This policy covers AI Assistant, Help/Voice Assistant, AI Reply Drafting, AI Phone Receptionist, Business Intelligence/Business Brain, SEO Autopilot, AI Website Builder, AI content/marketing tools, AI Photo Digitizer, AI workflow nodes/agents, Autonomous Commerce AI and other features identified as AI-powered.
Noxtill should identify customer-facing AI when a person could reasonably believe they are interacting with a human and must do so when applicable law requires it.
EU AI Act Article 50 requires providers of AI systems intended to interact directly with natural persons to design systems so people are informed they are interacting with AI unless this is obvious in context. Noxtill should therefore disclose AI at the start of AI phone interactions and in customer-facing AI chat where required.
AI may:
- summarize records and conversations;
- classify tickets, leads, products or events;
- draft replies, descriptions, reports, pages and campaign content;
- extract structured fields from text, images or voice;
- recommend actions, priorities, reorder decisions, forecasts or experiments; and
- execute only explicitly permitted tools/actions within configured permissions, limits and approval policies.
AI output is not final legal, tax, accounting, medical, financial or employment advice. It is not proof that a payment settled, delivery completed, signature is valid, stock exists, booking is available or external provider action succeeded.
The canonical module/provider must verify authoritative business state.
Material recommendations should link source records, data freshness and assumptions where feasible. Missing, stale or partial data should be visibly labelled rather than converted to a confident number.
Noxtill should store concise decision metadata, evidence references, tool calls, approval state and outcomes needed for audit. It should not expose or preserve hidden chain-of-thought.
| Tier | Examples | Default |
|---|---|---|
| Draft-only | reply, email, product copy, blog copy | Human reviews/sends/publishes. |
| Recommendation | reorder, opportunity, campaign, diagnosis | Human decides whether to act. |
| Bounded execution | configured reminder, approved workflow node | Executes within explicit policy/permission. |
| High-impact | payout, refund, payroll, hiring, vendor award, legal publication | Require approval unless lawful owner policy explicitly permits bounded automation. |
Recommended Noxtill commitment: Customer Content is not used to train generalized third-party foundation models or generalized Noxtill models without explicit customer opt-in through a separate, revocable program.
Where commercially available, AI provider settings/contracts should minimize retention and disable provider training on submitted business data. Reliability telemetry should be minimized and de-identified/aggregated where feasible.
Noxtill must not infer protected HR traits, medical conditions, intelligence or suitability from unsupported data. Customers must not use AI features for unlawful discriminatory decisions. Employment and performance features should preserve source evidence and require appropriate human review.
Agentic workflows may choose among explicitly allowed tools within configured budgets and data scopes, but cannot grant themselves new permissions. Financial limits, message consent, legal holds, tenant boundaries, provider scopes and high-impact approvals remain deterministic.
Users should be able to report unsafe, inaccurate or unexpected AI output. Noxtill should record the feature/model/provider version, relevant inputs/references, tool calls, approval state and result necessary for investigation, consistent with privacy/minimization rules.
