Legal

    AI Policy

    We are committed to building and deploying artificial intelligence responsibly. This AI Policy explains how we develop, use and govern AI within our platform, and applies to all AI-powered features on the Growy platform, including the Company Brain, AI Assistants and AI Agents.

    This is our top-level statement. Fuller detail is set out on three companion pages: AI Governance (accountability, autonomy levels, audit), GDPR & EU AI Act (legal roles, legal bases, regulatory position) and Security & Permissions (architecture and controls).

    Last updated: August 11th, 2026

    01 · Our AI principles

    Five commitments behind everything we build.

    01

    Your data is yours.

    We never use your company data to train general AI models or share it with other customers.

    02

    Transparency over black boxes.

    You should understand how decisions are made, especially when AI is involved.

    03

    Human oversight first.

    AI Agents act within boundaries you define. Critical decisions remain in human hands.

    04

    Security by design.

    AI processing meets the same security standards as the rest of our platform.

    05

    Continuous improvement.

    We monitor and improve our AI systems for accuracy, reliability and fairness.

    02 · How Growy uses AI

    Two types of AI-powered tools, built from your own knowledge.

    AI Assistants

    Chat-based interfaces powered by large language models. They answer questions, support problem-solving and provide information using your company's documents, PDFs, manuals, configuration files and connected tools. AI Assistants do not perform actions. They advise, inform and guide.

    AI Agents

    Autonomous workflows that execute operations. They connect to your internal systems through our node builder and perform multi-step operational tasks: processing requests, generating reports, updating records, coordinating across departments: within the boundaries you define.

    Both operate exclusively on the knowledge and integrations you provide. They do not access information outside your account.

    03 · Data isolation and privacy

    Your data stays yours, and stays separate.

    • Your uploaded documents, knowledge base and integrated services are stored and processed in isolation from other clients.
    • We do not use your company data to train, fine-tune or improve general-purpose AI models.
    • AI responses are generated from your documents, integrations and manuals.
    • All data is encrypted at rest and in transit.

    04 · AI models and third-party providers

    We do not train our own foundation models.

    We use large language models from established providers, currently Anthropic, OpenAI and Google, and select the model per task on capability, reliability and cost. When we do:

    • Your data is sent solely to generate a response or complete a task within your account.
    • Providers operate under data processing terms that prohibit training on customer data.
    • Providers are contractually barred from retaining or reusing your data beyond fulfilling your request.
    • We review and audit our AI providers for security, privacy and compliance.

    We may change or add providers over time. Material changes affecting how client data is processed are communicated to affected clients.

    05 · Accuracy and limitations

    AI gets things wrong. We say so plainly.

    • AI-generated outputs may not always be accurate, complete or up to date.
    • AI can make mistakes. Even with accurate inputs, it may misinterpret data or apply logic incorrectly.
    • AI can produce plausible-sounding but incorrect information ("hallucinations").
    • AI may reflect biases present in training data.
    • AI does not "understand" in the human sense. It generates statistically likely responses.

    We are transparent about these limitations because trust is built on honesty, not on overpromising.

    06 · Human oversight and control

    Control that stays with you, by design.

    • You define the boundaries.

      AI Agents only perform tasks within the workflows and integrations you configure.

    • You control what AI knows.

      You define the knowledge base.

    • You set the level of autonomy.

      Every agent is deployed at an agreed level of independence, with approval steps where you place them and confidence thresholds that escalate rather than guess.

    • You intervene at any time.

      AI Agents and Assistants can be paused, modified or deactivated.

    • Critical decisions remain with you.

      Actions that are irreversible, externally binding, financially material, or that determine an outcome for an individual sit behind human approval.

    Full detail is on our AI Governance page

    Accountability, autonomy levels, and audit, set out end to end.

    AI Governance

    07 · Fairness and bias

    Monitored, and corrected when it slips.

    • We monitor for bias, inaccuracy and unfair outputs.
    • We take corrective action through workflow changes, instruction adjustments, model selection changes or additional safeguards.
    • Report concerns to [email protected].

    08 · Security

    Encrypted, access-controlled, logged.

    • Data transmitted to and from AI-processing services is encrypted using TLS.
    • Access to AI-generated outputs is controlled by role-based access control.
    • We review the security of our AI pipeline as the platform changes.
    • Agent activity is logged at workflow and node level, and retained in line with our Privacy Policy.

    Full detail is on our Security & Permissions page

    Architecture and access controls, explained end to end.

    Security & Permissions

    09 · Regulatory alignment

    Built against the requirements now, not later.

    EU AI Act. The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy obligations have applied since 2 February 2025, obligations for general-purpose AI models since 2 August 2025, and transparency obligations under Article 50 since 2 August 2026. Following the Digital Omnibus on AI adopted in 2026, high-risk obligations apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. We build against these requirements now.

    GDPR. Our AI data processing complies with the UK GDPR and the EU GDPR. Our respective roles as controller and processor, and the legal bases we rely on, are set out on our GDPR & EU AI Act page.

    UK AI regulation. We follow developments in the UK's AI regulatory framework.

    Full detail is on our GDPR & EU AI Act page

    Legal roles, legal bases, and our regulatory position, set out end to end.

    GDPR & EU AI Act

    10 · Accountability

    Owned by a role, not diffused into a team.

    • AI governance is owned at leadership level by a designated owner.
    • AI systems, outputs and risks are reviewed periodically and after any significant incident or material change.
    • We maintain documentation of AI capabilities, limitations and data flows.
    • Our teams are trained on responsible AI practice, in line with the AI literacy obligation under Article 4 of the EU AI Act.
    • We engage external advisors and auditors as needed.

    11 · Transparency

    AI interactions are identified as AI-powered.

    Interactions with Growy AI Assistants and AI Agents are identified as AI-powered, in line with Article 50 of the EU AI Act, which has applied since 2 August 2026.

    12 · Risk classification

    Risk attaches to the use case, not the software.

    Growy is a general-purpose platform, so each deployment is classified with the client before it goes live.

    Most Growy deployments: operational reporting, document retrieval, internal coordination, administrative workflow, supplier and sales operations: sit within the minimal and limited risk categories.

    Some workflows require more care. Annex III of the Act designates certain employment and worker-management uses as high risk, including recruitment, candidate screening and evaluation, allocation of tasks, and monitoring or evaluation of performance. Growy is used in HR and onboarding contexts, so where a use case is in or near that scope we say so, we design the workflow so that determinations about individuals remain human decisions, and we support the client with the obligations that follow.

    We do not build agents for biometric identification, social scoring, emotion inference in workplaces or education, or any practice prohibited under Article 5 of the Act.

    14 · Contact us

    Questions about this policy? Ask directly.

    [email protected]Attitude Group Ltd.: 2 Alderney Court, Montague Street, Reading, England, RG1 4JW, United Kingdom

    We may update this policy from time to time. The current version is always indicated by the "Last updated" date at the top.