Responsible AI

AI usage and data governance

The operating principles used when AI is included in an approved sturdycore™ workflow.

Last updated: September 7, 2026

Scope and responsibility

SturdyCloud IT Ltd. is responsible for the sturdycore™ technology service. This policy applies to AI-assisted drafting, summarization, classification, retrieval, routing, voice, customer support, and workflow automation included in an approved engagement.

Human oversight

AI supports people. It does not replace accountable business or professional decision-making. A qualified person must review material output before it is used.

AI must not independently make legal, financial, employment, health, safety, or other material decisions, sign agreements, make binding promises, or take actions requiring professional judgment.

Approved purposes

  • drafting, summarization, writing support, and meeting notes
  • knowledge retrieval and document classification
  • customer inquiry intake, routing, and support drafts
  • workflow suggestions, reporting, and operational reminders
  • voice reception, scheduling, and live transfer under an approved call flow

Data minimization

AI workflows should use only the information reasonably needed for the approved purpose. Sensitive or regulated information should not be submitted unless the use, provider, environment, access, retention, and security requirements have been approved in writing.

Development and public demonstrations should use synthetic or specifically approved test data.

Providers and model use

Approved workflows may use third-party AI, voice, automation, hosting, or communications providers. Provider terms, retention, training practices, data location, security, and client restrictions are reviewed according to the service scope. We seek configurations that do not use client data for general model training where available.

Testing and limitations

AI output can be incomplete, incorrect, biased, or unsuitable. Testing may include representative prompts, known failure cases, access checks, human review, escalation paths, and monitoring where included in scope. No AI output is guaranteed to be accurate or complete.

Voice and call workflows

AI reception and call workflows should use approved scripts, clear limits, escalation rules, and live transfer for sensitive or complex matters. Recording, transcription, consent, notice, and retention requirements must be configured for the applicable jurisdiction and business use.

Automated email campaigns

AI and automation may assist with drafting, personalization, segmentation, scheduling, or sending. Commercial messages must use appropriate consent or another lawful basis, identify the sender, include contact information and an unsubscribe mechanism where required, and suppress contacts who have opted out.

Incident handling

Potential data exposure, harmful output, incorrect routing, unauthorized action, or other material AI failures should be reported promptly. We assess impact, contain the workflow where needed, preserve relevant records, and update safeguards or configuration as appropriate.

Contact

Questions or concerns about AI use can be sent to contact@sturdycloud.ca.