LEGAL & TRUST
AI Usage and Responsible AI Policy
KRAVIA uses AI as an assistive and appropriately controlled technology, not as an excuse to lower privacy, quality or accountability. Private customer content is not used to train general-purpose models. Important outputs require verification, and consequential decisions require meaningful human oversight.
1
Scope and product-specific disclosure
This Policy applies to AI features that expressly incorporate it. A product must identify its AI functions, intended use, relevant provider dependencies and important limitations. It must not claim that every feature is AI-powered or that an unreleased capability already exists.
A corporate assistant may help with navigation, information retrieval, support or product discovery. It is not a source of binding contract changes, regulated professional advice or autonomous high-impact decisions. A separate product may offer specialized functions only after its required risk, privacy and legal review.
2
Inputs, processing and the no-training commitment
Provide only information needed for the requested task and that you are authorized to submit. Do not place unrelated identity documents, payment secrets, private third-party records or high-risk information into a general assistant. A specialized product must define whether it is suitable for those records.
KRAVIA does not use private customer inputs, outputs, documents or conversations to train general-purpose AI models. External providers receiving that information on our behalf must be contractually and technically configured consistently with this commitment. If the selected service cannot meet it, private content must not be sent to that service. Commercial convenience is not an exception.
Generating a response, using an embedding for authorized retrieval or temporarily retaining information for a permitted operational purpose is still processing, but is not automatically model training. These activities require their own purpose, access and retention controls. Customer-specific fine-tuning or other additional use is not silently authorized by this Policy and requires a separately defined, compatible agreement and review.
3
Minimization and private content
Where practical and compatible with the requested function, unnecessary identifiers and sensitive information are removed, masked or excluded before model processing. Information retrieved for one customer must not be exposed to another customer. Prompt, response and audit logging must not become an uncontrolled duplicate of private content.
Human access is restricted to justified support, troubleshooting, security, legal or other specifically authorized purposes. Routine inspection of private conversations for general product improvement is not allowed. De-identified statistics may be used with genuine safeguards, not as a label attached to still-identifiable content.
4
Transparency and outputs
Material AI interactions are identified so users understand they are interacting with a system rather than a person. Products disclose important limits, the role of human review and relevant external processing. AI-generated media, messages or public-interest material carry appropriate labels and technical indicators where required by the applicable role and law. A notice in the Terms does not replace a required in-context disclosure.
Output can be incomplete, inaccurate, outdated, biased, unsafe or unexpectedly similar to other output. Citations generated by a model may be incorrect. Check important facts and inspect generated code, documents, calculations and instructions before relying on them. These user duties do not replace KRAVIA's own responsibility to evaluate and maintain the service with reasonable care.
5
Human oversight and consequential uses
AI may assist with recommendations, ranking, categorization and workflows. Decisions materially affecting employment, education, healthcare, finance, legal rights or comparable interests require proportionate safeguards and meaningful human involvement. Reviewers must have sufficient information and authority to challenge the output, not merely approve it automatically.
A product must identify an appropriate route to request correction or human review of a materially consequential result. Where KRAVIA processes data for an organization, the request may need coordination with that organization, but it must not be ignored simply because a customer issued the instruction. Applicable legal restrictions on solely automated decisions continue to apply.
6
Actions and communications
An AI agent may act only within explicit permissions, defined task scopes and valid account authority. Updating a record, initiating a message, scheduling an event or changing a setting must pass the same authorization checks as another action. Instructions contained in an untrusted document or external message do not create user authorization.
Irreversible, financial, legally significant, privacy-sensitive or other high-impact actions require stronger confirmation or human approval. Low-risk communications may be automated using approved rules, communication permissions and safety thresholds. Sensitive communications require appropriate review. A user must be able to identify the material action taken and its outcome through an appropriate audit or account record.
7
Memory, history and retention
Ordinary corporate-assistant conversation retention is 90 days under the corporate schedule, subject to separately restricted legal or security records. A conversation deliberately converted into an enquiry or support ticket follows the disclosed schedule for that record. Provider retention and backups must be reviewed and disclosed rather than assumed identical.
Cross-conversation memory is a separate, user-controlled feature, not automatic permanent storage of everything said. Available controls must permit management, correction, disabling and deletion. Disabling future memory does not by itself delete already saved memory; the interface must distinguish those choices. Sensitive information must receive stricter treatment. Product-specific retention overrides apply only when accurately disclosed and lawful.
8
Prohibited AI uses
Do not use AI for fraud, phishing, malware, credential theft, unlawful surveillance, deceptive impersonation, harassment, non-consensual intimate material, child exploitation, unlawful discrimination, prohibited biometric identification, manipulative exploitation or circumvention of safety controls. Do not use apparent confidence or synthetic identity to mislead people into decisions they have not freely authorized.
High-risk professional and regulated uses must stay within the explicitly approved product scope. A disclaimer is not authorization to deploy an unassessed hiring engine, diagnostic system, credit decision-maker or safety-critical controller. The Acceptable Use Policy also applies.
9
Children and sensitive contexts
AI offered directly to children or students must be age-appropriate, minimize information, provide suitable safety and oversight controls and avoid manipulative engagement. Necessary parental or other legally valid authorization is obtained through an appropriate process. Education-related processing does not automatically authorize unrelated commercial use.
Biometrics, precise location, health records and similarly sensitive information require a necessity assessment, applicable legal basis, additional permissions where required, and stronger security and retention controls before use. This Policy does not claim that KRAVIA currently offers all such functions.
10
Output rights and intellectual property
Users may use generated output to the extent permitted by law and relevant third-party rights. KRAVIA does not claim ownership merely because the output was generated through its service. However, an output may not be unique, protectable or free of third-party claims. Do not submit protected material without authority or knowingly use output to infringe another person's rights.
Rights in KRAVIA software, templates and pre-existing technology remain distinct from rights in customer content and permitted outputs. An AI feature does not transfer another person's copyright or confidential information to the user.
11
Governance, review and reporting
Before production release, a material AI feature is reviewed for purpose, data handling, security, accuracy limits, bias and unfair outcomes, misuse, human oversight, external dependencies and appropriate monitoring. High-risk processing requires a suitable privacy impact assessment and any applicable legal assessment. Material model or provider changes trigger reassessment.
Audits record necessary action, version, permission, approval and outcome metadata without requiring permanent full prompt storage. Report harmful or incorrect behaviour to the relevant product support channel or support@kraviaprivatelimited.com. Report privacy concerns to privacy@kraviaprivatelimited.com and vulnerabilities to security@kraviaprivatelimited.com. We investigate proportionately and restrict a feature when justified, while communicating material impact where appropriate.