AI use statement

AI use statement

1. Purpose

This statement describes how Purde Software uses artificial intelligence (AI) — both in the products we offer to customers and in our own development and operations. It supplements Code of Conduct §4.9 and the Privacy Policy.

2. Principles

  • Transparency. Where our products use AI, customers and users are informed and can see what data is processed.

  • Opt-in. AI features that send customer content to a third-party model are off by default and enabled only by an administrator.

  • Human in the loop. AI output is presented as a suggestion for human review; AI does not autonomously make decisions about individuals.

  • Data minimization. We send to AI providers only the minimum content required to obtain a useful result.

  • No model training on customer data. We choose AI providers that contractually commit not to use customer-submitted content to train their models, or we disable training where it is configurable.

  • Provider diligence. AI providers are treated as subprocessors and listed in the Subprocessor Register.

  • Compliance. We track and apply applicable AI rules, in particular the EU AI Act and its phased application; relevant obligations are reviewed at least annually.

3. Model inventory

3.1 AI used in our products

Product

Feature

Model / provider

Data sent to the model

Activation

Notes

Product

Feature

Model / provider

Data sent to the model

Activation

Notes

Smart Questions and Answers Cloud

AI-assisted answer suggestions

OpenAI (current provider; specific model selected by us GPT 5.1 mini)

Question title and question body submitted by the user

Off by default; opt-in by a Confluence administrator

Suggested answer is shown for human review; the user decides whether to publish it.

3.2 AI used in our internal work

We may use AI tools (for example, coding assistants and general-purpose chat assistants) for our own development, support, and administrative work, subject to the following rules:

  • We do not submit confidential customer data, non-public customer source code, customer credentials, or special categories of personal data to public or unlicensed AI services. [REVIEW: confirm that this matches actual practice; adjust if specific licensed tools are used]

  • AI-generated code, text, or analysis is reviewed by a contributor before it is used in a deliverable, committed to a repository, or sent to a customer.

  • We respect AI providers' terms of use and any licensing obligations on generated output.

  • A current list of internal AI tools and their permitted uses is maintained internally and reviewed at least annually.

4. Human-in-the-loop controls

For the customer-facing AI feature (§3.1):

  • The administrator must explicitly enable the feature for it to function.

  • Each AI-generated suggestion is presented to a user who decides whether to accept, modify, or reject it before publication.

  • No automated action — posting, deleting, sending, billing, or similar — is taken on the basis of AI output alone.

  • The feature can be disabled at any time by the administrator; existing answers are unaffected.

5. Data handling

For data sent to AI providers as part of §3.1:

  • Legal basis: consent of the administrator (Art. 6(1)(a) GDPR), recorded by their explicit opt-in.

  • Data sent: the question title and body, as written by the user.

  • Data not sent: usernames, email addresses, Confluence instance metadata beyond what is required by the API.

  • Retention: subject to the AI provider's policy; see Privacy Policy §8 for the provider link.

  • International transfer mechanism: documented in Privacy Policy §9.

6. Risk assessment

We performed a documented risk and impact assessment for the AI feature in §3.1 prior to release, covering: data categories sent, lawful basis, transfer mechanism, model-provider commitments on training and confidentiality, accuracy and bias considerations, and the human-review mitigation. The assessment is revisited when we change provider, model family, or feature behaviour, and at least annually. [REVIEW: if no formal assessment exists yet, run a short one (1–2 pages) and reference it here]

7. EU AI Act considerations

The current AI use described in §3.1 is, in our view, a limited-risk application under the EU AI Act (Regulation (EU) 2024/1689): it generates content suggestions for human review and does not perform any prohibited practice, biometric categorisation, or high-risk use case listed in Annex III. We meet the transparency obligation by informing users that suggestions are AI-generated. We will reassess the classification if we materially change the feature or add new AI capabilities.

8. Reporting concerns

To report a concern about an AI feature — including unexpected output, suspected bias, or a privacy concern — use the channels in Code of Conduct §6.

9. Related documents

10. Version history

Version

Date

Changes

Version

Date

Changes

1.0

May 31, 2026

Initial publication.