AI & Data Governance Statement
DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026
| Field | Value |
|---|---|
| Owner | DeepTech sp. z o.o. — CTO (system owner) and data protection coordinator (Kacper Raubo); approved by the Management Board |
| Version | 1.2 |
| Status | Pending management approval (Management Board of DeepTech sp. z o.o.) |
| Effective | On approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9) |
| Review | Every 12 months or after a material change |
| Classification | Public |
How AI is used in Audomate, which models run where, and the controls that keep outputs grounded and client data protected.
1. Model inventory
| Component | Model / service | Where it runs | Data terms |
|---|---|---|---|
| Analysis LLM | GPT-4o via OpenAI API, EU data residency project, zero data retention (endpoint eu.api.openai.com; contracting entity OpenAI Ireland Ltd, Dublin) | EEA (EU data residency) | Zero Data Retention (ZDR) and EU data residency enabled on the production project — OpenAI abuse monitoring otherwise keeps API logs for up to 30 days by default; no training on client data — contractual |
| Embeddings | text-embedding-3-large via OpenAI API, EU data residency project, zero data retention (3072 dimensions) | EEA (EU data residency) | Same Zero Data Retention terms |
| PL-language alternative | bge-m3 multilingual embeddings | Self-hosted, EEA | No third party |
2. Grounding — how outputs stay factual
The engine is retrieval-augmented generation: documents are chunked (512 tokens, 64 overlap) and embedded; for every checklist requirement it retrieves the most relevant fragments (top 5–10, with cross-encoder reranking, filtered by tenant), and the model answers only against retrieved context — returning a verdict (COMPLIANT / PARTIAL / NON-COMPLIANT), a justification, cited source fragments and a confidence score.
3. Human in the loop — mandatory
No AI verdict is final without human approval. A compliance officer reviews, edits or overrides every proposal; every change is recorded with author, timestamp and reason in a hash-chained audit trail. AI outputs are decision support, not decisions.
4. Data protection in the AI layer
- Prompts and completions are transient at the model provider (OpenAI Ireland Ltd, EU data residency) — Zero Data Retention approved on the project; never used for training, by DeepTech or the provider. No other cloud AI provider is used.
- Per-tenant session isolation; session context in memory only, cleared at session end.
- Prompt-injection detection and input sanitisation before any model call.
- Per-tenant token budgets with utilisation alerts.
5. No training on customer data — contractual and technical
Contractual. Our agreement with the model provider — the OpenAI API Services Agreement with the OpenAI Data Processing Addendum (OpenAI Ireland Ltd) — excludes the use of prompts and completions for training or improving models and provides Zero Data Retention. OpenAI abuse monitoring would by default keep API request logs for up to 30 days; ZDR has been approved on our project, so no prompts or completions are stored, and the project is pinned to EU data residency. OpenAI, L.L.C. (parent of OpenAI Ireland Ltd) is certified under the EU-U.S. Data Privacy Framework for residual support / telemetry access. Our Data Processing Agreement with each client commits DeepTech not to use client content for training or product development beyond the client's own tenant.
Technical. There is no training or fine-tuning pipeline on client content in the platform: documents are used only for retrieval within the client's tenant; prompts and completions are not written to durable storage; vector indexes are isolated per tenant and deleted with the client's data. Where a plan includes customer-specific configuration or tuning (e.g. checklists and prompts adapted to the client's documentation), it is performed solely for that client, on its instruction, within its tenant, and is never applied to other clients or passed to the model provider.
6. Data protection impact assessment
Because the contract-audit module systematically processes documents that may contain personal data of third parties (signatories, contact persons, representatives of ICT vendors) using AI, DeepTech carries out a data protection impact assessment (art. 35 GDPR) for this module, following the ICO seven-step template, coordinated by the Data Protection Coordinator (Kacper Raubo, kacper.raubo@deeptech.pl), and reviews it when the processing or the models change. The assessment for the current version of the module was prepared in October 2026 and is undergoing sign-off by the CTO, the CEO and the Data Protection Coordinator. A summary is available to clients on request to support their own DPIA as controllers.
7. Regulatory monitoring
A separate engine subscribes to ESMA, EBA and KNF publication feeds, delta-diffs regulatory changes against active checklists, and places changes in pending-review status — a compliance manager approves before anything goes live.
8. EU AI Act position
Based on our assessment, Audomate is not a high-risk AI system within the meaning of Annex III of the EU AI Act: it is a decision-support tool for corporate regulatory compliance — a use case not listed in Annex III — and, by design, no AI-generated verdict is final without human approval, consistent with the human-oversight principles of art. 14. We operate as a deployer of general-purpose AI models with transparency toward users about AI involvement, and we monitor Commission and ESA guidance; this position will be updated if the legal landscape changes.
Document control
| Version | Date | Author | Approved by | Changes |
|---|---|---|---|---|
| 0.9 | September 2026 | DeepTech (CTO / CEO) | — (working draft, not adopted) | Working draft published for transparency; items marked "to confirm". |
| 1.0 | October 2026 | DeepTech (CEO / CTO) | — (superseded by 1.1) | Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: on-premise model list flagged; new section 5 "No training on customer data — contractual and technical"; new section 6 "Data protection impact assessment" (art. 35 GDPR) for the AI contract-audit module; embeddings provider and RAG parameters specified from Annex #2; EU AI Act position unchanged. |
| 1.1 | 10 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Updates after Management Board decisions of 10 Oct 2026: model inventory corrected — GPT-4o and text-embedding-3-large via OpenAI API, EU data residency project, zero data retention (OpenAI Ireland Ltd); no other cloud AI provider used; ZDR approval and abuse-monitoring default described; OpenAI, L.L.C. DPF certification noted; Data Protection Coordinator named for the DPIA. |
| 1.2 | 11 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Based on Management Board answers of 11 Oct 2026: EU data residency and Zero Data Retention treated as enabled on the production OpenAI project; on-premise open-weight model row removed from the model inventory for now; DPIA status stated (prepared, sign-off in progress). |