Persooa Responsible AI Policy 2026 Version 2026.1
Purpose
Persooa designs, deploys and runs AI systems for customers in the Synerise ecosystem: AI decisioning, recommendations, predictions (churn, likelihood-to-buy, Next-Best-Action), real-time personalization and agentic customer engagement. This policy sets out the principles by which we do this responsibly - in line with the risk-based approach derived, among other things, from the AI Act, and with good market practice.
Risk categorization
We classify every AI use case by its level of impact on the end customer:
| Level | Examples | Required oversight |
|---|---|---|
| Low | Product recommendations, content personalization | Monitoring, ability to opt out |
| Medium | Segmentation, marketing scoring, best time to contact | Human review of rules, bias testing |
| High | Decisions affecting access to offers, prices or benefits | Human-in-the-loop, explainability, audit |
We do not carry out high-risk cases in regulated areas (e.g. credit scoring) without an explicit mandate, legal framework and oversight on the customer's side.
Prohibited practices. Persooa does not design or deploy AI systems that fall into the unacceptable-risk category within the meaning of the AI Act - in particular subliminal manipulation techniques, exploitation of vulnerabilities (age, disability, economic situation) or social scoring.
Scale mapping. We apply our own internal risk classification (low/medium/high) inspired by the risk-based approach of the AI Act; it is not identical to the statutory AI Act categories (unacceptable / high / limited / minimal). The formal qualification of a specific system within the meaning of the AI Act is carried out jointly with the customer.
Roles within the meaning of the AI Act. In a typical collaboration model, the customer acts as the deployer, and Persooa as the partner that configures and operates the solution on the Synerise platform. The obligations proper to the deployer (including a fundamental-rights impact assessment - FRIA where required, human oversight, informing individuals) remain on the customer's side; we provide the documentation and support necessary to fulfil them. Where the scope of work makes Persooa the provider of an AI component, we assume the corresponding documentation obligations - the division of roles is confirmed in the contract.
Human-in-the-loop
- Decisions with a significant impact on the end customer remain under human supervision.
- AI supports the decision; it does not remove responsibility from the organization.
- We define clear escalation points at which the system hands the matter over to a human.
- Operators have the ability to stop (kill switch) and override the operation of the automation.
Explainability
- For decision and recommendation models, we can describe the operating logic, the key input features and the limitations.
- We prefer interpretable solutions where the level of risk requires it.
- We document models (purpose, data, assumptions, metrics, known limitations) so that the customer can audit them.
Data minimization
- The model receives only the data genuinely necessary to achieve the objective.
- We avoid collecting data "just in case"; we tailor the scope of data to the use case.
- We apply pseudonymization and aggregation where these are sufficient to achieve the result.
Privacy by design
- Privacy is designed into the solution architecture from the start, not bolted on at the end.
- The purposes of processing are transparent; data is not used for purposes incompatible with the original one without a basis.
- The customer's consent and preference mechanisms are respected at the activation level (Data Ethics Charter).
Bias mitigation
- We test models for unintended discrimination against protected and vulnerable groups.
- We monitor model drift and the quality of input data over time.
- We do not use sensitive characteristics (or their direct proxies) as a basis for targeting.
- If harmful bias is detected, we suspend or correct the model.
Security controls
- Access to training and production data in accordance with the least privilege principle.
- Separated environments (dev/test/prod), version control of models and data.
- Safeguards against model abuse (e.g. prompt injection, data exfiltration) in GenAI solutions.
- Details: Security & Governance Statement.
AI Governance
- Every AI project has an assigned owner responsible for compliance with this policy.
- We maintain a register of the AI use cases carried out for the customer (model inventory).
- Decisions to launch high-risk cases require approval on the customer's side.
- The policy is reviewed at least once a year and upon significant regulatory changes.
- For higher-risk cases, we provide logging of key system-operation events (audit trail) that makes it possible to trace decisions.
- After deployment, we monitor models (quality, drift, incidents); we report significant anomalies to the customer and support them in fulfilling the reporting obligations arising from regulations.
Generative AI (GenAI) principles
- A human verifies - AI-generated content undergoes human review before publication or action wherever the risk requires it.
- No customer data in public models - we do not enter confidential customer data into GenAI tools that do not provide appropriate processing guarantees.
- Labelling - where regulations or ethics require it, we label interactions and content generated by AI.
- No deceptive AI - we do not create systems that impersonate a human in a misleading way, or manipulative deepfakes.
- Intellectual property rights - we respect copyright and licences when using GenAI.
- Transparency under the AI Act (Article 50). Where applicable, we ensure that a natural person is informed of an interaction with an AI system, and that content generated or substantially modified by AI can be labelled as artificially generated (including in a machine-readable format where regulation requires it).
AI agents (agentic commerce)
- Agents operate within clearly defined limits of authority; beyond them they escalate to a human.
- Agents' critical actions are reversible or require confirmation.
- Agents' actions are logged and auditable.
- The end customer is informed when they are interacting with an AI system.
- In the personalization of offers and prices in the EU, we do not differentiate between customers solely on the basis of nationality or location, in accordance with the principles for preventing unjustified geo-blocking (EU Regulation 2018/302).
Document owner: Persooa Management Board / person responsible for AI Governance. Review: annual. Version: 2026.1. This document is informational and does not constitute a binding contractual commitment.