This AI Policy (the “Policy”) governs the deployment and use of Artificial Intelligence systems within the services provided by Dcipher Analytics AB (“DA”, “we”, “us” or “our”), Swedish registration number 559169-9268. This Policy serves as a supplemental agreement to our Terms of Use and defines the standards for data privacy and transparency regarding AI-driven insights. By using our services, you (“Customer”, “User”, “you”) acknowledge the AI usage practices and governance frameworks outlined herein.
1. Scope and Definitions
1.1 Applicability. This policy applies to all Dcipher Analytics employees, contractors, third-party vendors, and the operation of the Dcipher Analytics platform. It governs the entire lifecycle of AI systems - from data ingestion and model selection to the delivery of automated insights.
1.2 Definition of AI System. In alignment with Article 3 of the EU AI Act, Dcipher defines an "AI System" as a machine-based system designed to operate with varying levels of autonomy and adaptiveness. This includes:
- 1.2.1 Generative AI: Large Language Models (LLMs) used for text or insight generation (e.g., Gemini, GPT, Claude).
- 1.2.2 Predictive Analytics: Models used for trend forecasting, sentiment detection, topic analysis, and similar NLP tasks.
- 1.2.3 Automated Systems: Workflows that automate data categorization or visualization.
2. Summary
Dcipher Analytics ("the Company") provides an end-to-end insights platform utilizing Artificial Intelligence (AI) and Machine Learning (ML). We are committed to the ethical, secure, and transparent use of AI. Our "Hybrid Model" allows clients to choose between commercial and open-source models, ensuring they retain full control over their data residency and privacy.
3. Technical Architecture & AI Stack
Dcipher employs a multi-layered AI approach to provide maximum flexibility:
3.1 Commercial LLM Integration. Dcipher provides access to a selection of enterprise-grade Large Language Models (LLMs) from leading global providers. These include, but are not limited to: OpenAI (e.g., GPT-5 series), Google (e.g., Gemini series), Anthropic (e.g., Claude series), Cohere, and other Tier-1 providers as integrated and updated within the platform. Users have the autonomy to switch between these providers based on their specific analytical needs. Dcipher continuously evaluates the market for new high-performance models to integrate into the platform.
3.2 Open-Source Models. Users may opt for open-source pretrained models hosted on Dcipher’s private cloud infrastructure (e.g., Gemma, Phi, Llama).
3.3 Offline NLP/NLU. Proprietary models for content analysis and enrichment run within isolated, account-specific computation workspaces.
3.4 Isolated Workspaces. All proprietary ML models are executed within cloud environments dedicated to individual customer accounts to ensure zero cross-contamination of data.
4. Data Privacy & Zero-Training Guarantee
We recognize that data is our clients’ most valuable asset. Dcipher adheres to the following strict privacy protocols:
4.1 Enterprise API Safeguards. Dcipher exclusively utilizes the Enterprise/API versions of commercial AI providers. These agreements legally guarantee that any data submitted by Dcipher or its clients is never used to train the providers’ global models.
4.2 Client-Provided Data. Customers may upload their own datasets at their own discretion. Dcipher provides the tools for analysis, but remains a "Processor"; the responsibility for removing sensitive Personal Identifiable Information (PII) before upload remains with the client.
4.3 Public Data Integrity. Data collected from social media, news, and the web is processed in compliance with public access terms and copyright laws.
5. Data Residency & Retention
Dcipher provides users with granular control over their digital footprint:
5.1 Geographic Sovereignty. By default, data is processed in Google Cloud (Belgium, EU). However, customers may select alternative regions via account settings to meet local compliance (e.g., GDPR, CCPA).
5.2 Immediate Deletion. Dcipher respects the "Right to be Forgotten." When a user deletes data or an account, the information is purged from our active systems immediately. We do not maintain "soft-delete" buffers or shadow backups of deleted client data.
6. Transparency & Human-in-the-Loop
While Dcipher automates insights at scale, we believe AI should augment, not replace, human judgment.
6.1 Pre-Execution Disclosure. All workflows utilizing external AI providers include a mandatory notification to the user before execution.
6.2 Validation Disclaimer. All AI-generated outputs are clearly labeled. Because Dcipher processes high volumes of content daily, manual validation by Dcipher staff is not feasible.
6.3 Client Responsibility. Users are advised that AI-generated insights should be validated for accuracy and context before being used as the basis for critical business or legal decisions.
7. Prohibited Use Cases
7.1 Prohibited Activities. Use of the Dcipher platform is subject to the following restrictions. Dcipher reserves the right to suspend or terminate access for any user found engaging in these activities.
- 7.1.1 Using the platform to generate or distribute misinformation or "deepfake" content.
- 7.1.2 Attempting to "jailbreak" or reverse-engineer the integrated LLMs.
- 7.1.3 Uploading data that violates international intellectual property or privacy laws.
7.2 Technical Enforcement. While Dcipher and its AI sub-processors employ automated safety guardrails to detect and reject AI usage that violates these terms, the ultimate responsibility for the ethical use of the platform rests with the User. Technical rejection of an AI usage does not waive the user's liability under this Policy.
8. Accountability & Governance
8.1 AI Compliance Oversight. The Data Protection Officer (DPO), as defined in the Dcipher Information Security Handbook, serves as the AI Compliance Officer (AICO). The DPO/AICO is responsible for:
- 8.1.1 Maintaining an inventory of all AI models and sub-processors.
- 8.1.2 Conducting Fundamental Rights Impact Assessments (FRIA) for high-risk features.
- 8.1.3 Serving as the primary point of contact for client inquiries regarding algorithmic transparency.
8.2 Audit & Policy Review. This policy is reviewed quarterly by our Engineering team to ensure alignment with the evolving global regulatory landscape, including guidelines from the European AI Office.
8.3 Sub-processor Transparency. Dcipher Analytics maintains a dynamic list of all third-party AI sub-processors and model providers utilized within the platform. To maintain operational agility while ensuring full transparency under the EU AI Act and GDPR, clients may request the current list of sub-processors at any time.