AI Usage Policy
Effective date: 1 January 2026
Last reviewed: 27 June 2026
Applies to: all users of phaneosAI services, including agency partners and their end-clients.
1. Purpose and scope
This policy explains how phaneosAI uses artificial intelligence, how we protect client data when using AI systems, and the limits and responsibilities that apply to AI-generated outputs. It supports compliance with the EU AI Act (Regulation 2024/1689), GDPR, and Vietnam's Law on AI and Law on Personal Data Protection.
2. Transparency
phaneosAI uses large-language-model (LLM) APIs and related machine-learning tools to:
- draft, review, and refine content, code, and strategy materials;
- automate workflows and data-processing tasks;
- generate prototypes, reports, and client deliverables;
- analyze, classify, and summarize information you provide.
We disclose the use of AI in deliverables where it is materially relevant or where disclosure is required by law or contract.
3. No use of client data for model training
- We do not use your personal data, prompts, client content, or outputs to train, fine-tune, or improve any third-party or phaneosAI-owned AI model.
- We configure our AI provider accounts to opt out of model training and improvement programs where such options exist.
- We prefer providers that offer Zero Data Retention (ZDR) or equivalent business-tier data-protection terms.
- For providers where ZDR is not available, we minimize data inclusion and process only what is necessary for the specific task.
4. Human oversight
AI is a tool, not a substitute for human judgment. phaneosAI commits to:
- reviewing AI-generated outputs before delivery to clients or end-users, especially for legally, financially, or reputationally significant use cases;
- clearly labeling AI-generated drafts, suggestions, or options that require client review;
- maintaining a human-in-the-loop process for any deployment that may affect individual rights or significant interests.
5. Accuracy, completeness, and limitations
AI systems can produce outputs that are:
- factually incorrect, outdated, or inconsistent;
- incomplete or missing important context;
- biased or reflecting patterns in training data;
- not tailored to your specific jurisdiction or regulatory requirements.
You must verify AI-generated outputs before relying on them. phaneosAI does not warrant that AI outputs are error-free, complete, or suitable for any particular purpose without review.
6. Prohibited AI use cases
Unless expressly agreed in writing, you may not use phaneosAI services or AI outputs for:
- medical diagnosis, treatment, or regulated healthcare decisions;
- credit, lending, insurance, or other financial eligibility decisions about individuals;
- automated hiring, firing, or worker-evaluation decisions;
- criminal justice, law enforcement, or migration decisions;
- real-time biometric identification in public or sensitive spaces;
- generation of deceptive synthetic media for fraud, defamation, or political manipulation;
- creation of non-consensual intimate imagery, child sexual abuse material, or content that promotes self-harm, violence, or hatred.
For high-risk use cases permitted under the EU AI Act, we will agree in writing on risk management, data governance, transparency, human oversight, accuracy, and record-keeping obligations.
7. Intellectual property and output ownership
- You retain ownership of your inputs and of final deliverables after payment, subject to your agreement with us.
- AI-generated content may not be copyrightable in all jurisdictions. We cannot guarantee exclusive ownership or enforceability of rights in raw AI outputs.
- You are responsible for ensuring that your use of AI outputs does not infringe third-party rights.
8. Model providers and sub-processors
We currently use the following AI model providers as sub-processors:
| Provider | Use | Data-retention posture |
|---|---|---|
| OpenAI | General-purpose LLM inference | Business API terms; ZDR where available |
| Anthropic | General-purpose LLM inference | Business API terms; ZDR where available |
We may add or change providers. For material changes, we will update our Data Processing Addendum and provide notice where required.
9. EU AI Act compliance
For AI systems placed on the EU market or used in the EU through phaneosAI services:
- We classify AI use cases and document whether they are prohibited, high-risk, or limited/minimal risk.
- High-risk systems will be subject to conformity assessment, risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, and post-market monitoring obligations.
- We will provide transparency information and user instructions required by Article 52 of the EU AI Act for applicable systems.
- We will not deploy AI systems prohibited under the EU AI Act.
The EU AI Act's high-risk obligations for relevant systems generally apply from August 2026.
10. Changes
We review this policy at least annually and whenever we materially change our AI providers or use cases. The effective date at the top shows the latest revision.
This AI Usage Policy is provided for transparency and compliance purposes. It does not constitute legal advice. Clients should conduct their own AI risk assessments and consult local counsel, particularly for high-risk or regulated use cases.