Scope and responsibility
SturdyCloud IT Ltd. is responsible for the sturdycore™ technology service. This policy applies to AI-assisted drafting, summarization, classification, retrieval, routing, voice, customer support, and workflow automation included in an approved engagement.
Human oversight
AI supports people. It does not replace accountable business or professional decision-making. A qualified person must review material output before it is used.
AI must not independently make legal, financial, employment, health, safety, or other material decisions, sign agreements, make binding promises, or take actions requiring professional judgment.
Approved purposes
- drafting, summarization, writing support, and meeting notes
- knowledge retrieval and document classification
- customer inquiry intake, routing, and support drafts
- workflow suggestions, reporting, and operational reminders
- voice reception, scheduling, and live transfer under an approved call flow
Data minimization
AI workflows should use only the information reasonably needed for the approved purpose. Sensitive or regulated information should not be submitted unless the use, provider, environment, access, retention, and security requirements have been approved in writing.
Development and public demonstrations should use synthetic or specifically approved test data.
Providers and model use
Approved workflows may use third-party AI, voice, automation, hosting, or communications providers. Provider terms, retention, training practices, data location, security, and client restrictions are reviewed according to the service scope. We seek configurations that do not use client data for general model training where available.
Testing and limitations
AI output can be incomplete, incorrect, biased, or unsuitable. Testing may include representative prompts, known failure cases, access checks, human review, escalation paths, and monitoring where included in scope. No AI output is guaranteed to be accurate or complete.
Voice and call workflows
AI reception and call workflows should use approved scripts, clear limits, escalation rules, and live transfer for sensitive or complex matters. Recording, transcription, consent, notice, and retention requirements must be configured for the applicable jurisdiction and business use.
Automated email campaigns
AI and automation may assist with drafting, personalization, segmentation, scheduling, or sending. Commercial messages must use appropriate consent or another lawful basis, identify the sender, include contact information and an unsubscribe mechanism where required, and suppress contacts who have opted out.
Incident handling
Potential data exposure, harmful output, incorrect routing, unauthorized action, or other material AI failures should be reported promptly. We assess impact, contain the workflow where needed, preserve relevant records, and update safeguards or configuration as appropriate.
Contact
Questions or concerns about AI use can be sent to contact@sturdycloud.ca.