Version 1.0 · In force from 4 August 2026

SCHEDULE G

PRIVACY POLICY

Version 1.0 · Effective Date: 4 August 2026

This Privacy Policy ("Privacy Policy") explains how Dostart Ventures Limited ("ONLYAI", "Company", "we", "our" or "us") collects, uses, discloses, transfers, stores and otherwise Processes Personal Data where ONLYAI acts as a Data Controller.

1. INTRODUCTION

1.1 Our Commitment to Privacy

ONLYAI recognizes that the protection of Personal Data constitutes a fundamental component of responsible corporate governance, information security and trustworthy artificial intelligence.

Accordingly, ONLYAI is committed to Processing Personal Data in a lawful, fair and transparent manner while implementing appropriate technical, organizational and contractual safeguards designed to protect the rights and freedoms of individuals.

As an enterprise technology provider, ONLYAI has adopted a privacy-by-design and security-by-design approach throughout the lifecycle of its products, services and internal business operations.

Our objective is not merely to comply with Applicable Data Protection Laws, but to establish a comprehensive privacy governance framework consistent with internationally recognized best practices relating to cloud computing, cybersecurity and artificial intelligence.

1.2 Purpose of this Privacy Policy

This Privacy Policy describes the circumstances in which ONLYAI acts as a Data Controller and explains how we collect, use, disclose, retain and otherwise Process Personal Data in connection with:

  • operation of our corporate website;
  • customer relationship management;
  • commercial negotiations;
  • sales activities;
  • customer onboarding;
  • supplier management;
  • business communications;
  • technical support;
  • marketing activities;
  • recruitment processes;
  • legal and regulatory compliance;
  • protection of our legitimate business interests.

This Privacy Policy further explains the rights available to individuals under Applicable Data Protection Laws and the mechanisms available for exercising those rights.

1.3 Scope of this Privacy Policy

This Privacy Policy applies exclusively to Processing activities for which ONLYAI determines the purposes and means of Processing and therefore acts as a Data Controller.

For the avoidance of doubt, this Privacy Policy does not apply to Personal Data Processed by ONLYAI solely on behalf of its enterprise customers through the ONLYAI Platform.

Where ONLYAI Processes Personal Data contained within customer accounts, creator accounts, fan communications or other Customer Data submitted through the Services, ONLYAI acts exclusively as a Data Processor pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR") and the applicable Data Processing Agreement.

In such circumstances, the relevant Customer remains the Data Controller responsible for determining:

  • the purposes of Processing;
  • the lawful basis for Processing;
  • applicable retention periods;
  • categories of Personal Data Processed;
  • responses to Data Subject Requests;
  • compliance with applicable data protection legislation.

Individuals seeking to exercise their privacy rights in relation to Customer Data should therefore contact the relevant Customer directly.

2. ABOUT ONLYAI

2.1 Identity of the Controller

Unless otherwise expressly stated, the Data Controller responsible for the Processing activities described in this Privacy Policy is:

DOSTART VENTURES LIMITED

Registration Number: HE 487770, registered under the laws of Cyprus

Email:

info@onlyai.work

2.2 Data Protection Governance

ONLYAI maintains an internal Privacy Governance Programme designed to ensure ongoing compliance with Applicable Data Protection Laws and internationally recognized information governance principles.

Our governance framework includes, where appropriate:

  • documented privacy policies and procedures;
  • role-based access controls;
  • privacy impact assessments;
  • information security controls;
  • vendor due diligence procedures;
  • contractual data protection safeguards;
  • incident response procedures;
  • AI governance measures;
  • employee confidentiality obligations;
  • regular compliance reviews.

2.3 Data Protection Officer and Representatives

Where required by Applicable Data Protection Laws, ONLYAI may designate:

  • a Data Protection Officer ("DPO");
  • an EU Representative;
  • a UK Representative;
  • other privacy contacts.

The relevant contact details shall be published on our Website and updated from time to time.

3. APPLICABILITY OF THIS PRIVACY POLICY

3.1 Controller Activities

This Privacy Policy governs ONLYAI's Processing of Personal Data in connection with:

Corporate Website

including:

  • website operation;
  • visitor analytics;
  • security monitoring;
  • contact forms;
  • cookie management.

Business Development

including:

  • demonstrations;
  • commercial discussions;
  • requests for proposals;
  • quotations;
  • contract negotiations.

Customer Relationship Management

including:

  • account administration;
  • onboarding;
  • billing;
  • subscription management;
  • customer communications.

Technical Support

including:

  • support tickets;
  • troubleshooting;
  • product inquiries;
  • service notifications.

Marketing Activities

including:

  • newsletters;
  • webinars;
  • conferences;
  • promotional communications;
  • surveys;
  • customer success initiatives.

Recruitment

including:

  • employment applications;
  • candidate evaluations;
  • interview processes;
  • recruitment communications.

Supplier Management

including:

  • procurement;
  • vendor onboarding;
  • contract administration;
  • payment processing.

Legal & Compliance

including:

  • legal claims;
  • regulatory reporting;
  • fraud prevention;
  • compliance investigations;
  • corporate governance.

3.2 Processor Activities Excluded

This Privacy Policy does not apply to Processing activities performed by ONLYAI exclusively on behalf of Customers.

Examples include, without limitation:

  • creator account information;
  • fan communications;
  • AI-generated conversations;
  • uploaded media;
  • workflow configurations;
  • prompts;
  • platform messages;
  • customer analytics;
  • AI memory associated with Customer accounts;
  • Customer Content;
  • Customer platform integrations.

Such Processing is governed exclusively by:

  • the applicable Terms of Service (Master SaaS Terms);
  • the Data Processing Agreement;
  • documented Customer instructions;
  • Applicable Data Protection Laws.

ONLYAI does not independently determine the purposes or essential means of such Processing.

4. OUR ROLE UNDER DATA PROTECTION LAW

4.1 Controller Processing

ONLYAI acts as a Data Controller where ONLYAI independently determines the purposes and means of Processing Personal Data.

Examples include Processing relating to:

  • prospective customers;
  • existing customers;
  • suppliers;
  • business contacts;
  • website visitors;
  • employees;
  • contractors;
  • recruitment candidates;
  • marketing recipients.

For such Processing, ONLYAI is responsible for compliance with Applicable Data Protection Laws.

4.2 Processor Processing

ONLYAI acts as a Data Processor where it Processes Personal Data solely on behalf of Customers using the ONLYAI Platform.

Processor activities include, by way of example:

  • hosting Customer Data;
  • AI-assisted message generation;
  • cloud storage;
  • workflow execution;
  • technical support;
  • platform administration;
  • security monitoring;
  • backup and disaster recovery;
  • deletion of Customer Data upon instruction.

In relation to such Processing:

Customer determines the purposes and means of Processing.

ONLYAI acts solely on documented instructions provided by Customer.

4.3 No Ownership of Customer Data

ONLYAI does not acquire any ownership rights in Customer Data.

Except as expressly instructed by the Customer or required by Applicable Law, ONLYAI shall not:

  • use Customer Data for its own commercial purposes;
  • sell Customer Data;
  • license Customer Data;
  • disclose Customer Data to unauthorized third parties;
  • use Customer Data to train foundation AI models without Customer's separate express written authorization.

Customer retains all rights, title and interest in Customer Data.

5. CATEGORIES OF PERSONAL DATA PROCESSED

The categories of Personal Data Processed by ONLYAI vary depending upon the nature of an individual's relationship with the Company, the products or services requested, and the manner in which our Website or Services are used.

ONLYAI applies the principle of data minimization and limits the collection of Personal Data to that which is reasonably necessary, relevant and proportionate for the applicable Processing purpose.

Subject to the foregoing, ONLYAI may Process the following categories of Personal Data.

5.1 Identification Data

We may Process identification information necessary to establish or maintain a business relationship, including:

  • full name;
  • professional title;
  • employer or affiliated organization;
  • business position;
  • company registration details (where applicable);
  • customer or account reference numbers;
  • user identifiers assigned within our systems.

5.2 Contact Information

We may Process business contact information, including:

  • business email address;
  • telephone number;
  • business mailing address;
  • billing address;
  • correspondence details;
  • preferred communication channels, including telephone number and Telegram handle where provided.

5.3 Account and Subscription Information

Where an individual represents a Customer or otherwise accesses the Services, we may Process:

  • account identifiers;
  • authentication credentials (in encrypted or hashed form where applicable), including identifiers received from third-party sign-in providers (e.g. Google) where such sign-in is used;
  • user roles;
  • access permissions;
  • subscription details;
  • Order Forms and electronic acceptance records (including timestamps, IP addresses, account identifiers and accepted document versions);
  • account status, selected account type (Solo or Agency) and email verification status;
  • billing profile information, including billing status (individual or business), payment method details (bank card data processed by our payment processors; cryptocurrency wallet or transaction identifiers for USDT top-ups) and Account Balance transaction history.
  • fraud prevention and payment risk signals;

5.4 Commercial and Transactional Information

To administer our commercial relationships, we may Process:

  • invoices;
  • payment references;
  • subscription history;
  • contract information;
  • pricing arrangements;
  • tax identification numbers (where required);
  • purchase history;
  • customer support entitlements.

Financial payment card information is generally Processed directly by independent payment service providers and is not stored by ONLYAI except where necessary for accounting or regulatory purposes.

5.5 Technical and Device Information

When individuals access our Website or Services, we may automatically collect technical information, including:

  • IP address;
  • browser type and version;
  • operating system;
  • device identifiers;
  • language preferences;
  • time zone settings;
  • access timestamps;
  • session identifiers;
  • log files;
  • diagnostic information;
  • API request metadata.

Such information is primarily Processed for security, operational integrity and service improvement purposes.

5.6 Website Usage Information

We may collect information relating to interactions with our Website, including:

  • pages visited;
  • navigation paths;
  • referring websites;
  • clickstream data;
  • session duration;
  • interaction events;
  • cookie identifiers;
  • analytics information.

Such Processing assists us in improving usability, performance and security.

5.7 Communications

Where individuals communicate with ONLYAI, we may Process:

  • emails;
  • support tickets;
  • live chat communications;
  • telephone records;
  • webinar participation;
  • meeting notes;
  • customer success communications;
  • satisfaction surveys.

5.8 Recruitment Information

Where individuals apply for employment or engagement opportunities, we may Process:

  • curriculum vitae;
  • professional qualifications;
  • employment history;
  • education records;
  • interview notes;
  • references;
  • publicly available professional profile information.

Sensitive recruitment information shall only be Processed where permitted by Applicable Law.

5.9 Compliance Information

ONLYAI may Process information necessary to comply with legal and regulatory obligations, including:

  • sanctions screening information;
  • anti-fraud records;
  • due diligence documentation;
  • corporate ownership information;
  • audit records;
  • regulatory correspondence;
  • litigation records.

6. SOURCES OF PERSONAL DATA

ONLYAI generally collects Personal Data directly from the individual concerned.

However, depending upon the circumstances, Personal Data may also be obtained from other lawful sources.

6.1 Information Provided Directly

Individuals may provide Personal Data directly when:

  • contacting ONLYAI;
  • requesting product demonstrations;
  • registering for webinars;
  • subscribing to newsletters;
  • creating user accounts;
  • submitting support requests;
  • negotiating commercial agreements;
  • participating in recruitment processes.

6.2 Information Collected Automatically

When our Website or Services are accessed, certain information may be collected automatically using technologies such as:

  • cookies;
  • server logs;
  • analytics tools;
  • application monitoring tools;
  • security monitoring systems;
  • API logs.

Further information is available in our Cookie Policy where applicable.

6.3 Information Received from Third Parties

We may receive Personal Data from third parties including:

  • Customer organizations;
  • Authorized Users;
  • publicly available business directories;
  • professional networking platforms;
  • business partners;
  • service providers;
  • payment providers;
  • marketing partners;
  • regulatory authorities.

ONLYAI shall Process such information only where a lawful basis exists.

7. PURPOSES OF PROCESSING

ONLYAI Processes Personal Data solely for specified, explicit and legitimate purposes.

Such purposes include:

7.1 Website Administration

Including:

  • operation of the Website;
  • security monitoring;
  • fraud prevention;
  • performance optimization;
  • troubleshooting.

7.2 Contract Administration

Including:

  • contract negotiation;
  • execution of agreements;
  • customer onboarding;
  • subscription management;
  • billing;
  • payment administration;
  • contract renewals.

7.3 Customer Relationship Management

Including:

  • customer communications;
  • account management;
  • customer success activities;
  • service notifications;
  • product updates.

7.4 Technical Support

Including:

  • responding to support requests;
  • diagnosing technical issues;
  • resolving service incidents;
  • maintaining operational continuity.

7.5 Information Security

Including:

  • authentication;
  • cybersecurity monitoring;
  • vulnerability management;
  • threat detection;
  • incident response;
  • fraud prevention;
  • protection of corporate assets.

7.6 Product Improvement

Where permitted by Applicable Law, ONLYAI may Process operational information for purposes of:

  • improving platform stability;
  • enhancing software performance;
  • improving security;
  • optimizing user experience;
  • evaluating product features.

For the avoidance of doubt, Customer Data Processed by ONLYAI as a Processor shall not be used to train foundation AI models except pursuant to Customer's separate documented authorization.

7.7 Marketing Activities

Where permitted by Applicable Law, ONLYAI may Process Personal Data to:

  • distribute newsletters;
  • announce product updates;
  • invite participation in events;
  • communicate industry insights;
  • conduct customer satisfaction surveys.

Individuals may withdraw marketing consent or opt out of marketing communications at any time.

7.8 Legal and Regulatory Compliance

ONLYAI may Process Personal Data where reasonably necessary to:

  • comply with legal obligations;
  • satisfy regulatory requirements;
  • respond to lawful governmental requests;
  • establish, exercise or defend legal claims;
  • protect the rights, property or safety of ONLYAI, its Customers or third parties.

8. LEGAL BASES FOR PROCESSING

ONLYAI Processes Personal Data only where an appropriate legal basis exists under Applicable Data Protection Laws.

Depending upon the circumstances, such legal bases may include:

  • performance of a contract (Article 6(1)(b) GDPR);
  • compliance with a legal obligation (Article 6(1)(c) GDPR);
  • protection of vital interests (Article 6(1)(d) GDPR), where applicable;
  • performance of a task carried out in the public interest (Article 6(1)(e) GDPR), where applicable;
  • legitimate interests pursued by ONLYAI or a third party (Article 6(1)(f) GDPR); and
  • the individual's freely given, specific, informed and unambiguous consent (Article 6(1)(a) GDPR), where required.
  • By way of illustration: account creation, the trial and payment processing rely on performance of a contract; invoicing and tax records rely on compliance with legal obligations; security, fraud prevention and the retention of contract acceptance evidence rely on legitimate interests; optional marketing communications rely on consent; and strictly necessary cookies (authentication, session and security) rely on the legal bases described in the Cookie Policy.

Where Processing is based on legitimate interests, ONLYAI performs an assessment to ensure that such interests are not overridden by the rights and freedoms of the individuals concerned.

9. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

9.1 Responsible AI Principles

ONLYAI is committed to the responsible development and deployment of artificial intelligence technologies.

Where ONLYAI acts as a Data Controller, AI technologies may be used to support internal business functions such as:

  • customer support;
  • knowledge management;
  • fraud detection;
  • information security;
  • document classification;
  • operational analytics.

Such Processing is carried out in accordance with ONLYAI's AI Governance Framework and applicable legal requirements.

9.2 Customer Data

For the avoidance of doubt, ONLYAI does not use Customer Data Processed in its capacity as a Data Processor to train or improve foundation AI models unless expressly authorized in writing by the relevant Customer.

Customer Data remains subject to the Terms of Service (Master SaaS Terms), the Data Processing Agreement and Customer instructions.

10. DISCLOSURE OF PERSONAL DATA

10.1 General Principles

ONLYAI does not sell, rent or otherwise commercialize Personal Data.

Personal Data shall be disclosed only where such disclosure is:

  • necessary for the purposes described in this Privacy Policy;
  • required to perform contractual obligations;
  • required by Applicable Law;
  • necessary to protect the legitimate rights and interests of ONLYAI, its Customers or third parties.

All disclosures are made on a strict need-to-know basis and are subject to appropriate contractual, technical and organizational safeguards.

10.2 Categories of Recipients

Depending upon the relevant Processing activity, Personal Data may be disclosed to the following categories of recipients:

(a) Group Companies

Where necessary for legitimate internal administrative purposes.

(b) Service Providers

Including providers of:

  • cloud infrastructure;
  • hosting services;
  • customer relationship management systems;
  • payment processing;
  • accounting services;
  • information security services;
  • monitoring services;
  • communications platforms;
  • customer support platforms;
  • productivity software.

Each provider is subject to appropriate contractual confidentiality and data protection obligations.

(c) Professional Advisers

Including:

  • external legal counsel;
  • auditors;
  • accountants;
  • tax advisers;
  • corporate advisers;
  • insurance providers.

(d) Regulatory Authorities

Where disclosure is required by Applicable Law or pursuant to a legally binding request issued by a competent authority.

(e) Corporate Transactions

Where reasonably necessary in connection with:

  • mergers;
  • acquisitions;
  • corporate restructurings;
  • financing transactions;
  • sale of assets;
  • investment due diligence.

Appropriate confidentiality obligations shall apply to any such disclosure.

11. INTERNATIONAL TRANSFERS OF PERSONAL DATA

11.1 General Principle

ONLYAI operates internationally and may transfer Personal Data to recipients located outside the European Economic Area ("EEA"), the United Kingdom or Switzerland where necessary for the operation of its business.

Where such transfers occur, ONLYAI shall ensure that an appropriate transfer mechanism is implemented in accordance with Applicable Data Protection Laws.

11.2 Transfer Mechanisms

Where required, international transfers shall be supported by one or more of the following safeguards:

  • adequacy decisions adopted by the European Commission;
  • the European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914);
  • the UK International Data Transfer Addendum or International Data Transfer Agreement;
  • other lawful transfer mechanisms recognized under Applicable Data Protection Laws.

11.3 Supplementary Safeguards

Where appropriate, ONLYAI may implement supplementary measures including:

  • encryption in transit and at rest;
  • pseudonymization;
  • contractual commitments;
  • access restrictions;
  • technical security controls;
  • transfer impact assessments.

12. INFORMATION SECURITY

12.1 Security Governance

ONLYAI maintains a comprehensive Information Security Management Framework designed to protect Personal Data against accidental, unauthorized or unlawful destruction, loss, alteration, disclosure or access.

Our security programme is based upon internationally recognized information security principles and incorporates administrative, technical and physical safeguards proportionate to the nature of the Processing activities performed.

12.2 Technical and Organizational Measures

Without limitation, ONLYAI may implement measures including:

  • encryption of Personal Data in transit using industry-standard cryptographic protocols;
  • encryption of Personal Data at rest where appropriate;
  • role-based access controls;
  • multi-factor authentication;
  • identity and access management;
  • security monitoring and logging;
  • vulnerability management;
  • secure software development lifecycle (SSDLC);
  • network segmentation;
  • endpoint protection;
  • disaster recovery and business continuity procedures;
  • regular backup procedures;
  • security awareness training;
  • incident response procedures.

A detailed description of the measures implemented by ONLYAI is contained within the Technical & Organizational Measures Schedule incorporated into the Agreement.

12.3 Shared Responsibility

Where individuals access ONLYAI's Services on behalf of Customers, information security remains a shared responsibility.

ONLYAI is responsible for protecting the infrastructure and services under its control.

Customers remain responsible for:

  • user administration;
  • password management;
  • endpoint security;
  • local network security;
  • internal access governance;
  • appropriate use of the Services.

13. DATA RETENTION

13.1 General Principle

ONLYAI retains Personal Data only for so long as reasonably necessary to fulfil the purposes for which it was collected, including the purposes of satisfying legal, regulatory, accounting and contractual obligations.

The applicable retention period depends upon:

  • the nature of the Personal Data;
  • the purpose of Processing;
  • contractual requirements;
  • legal obligations;
  • regulatory requirements;
  • limitation periods applicable to legal claims.

13.2 Retention Criteria

When determining appropriate retention periods, ONLYAI considers, among other factors:

  • the volume, nature and sensitivity of the Personal Data;
  • the potential risk of harm resulting from unauthorized use or disclosure;
  • the purposes of the Processing;
  • whether those purposes can be achieved through alternative means;
  • applicable legal and regulatory retention requirements.

13.3 Secure Deletion

Upon expiration of the applicable retention period, Personal Data shall be securely deleted, anonymized or otherwise rendered permanently inaccessible, unless continued retention is required by Applicable Law or necessary for the establishment, exercise or defence of legal claims.

14. DATA SUBJECT RIGHTS

Subject to Applicable Data Protection Laws, individuals may have the following rights:

  • the right to obtain confirmation as to whether Personal Data concerning them is being Processed;
  • the right of access to Personal Data;
  • the right to rectification of inaccurate or incomplete Personal Data;
  • the right to erasure ("right to be forgotten");
  • the right to restriction of Processing;
  • the right to data portability;
  • the right to object to Processing;
  • the right not to be subject to a decision based solely on automated Processing, including profiling, where such decision produces legal or similarly significant effects;
  • the right to withdraw consent at any time where Processing is based on consent.

The exercise of these rights may be subject to limitations and exceptions provided under Applicable Data Protection Laws.

Requests may be submitted using the contact details provided in Section 19 of this Privacy Policy.

15. MARKETING COMMUNICATIONS

Where permitted by Applicable Law, ONLYAI may send individuals information regarding:

  • product updates;
  • new features;
  • webinars;
  • events;
  • industry publications;
  • marketing communications.

Individuals may opt out of receiving marketing communications at any time by:

  • following the unsubscribe instructions contained in the relevant communication;
  • contacting ONLYAI using the contact details provided below.

Withdrawal of marketing consent shall not affect the lawfulness of Processing carried out prior to such withdrawal.

16. COOKIES AND SIMILAR TECHNOLOGIES

ONLYAI may use cookies, pixels and similar technologies to:

  • operate the Website;
  • authenticate users;
  • maintain security;
  • analyze Website usage;
  • improve user experience;
  • measure the effectiveness of communications.

Where required by Applicable Law, ONLYAI shall obtain consent prior to placing non-essential cookies on an individual's device.

Further information is available in ONLYAI's Cookie Policy.

17. CHILDREN'S PRIVACY

ONLYAI's Website, Services and business activities are directed exclusively toward businesses and individuals acting in a professional capacity.

ONLYAI does not knowingly collect Personal Data directly from children.

Where ONLYAI becomes aware that Personal Data has been collected from a child in violation of Applicable Law, ONLYAI shall take appropriate steps to delete such information without undue delay.

18. CHANGES TO THIS PRIVACY POLICY

ONLYAI may amend this Privacy Policy from time to time to reflect:

  • changes in Applicable Law;
  • technological developments;
  • changes to our business operations;
  • enhancements to our products or services;
  • improvements to our privacy governance framework.

The updated version shall be published on our Website together with the revised effective date.

Where required by Applicable Law, ONLYAI shall provide appropriate notice of material changes.

19. CONTACT DETAILS

Questions, requests or concerns relating to this Privacy Policy or ONLYAI's Processing of Personal Data may be directed to:

Privacy Team

Dostart Ventures Limited

Email: info@onlyai.work

Where applicable, individuals may also contact ONLYAI's appointed Data Protection Officer or EU/UK Representative using the contact details published on the Website.

Individuals also have the right to lodge a complaint with the competent Supervisory Authority in the Member State of their habitual residence, place of work or the place of the alleged infringement.

ANNEX I – LEGAL BASIS MATRIX

Processing ActivityLegal Basis (GDPR)
Website operationArticle 6(1)(f) – Legitimate Interests
Customer onboardingArticle 6(1)(b) – Contract
Contract administrationArticle 6(1)(b) – Contract
Billing and accountingArticle 6(1)(c) – Legal Obligation
Customer supportArticle 6(1)(b) and (f)
Information securityArticle 6(1)(f)
Marketing communicationsArticle 6(1)(a) or (f), as applicable
RecruitmentArticle 6(1)(b), (c) and (f)
Regulatory complianceArticle 6(1)(c)
Legal claimsArticle 6(1)(f)

ANNEX II – INTERNATIONAL DATA TRANSFER SAFEGUARDS

Where Personal Data is transferred outside the EEA, the UK or Switzerland, ONLYAI implements appropriate safeguards, including:

  • European Commission Adequacy Decisions;
  • Standard Contractual Clauses (EU 2021/914);
  • UK International Data Transfer Addendum;
  • Transfer Impact Assessments;
  • supplementary technical and organizational safeguards where appropriate.

ANNEX III – AI TRANSPARENCY STATEMENT

ONLYAI develops and operates AI-assisted enterprise software in accordance with principles of responsible AI governance.

Accordingly:

  • AI functionality is designed to support, not replace, human decision-making;
  • AI outputs are probabilistic and should not be treated as definitive or authoritative;
  • meaningful Human Oversight remains an essential operational principle of the Services;
  • ONLYAI maintains governance procedures for AI risk management, security, testing and continuous improvement;
  • where ONLYAI acts as a Data Processor, Customer Data is processed solely on documented Customer instructions and is not used to train foundation AI models without the Customer's separate express written authorization.