Note: The Portuguese version is the legally binding version.

Artificial Intelligence Policy

Version 3.0 — Effective as of August 10, 2026

VertexHub do Brasil Ltda ("ChatSense," "we," "our," or "Platform"), committed to transparency and the responsible use of Artificial Intelligence (AI) technologies, publishes this Policy to describe the AI systems utilized, their purposes, limitations, security safeguards, and the shared responsibilities between the Platform and its customers.

1. Description of Artificial Intelligence Systems

1.1 Artificial Intelligence Model Providers

ChatSense uses an orchestration of multiple AI model providers, which may include, depending on the configuration in effect for each organization:

  • Google (Gemini, Gemini Live and Veo) — Response generation, sentiment analysis, intent classification, conversation summarization, topic extraction, real-time voice processing and media generation for campaigns
  • Anthropic (Claude models) — AI inference as determined by the platform's orchestration
  • OpenAI — AI inference as determined by the platform's orchestration
  • DeepSeek (accessed through the OpenRouter aggregator) — AI inference for specific tasks, as determined by the platform's orchestration
  • Deepgram — Real-time speech-to-text (STT) transcription, when configured by the organization
  • Self-hosted models (own infrastructure) — Image analysis (Vision), audio transcription (Whisper), text-to-speech (TTS) and vector embedding generation for semantic search (RAG) are performed by self-hosted models on the platform's own infrastructure, without sending such data to third-party providers

The up-to-date list of AI sub-processors, with processing countries and safeguards, is set out in the Sub-processor Annex of the Data Processing Agreement (DPA).

1.2 AI Features

The platform offers the following Artificial Intelligence-based features:

  • Automated responses (bot pipeline) — AI-generated responses for automated customer service
  • Response suggestions — Contextual suggestions for human agents during customer interactions
  • Conversation summarization — Automatic summaries of the content and key points of each conversation
  • Sentiment analysis — Automatic classification of customer sentiment (positive, neutral, negative)
  • Auto-tagging — Automatic categorization of conversations by relevant topics
  • Topic extraction — Identification of the main subjects addressed in each interaction
  • Audio transcription (STT) — Conversion of audio messages to text for processing and display, performed by self-hosted models on the platform's own infrastructure; only real-time voice (Clause 1.1) uses third-party providers (Google Gemini Live and, when configured, Deepgram)
  • Image analysis (Vision) — Interpretation of the content of images sent by customers, performed by a self-hosted model on the platform's own infrastructure
  • Text-to-speech (TTS) — Audio generation from text-based responses, where available to the organization, by a self-hosted model on the platform's own infrastructure
  • AI voice calls — Handling of telephone calls by an AI voice agent, subject to activation by the customer and where available to the organization
  • Specialized AI agents — Sales and CRM agents (assisted prospecting, qualification, follow-up and closing) and an operations assistant (Copilot)
  • Campaign content generation — Assisted creation of copy and media for marketing campaigns

1.3 RAG (Retrieval-Augmented Generation)

ChatSense utilizes a Retrieval-Augmented Generation (RAG) system to improve the accuracy of AI responses. The customer's knowledge base is indexed with vector embeddings using the PostgreSQL pgvector extension. During customer service interactions, the system performs semantic searches to locate relevant excerpts from the knowledge base and inject them as context into the prompts sent to the language model.

1.4 Bot Pipeline

The processing flow for each AI interaction follows this sequence:

  • Intent classification — Identification of the customer's intent in the received message
  • RAG retrieval — Semantic search of the knowledge base for relevant content
  • Conversation history — Inclusion of context from previous messages
  • Guardrail injection — Application of the configured security safeguards
  • LLM call — Submission of the complete prompt to the language model
  • Response delivery — Delivery of the generated response to the customer via the corresponding channel

1.5 Escalation System

The AI is capable of detecting when an interaction requires human intervention. The system identifies escalation keywords, excessive complexity, or customer dissatisfaction and automatically transfers the conversation to a human agent, accompanied by a configurable transition message.

2. Classification Under the EU AI Act (Regulation 2024/1689)

2.1 System Classification

ChatSense is an AI system that integrates general-purpose AI models (GPAI) provided by third parties, within the meaning of Regulation (EU) 2024/1689 (EU AI Act). In the EU AI Act value chain, VertexHub acts as the provider of the AI system and customers act as deployers. The platform provides AI capabilities that may be utilized across various customer service contexts.

2.2 Risk Assessment

The ChatSense platform is not inherently high-risk. However, we acknowledge that customers (deployers) may create use cases that fall within the high-risk category, depending on the sector and purpose of deployment (for example, healthcare, financial services, or legal services).

2.3 Deployer Responsibilities

Under the EU AI Act, the customer (deployer) is responsible for:

  • Informing end users about interaction with AI systems
  • Maintaining adequate human oversight over deployed AI systems
  • Ensuring the quality of data used in the training and configuration of agents
  • Assessing whether the specific use case constitutes high-risk within their regulatory context

The obligations under Article 26 (and, where applicable, the impact assessment under Article 27) apply only if the customer's use case qualifies as a high-risk AI system within the meaning of Article 6 and Annex III; the duty to inform end users that they are interacting with AI arises from Article 50.

2.4 Transparency Obligations

In compliance with Article 50, AI-generated content must be properly identified. ChatSense implements identification markers on AI-generated messages and provides information about the model, version, and execution traces to administrators.

2.5 Obligations Regarding the Integrated GPAI Models

The general-purpose AI (GPAI) models integrated into ChatSense are developed by third parties (Clause 1.1), which bear the obligations under Chapter V of the EU AI Act. ChatSense passes on to customers the transparency information made available by the providers of those models (Article 53(1)(b)) and fulfills the transparency obligations applicable to providers of AI systems, including Article 50.

3. Transparency and AI Content Identification

  • Identification markers — AI-generated messages carry system identification markers, distinguishing them from messages sent by human agents
  • Administrator visibility — Administrators have access to system prompts, model versions used, and complete execution traces
  • Audit trail — Each AI interaction is logged in an internal audit trail, including: input and output tokens, latency, model used, and provider
  • Model versioning — Model versions are recorded to ensure reproducibility and traceability
  • Customer obligation — The customer must inform its end users when they are interacting with an AI system rather than a human being

4. Data Processing for AI

4.1 Data Sent to Language Models

The following data is included in prompts sent to LLM providers:

  • Conversation messages (last 20 messages for context)
  • System prompt configured by the administrator
  • RAG context (knowledge base excerpts retrieved via semantic search)
  • Contact name
  • Platform/channel type (WhatsApp, Instagram, Facebook Messenger, Telegram, Webchat/Widget, Email)

For AI voice features, where enabled for the organization, the call audio is processed in real time by speech recognition and synthesis providers (Google Gemini Live and, when configured by the organization, Deepgram), exclusively for the purpose of conducting the conversation.

4.2 Data That Is NOT Sent

The following data is never included in AI prompts:

  • Passwords and access credentials
  • Payment information and financial data
  • Internal team notes
  • System audit logs

4.3 Use of Customer Data and Prohibition on Model Training

The AI model providers listed in Clause 1.1 do not use the data submitted via API to train their models, as provided in the enterprise terms of service of each provider. ChatSense does not train global models with customer data. The platform may, however, reuse excerpts of conversations from the customer's own organization as reference examples (governed intra-organizational learning) to improve the quality of the AI agent responses of that organization. This learning is strictly isolated per organization: data from one organization is never used to improve responses for another, nor shared between different organizations.

4.4 Embeddings and Local Storage

Vector embeddings are generated by a self-hosted model on the platform's own infrastructure (Clause 1.1) and stored locally in the platform's database (PostgreSQL, pgvector extension). The vectors are not shared with third parties and remain under the exclusive control of the platform.

4.5 Data Minimization

Only the conversation context strictly necessary is included in AI prompts, in compliance with the data minimization principle of the LGPD (art. 6, III).

4.6 AI Data Retention

AI execution records (execution traces) are retained for the period necessary for debugging, auditing and service quality improvement, and are deleted at the end of that period.

4.7 International Data Transfers

Processing by AI providers may involve the international transfer of personal data, carried out on the basis of art. 33 of the LGPD (Brazilian General Data Protection Law), under contractual clauses and appropriate safeguards with each provider. The list of providers, processing countries and safeguards is set out in the DPA and its sub-processor list.

4.8 Roles in Processing

In the processing of end users' personal data by the AI features, the customer acts as controller and VertexHub as processor, under the terms of the DPA. Requests for review of automated decisions (art. 20 of the LGPD) must be directed to the customer-controller; VertexHub will provide the necessary technical support, including the audit records described in Clause 7.4.

5. Guardrails System (Security Safeguards)

5.1 Security Flags

ChatSense implements 10 security flags that are enabled by default on all AI agents. Control over these flags is restricted to superadministrators:

  • no_profanity — Blocks vulgar, obscene, or offensive language
  • no_threats — Blocks intimidation, coercion, or threats
  • no_discrimination — Blocks racial, gender, religious, sexual orientation, or disability-based discrimination
  • no_sexual_content — Blocks sexual or adult content (administrator may disable upon acceptance of a liability disclaimer)
  • no_violence — Blocks glorification of or incitement to violence
  • no_illegal_activity — Blocks guidance or instructions regarding illegal activities
  • no_personal_data — Blocks the AI from sharing third-party personal data
  • no_impersonation — Blocks impersonation of real persons, authorities, or institutions
  • no_medical_diagnosis — Enforces referral to a qualified healthcare professional, preventing medical diagnoses
  • no_financial_advice — Prevents unlicensed financial, tax, or investment advice

5.2 Per-Agent Tone Settings

Each AI agent has 8 tone settings controllable by the administrator:

  • allow_slang — Allows use of slang and informal language
  • allow_humor — Allows responses with a humorous tone
  • allow_emojis — Allows use of emojis in responses
  • allow_price_negotiation — Allows price negotiation (requires acceptance of a liability disclaimer)
  • allow_competitor_mentions — Allows mentions of competitors
  • allow_external_links — Allows inclusion of external links in responses
  • allow_political_topics — Allows discussion of political topics
  • allow_religious_references — Allows religious references (requires acceptance of a liability disclaimer)

5.3 Liability Disclaimers

Certain settings (no_sexual_content disabled, allow_price_negotiation, allow_religious_references) require explicit acceptance of a liability disclaimer by the administrator. The acceptance is recorded with IP address, user-agent, and timestamp for auditing and legal compliance purposes.

6. Accuracy, Limitations, and Hallucinations

6.1 Probabilistic Nature

The Artificial Intelligence systems used by ChatSense are probabilistic in nature. This means that generated responses may be inaccurate, incomplete, or fabricated (a phenomenon known as "hallucination").

6.2 No Warranty

ChatSense DOES NOT guarantee the accuracy, completeness, timeliness, or suitability of AI-generated responses for any specific purpose. AI responses are provided "as is," without any express or implied warranties.

6.3 Does Not Constitute Professional Advice

AI-generated responses do not constitute professional advice of any kind, including but not limited to: medical, legal, financial, tax, accounting, or psychological advice. Customers operating in regulated sectors must ensure qualified human oversight.

6.4 Known Risks

Despite the implemented guardrails, the AI may occasionally generate responses that are:

  • Factually incorrect or outdated
  • Inconsistent with the configured knowledge base
  • Inappropriate even with active safeguards
  • Biased or unfair (algorithmic bias)

ChatSense implements guardrails and safety systems to reduce (not eliminate) these risks. The customer must maintain active and continuous human oversight.

7. Human Oversight and Right to Intervention

7.1 Oversight Mechanisms

  • Escalation system — The AI detects escalation keywords and automatically transfers the conversation to human agents
  • Per-agent deactivation — The administrator may deactivate AI for individual agents at any time
  • Organization-wide deactivation — The administrator may deactivate all AI for the entire organization
  • Per-conversation toggle — Human agents may enable or disable AI on each conversation individually

7.2 Data Subject Rights Under the LGPD

In compliance with art. 20 of the LGPD (Law No. 13,709/2018), the data subject has the right to request human review of decisions made solely on the basis of automated processing of personal data that affect their interests, including decisions intended to define their personal, professional, consumer, or credit profile.

7.3 Rights Under the GDPR

In compliance with art. 22 of the GDPR (EU Regulation 2016/679), data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect them.

7.4 Auditability

Each AI interaction is logged with full context (input, output, model, provider, latency, tokens used) in the audit trail, enabling subsequent review and investigation by administrators and, where applicable, by regulatory authorities.

8. Bias, Fairness, and Non-Discrimination

  • The no_discrimination guardrail is enabled by default and cannot be disabled by customer organizations (its control is restricted to the platform team)
  • We acknowledge that AI models may reflect biases present in the training data of LLM providers
  • ChatSense monitors for discriminatory patterns and implements corrective measures when identified
  • Customers who identify potentially discriminatory or biased responses should report them immediately to vertexhub@vertexhub.ai
  • As we do not train models with customer data, identified biases originate from the upstream provider models listed in Clause 1.1, and ChatSense applies guardrails to mitigate them

9. Customer Responsibilities (Deployer)

By using ChatSense's Artificial Intelligence features, the customer assumes the following responsibilities:

  • Configuring AI agents with system prompts appropriate to their business context
  • Reviewing and maintaining guardrail settings in accordance with their industry sector
  • Keeping the escalation system enabled to ensure human intervention when necessary
  • Monitoring AI agent conversations on a regular basis
  • Training human agents on oversight and quality control of AI systems
  • Informing end users that they are interacting with an AI system rather than a human being
  • Not disabling security guardrails in regulated sectors (healthcare, financial, legal)
  • Complying with sector-specific AI regulations applicable to their industry
  • Promptly reporting AI security incidents as described in Section 11

10. Limitation of Liability and Disclaimers

10.1 ChatSense IS NOT Liable For:

  • Accuracy, completeness, or timeliness of AI-generated content
  • Decisions made by customers or end users based on AI responses
  • Losses, damages, or harm arising from AI hallucinations or incorrect responses
  • Fines, penalties, or regulatory sanctions resulting from the customer's AI deployment choices
  • End-user complaints regarding AI interactions
  • The customer's failure to properly configure guardrails
  • The customer's failure to maintain human oversight over AI agents

10.2 Assumption of Risk by the Customer

The customer fully assumes all risks related to:

  • Deployment of AI agents within their business context
  • Content generated by AI agents configured by the customer
  • Compliance with sector-specific AI regulations applicable to their industry
  • End-user interactions with AI systems

10.3 Maximum Liability Cap

In any event, ChatSense's total liability shall be limited to the fees actually paid by the customer in the preceding 3 (three) months prior to the event giving rise to the claim.

10.4 Legal Basis

This limitation of liability applies to business-to-business (B2B) relationships governed by the Brazilian Civil Code (arts. 421, 421-A and 425), reflecting the allocation of risks freely agreed between the parties. Where applicable law prohibits the limitation — including consumer relationships that may be characterized, willful misconduct (dolo) or gross negligence —, the limitation shall apply to the maximum extent permitted by law. As regards content inserted by third parties (end users), arts. 18 and 19 of the Marco Civil da Internet (Law No. 12,965/2014) apply where relevant.

11. AI Security Incidents and Reporting Channel

11.1 Reporting Channel

To report security incidents related to Artificial Intelligence, please contact:

AI Security Email: vertexhub@vertexhub.ai

11.2 What Constitutes an AI Security Incident

  • Generation of harmful, offensive, or dangerous content by the AI
  • Leakage of personal or sensitive data through AI responses
  • Discriminatory, prejudiced, or biased responses
  • Unauthorized actions executed by AI agents
  • Systematic failure of security guardrails

11.3 Response Timelines

  • Acknowledgment of receipt: within 24 hours of the report
  • Initial investigation: within 72 hours of the report

11.4 Remediation

Remediation actions may include:

  • Updating guardrails and security safeguards
  • Changing AI models or providers
  • Prompt hardening
  • Adjustments to tone and safety settings

11.5 Transparency

Material AI security incidents may be disclosed in security advisories, in accordance with the principles of transparency and accountability.

Contact

For questions regarding this Artificial Intelligence Policy:

ChatSense — VertexHub do Brasil Ltda
General email: vertexhub@vertexhub.ai
Data Protection Officer (DPO): vertexhub@vertexhub.ai
AI Security: vertexhub@vertexhub.ai