Legal
We are committed to building and deploying artificial intelligence responsibly. This AI Policy explains how we develop, use and govern AI within our platform, and applies to all AI-powered features on the Growy platform, including the Company Brain, AI Assistants and AI Agents.
This is our top-level statement. Fuller detail is set out on three companion pages: AI Governance (accountability, autonomy levels, audit), GDPR & EU AI Act (legal roles, legal bases, regulatory position) and Security & Permissions (architecture and controls).
Last updated: August 11th, 2026
01 · Our AI principles
We never use your company data to train general AI models or share it with other customers.
You should understand how decisions are made, especially when AI is involved.
AI Agents act within boundaries you define. Critical decisions remain in human hands.
AI processing meets the same security standards as the rest of our platform.
We monitor and improve our AI systems for accuracy, reliability and fairness.
02 · How Growy uses AI
Chat-based interfaces powered by large language models. They answer questions, support problem-solving and provide information using your company's documents, PDFs, manuals, configuration files and connected tools. AI Assistants do not perform actions. They advise, inform and guide.
Autonomous workflows that execute operations. They connect to your internal systems through our node builder and perform multi-step operational tasks: processing requests, generating reports, updating records, coordinating across departments: within the boundaries you define.
Both operate exclusively on the knowledge and integrations you provide. They do not access information outside your account.
03 · Data isolation and privacy
04 · AI models and third-party providers
We use large language models from established providers, currently Anthropic, OpenAI and Google, and select the model per task on capability, reliability and cost. When we do:
We may change or add providers over time. Material changes affecting how client data is processed are communicated to affected clients.
05 · Accuracy and limitations
We are transparent about these limitations because trust is built on honesty, not on overpromising.
06 · Human oversight and control
AI Agents only perform tasks within the workflows and integrations you configure.
You define the knowledge base.
Every agent is deployed at an agreed level of independence, with approval steps where you place them and confidence thresholds that escalate rather than guess.
AI Agents and Assistants can be paused, modified or deactivated.
Actions that are irreversible, externally binding, financially material, or that determine an outcome for an individual sit behind human approval.
Accountability, autonomy levels, and audit, set out end to end.
07 · Fairness and bias
08 · Security
Architecture and access controls, explained end to end.
09 · Regulatory alignment
EU AI Act. The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy obligations have applied since 2 February 2025, obligations for general-purpose AI models since 2 August 2025, and transparency obligations under Article 50 since 2 August 2026. Following the Digital Omnibus on AI adopted in 2026, high-risk obligations apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. We build against these requirements now.
GDPR. Our AI data processing complies with the UK GDPR and the EU GDPR. Our respective roles as controller and processor, and the legal bases we rely on, are set out on our GDPR & EU AI Act page.
UK AI regulation. We follow developments in the UK's AI regulatory framework.
Legal roles, legal bases, and our regulatory position, set out end to end.
10 · Accountability
11 · Transparency
Interactions with Growy AI Assistants and AI Agents are identified as AI-powered, in line with Article 50 of the EU AI Act, which has applied since 2 August 2026.
12 · Risk classification
Growy is a general-purpose platform, so each deployment is classified with the client before it goes live.
Most Growy deployments: operational reporting, document retrieval, internal coordination, administrative workflow, supplier and sales operations: sit within the minimal and limited risk categories.
Some workflows require more care. Annex III of the Act designates certain employment and worker-management uses as high risk, including recruitment, candidate screening and evaluation, allocation of tasks, and monitoring or evaluation of performance. Growy is used in HR and onboarding contexts, so where a use case is in or near that scope we say so, we design the workflow so that determinations about individuals remain human decisions, and we support the client with the obligations that follow.
We do not build agents for biometric identification, social scoring, emotion inference in workplaces or education, or any practice prohibited under Article 5 of the Act.
14 · Contact us
We may update this policy from time to time. The current version is always indicated by the "Last updated" date at the top.