strengthen responsible AI practices.

PART VII

TRANSPARENCY, EXPLAINABILITY, CUSTOMER CONTROLS, REGULATORY COMPLIANCE AND AI ACCOUNTABILITY

77. General Principles

77.1 The Company recognises that transparency and accountability are fundamental to the responsible development and deployment of artificial intelligence.

77.2Accordingly, the Company endeavours to provide Customers with sufficient information regarding the nature, purpose and intended use of AI-powered Services while protecting its proprietary technology, confidential information and intellectual property.

77.3 Nothing contained in this AI Policy requires the Company to disclose source code, model architecture, proprietary datasets, trade secrets, confidential algorithms or other confidential technical information.

78. Transparency

The Company shall use commercially reasonable efforts to promote transparency regarding AI-powered functionality by:

(a) identifying features that utilise AI where appropriate;

(b) describing the intended purpose of AI functionality;

(c) communicating material limitations of AI-generated Outputs;

(d) providing guidance regarding appropriate human oversight;

(e) informing Customers that AI Outputs may require independent verification; and

(f) publishing appropriate documentation concerning AI-enabled Services.

Transparency does not require disclosure of confidential commercial information or proprietary AI methodologies.

79. Explainability

Where reasonably practicable and appropriate to the nature of the AI functionality, the Company shall endeavour to provide information enabling Customers to understand:

(a) the intended function of AI Services;

(b) the general factors influencing AI Outputs;

(c) the limitations of AI-generated recommendations;

(d) circumstances requiring human review; and

(e) the appropriate use of AI-generated content.

The Company does not warrant that every AI Output will be individually explainable or capable of complete technical interpretation.

80. Customer Controls

The Company may provide Customers with administrative controls allowing them, where applicable, to:

(a) enable or disable particular AI features;

(b) configure workflow automation;

(c) manage user permissions;

(d) control AI-assisted communications;

(e) manage integrations with third-party AI providers;

(f) review AI-generated Outputs prior to publication;

(g) configure organisational preferences; and

(h) otherwise administer AI functionality available under the applicable Subscription Plan.

Availability of specific controls may vary depending upon the Services subscribed to by the Customer.

81. Human-Centred Decision-Making

The Company encourages Customers to maintain meaningful human involvement in decisions that may produce significant legal, financial, employment or commercial consequences.

Customers should ensure that appropriately qualified personnel review AI Outputs before implementing decisions capable of materially affecting individuals, organisations or legal rights.

The Company does not recommend reliance upon AI as the sole basis for significant decisions.

82. Customer Notifications

Where reasonably appropriate, the Company may notify Customers regarding:

(a) material AI model updates;

(b) introduction of significant AI functionality;

(c) important operational limitations;

(d) significant security developments affecting AI Services;

(e) material changes to AI governance practices; and

(f) updates to this AI Policy.

Such notifications may be provided through the Platform, email or other appropriate communication channels.

83. Regulatory Compliance

The Company endeavours to develop and operate AI-powered Services in accordance with Applicable Laws and recognised AI governance principles.

Accordingly, the Company may adopt governance practices consistent with, where applicable:

(a) the European Union Artificial Intelligence Act;

(b) the OECD AI Principles;

(c) the NIST Artificial Intelligence Risk Management Framework;

(d) ISO/IEC 42001 Artificial Intelligence Management Systems;

(e) applicable privacy legislation;

(f) consumer protection laws;

(g) electronic communications regulations; and

(h) other legal requirements applicable to AI-enabled Services.

References to recognised frameworks do not constitute a representation that the Company is formally certified or legally subject to every referenced framework.

84. Regulatory Cooperation

Where required by Applicable Laws, the Company may cooperate with competent governmental authorities, regulators, supervisory authorities and courts in relation to AI governance matters.

Such cooperation may include:

(a) responding to lawful requests;

(b) providing information required by Applicable Laws;

(c) participating in regulatory investigations;

(d) supporting lawful audits; and

(e) implementing legally required corrective measures.

Nothing contained herein obliges the Company to disclose privileged, confidential or proprietary information except where required by Applicable Laws.

85. Internal Governance and Accountability

The Company shall maintain internal governance measures appropriate to the nature of its AI-powered Services, which may include:

(a) governance policies;

(b) documented operational procedures;

(c) allocation of organisational responsibilities;

(d) internal reporting processes;

(e) periodic governance reviews;

(f) compliance oversight; and

(g) continuous improvement initiatives.

The specific governance structure adopted by the Company may evolve as its operations and AI technologies develop.

86. Third-Party AI Providers

Where the Company incorporates AI technologies supplied by third-party providers, the Company shall use commercially reasonable efforts to evaluate such providers with regard to:

(a) operational reliability;

(b) security;

(c) privacy;

(d) contractual protections;

(e) responsible AI practices; and

(f) compliance with Applicable Laws.

The Company remains responsible for the governance of AI-enabled Services that it provides to Customers, subject to the limitations contained in the Terms of Service and applicable agreements.

87. Audits and Assessments

The Company may conduct or commission internal or external assessments of aspects of its AI governance programme where appropriate.

Such assessments may include reviews relating to:

(a) governance effectiveness;

(b) operational controls;

(c) security practices;

(d) AI risk management;

(e) compliance obligations;

(f) documentation; and

(g) continuous improvement.

Completion of any assessment shall not constitute a guarantee that AI systems are entirely free from defects, vulnerabilities or operational risks.

88. Documentation and Recordkeeping

The Company may maintain records relating to:

(a) AI governance;

(b) operational procedures;

(c) AI model updates;

(d) testing activities;

(e) risk assessments;

(f) incident investigations;

(g) policy reviews; and

(h) regulatory compliance activities.

Such documentation may be retained for governance, audit, legal and operational purposes in accordance with the Company’s retention practices.

89. Continuous Improvement of Governance

Recognizing the rapidly evolving nature of artificial intelligence, the Company shall periodically review and enhance its AI governance framework to reflect:

(a) technological innovation;

(b) recognized industry standards;

(c) regulatory developments;

(d) operational experience;

(e) customer feedback;

(f) emerging risks; and

(g) advancements in responsible AI practices.

Updates to governance practices may be implemented without prior notice where necessary to protect the security, integrity or lawful operation of the Services, subject to Applicable Laws and contractual obligations.

PART VIII

INTELLECTUAL PROPERTY, AI TRAINING, MODEL IMPROVEMENT, FEEDBACK AND INNOVATION

90. General Principles

90.1The Company invests substantial resources in the research, development, deployment and continuous improvement of its artificial intelligence technologies.

90.2This AI Policy establishes the principles governing ownership of AI technology, the treatment of AI Inputs and Outputs, model improvement activities and innovation practices, while respecting Customer rights, intellectual property laws and Applicable Laws.

90.3Nothing contained in this AI Policy shall transfer ownership of any intellectual property except as expressly provided in the applicable Terms of Service or other written agreement.

91. Ownership of AI Technology

91.1The Company retains all right, title and interest in and to:

(a) AI models;

(b) proprietary algorithms;

(c) software;

(d) source code;

(e) prompts developed by the Company;

(f) machine learning systems;

(g) workflows;

(h) model architecture;

(i) documentation;

(j) methodologies;

(k) databases owned by the Company;

(l) know-how; and

(m) all associated intellectual property rights.

91.2Nothing in this AI Policy grants any Customer ownership of the Company’s proprietary AI technologies except as expressly provided under a written agreement.

92. Customer Data Ownership

92.1Customers retain ownership of all Customer Data, AI Inputs and other information submitted to the Services.

92.2The Company does not acquire ownership of Customer Data solely because such data is processed by AI-powered Services.

92.3The Company’s rights to process Customer Data shall be limited to those granted under:

(a) the Terms of Service;

(b) the Privacy Policy;

(c) the Data Processing Agreement;

(d) Customer instructions; and

(e) Applicable Laws.

93. AI Outputs

93.1Ownership, licensing and permitted use of AI Outputs shall be governed by the Terms of Service and any applicable Enterprise Agreement.

93.2Because AI systems may generate similar outputs for different users, the Company does not represent or warrant that every AI Output will be unique or exclusively generated for a particular Customer.

93.3Customers remain responsible for determining whether AI Outputs are suitable for their intended commercial, legal or operational purposes.

94. AI Model Improvement

94.1The Company continuously improves its AI-powered Services through research, testing, quality assurance, operational monitoring and technological innovation.

94.2Any use of Customer Data or Personal Data in connection with AI model improvement shall be undertaken only where permitted by:

(a) Applicable Laws;

(b) contractual commitments;

(c) Customer instructions; or

(d) valid consent where required.

94.3The Company shall not use Customer Data for training general-purpose AI models in a manner inconsistent with its contractual commitments or Applicable Privacy Laws.

95. Feedback

Customers may voluntarily submit suggestions, comments, ideas or other feedback relating to AI-powered Services.

Unless otherwise agreed in writing:

(a) such feedback may be used by the Company to improve the Services;

(b) the Company shall not be obligated to implement any suggestion;

(c) submission of feedback does not create any confidentiality obligation unless separately agreed; and

(d) no compensation shall be payable for voluntarily submitted feedback.

96. Innovation

The Company is committed to responsible innovation and may develop new AI capabilities to improve:

(a) productivity;

(b) automation;

(c) operational efficiency;

(d) customer experience;

(e) reliability;

(f) explainability;

(g) security; and

(h) compliance.

New AI functionality may be introduced subject to the Terms of Service and Applicable Laws.

97. Third-Party AI Models

The Company may incorporate AI technologies provided by third-party providers where appropriate.

Before integrating such technologies, the Company shall use commercially reasonable efforts to evaluate factors including:

(a) operational reliability;

(b) security;

(c) privacy protections;

(d) contractual safeguards;

(e) responsible AI practices; and

(f) legal compliance.

The Company may replace, supplement or discontinue third-party AI providers where reasonably necessary to improve the Services or address legal, operational or security considerations.

98. Research and Development

The Company may undertake research and development activities intended to:

(a) improve AI performance;

(b) enhance user experience;

(c) reduce operational risks;

(d) improve model reliability;

(e) develop new AI-enabled features;

(f) strengthen governance practices; and

(g) advance responsible AI innovation.

Where Personal Data is involved, such activities shall remain subject to the Privacy Policy, the Data Processing Agreement and Applicable Laws.

99. Benchmarking and Performance Evaluation

The Company may evaluate AI models through benchmarking, testing and comparative performance analysis to improve:

(a) accuracy;

(b) reliability;

(c) efficiency;

(d) safety;

(e) scalability;

(f) robustness; and

(g) customer experience.

Such evaluations shall be conducted in accordance with appropriate governance procedures and shall not constitute guarantees regarding future AI performance.

100. Future Technologies

Artificial intelligence technologies continue to evolve rapidly.

Accordingly, the Company may adopt, replace or retire AI technologies where reasonably necessary to:

(a) improve Services;

(b) enhance security;

(c) comply with Applicable Laws;

(d) address emerging risks;

(e) improve operational resilience;

(f) support innovation; or

(g) meet Customer requirements.

Material changes affecting the operation of AI-powered Services may be communicated in accordance with the Terms of Service or this AI Policy.

101. Reservation of Rights

Except where expressly provided under a written agreement, the Company reserves all rights relating to its AI technologies, software, documentation, methodologies, improvements, inventions, discoveries and other intellectual property.

No licence shall be implied except as expressly granted under the Terms of Service or other applicable contractual documentation.

PART IX

REGULATORY COMPLIANCE, GOVERNANCE, INCIDENT MANAGEMENT AND FINAL PROVISIONS

102. Commitment to Regulatory Compliance

102.1The Company is committed to designing, developing, deploying and operating AI-powered Services in accordance with Applicable Laws and recognised principles of responsible artificial intelligence.

102.2The Company shall endeavour to monitor significant legal and regulatory developments affecting artificial intelligence and, where appropriate, update its governance framework to reflect such developments.

102.3Nothing contained in this AI Policy constitutes a representation that every AI feature is subject to every AI-specific law or regulatory framework in every jurisdiction. The applicability of such laws shall depend upon the nature of the Services, the relevant jurisdiction and the circumstances of Processing.

103. AI Governance Programme

The Company shall maintain an internal AI governance programme appropriate to the nature, scale and complexity of its AI-powered Services.

Such programme may include:

(a) governance policies;

(b) documented procedures;

(c) assignment of governance responsibilities;

(d) periodic policy reviews;

(e) internal reporting mechanisms;

(f) compliance oversight;

(g) AI risk assessments;

(h) governance documentation; and

(i) continuous improvement initiatives.

104. AI Incident Reporting and Response

104.1The Company shall maintain procedures designed to identify, investigate, assess and respond to significant AI-related incidents affecting the integrity, security, reliability or lawful operation of AI-powered Services.

104.2 AI-related incidents may include:

(a) material failures of AI functionality;

(b) significant operational disruptions;

(c) security incidents affecting AI systems;

(d) identified misuse of AI Services;

(e) significant bias or discrimination concerns;

(f) material privacy incidents involving AI Processing;

(g) unauthorised manipulation of AI systems; or

(h) other incidents reasonably requiring investigation.

104.3Where required by Applicable Laws or contractual commitments, affected Customers shall be notified of reportable incidents within the timeframes prescribed by Applicable Laws or the applicable agreement.

105. Customer Reporting

Customers are encouraged to promptly notify the Company of:

(a) suspected AI malfunctions;

(b) materially inaccurate AI Outputs;

(c) unexpected AI behaviour;

(d) security vulnerabilities;

(e) suspected policy violations;

(f) unlawful use of AI Services; or

(g) other significant concerns relating to AI-powered functionality.

The Company may investigate such reports and take appropriate corrective action where reasonably necessary.

106. Cooperation with Regulatory Authorities

Where required by Applicable Laws, the Company may cooperate with competent governmental authorities, supervisory authorities, regulators and courts concerning AI governance matters.

Such cooperation may include:

(a) responding to lawful requests;

(b) participating in regulatory investigations;

(c) providing information required by law;

(d) implementing legally required corrective measures; and

(e) supporting compliance activities.

Nothing in this AI Policy requires the Company to disclose confidential information, trade secrets or privileged material except where disclosure is required by Applicable Laws.

107. Audits and Internal Reviews

The Company may periodically conduct or commission internal or independent reviews of aspects of its AI governance programme.

Such reviews may evaluate:

(a) governance effectiveness;

(b) operational controls;

(c) AI risk management;

(d) security measures;

(e) privacy safeguards;

(f) regulatory compliance;

(g) policy implementation; and

(h) opportunities for continuous improvement.

Completion of any review does not constitute a warranty that AI systems are entirely free from defects, vulnerabilities or operational risks.

108. Policy Review and Amendments

108.1Artificial intelligence technologies, industry standards and regulatory expectations continue to evolve.

Accordingly, the Company may amend this AI Policy from time to time to reflect:

(a) changes in Applicable Laws;

(b) regulatory guidance;

(c) technological developments;

(d) operational experience;

(e) customer feedback;

(f) security improvements;

(g) recognised industry standards; or

(h) other legitimate business requirements.

108.2Material revisions shall become effective upon publication or on the effective date specified by the Company, unless Applicable Laws require otherwise.

109. Relationship with Other Policies:

This AI Policy forms part of the Company’s overall governance framework and should be read together with:

(a) the Terms of Service;

(b) the Privacy Policy;

(c) the Data Processing Agreement;

(d) the Information Security Policy;

(e) the Cookie Policy;

(f) the API and Integration Terms;

(g) the Service Level Agreement; and

(h) other policies incorporated by reference.

Where mandatory provisions of Applicable Laws conflict with this AI Policy, the mandatory legal requirements shall prevail to the extent of the inconsistency.

110. Limitation of AI Commitments

While the Company is committed to responsible AI governance, Customers acknowledge that:

(a) AI technologies remain inherently probabilistic;

(b) AI systems may produce inaccurate or unexpected Outputs;

(c) no AI system can guarantee complete accuracy, fairness or reliability in every circumstance;

(d) AI technologies continue to evolve; and

(e) meaningful human oversight remains an essential safeguard.

Nothing contained in this AI Policy shall be interpreted as creating a guarantee regarding the accuracy, completeness or suitability of AI Outputs.

111. Contact Information

Questions, concerns or requests relating to this AI Policy or the Company’s AI governance programme may be directed to the Company using the contact details published on the Platform.

Where required by Applicable Laws, the Company may designate appropriate contacts responsible for AI governance, compliance or regulatory communications.

112. Severability

If any provision of this AI Policy is determined by a court or competent authority to be invalid, illegal or unenforceable, such provision shall be interpreted, modified or severed only to the extent necessary.

The remaining provisions shall continue in full force and effect.

113. No Waiver

Failure by the Company to enforce any provision of this AI Policy shall not constitute a waiver of any right or remedy. Any waiver shall be effective only if made in writing by an authorised representative of the Company.

114. Survival

Those provisions of this AI Policy which by their nature are intended to survive termination of the Services, including provisions relating to confidentiality, intellectual property, compliance, incident reporting, dispute resolution, limitation of liability and responsible AI governance, shall survive termination to the extent necessary to fulfil their intended purpose.

115. Effective Date

This AI Policy shall become effective on the date specified by the Company and shall remain in effect until amended or replaced.

The most current version shall be made available through the Platform or the Company’s official website.

116. Acceptance

By accessing or using AI-powered Services provided by the Company, each Customer and User acknowledges that they have read, understood and agree to comply with this AI Policy together with the Terms of Service and other applicable contractual documentation.

Where Applicable Laws require additional notices or consents relating to AI Processing, such notices or consents shall be obtained separately.

ANNEXURES

To support enterprise customers and procurement reviews, this AI Policy should include the following annexures:

* Annexure A – AI Risk Classification Framework

* Annexure B – Human Oversight Framework

* Annexure C – AI System Lifecycle Governance

* Annexure D – AI Incident Response Framework

* Annexure E – AI Acceptable Use Standards

* Annexure F – AI Model Governance and Change Management

* Annexure G – AI Transparency and User Disclosure Standards

* Annexure H – AI Compliance Mapping (EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD AI Principles)

ANNEXURE A

AI RISK CLASSIFICATION FRAMEWORK

A.1 Purpose

This Annexure establishes Email Marketer’s risk-based framework for identifying, assessing, classifying and managing risks associated with its AI-enabled functionality.

The framework is proportionate to the actual purpose, functionality, data processed and potential impact of the Company’s AI systems and shall be reviewed as the Services, applicable laws and AI capabilities evolve.

A.2 Current AI Functionality

Email Marketer’s current AI functionality includes:

(a) AI-generated email drafting, including subject lines and body content;

(b) personalised per-recipient messaging;

(c) follow-up sequencing;

(d) AI lead scoring and sales prioritisation;

(e) reply sentiment and intent classification;

(f) AI-generated presentation decks; and

(g) multi-provider AI contact research and enrichment.

A.3 Current Risk Classification

Based on the Company’s current intended use and functionality, the above AI-enabled features are classified as Limited / Lower Risk AI Functionality, subject to reassessment where the intended purpose, functionality, data or potential impact materially changes.

This classification is based, among other factors, on the fact that:

(a) the AI is primarily used for content generation, enrichment and B2B sales prioritisation;

(b) the AI is not used to make decisions concerning employment, credit, insurance, healthcare or other similarly consequential decisions about individuals;

(c) the AI does not use biometric identification or categorisation;

(d) the AI does not independently determine legal rights or similarly significant effects concerning individuals; and

(e) lead score, champion score and decision-authority assessments are intended for B2B prospect sales prioritisation and are not intended to constitute decisions producing legal or similarly significant effects.

A.4 Risk Assessment Factors

The Company may consider:

(a) intended purpose;

(b) functionality;

(c) categories and sensitivity of data;

(d) persons potentially affected;

(e) degree of automation;

(f) human involvement;

(g) potential for discrimination or unfair treatment;

(h) privacy and security implications;

(i) scale of deployment;

(j) foreseeable misuse;

(k) reversibility of consequences;

(l) applicable legal requirements; and

(m) changes to the AI model, provider or processing context.

A.5 Elevated or High-Risk Use

If an AI feature is proposed to be used for a materially different purpose, particularly one involving consequential decisions concerning individuals, the Company shall reassess its classification before such use is introduced.

Where appropriate, enhanced controls may include additional risk assessment, testing, documentation, human oversight, approval and monitoring.

A.6 Prohibited Consequential Decision-Making

Email Marketer’s AI functionality shall not be represented or designed as a system for making decisions concerning:

(a) employment;

(b) credit;

(c) insurance;

(d) healthcare;

(e) housing;

(f) education access;

(g) legal rights; or

(h) other similarly consequential decisions concerning individuals.

A.7 Reassessment

The Company may reassess an AI system where there is:

(a) a material change in functionality;

(b) a new AI provider or model;

(c) a material change in the categories of data processed;

(d) a change in intended purpose;

(e) a significant change in automation;

(f) a significant incident; or

(g) a material change in Applicable Laws.

A.8 Documentation

The Company may maintain records of material AI risk assessments, classifications, material changes and governance decisions in accordance with its AI governance procedures.

ANNEXURE B

HUMAN OVERSIGHT FRAMEWORK

B.1 Purpose

This Annexure establishes the human oversight measures applicable to Email Marketer’s AI-enabled functionality.

B.2 Human Responsibility

Customers and Users remain responsible for:

(a) configuring AI-enabled workflows;

(b) selecting or approving campaign templates and instructions;

(c) determining campaign objectives and recipients;

(d) reviewing AI-generated content where appropriate;

(e) ensuring compliance with Applicable Laws; and

(f) determining whether automated sending is appropriate for the relevant campaign.

B.3 Workflow-Level Human Control

Human Users retain control over the configuration and activation of campaigns and workflows.

A Customer may configure automated workflows under which AI-generated communications are sent automatically after the workflow has been launched.

B.4 Automated AI-Generated Communications

The Platform currently permits AI-generated emails to be sent automatically without mandatory per-message human review.

Accordingly, this Policy shall not be interpreted as representing that a human reviews and approves every AI-generated email before transmission.

B.5 AI Quality Self-Check

Certain AI functionality may employ an AI-based “critic” or self-check mechanism designed to identify potential quality issues in AI-generated content.

Such AI-based checking is an additional safeguard and does not constitute human review or human approval.

B.6 Human Review

Human review is strongly recommended, and may be required by the Customer’s own policies or Applicable Laws, before:

(a) launching a campaign;

(b) sending sensitive or high-impact communications;

(c) relying on factual or business claims generated by AI;

(d) using AI-generated content in circumstances requiring heightened accuracy; or

(e) taking action that may materially affect an individual.

B.7 Customer Responsibility for Automated Workflows

Where a Customer enables automated campaign or workflow execution, the Customer is responsible for ensuring that:

(a) the workflow is appropriately configured;

(b) the AI instructions are appropriate;

(c) recipient data has been lawfully obtained and may be used;

(d) communications comply with applicable marketing and privacy laws;

(e) unsubscribe and suppression requirements are respected; and

(f) appropriate safeguards are applied to the Customer’s intended use.

B.8 Escalation and Intervention

Where a significant AI-related issue is identified, the Company may restrict, suspend or modify the affected AI feature, model or workflow where reasonably necessary to mitigate risk.

B.9 Future Enhancements

The Company may introduce additional human-oversight controls as AI functionality, applicable laws, customer requirements and recognised governance practices evolve.

ANNEXURE C

AI SYSTEM LIFECYCLE GOVERNANCE

C.1 Purpose

This Annexure establishes governance principles for the lifecycle of AI-enabled functionality from design through deployment, operation, modification and retirement.

C.2 Lifecycle Stages

Where applicable, the Company may apply governance controls across:

(a) planning and intended-purpose definition;

(b) design;

(c) provider/model selection;

(d) development and configuration;

(e) testing and quality assessment;

(f) deployment;

(g) operational monitoring;

(h) maintenance;

(i) material modification;

(j) incident response; and

(k) retirement or replacement.

C.3 Intended Purpose

AI functionality shall be developed and deployed for identified business purposes consistent with the Services.

The current principal purposes include content generation, personalisation, sales prioritisation, reply classification, presentation generation and contact enrichment.

C.4 Data Governance

The Company shall seek to limit AI Processing to information reasonably necessary for the relevant functionality.

Customer Data submitted for AI functionality shall remain subject to the Privacy Policy, Data Processing Agreement and applicable contractual restrictions.

C.5 AI Provider Selection

AI functionality may use approved third-party providers including:

(a) OpenAI;

(b) Anthropic; and

(c) Llama/Ollama where configured as an optional self-hosted alternative.

C.6 Testing and Evaluation

The Company may conduct appropriate functional, reliability, security and quality checks before or during deployment.

Formal bias and structured evaluation testing are identified as governance enhancements for a later stage and shall not be represented as fully implemented controls unless separately confirmed.

C.7 Deployment

Before material AI functionality is deployed, the Company may consider:

(a) intended purpose;

(b) applicable risks;

(c) provider/model suitability;

(d) data-processing implications;

(e) security considerations;

(f) operational reliability; and

(g) applicable legal requirements.

C.8 Monitoring

The Company may monitor AI functionality for operational issues, reliability, security, abnormal behaviour, customer feedback and other reasonably foreseeable risks.

C.9 Modification

Material changes to AI models, providers, functionality or intended purpose shall be subject to the Company’s applicable model governance and change-management procedures.

C.10 Retirement

The Company may discontinue or replace an AI model, provider or feature where reasonably necessary because of:

(a) security concerns;

(b) legal requirements;

(c) reliability concerns;

(d) provider changes;

(e) operational considerations; or

(f) material AI risk.

ANNEXURE D

AI INCIDENT RESPONSE FRAMEWORK

D.1 Purpose

This Annexure establishes the framework for identifying, assessing, containing, investigating and responding to significant AI-related incidents.

D.2 AI Incident

An “AI Incident” may include an event involving:

(a) significant AI malfunction;

(b) material or repeated harmful AI Output;

(c) material security compromise affecting an AI system;

(d) unauthorised AI Processing;

(e) significant privacy impact;

(f) material discriminatory or unsafe behaviour;

(g) compromise of AI credentials;

(h) material failure of an AI safeguard; or

(i) another event reasonably requiring AI governance intervention.

D.3 Reporting Channel

AI-related concerns may be reported to:

Email: support@beevelope.com

The in-product “Contact Support” functionality may be introduced in the future.

D.4 Accountable Owner

The current accountable owner for AI incident governance is:

Abhishek Ray, Founder

The Company may designate another responsible person as the AI governance programme develops.

D.5 Intake

Reported incidents shall, where appropriate, be recorded with available information concerning:

(a) the affected AI functionality;

(b) date and time;

(c) nature of the issue;

(d) affected Customer or User;

(e) relevant data;

(f) potential impact; and

(g) immediate mitigation measures.

D.6 Triage

Incidents may be assessed according to severity, considering:

(a) potential harm;

(b) number of affected persons;

(c) data involved;

(d) duration;

(e) security implications;

(f) legal implications; and

(g) likelihood of recurrence.

D.7 Containment

Where reasonably necessary, the Company may:

(a) pause the affected AI feature;

(b) disable an affected model or provider;

(c) suspend an affected workflow;

(d) revoke or rotate relevant credentials;

(e) restrict access; or

(f) implement other reasonable containment measures.

D.8 Investigation

The Company may investigate:

(a) root cause;

(b) affected model/provider;

(c) affected data;

(d) affected Users;

(e) scope and duration;

(f) legal and regulatory implications; and

(g) appropriate remediation.

D.9 Remediation

Remediation may include:

(a) correcting the affected functionality;

(b) modifying prompts or configurations;

(c) changing or disabling a model/provider;

(d) implementing additional safeguards;

(e) restoring affected functionality following verification; and

(f) conducting a post-incident review.

D.10 Notification

Where a Customer’s Personal Data is affected, the Company shall notify the affected Customer in accordance with the applicable DPA, Privacy Policy and Applicable Laws.

Regulators or other affected persons may be notified where required by Applicable Laws.

D.11 Post-Incident Review

Material incidents may result in:

(a) root-cause analysis;

(b) corrective action;

(c) governance review;

(d) control improvements;

(e) additional testing; and

(f) reassessment of the applicable AI risk classification.

ANNEXURE E

AI ACCEPTABLE USE STANDARDS

E.1 Permitted Uses

Users may use Email Marketer’s AI functionality for legitimate business purposes, including:

(a) email drafting;

(b) subject-line generation;

(c) personalisation;

(d) follow-up sequencing;

(e) campaign optimisation;

(f) contact research and enrichment;

(g) lead scoring and sales prioritisation;

(h) reply sentiment and intent classification;

(i) presentation-deck generation;

(j) summarisation and related productivity functions; and

(k) other functionality expressly provided through the Platform.

E.2 Prohibited Uses

Users shall not use AI functionality to:

(a) facilitate fraud or phishing;

(b) generate malware or malicious code for unlawful purposes;

(c) unlawfully obtain credentials;

(d) impersonate persons or organisations deceptively;

(e) generate fraudulent or materially deceptive communications;

(f) unlawfully discriminate against individuals;

(g) unlawfully process sensitive or special-category Personal Data;

(h) conduct unlawful surveillance;

(i) facilitate harassment or unlawful abuse;

(j) circumvent security or safety controls;

(k) violate Applicable Laws;

(l) generate unlawful content; or

(m) otherwise misuse the Platform.

E.3 Consequential Decision-Making

Users shall not use Email Marketer’s AI functionality as the sole basis for decisions concerning:

(a) employment;

(b) credit;

(c) insurance;

(d) healthcare;

(e) housing;

(f) education access;

(g) legal rights; or

(h) other similarly consequential decisions concerning individuals.

E.4 Sales Prioritisation

AI-generated lead scores, champion scores, decision-authority assessments and related enrichment are intended for B2B sales prioritisation.

Users shall not treat such scores as definitive statements about an individual’s legal status, eligibility, entitlement, character or suitability for a consequential decision.

E.5 Personal Data

Users shall submit Personal Data to AI functionality only where:

(a) they have lawful authority to do so;

(b) the Processing has an appropriate legal basis;

(c) required notices have been provided;

(d) applicable contractual obligations are satisfied; and

(e) appropriate safeguards are maintained.

E.6 Automated Communications

Users may configure automated AI-generated communications where the relevant Platform functionality permits such automation.

The Customer remains responsible for reviewing and configuring the applicable workflow, ensuring lawful use and complying with applicable email-marketing requirements.

E.7 Accuracy

Users shall not knowingly rely upon AI Outputs as inherently accurate or complete.

Material factual, commercial, legal or regulatory claims should be independently verified before reliance or publication where appropriate.

E.8 Circumvention

Users shall not attempt to circumvent:

(a) AI safety controls;

(b) content restrictions;

(c) rate limits;

(d) security mechanisms;

(e) access controls; or

(f) monitoring or abuse-prevention mechanisms.

ANNEXURE F

AI MODEL GOVERNANCE AND CHANGE MANAGEMENT

F.1 Approved AI Providers

The Company’s current AI provider set comprises:

(a) OpenAI;

(b) Anthropic; and

(c) Llama/Ollama as an optional self-hosted alternative.

F.2 Model Configuration

Models may be configured on a feature-specific basis.

The Platform may use an alternate model through a fallback mechanism where the configured model is unavailable, subject to the applicable feature configuration.

F.3 AI Credentials

AI provider credentials controlled by the Company shall be protected using applicable security controls, including encryption at rest.

F.4 No Customer Data Training

Customer Data is not used by Email Marketer to train, fine-tune, evaluate or improve AI models.

The Company’s AI functionality is provided through third-party AI APIs at inference time, and embeddings used for Retrieval-Augmented Generation are used for retrieval rather than model training.

F.5 Model Register

The Company shall maintain a simple, dated record identifying, where applicable:

(a) AI provider;

(b) model;

(c) model version;

(d) feature for which the model is used; and

(e) material changes to the model configuration.

F.6 Approved Provider List

The Company shall maintain an internal list of approved AI providers and document its no-training position.

F.7 Model or Provider Changes

Before adding or switching a material AI model or provider, the Company shall obtain sign-off from the Founder or Dev Lead, or their designated successor.

F.8 Change Assessment

Material changes may be assessed with regard to:

(a) functionality;

(b) intended purpose;

(c) data Processing;

(d) security;

(e) privacy;

(f) reliability;

(g) applicable risk classification; and

(h) legal or regulatory implications.

F.9 Fallback Models

Where a fallback model is configured, the Company shall seek to ensure that the fallback remains appropriate for the relevant feature and intended purpose.

F.10 Model Retirement

A model or provider may be replaced, suspended or retired where reasonably necessary due to:

(a) availability;

(b) performance;

(c) security;

(d) privacy;

(e) legal requirements;

(f) provider changes; or

(g) other material operational considerations.

F.11 Current Governance Limitations

Formal bias/evaluation testing and a structured model-approval workflow are currently identified as future governance enhancements and shall not be represented as fully implemented controls unless and until deployed.

F.12 Provider Terms

The Company shall seek to use applicable AI provider/API arrangements that are consistent with its contractual position that Customer Data is not used for AI model training, fine-tuning, evaluation or improvement.

ANNEXURE G

AI TRANSPARENCY AND USER DISCLOSURE STANDARDS

G.1 Purpose

This Annexure establishes standards for communicating AI involvement to Customers, Users and, where legally required or otherwise appropriate, persons affected by AI-enabled functionality.

G.2 Disclosure to Customers and Users

Email Marketer shall disclose to Customers and Users that the Platform uses AI-enabled functionality for purposes including:

(a) drafting communications;

(b) personalising communications;

(c) contact research and enrichment;

(d) classification;

(e) sales prioritisation; and

(f) other applicable AI-enabled functions.

Such disclosure may be provided through the Platform, Terms of Use, this AI Policy, Privacy Policy or other appropriate documentation.

G.3 Direct AI Interaction

Where a User directly interacts with an AI system through the Platform, the Company shall provide appropriate indication of AI involvement where reasonably appropriate or required by Applicable Laws.

G.4 Recipient-Facing Email Disclosure

The Platform currently does not apply an “AI-generated” label or equivalent AI disclosure to outbound emails sent through a Customer’s connected mailbox.

Such emails are sent from the Customer’s own mailbox and are associated with a real, contactable sender.

G.5 Responsible-Use Safeguards

In the absence of a current recipient-facing AI-generated label, the Company commits to safeguards including:

(a) reasonable quality and accuracy checks within the AI workflow;

(b) compliance with applicable unsubscribe and opt-out requirements;

(c) prohibition of deceptive impersonation;

(d) use of a genuine, contactable sender; and

(e) appropriate Customer responsibility for campaign configuration and content.

G.6 Customer Responsibility

Customers remain responsible for determining whether additional AI disclosure is required for their particular campaigns, jurisdictions, industries or recipients.

G.7 Legal and Regulatory Review

The Company shall monitor developments concerning AI transparency and disclosure requirements, including applicable provisions of the EU AI Act and other Applicable Laws.

Where a legal requirement becomes applicable to the Company’s functionality or use case, the Company may modify its disclosure practices and Platform functionality as reasonably necessary.

G.8 Accuracy and Limitations

Where appropriate, Users may be informed that AI Outputs may contain errors, omissions, inaccuracies or unexpected results and should be reviewed before reliance where appropriate.

G.9 No Disclosure of Protected Information

Transparency obligations shall not require disclosure of:

(a) source code;

(b) proprietary model architecture;

(c) confidential algorithms;

(d) trade secrets;

(e) security-sensitive information; or

(f) confidential third-party information,

except where disclosure is required by Applicable Law.

ANNEXURE H

AI COMPLIANCE MAPPING

Beevelope Governance AreaEU AI ActNIST AI RMFISO/IEC 42001OECD AI Principles
AI governanceGovernance obligationsGOVERNAIMS governanceAccountability
Risk classificationRisk-based frameworkMAP / MANAGERisk managementRisk-based responsible AI
AI risk assessmentRisk managementMAP / MEASUREAI risk assessmentRobustness & safety
Human oversightApplicable high-risk requirementsMAP / GOVERNHuman oversight controlsHuman-centred values
TransparencyArticle 50 where applicableGOVERN / MAPTransparency controlsTransparency & explainability
Data governanceData-related requirementsMAP / MEASUREData governanceData quality / privacy
TestingHigh-risk requirements where applicableMEASUREEvaluation controlsRobustness
MonitoringPost-deployment obligations where applicableMEASURE / MANAGEMonitoring / continual improvementContinuous risk management
Incident managementIncident obligations where applicableMANAGECorrective actionAccountability
SecurityCybersecurity requirements where applicableGOVERN / MEASURE / MANAGESecurity controlsRobustness & safety
DocumentationDocumentation requirements where applicableGOVERN / MAPDocumented informationTraceability
AccountabilityProvider/deployer responsibilitiesGOVERNAIMS responsibilitiesAccountability
Lifecycle governanceLifecycle obligations where applicableAll four functionsContinual improvementLifecycle risk management
AI content disclosureArticle 50GOVERNTransparencyTransparency
Third-party AIProvider/deployer controlsGOVERN / MAPSupplier controlsAccountability
Continuous improvementCompliance monitoringMANAGEPlan–Do–Check–ActContinuous risk management

H.1 Purpose

This Annexure provides a high-level mapping of Email Marketer’s responsible AI governance framework against recognised AI governance frameworks and principles.

This mapping is intended as a governance reference and shall not be interpreted as a certification, conformity assessment or representation that every provision of any referenced framework is currently implemented.

H.2 EU AI Act

Email Marketer shall periodically assess the applicability of the EU AI Act to its AI-enabled functionality having regard to:

(a) intended purpose;

(b) role of the Company and Customer;

(c) nature of the AI system;

(d) affected persons;

(e) applicable risk classification;

(f) transparency requirements; and

(g) other applicable obligations.

The Company’s current AI functionality is primarily directed toward content generation, contact enrichment and B2B sales prioritisation and is not intended for employment, credit, insurance, healthcare or other similarly consequential decision-making concerning individuals.

H.3 NIST AI Risk Management Framework

The Company’s governance approach broadly aligns with the NIST AI RMF functions:

GOVERN – policies, accountability, governance responsibilities and oversight.

MAP – intended purpose, context, stakeholders and risk identification.

MEASURE – performance, reliability, security and risk evaluation as appropriate.

MANAGE – risk mitigation, incident response, corrective action and continuous improvement.

H.4 ISO/IEC 42001

The Company’s AI governance framework is designed to incorporate concepts relevant to an AI Management System, including:

(a) governance;

(b) risk management;

(c) documented processes;

(d) accountability;

(e) lifecycle governance;

(f) monitoring;

(g) corrective action; and

(h) continual improvement.

Nothing in this Annexure constitutes a representation that the Company is certified under ISO/IEC 42001.

H.5 OECD AI Principles

The Company’s responsible AI approach is informed by principles including:

(a) inclusive growth and sustainable development;

(b) human-centred values and fairness;

(c) transparency and explainability;

(d) robustness, security and safety;

(e) accountability; and

(f) responsible stewardship of AI systems.

H.6 Applicability

The applicability of a particular obligation under any referenced framework shall depend upon:

(a) the jurisdiction;

(b) the Company’s role;

(c) the Customer’s role;

(d) the intended purpose;

(e) the particular AI functionality;

(f) the category of data processed; and

(g) the circumstances in which the AI system is used.

H.7 Continuous Review

The Company may periodically review this mapping as AI functionality, applicable law, regulatory guidance and recognised governance standards develop.