Web Policy
Last Updated May 4, 2026

Part I: Core Contractual Documents

  1. Cookie Policy
  2. Data Processing Addendum (DPA)

A. COOKIE POLICY

This Cookie Policy explains how UgenticAI, Inc. and all subsidiaries, affiliates, business units, joint ventures, and partners (“UgenticAI,” “we,” “us,” or “our”) use cookies and similar tracking technologies on our websites, applications, platforms, and online Services (“Services”). For information on how we collect, use, and protect personal data, please see our Privacy Policy.

1. What Are Cookies? Cookies are small text files placed on your device by websites you visit. They are used to make websites work efficiently, enhance your experience, and provide reporting information. Cookies may be:

  1. First-party cookies – set directly by UgenticAI
  2. Third-party cookies – set by service providers (e.g., analytics, advertising partners)
  3. Session cookies – deleted when you close your browser
  4. Persistent cookies – remain until they expire or you delete them

2. Types of Cookies We Use. UgenticAI uses the following categories of cookies:

2.1 Required / Strictly Necessary Cookies. These cookies enable core functions such as:

  1. security and authentication
  2. account login
  3. user session management
  4. load balancing
  5. fraud prevention

Without these cookies, the Services may not function properly.

Consent required? No (allowed under EU/UK law).

2.2 Performance & Analytics Cookies. Used to understand how users interact with the Services, including:

  1. pages visited
  2. clicked links
  3. time spent on pages
  4. error diagnostics
  5. product usage statistics
  6. device/browser information

Tools may include:

  1. Google Analytics
  2. Mixpanel
  3. Amplitude
  4. Segment
  5. Microsoft Clarity

Consent required? Yes (EU/UK)

2.3 Functionality Cookies. Used to:

  1. remember user preferences
  2. store settings
  3. keep you logged in
  4. customize your experience

Consent required? Yes (EU/UK)

2.4 Advertising & Targeting Cookies. Used to:

  1. deliver relevant ads
  2. measure ad effectiveness
  3. build audience segments
  4. track conversions
  5. integrate with social media advertising systems

Platforms may include:

  1. Meta (Facebook/Instagram)
  2. LinkedIn Insight Tag
  3. Google Ads / DoubleClick
  4. Twitter/X Ads Pixel
  5. TikTok Pixel

Consent required? Yes (EU/UK). Must allow opting out (U.S. state privacy laws).

2.5 Web Beacons, Pixels, and Similar Technologies. We may use:

  1. tracking pixels
  2. tags
  3. clear GIFs
  4. local storage
  5. software development kits (SDKs)

These allow us to:

  1. monitor user behavior
  2. determine email open/click rates
  3. evaluate campaign performance
  4. personalize experiences

3. How We Use Cookies. We use cookies to:

  1. operate and secure the Services
  2. enable essential features
  3. analyze usage and performance
  4. provide personalization
  5. offer customer support and troubleshooting
  6. deliver and measure advertising
  7. identify returning visitors
  8. improve products and develop new features

We do not sell personal data collected through cookies.

4. Third-Party Cookies. Third parties may set cookies through the Services, including:

  1. analytics providers
  2. ad networks
  3. payment processors
  4. customer support tools
  5. social media integrations
  6. embedded content (e.g., YouTube, Vimeo)

These third parties may use cookies to:

  1. track your browsing activity
  2. deliver targeted ads
  3. analyze performance
  4. help us identify issues

5. Cookie Consent Banner (EU/UK and Global Requirements). When you first visit our Services from a region where consent is required, you will see a cookie consent banner that allows you to:

  1. accept all cookies
  2. reject non-essential cookies
  3. manage individual preferences by category

Your preferences can be changed at any time.

6. How to Manage or Disable Cookies. You may manage cookies using one or more of the following methods:

6.1 Through Our Website Banner or Preferences Panel. Click “Cookie Settings” (or similar) located in the footer or within the banner to modify your choices.

6.2 Through Your Browser Settings. You may block or delete cookies in your browser. Common browser links:

  1. Chrome
  2. Firefox
  3. Safari
  4. Edge

6.3 Through Platform-Specific Opt-Outs (Advertising). You may opt out of targeted advertising via:

  1. Google Ads Settings
  2. LinkedIn Ad Preferences
  3. Meta Ad Preferences
  4. Twitter/X Privacy & Safety
  5. TikTok Ad Personalization

We honor:

  1. Global Privacy Control (GPC)
  2. Do Not Sell or Sell My Personal Information requests (California)

7. Do Not Track Signals. Some browsers send “Do Not Track” (DNT) signals. We do not respond to DNT signals due to inconsistent standards, but we honor legally mandated opt-out mechanisms (e.g., GPC).

8. Changes to This Cookie Policy. We may update this Cookie Policy periodically. The “Last Updated” date reflects the latest version.

B. DATA PROCESSING ADDENDUM (DPA)

This Data Processing Addendum (“DPA”) forms part of any subscription agreement, master services agreement, terms of service, order form, or contract (“Agreement”) between the Customer (“Customer,” “Controller,” or “Business”) and UgenticAI, Inc., including its subsidiaries, affiliates, partners, business units, and processors (“UgenticAI,” “Processor,” or “Service Provider”). This DPA governs UgenticAI’s processing of Customer Personal Data in connection with the Services. This DPA applies only where applicable data protection laws require a written data processing agreement (e.g., GDPR, UK-GDPR, CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, APPI, LGPD).

1. Definitions. For purposes of this DPA:

  1. “Personal Data” means any information relating to an identified or identifiable natural person.
  2. “Customer Personal Data” means Personal Data supplied, transmitted, or made available to UgenticAI by Customer or its users.
  3. “Controller” / “Business” means the entity determining purposes and means of processing.
  4. “Processor” / “Service Provider” means UgenticAI when processing Customer Personal Data on Customer’s behalf.
  5. “Subprocessor” means a third party engaged by UgenticAI to process Customer Personal Data.
  6. “Data Protection Laws” includes GDPR, UK-GDPR, CCPA/CPRA, and all global privacy laws referenced above.

Other terms not defined herein have the meaning given in the Agreement or applicable laws.

2. Scope & Roles

2.1 Roles. For Customer Personal Data:

  1. Customer is the Controller.
  2. UgenticAI is the Processor.

2.2 Instructions. UgenticAI will process Customer Personal Data solely on documented instructions from Customer, including as necessary to provide the Services. Customer’s instructions are:

  1. the Agreement,
  2. any configuration or instruction provided via the Services, and
  3. this DPA.
  4.  

3. UgenticAI Obligations. UgenticAI shall:

3.1 Process Only as Instructed. Process Customer Personal Data only to provide the Services unless otherwise required by law.

3.2 Confidentiality. Ensure personnel with access have committed to confidentiality obligations.

3.3 Security Measures. Implement appropriate technical and organizational security measures, including:

  1. encryption in transit and at rest
  2. access control and authentication
  3. least-privilege access
  4. network and application security
  5. monitoring, logging, and auditing
  6. incident detection and response
  7. business continuity and disaster recovery controls

See Security Policy for details.

3.4 Subprocessors. UgenticAI may engage Subprocessors but will:

  1. enter written agreements imposing data protection obligations;
  2. remain responsible for Subprocessor compliance;
  3. maintain a public Subprocessor List;
  4. notify Customer of new Subprocessors and provide opportunity to object on reasonable grounds.

3.5 Data Subject Requests (DSRs). Provide assistance to Customer in responding to:

  1. access requests
  2. deletion requests
  3. correction requests
  4. portability requests
  5. opt-out requests (California)

3.6 Personal Data Breach Notification. Notify Customer without undue delay after becoming aware of a breach affecting Customer Personal Data. Notification will include:

  1. nature of breach
  2. categories and number of individuals affected
  3. likely consequences
  4. remediation steps

3.7 Return or Deletion of Data. Upon request or termination of Services, UgenticAI will:

  1. return Customer Personal Data, or
  2. securely delete it (unless retention is required by law).

4. Customer Responsibilities. Customer shall:

  1. ensure it has all rights and lawful bases to provide Personal Data to UgenticAI;
  2. ensure all instructions comply with applicable laws;
  3. configure the Services to comply with its obligations;
  4. provide legally required notices and consents to end users;
  5. not submit Special Category Data unless agreed in writing.

5. Subprocessors

5.1 Authorization. Customer grants general authorization for UgenticAI to engage Subprocessors.

5.2 Subprocessor List. UgenticAI maintains a publicly accessible Subprocessor List (see separate policy).

5.3 Objection. Customer may object in writing to a new Subprocessor within 10 days of notice. If the parties cannot resolve the objection, Customer may stop using the affected Services.

6. Cross-Border Transfers. Customer Personal Data may be transferred globally to UgenticAI or its Subprocessors.

When transferring from the EEA, UK, or Switzerland, UgenticAI will implement appropriate safeguards, including:

  1. EU Standard Contractual Clauses (SCCs)
  2. UK ICO Addendum
  3. Swiss Addendum

These SCCs and Addenda are incorporated into this DPA by reference.

7. CCPA/CPRA Requirements (U.S.). When UgenticAI processes Customer Personal Data subject to California law, UgenticAI will:

  1. act as a Service Provider
  2. not sell or share Customer Personal Data
  3. not combine Customer Personal Data with external data except as permitted
  4. process only for the purposes of the Agreement
  5. comply with customer deletion, correction, and opt-out rights

Customer certifies that disclosures of Personal Data to UgenticAI are for permissible purposes.

8. Audit Rights. UgenticAI will:

  1. provide documentation necessary to demonstrate compliance
  2. allow audits conducted by Customer or an independent auditor once per year
  3. satisfy most audit requests by providing SOC reports, penetration tests, policy documentation, and certifications

On-site audits must be:

  1. limited to security and privacy controls
  2. scheduled with 30 days’ notice
  3. conducted during normal business hours
  4. subject to confidentiality obligations

9. Data Protection Impact Assessments (DPIAs). UgenticAI will provide reasonable cooperation when Customer is required to conduct:

  1. DPIAs
  2. prior consultations with data protection authorities

10. Duration. This DPA remains in effect for as long as UgenticAI processes Customer Personal Data under the Agreement.

11. Conflict of Terms. If there is a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict.

ANNEX I — DETAILS OF PROCESSING

A. Categories of Data Subjects

  1. Customer employees
  2. Customer users
  3. Customer’s end-users, clients, or prospects
  4. Website/app visitors
  5. Social media account audiences (if integrated)

B. Categories of Personal Data

  1. Identifiers (name, email, phone, IP)
  2. Device and usage data
  3. Social media profile information (if connected)
  4. Account data and settings
  5. Uploaded content, documents, media
  6. Behavioral and analytics data
  7. Payment identifiers (tokenized)
  8. Any data submitted via the Services

C. Special Category Data. UgenticAI does not knowingly process Special Category Data unless expressly agreed.

D. Nature and Purpose of Processing

  1. storage
  2. retrieval
  3. Analysis
  4. Transformation
  5. AI processing and inference
  6. output generation
  7. support and troubleshooting
  8. security and fraud detection

E. Retention Period. As specified in the Agreement and Privacy Policy.

ANNEX II — SECURITY MEASURES. UgenticAI implements:

  1. encryption in transit (TLS 1.2+) and at rest (AES-256)
  2. password hashing (bcrypt/argon2)
  3. firewalls and DDoS protection
  4. identity/access management (IAM) controls
  5. role-based access control (RBAC)
  6. audit logging and monitoring
  7. vulnerability scanning
  8. periodic penetration testing
  9. secure SDLC practices
  10. business continuity and disaster recovery plans

ANNEX III — STANDARD CONTRACTUAL CLAUSES (Summary). The parties agree the following SCC modules apply:

Transfer Type Module
EU → UgenticAI (Processor) Module 2
UK → UgenticAI (Processor) UK Addendum
Switzerland → UgenticAI SCCs with Swiss variations

Full text incorporated by reference per GDPR Article 46(2).

Part II: Safety + Security + Compliance Policies

  1. Acceptable Use Policy (AUP)
  2. AI Use & Safety Policy
  3. KYC/AML/ATF Complaince Policy
  4. Responsible Disclousre & Vulnerability Disclusure Policy
  5. Security Policy
  6. Subprocessor List & Change Notification Policy

A. ACCEPTABLE USE POLICY (AUP)

This Acceptable Use Policy (“AUP”) governs how users may access and use the websites, platforms, APIs, AI systems, software, integrations, and services operated by UgenticAI, Inc. and its subsidiaries, affiliates, partners, and business units (“UgenticAI,” “we,” “us,” or “our”). This AUP is incorporated by reference into the Terms of Use and applies to all users, including customers, developers, enterprise clients, guests, and anyone accessing the Services. By using the Services, you agree to comply with this AUP.

1. General Principles. Users must:

  1. comply with all applicable laws, regulations, and industry requirements
  2. use the Services safely, responsibly, and ethically
  3. not harm UgenticAI systems, users, partners, or third parties
  4. maintain the confidentiality of their login credentials
  5. ensure all data provided is lawful, accurate, and properly authorized

UgenticAI may suspend, restrict, or terminate access for violations of this AUP.

2. Prohibited Activities. The following activities are strictly prohibited, whether done directly, indirectly, manually, or through automation or AI.

2.1 Illegal Activities. Users may NOT use the Services to:

  1. violate any law, regulation, or industry rule (U.S., EU, or international)
  2. engage in fraud, identity theft, or financial crimes
  3. support terrorism, violent acts, or extremism
  4. facilitate money laundering or sanctions evasion
  5. engage in stalking, harassment, or threats
    distribute illegal content or contraband

2.2 Security Violations

Users may NOT:

  1. attempt unauthorized access to any system or network
  2. breach, disable, or defeat security controls
  3. scan, probe, or test vulnerabilities
  4. distribute malware, ransomware, bots, viruses, worms, or exploits
  5. attempt to gain access to other users’ data
  6. impersonate or misrepresent identity

2.3 Intellectual Property Abuse

Users may NOT:

  1. upload or use content they do not have the right to use
  2. infringe copyrights, trademarks, patents, or proprietary rights
  3. violate third-party API or platform terms

Including but not limited to:

  1. LinkedIn API
  2. Google API
  3. Meta/Instagram/Facebook API
  4. Twitter/X API
  5. TikTok API

2.4 Content Restrictions

You may NOT use the Services to create, upload, or distribute:

  1. hateful, harassing, or abusive content
  2. obscene, pornographic, or sexual content involving minors
  3. violent or extremist propaganda
  4. instructions for harming others
  5. deception, impersonation, or misinformation
  6. content meant to manipulate elections or political processes

2.5 Fraud & Deceptive Practices

You may NOT:

  1. create fake profiles or identities
  2. mislead users about your affiliation or qualifications
  3. generate fraudulent reviews, testimonials, or engagement
  4. manipulate metrics or analytics
  5. use AI-generated content to defraud or misrepresent

2.6 Automated Abuse

You may NOT:

  1. build scraper bots
  2. bypass rate limits
  3. use automation to overwhelm or degrade systems
  4. run high-volume requests that impair service
  5. attempt to reverse-engineer or extract proprietary models

2.7 Prohibited AI Use Cases (Safety Restrictions)

Users may NOT use UgenticAI models or outputs to:

  1. generate disallowed content under safety policies
  2. develop competing AI models via data extraction or distillation
  3. build surveillance systems that violate privacy laws
  4. analyze biometric data without explicit consent
  5. provide medical, legal, or financial advice without a licensed professional
  6. conduct high-risk decision-making that affects individual rights or access to essential services

Examples of high-risk prohibited uses:

  1. credit/loan approvals
  2. insurance decisions
  3. hiring or HR decision-making
  4. housing eligibility
  5. legal determinations
  6. diagnostic or medical decisions

These require written approval from legal@ugenticai.com.

3. Data & Privacy Requirements. Users must NOT:

  1. submit personal data for which they lack lawful rights
  2. upload sensitive data unless explicitly permitted (e.g., health data, minors’ data, financial IDs)
  3. circumvent consent requirements
  4. attempt to re-identify anonymized data
  5. upload data that violates third-party privacy rules
  6. misuse social media API data or violate platform policies

4. Usage Limits & Fair Use. Users must:

  1. follow documented API limits
  2. avoid excessive or abusive traffic patterns
  3. refrain from behavior that degrades system performance
  4. avoid using multiple accounts to bypass restrictions

UgenticAI may throttle or restrict usage to maintain platform stability.

5. Anti-Spam Requirements. Users may NOT use the Services to:

  1. send unsolicited communications or mass emails
  2. generate spam messages
  3. collect or harvest email addresses improperly
  4. violate the CAN-SPAM Act, TCPA, CASL, or EU e-Privacy laws

See also the Anti-Spam Policy.

6. Enforcement & Remedies. UgenticAI may take any action deemed necessary, including:

  1. warnings
  2. removal of content
  3. suspension or termination
  4. IP address blocking
  5. API key revocation
  6. notification to authorities
  7. legal claims for damages

Serious violations may lead to permanent loss of access.

7. Reporting Violations. Report abuse or violations to: compliance@ugenticai.com
Please include:

  1. description of the violation
  2. URLs, screenshots, or evidence
  3. your contact information

8. Changes to This AUP. We may update this AUP.  The “Last Updated” date reflects the latest version.

B. AI USE & SAFETY POLICY

This AI Use & Safety Policy (“Policy”) describes the rules, restrictions, safety expectations, and responsibilities associated with the use of UgenticAI, Inc. artificial intelligence systems, models, tools, and platforms (“AI Systems” or “Services”). This Policy applies to:

  1. all users of UgenticAI Services
  2. all UgenticAI subsidiaries, affiliates, partners, and contractors
  3. all developers, API users, enterprise customers, and integration partners

By accessing or using any AI functionality provided by UgenticAI, you agree to comply with this Policy.

1. Purpose of This Policy. The goals of this policy are to:

  1. ensure safe and responsible use of AI systems
  2. protect individuals from harm
  3. prevent misuse of AI or automated decision-making
  4. comply with global AI-related regulations
  5. promote transparency and accountability

UgenticAI reserves the right to refuse or restrict access if use cases violate this Policy.

2. How UgenticAI AI Systems Work. UgenticAI AI Systems may:

  1. generate text, images, classifications, or insights
  2. analyze user-submitted data
  3. integrate with Customer or third-party systems
  4. operate autonomously in limited contexts
  5. learn from patterns in data (non-identifiable training unless agreed in a DPA)

AI outputs may contain inaccuracies (“hallucinations”), errors, or outdated information. AI outputs should never be relied upon as the sole source for decisions of consequence.

3. User Responsibilities. Users must:

  1. use AI Systems ethically and lawfully
  2. validate important outputs before acting on them
  3. avoid submitting illegal, unauthorized, or harmful data
  4. comply with data protection, privacy, and intellectual property laws
  5. maintain control and oversight over critical decisions
  6. disclose AI involvement where required by law

Users are responsible for all actions taken via their accounts, including those involving AI outputs.

4. Prohibited AI Uses. The following uses are strictly prohibited, regardless of intent. Violations may result in suspension or legal action.

4.1 Illegal, Harmful, or Dangerous Uses. You may NOT use the Services to:

  1. generate content promoting violence, extremism, or harm
  2. produce malware, exploits, or hacking instructions
  3. engage in impersonation, fraud, or identity deception
  4. automate harassment, threats, cyberbullying, or abuse
  5. support terrorism or organized crime

4.2 Disallowed High-Risk or Automated Decision-Making. You may NOT use AI Systems for high-risk decisions that significantly affect individuals’ rights or access to essential services, including:

  1. hiring or employment eligibility
  2. credit scoring, lending, or loan approvals
  3. insurance eligibility or pricing
  4. legal determinations or case outcomes
  5. immigration, benefits, or government services
  6. medical diagnosis or treatment recommendations
  7. biometric identification or surveillance

These uses require written approval from: complinace@ugenticai.com

4.3 Disallowed Content Generation. You may NOT use AI Systems to generate:

  1. misinformation or disinformation
  2. deepfakes without explicit consent
  3. synthetic voices or likenesses of real individuals without permission
  4. explicit content involving minors
  5. hateful, extremist, or violent content
  6. political persuasion targeted at specific individuals or groups

4.4 Unauthorized Training or Data Extraction. You may NOT:

  1. use UgenticAI outputs to train competing AI models
  2. attempt to reverse-engineer, extract, or clone UgenticAI models
  3. scrape or harvest large volumes of outputs
  4. analyze model vulnerabilities

This includes prompt-mining, fine-tuning attempts, or model-distillation attacks.

5. Restricted Use Cases (Require Written Approval). The following uses require advance written authorization:

  1. biometric analysis (facial, voice, gait)
  2. medical or health-related AI assistance
  3. financial forecasting or investment advisory models
  4. cryptocurrency, trading, or market-manipulation models
  5. law enforcement or intelligence applications
  6. political campaign uses
  7. autonomous decision-making affecting employment or finances

6. Data Handling Requirements

6.1 User Data Rights

Users must ensure:

  1. they have the legal right to upload any data
  2. data from Connected Accounts (LinkedIn, Meta, Google, etc.) is used in compliance with those platforms’ terms
  3. no unlawful personal data is submitted

6.2 Sensitive Data. Unless permitted in writing, you may NOT submit:

  1. medical or genetic data
  2. biometric data
  3. children’s data
  4. financial account numbers
  5. government ID numbers
  6. criminal history

6.3 Social Media & Connected Accounts. Users connecting social media platforms must:

  1. comply with the platform’s API and data policies
  2. not export user data in ways that violate platform restrictions
  3. not use AI to recreate or approximate personal data of social media users

7. AI Transparency Requirements. Where required by law, users must disclose:

  1. when content is AI-generated
  2. when individuals are interacting with AI rather than a human
  3. when AI outputs are used in automated workflows
  4. when AI materially influences decisions affecting others
    This includes disclosure for marketing, recruitment, or financial applications.

8. Human Oversight Requirements. AI should augment, not replace, human judgment. Users must perform human review when:

  1. decisions carry material consequences
  2. safety or accuracy is critical
  3. outputs affect financial, legal, or regulatory matters
  4. personal data is involved
  5. information is sent to external parties

9. Evaluation & Testing of AI Systems. Users must NOT:

  1. stress test or load test without permission
  2. attempt prompt injection or adversarial attacks
  3. probe model behavior using unsafe methods

For approved research/testing, contact: compliance@ugenticai.com

10. Safety Monitoring & Enforcement. UgenticAI may:

  1. monitor usage for abuse
  2. suspend or terminate accounts violating this policy
  3. block queries or outputs that indicate unsafe use
  4. report illegal activities to authorities
  5. update the AI safety filters and behavior

11. Feedback & Reporting Harmful Outputs. If you encounter harmful, biased, unsafe, or incorrect AI outputs, report them to: complaince@ugenticai.com

Include:

  1. specific prompt(s) used
  2. screenshots or logs
  3. explanation of the issue

This enables us to improve system safety.

12. Updates to This Policy. We may revise this Policy at any time.  The “Last Updated” date reflects the most recent version.

C. KYC / AML / ATF COMPLIANCE POLICY

This KYC/AML/ATF Compliance Policy (“Policy”) establishes the guidelines, responsibilities, and procedures adopted by UgenticAI, Inc. and all subsidiaries, affiliates, related entities, partners, and business units (“UgenticAI,” “we,” “our,” “us”) to prevent and detect:

  1. money laundering (“ML”)
  2. terrorist financing (“TF” or “ATF”)
  3. fraud
  4. sanctions violations
  5. other illicit financial activities

This Policy applies to:

  1. all UgenticAI employees, contractors, and officers
  2. all UgenticAI products that involve identity, payments, wallets, funds movement, investment onboarding, or sensitive credential verification
  3. all enterprise and partner integrations handling financial or identity verification tasks
  4. certain AI tools that generate, analyze, or process identity-related data

1. Purpose of the Policy

UgenticAI maintains a comprehensive anti–money laundering, counter–terrorist financing (AML/CTF or AML/ATF), and customer due diligence (CDD) program designed to:

  1. comply with applicable laws and global standards
  2. prevent the misuse of UgenticAI products for illicit purposes
  3. ensure safe onboarding of customers and investors
  4. maintain trust and transparency
  5. support regulatory investigations and audits when required

2. Regulatory Framework. This Policy is designed to meet or exceed the following requirements, where applicable:

United States

  1. Bank Secrecy Act (BSA)
  2. USA PATRIOT Act
  3. FinCEN AML Rule
  4. FinCEN Customer Identification Program (CIP) guidance
  5. OFAC sanctions requirements
  6. SEC Regulation Crowdfunding (Reg CF)
  7. SEC Regulation D (Reg D)
  8. State money transmitter rules (if applicable)

International

  1. FATF 40 Recommendations
  2. EU Anti-Money Laundering Directives (AMLD)
  3. UK Money Laundering Regulations
  4. UN sanctions lists

Platform/Partner Requirements

  1. Identity verification vendors
  2. Payments partners (Stripe, Plaid, etc.)
  3. Brokerage/ATS/Crowdfunding intermediaries

3. Risk-Based Approach. UgenticAI uses a risk-based approach (RBA) by:

  1. assessing risks during initial customer onboarding
  2. adjusting verification level based on jurisdiction, transaction type, and product
  3. applying enhanced due diligence (EDD) where appropriate
  4. conducting periodic reviews

4. Customer Identification Program (CIP). For products where identity verification is required, UgenticAI (or an approved KYC partner) will collect and verify:

4.1 Required Identification Data

  1. Full legal name
  2. Date of birth
  3. Physical residential address
  4. Government-issued photo ID
  5. Tax identification number (if required)
  6. Email address and phone number
  7. Social security number (U.S., if applicable)

4.2 Verification Methods. We use one or more of the following:

  1. government ID verification
  2. biometric matching (where allowed by law)
  3. database checks
  4. sanctions and PEP screening
  5. address and document authentication
  6. liveness checks
  7. multi-factor authentication

4.3 Business Accounts. For business customers, we may require:

  1. legal business name
  2. EIN or business tax ID
  3. beneficial ownership information (BOI) meeting FinCEN CDD Rule requirements
  4. corporate documentation
  5. authorized signatory verification

5. Customer Due Diligence (CDD). CDD includes:

  1. assessing customer risk levels
  2. validating identity
  3. understanding the nature of the customer’s activities
  4. monitoring usage patterns
  5. identifying high-risk categories

6. Enhanced Due Diligence (EDD). EDD is required for customers or entities exhibiting higher risk characteristics, including:

  1. Politically Exposed Persons (“PEPs”) or close associates
  2. high-risk jurisdictions (FATF-listed)
  3. unusual funding activity
  4. unclear or unverifiable identity data
  5. mismatches between customer activity and expected behavior

EDD measures may include:

  1. additional documentation
  2. source-of-funds verification
  3. manual review
  4. identity video call verification
  5. approval from UgenticAI’s Compliance Officer

7. Sanctions & Watchlist Screening. UgenticAI screens customers, transactions, and relevant data against:

  1. OFAC SDN List
  2. OFAC Non-SDN Lists
  3. United Nations sanctions lists
  4. EU/UK consolidated sanctions
  5. PEP databases
  6. Law enforcement and adverse media databases

Matches or potential matches trigger immediate review and possible account restrictions.

8. Transaction Monitoring. Where applicable, UgenticAI monitors customer activity for:

  1. unusual transaction patterns
  2. rapid in/out movement (“smurfing,” layering)
  3. high-frequency or high-value transactions inconsistent with profile
  4. attempts to circumvent limits or verification
  5. use of anonymizing tools (TOR, mixers, VPN services where relevant)
  6. suspicious AI-assisted activity
  7. indicators of fraud or identity theft

9. Suspicious Activity Reporting (SARs). UgenticAI will file Suspicious Activity Reports (SARs) or equivalent filings where required by law. Triggers for SAR consideration include:

  1. suspected money laundering
  2. structuring
  3. sanctions evasion
  4. terrorist financing
  5. fraud
  6. identity theft
  7. use of stolen credentials
  8. illegal or harmful activities

SAR information is confidential and will not be disclosed to the customer.

10. Recordkeeping. UgenticAI retains records consistent with legal requirements, including:

  1. identity verification documentation
  2. transactional history
  3. screening results
  4. EDD findings
  5. SAR filings (if applicable)
  6. audit logs and compliance notes

Retention periods typically range from 5 to 7 years, depending on jurisdiction.

11. AI and Automated System Monitoring. UgenticAI may use AI-driven systems to:

  1. detect fraudulent behavior
  2. identify anomalous patterns
  3. enhance sanctions screening
  4. flag suspicious account activity
  5. prevent abuse of UgenticAI AI systems

All automated flags involving high-risk activity undergo human review.

12. Training & Employee Responsibilities. All employees involved in:

  1. onboarding
  2. identity verification
  3. customer service
  4. product development
  5. financial systems
  6. compliance

receive mandatory AML/ATF training annually or as regulations change.

13. Policy Enforcement. UgenticAI may:

  1. freeze or suspend accounts
  2. request additional documentation
  3. restrict platform access
  4. disable or limit certain features
  5. terminate accounts
  6. report suspicious activity to authorities
  7. block or close transactions

Non-compliant behavior will not be tolerated.

14. Independent Testing & Audits. UgenticAI conducts:

  1. periodic internal compliance reviews
  2. third-party audits (if required)
  3. testing of KYC/AML controls

reviews aligned with regulatory expectations (e.g., FinCEN, SEC)

D. RESPONSIBLE DISCLOSURE & VULNERABILITY DISCLOSURE POLICY

UgenticAI, Inc. (“UgenticAI,” “we,” “our,” “us”), including all subsidiaries, affiliates, business units, and partners, is committed to maintaining the security and integrity of our systems, Services, data, and users. We value and support the cybersecurity community’s efforts to help protect our ecosystem. This Responsible Disclosure & Vulnerability Disclosure Policy (“Policy”) outlines how researchers can report security vulnerabilities to us safely, legally, and in good faith.
1. Purpose of This Policy. This Policy aims to:

  1. provide clear guidelines for reporting potential vulnerabilities
  2. authorize good-faith security research within defined boundaries
  3. minimize risk to users, systems, and data
  4. allow UgenticAI to triage, verify, and resolve issues efficiently
  5. establish safe harbor for ethical security researchers

2. Scope of This Policy. This Policy applies to all:

  1. UgenticAI websites, applications, APIs, and platforms
  2. cloud-based Services
  3. AI platforms and models
  4. authenticated and unauthenticated interfaces
  5. dashboards, investor portals, compliance tools, and integrations
  6. systems owned or operated by UgenticAI or its subsidiaries

Out-of-Scope:

  1. third-party services not controlled by UgenticAI
  2. user-installed third-party extensions or integrations
  3. social media accounts

If you are unsure whether a system is in scope, contact us prior to testing.
3. Safe Harbor Commitment. UgenticAI commits that:

  1. we will not initiate or support legal action against researchers acting in good faith and in compliance with this Policy
  2. we will consider your actions “authorized” under applicable laws, including the Computer Fraud and Abuse Act (CFAA) and applicable anti-hacking laws
  3. we waive any DMCA or anti-circumvention claims for research performed under this Policy

To qualify for safe harbor, researchers must:

  1. follow all rules in this Policy
  2. avoid harming UgenticAI systems or users
  3. report the vulnerability promptly
  4. maintain strict confidentiality until UgenticAI resolves it

4. Reporting a Vulnerability. If you believe you have discovered a security vulnerability, report it to: compliance@ugenticai.com .
Include:

  1. Description of the vulnerability
  2. Steps to reproduce (proof of concept preferred)
  3. Impact assessment
  4. Affected URLs, endpoints, or systems
  5. Any screenshots, logs, videos, or evidence
  6. Your contact information for follow-up

UgenticAI will acknowledge receipt within 72 hours.
5. What You May Do (Authorized Activities). Researchers may:

  1. conduct good-faith testing to detect security flaws
  2. investigate application behavior within reasonable limits
  3. examine publicly accessible resources
  4. test non-destructive exploitation to confirm findings
  5. create proof-of-concept code that does not cause harm
  6. scan and interact with test accounts created by researchers

Provided that such activities do not:

  1. degrade service
  2. impact real users
  3. access private or proprietary data
  4. involve destructive actions

6. What You Must NOT Do. Under no circumstances may you:

6.1 Access or Modify Data You Do Not Own

  1. no accessing other users’ data
  2. no exfiltrating data
  3. no copying personal information
  4. no modifying or deleting data

6.2 Cause Service Disruption

  1. no DDoS/DOS
  2. no flooding, brute force, or excessive automated requests
  3. no intentionally overloading servers

6.3 Exploit Beyond What Is Needed. Do not:

  1. pivot or move laterally through internal systems
  2. establish backdoors
  3. use found vulnerabilities for personal gain
  4. perform social engineering on employees or users
  5. test physical security (doors, devices, data centers)

6.4 Use Tools Intended for Harm. Examples include:

  1. ransomware
  2. malware
  3. credential stuffing tools
  4. password cracking at scale
  5. automated scanning that resembles attack traffic

7. Coordinated Disclosure Process. UgenticAI follows a structured review and remediation process:

Step 1 — Acknowledgement. Within 72 hours, we confirm receipt.

Step 2 — Evaluation. Within 7 days, we:

  1. validate the issue
  2. assign a severity rating
  3. determine mitigation steps

Step 3 — Remediation. We work to resolve validated vulnerabilities promptly based on severity:

  1. Critical: 7–14 days
  2. High: 14–30 days
  3. Medium: 30–60 days
  4. Low: 60–90 days

Step 4 — Researcher Confirmation. We may ask you to re-test fixes (optional).

Step 5 — Public Disclosure (Optional). Once resolved:

  1. We may publicly thank the researcher (if desired).
  2. Disclosure timing will be mutually agreed upon.

We request 90 days’ confidentiality from initial report.

8. Recognition & Acknowledgment. UgenticAI may recognize researchers who follow this Policy through:

  1. optional public acknowledgment
  2. optional “Hall of Thanks” page
  3. eligibility for swag or internal recognition programs

Note: This Policy does not currently include a paid bug bounty, but UgenticAI may introduce one later.

9. Compliance With Applicable Laws. Researchers must comply with:

  1. all national and international cybersecurity laws
  2. U.S. federal and state laws
  3. GDPR/UK-GDPR (if applicable)
  4. export control and sanctions restrictions

Good-faith, Policy-compliant research is deemed authorized by UgenticAI.

10. Changes to This Policy. We may update this Policy periodically. The “Last Updated” date reflects the most recent version.

E. SECURITY POLICY

This Security Policy (“Policy”) describes the security controls, standards, and practices implemented by UgenticAI, Inc., including all subsidiaries, affiliates, partners, business units, and related entities (collectively, “UgenticAI,” “we,” “our,” “us”). This Policy demonstrates UgenticAI’s commitment to safeguarding:

  1. customer data
  2. confidential information
  3. AI-related data and model integrity
  4. platform reliability and resilience
  5. compliance with global regulatory obligations

1. Security Principles. UgenticAI follows six foundational principles:

  1. Confidentiality — protecting data from unauthorized access
  2. Integrity — ensuring systems and data remain accurate and unaltered
  3. Availability — maintaining resilient, highly available services
  4. Least Privilege — restricting access to what is strictly required
  5. Defense in Depth — layering protections at every point of risk
  6. Privacy by Design — embedding privacy and data minimization into operations

2. Governance & Framework Alignment. UgenticAI maintains an information security program aligned with:

  1. SOC 2 Type II Trust Services Criteria
  2. ISO/IEC 27001:2022 controls
  3. NIST Cybersecurity Framework (CSF)
  4. OWASP best practices
  5. GDPR/UK-GDPR technical and organizational measures (TOMs)
  6. CCPA/CPRA security requirements
  7. EU AI Act safety and governance principles

A designated Security Officer and Data Protection Officer (DPO) oversee the program.

3. Infrastructure & Network Security

3.1 Cloud Infrastructure. UgenticAI uses secure, industry-leading cloud providers (e.g., AWS, GCP, Azure). Providers meet or exceed:

  1. SOC 1/2/3
  2. ISO 27001
  3. PCI DSS
  4. FedRAMP (where applicable)

3.2 Network Segmentation. We implement:

  1. virtual private clouds (VPCs)
  2. subnet segmentation
  3. security groups and firewall rules
  4. zero-trust–aligned access boundaries

3.3 DDoS Protection. Traffic is protected via:

  1. cloud DDoS mitigation services
  2. rate limiting
  3. intelligent traffic filtering

4. Application Security

4.1 Secure Development Lifecycle (SDLC). UgenticAI applies a secure SDLC including:

  1. threat modeling
  2. code reviews
  3. automated static analysis (SAST)
  4. dependency vulnerability scanning
  5. secrets scanning

4.2 Penetration Testing. Annual or more frequent independent penetration testing includes:

  1. black-box testing
  2. authenticated testing
  3. API-specific testing
  4. AI-specific prompt injection and model security tests

4.3 Vulnerability Management. We scan for vulnerabilities on a continuous basis and remediate based on severity-level SLAs:

  1. Critical: 7–14 days
  2. High: 14–30 days
  3. Medium: 30–60 days
  4. Low: 60–90 days

5. Data Security

5.1 Encryption

  1. In Transit: TLS 1.2+
  2. At Rest: AES-256 or equivalent
  3. Key Management: Cloud-native KMS with restricted privileges

5.2 Data Segregation

Customer data is logically separated via:

  1. tenant identifiers
  2. access control boundaries
  3. isolated data stores for sensitive workloads

5.3 Data Minimization. We only collect data required for Services. Customer data is not used to train models unless explicitly permitted or covered under a DPA.

5.4 Backup & Disaster Recovery

Backups occur regularly and are:

  1. encrypted
  2. stored in geographically redundant regions
  3. tested for restoration
  4. part of a documented DR plan

6. Access Control & Identity Management

6.1 Authentication

  1. Multi-factor authentication (MFA) for all admin access
  2. SSO (OAuth/SAML) where available
  3. Strong password requirements
  4. Session expiration and device verification

6.2 Authorization

  1. Role-Based Access Control (RBAC)
  2. Least privilege and need-to-access model
  3. Periodic access reviews

6.3 Administrative Access. Admin privileges are:

  1. tightly restricted
  2. monitored
  3. logged

7. Logging & Monitoring. We maintain comprehensive monitoring across:

  1. authentication events
  2. API usage
  3. system performance
  4. anomaly detection
  5. audit logs
  6. model-level abuse signals

Security logs are retained per legal and operational requirements.

8. AI Model Security & Abuse Prevention. UgenticAI maintains specialized AI security measures:

  1. prompt-injection defense
  2. output filtering & safety constraints
  3. abuse-detection heuristics
  4. monitoring for harmful or malicious queries
  5. rate limiting and anomaly detection
  6. isolation boundaries between model layers

We do not allow:

  1. model extraction
  2. training competing models using outputs
  3. misuse of social-media–derived data
  4. unsafe or disallowed AI use (see AI Use & Safety Policy)

9. Incident Response. UgenticAI maintains a documented Incident Response Plan (IRP) including:

  1. 24/7 monitoring
  2. incident classification (low → critical)
  3. coordinated response teams
  4. forensic investigation procedures
  5. post-incident reviews (PIRs)
  6. communication with affected customers

Breach Notification:

UgenticAI notifies customers without undue delay after confirmation of a data breach involving Customer Data.

10. Third-Party Risk Management. Before onboarding third-party vendors or subprocessors, UgenticAI conducts:

  1. security and privacy assessments
  2. contract and compliance reviews
  3. ongoing monitoring for critical vendors
  4. SOC/ISO report evaluations

The Subprocessor List is available in a separate policy, with notification procedures for updates.

11. Physical Security. UgenticAI leverages cloud providers’ data centers with:

  1. 24/7 security monitoring
  2. badge access control
  3. surveillance
  4. environmental controls (HVAC, fire suppression)
  5. redundant power and network systems

UgenticAI does not operate physical data centers.

12. Employee Security. Employees undergo:

  1. background checks (where legally permitted)
  2. mandatory security training
  3. role-based privacy training for sensitive data
  4. annual testing and phishing simulations

Employees must sign:

  1. confidentiality agreements
  2. acceptable use acknowledgment
  3. data protection and security policies

13. Compliance & Certifications. UgenticAI maintains or is pursuing compliance with:

  1. SOC 2 (Type II) readiness
  2. GDPR controller/processor requirements
  3. CCPA/CPRA
  4. other jurisdictional privacy laws

We provide security documentation to enterprise customers on request.

14. Customer Security Responsibilities. Customers must:

  1. protect their login credentials
  2. maintain endpoint security
  3. configure privacy/security settings appropriately
  4. manage internal user access
  5. not upload data in violation of laws or rights
  6. comply with UgenticAI’s AUP and AI Use & Safety Policy

15. Updates to This Security Policy. We may update this Policy from time to time. The “Last Updated” date reflects the latest version. 

F. SUBPROCESSOR LIST & CHANGE NOTIFICATION POLICY

This Subprocessor List & Change Notification Policy (“Policy”) identifies the subprocessors authorized by UgenticAI, Inc., including its affiliates, subsidiaries, business units, and partners (“UgenticAI”), to process Personal Data on behalf of customers (“Customer”) in connection with UgenticAI Services. This Policy supplements the Data Processing Addendum (DPA) between UgenticAI and Customer.

1. Definition of Subprocessors. A Subprocessor is:A third-party data processor engaged by UgenticAI who, as part of providing services to UgenticAI, processes Customer Personal Data. Subprocessors may include:

  1. hosting providers
  2. cloud infrastructure services
  3. analytics tools
  4. email/SMS service providers
  5. identity verification partners
  6. customer support tools
  7. backup and storage systems
  8. AI infrastructure partners
  9. contractually bound affiliates or subsidiaries

UgenticAI ensures all Subprocessors comply with the same or equivalent data protection obligations as those in the DPA.

2. Current Authorized Subprocessors. The following subprocessors may be engaged depending on the services and region.

(This list includes standard vendor placeholders — we will customize during implementation):

2.1 Infrastructure & Hosting Providers

Subprocessor

Purpose

Location

Data Processed

Amazon Web Services (AWS) Hosting, compute, storage United States / Global Personal data, logs, uploaded content
Google Cloud Platform (GCP) Hosting, compute, storage United States / Global Personal data, logs, uploaded content
Microsoft Azure (if applicable) Cloud hosting & AI infrastructure United States / Global Personal data, logs, metadata

2.2 Analytics, Monitoring & Logging

Subprocessor

Purpose

Datadog Monitoring, logging, performance metrics
Sentry Error tracking and diagnostics
Mixpanel / Amplitude Product analytics
Segment Customer data routing

2.3 Customer Support Tools

Subprocessor

Purpose

Intercom / Zendesk / Freshdesk Customer communication and support
Statuspage Service status & incident notifications

2.4 Payment Processors

Subprocessor

Purpose

Stripe Payment processing & billing
Plaid (if applicable) Bank account & financial verification
PayPal / Braintree Payment processing

2.5 Communications Tools

Subprocessor

Purpose

SendGrid / Postmark / SES Transactional email
Twilio SMS, 2FA, phone verification
Mailchimp / HubSpot Optional marketing email

2.6 Identity Verification & Fraud Prevention (If Applicable)

Subprocessor

Purpose

Jumio / Onfido KYC/AML identity verification
LexisNexis / ComplyAdvantage KYC, sanctions screening
Persona Identity & document verification

2.7 AI & Model Infrastructure Partners

Subprocessor

Purpose

OpenAI (if applicable) AI inference & model execution
Anthropic AI inference
Hugging Face / Replicate Model hosting/inference
Vector database providers (Pinecone, Weaviate, Qdrant) Semantic search embeddings

UgenticAI will NOT use Customer Personal Data to train third-party AI models unless expressly agreed in writing under the DPA.
3. Subprocessor Due Diligence. Before onboarding a Subprocessor, UgenticAI:

  1. evaluates the vendor’s security & privacy posture
  2. reviews SOC 2 / ISO certifications
  3. enters into a binding data processing agreement
  4. verifies appropriate technical and organizational measures (TOMs)
  5. ensures compliance with GDPR, CCPA, and AI safety requirements

UgenticAI remains responsible for Subprocessors’ performance.

4. Subprocessor Change Notifications (GDPR-Compliant). UgenticAI will:

  1. update this Policy when a new Subprocessor is added or an existing one is removed; and
  2. notify Customers of such changes via email or account dashboard.

4.1 Notification Period. Customers will be notified at least 30 days before a new Subprocessor begins processing Customer Personal Data. This allows Customers to object as described below.

5. Customer Right to Object. A Customer may object to a new Subprocessor only if:

  1. The objection is based on reasonable, good-faith, and documented privacy or security concerns; and
  2. The Customer provides a written objection to: compliance@ugenticai.com

UgenticAI will work with the Customer in good faith to:

  1. address concerns, or
  2. propose alternative solutions.

If the parties cannot reach resolution, Customer may:

  1. suspend or terminate affected Services per the DPA;
  2. obtain a prorated refund (if applicable).

6. Emergency Subprocessor Additions. If a new Subprocessor must be added urgently (e.g., security emergency, outage remediation):

  1. UgenticAI may provisionally engage the Subprocessor
  2. Customers will be notified immediately afterward
  3. Customer rights under Section 5 remain intact

7. Subprocessor Responsibilities. All Subprocessors must:

  1. comply with UgenticAI’s DPA
  2. meet security and privacy standards equivalent to UgenticAI’s obligations
  3. process Customer Personal Data solely for purposes required by the Services
  4. maintain confidentiality
  5. cooperate with incident response procedures
  6. notify UgenticAI promptly of any breach affecting Customer Personal Data

8. Cross-Border Transfers. If a Subprocessor processes Customer Personal Data outside the relevant jurisdiction (e.g., EEA, UK, Switzerland), UgenticAI ensures lawful transfer mechanisms such as:

  1. EU Standard Contractual Clauses (SCCs)
  2. UK Addendum
  3. Swiss Transborder Guidelines
  4. Adequacy decisions
  5. Supplementary security measures

9. Updates to This Policy. UgenticAI may update this list and Policy at any time to reflect:

  1. business needs
  2. security improvements
  3. vendor changes
  4. regulatory requirements

The “Last Updated” date reflects the latest version.

Part III: Commerce + Communications + IP Policies 

  1. SMS Terms & Conditions

A. SMS TERMS & CONDITIONS

These SMS Terms & Conditions (“Terms”) govern the use of SMS, MMS, text messaging, and mobile communication programs operated by UgenticAI, Inc., including all subsidiaries, affiliates, business units, and partners (“UgenticAI,” “we,” “us,” “our”). By opting in to receive text messages from UgenticAI, you agree to these Terms.

1. Program Description. UgenticAI may send text messages for purposes including:

  1. account verification (2FA)
  2. product updates & alerts
  3. transactional notifications
  4. customer support communications
  5. appointment reminders
  6. promotional messages (with express consent)
  7. marketing campaigns
  8. AI-generated informational content
  9. onboarding messages
  10. system notifications

Message frequency varies based on your account usage and preferences.

2. Opt-In Requirements. You must provide express consent before receiving SMS messages from UgenticAI. Acceptable opt-in methods include:

  1. signing up through our website or application
  2. checking a consent box during registration
  3. entering your phone number and confirming via OTP
  4. texting a keyword (e.g., “START,” “JOIN”) to our number
  5. written consent during signup or contract execution

You cannot opt in another person.

3. Opt-Out Instructions. You may opt out at any time. To stop receiving messages:

  1. Text STOP to any UgenticAI message
  2. Or email support@ugenticai.com with “SMS Opt-Out”
  3. Or update your account messaging preferences

After opting out:

  1. You may receive a single confirmation message
  2. No further marketing SMS will be sent

Transactional or security-related SMS (e.g., 2FA) may still be required for account protection.

4. Help / Support. For SMS support: support@ugenticai.com. Text HELP to any UgenticAI SMS message. We respond to support requests within standard business hours.

5. Message & Data Rates. Message and data rates may apply, depending on your carrier and plan.

UgenticAI is not responsible for carrier fees, roaming charges, or data costs. Carriers are not liable for delayed or undelivered messages.

6. Supported Carriers. UgenticAI supports major carriers including:

  1. AT&T
  2. Verizon
  3. T-Mobile
  4. Sprint (legacy)
  5. U.S. Cellular
  6. And most Canadian/EU carriers

Carrier support may vary by region and message type.

7. AI-Generated SMS (Important Disclosure). UgenticAI may send AI-generated text messages, including:

  1. summaries
  2. notifications
  3. personalized recommendations
  4. automated support responses

AI-generated SMS:

  1. may contain errors or incomplete information
  2. should not be relied upon for legal, financial, or medical decisions
  3. is provided “as-is” without warranties

Users are responsible for verifying any information provided.

8. Prohibited Uses. You may NOT use UgenticAI SMS programs to:

  1. send unauthorized messages
  2. distribute illegal content
  3. harass or threaten others
  4. impersonate individuals
  5. bypass messaging filters
  6. send bulk solicitations without consent
  7. violate TCPA, CTIA, CASL, or GDPR rules
  8. use numbers harvested through scraping or purchased lists

Violations may result in account suspension or termination.

9. Data Privacy & Security. UgenticAI collects and stores:

  1. phone number
  2. message content
  3. opt-in/opt-out events
  4. delivery confirmations
  5. metadata required for compliance

All processing complies with:

  1. UgenticAI Privacy Policy
  2. GDPR/UK-GDPR
  3. CCPA/CPRA
  4. COPPA (where applicable)
  5. Applicable telecommunications laws

We do not sell your personal information.

10. Consent to Receive Automated Messages. By opting in, you consent to receive:

  1. automated messages
  2. AI-generated messages
  3. autodialed messages
  4. recurring text messages
  5. marketing messages (if explicitly consented)

Consent is not a condition of purchase, unless required for account access (e.g., 2FA).

11. Age Requirements. You must be at least 16 years old to opt in to marketing SMS programs, or the age required by applicable law.. Parents or guardians must supervise usage for minors.

12. Delivery & Reliability. SMS delivery is affected by:

  1. mobile carriers
  2. device compatibility
  3. message blocking/filtering
  4. local regulations
  5. geographic limitations

UgenticAI is not responsible for:

  1. delayed messages
  2. undelivered messages
  3. duplicated messages
  4. technical failures

13. Changes to These Terms. UgenticAI may update these Terms at any time. The “Last Updated” date reflects the most current version. Continued use after changes constitutes acceptance.

Part IV: Operating Buiness Policies 

  1. Accessibility Staement
  2. AI Transparency & Model Explanation Policy
  3. API TErms of Service
  4. Community Guidelines
  5. Content Moderation Policy
  6. Date REtention + Deletion Policy
  7. Ethics + Social Impact Policy

A. ACCESSIBILITY STATEMENT

UgenticAI, Inc., including all subsidiaries, affiliates, and partners (“UgenticAI,” “we,” “our”), is committed to providing digital products, services, and experiences that are accessible, inclusive, and usable for all individuals, including people with disabilities. We strive to ensure that everyone can access and benefit from UgenticAI technology, regardless of ability.

1. Our Commitment to Accessibility. UgenticAI aims to:

  1. conform to Web Content Accessibility Guidelines (WCAG) 2.2 Level AA
  2. provide inclusive design across all products and services
  3. continually enhance accessibility as part of our development lifecycle
  4. remove barriers that prevent equitable access to information and functionality

We believe accessibility is an ongoing commitment, not a one-time project.

2. Accessibility Standards We Follow. UgenticAI adheres to internationally recognized accessibility standards, including:

  1. WCAG 2.2 Level AA
  2. ADA Title III (where applicable)
  3. Section 508 (U.S. federal accessibility law)
  4. EN 301 549 (EU accessibility standard)
  5. Global digital inclusion best practices

Our accessibility strategy integrates:

  1. universal design principles
  2. human-centered design
  3. continuous testing and improvement
  4. integration of assistive technology considerations

3. Accessibility Features in UgenticAI Products. UgenticAI products incorporate a range of accessibility features, including:

3.1 Visual Accessibility

  1. Support for screen readers
  2. High-contrast modes
  3. Adjustable font sizes
  4. Color usage adherence to minimum contrast standards
  5. Avoidance of color-only information cues

3.2 Motor & Physical Accessibility

  1. Keyboard-only navigation
  2. Logical tab order
  3. Sufficient hit area for interactive elements
  4. Clear focus states

3.3 Cognitive Accessibility

  1. Clear language and instructions
  2. Predictable navigation
  3. Consistent layout and labeling
  4. Warning messages before timeouts or major actions

3.4 Hearing Accessibility

  1. Captions for videos (where applicable)
  2. Visual alternatives for sound-based notifications

3.5 Speech Accessibility

  1. No requirements for speech-only input
  2. Multiple input modalities where feasible

3.6 AI Accessibility Support

  1. AI-generated summaries
  2. reading-assistance tools
  3. simplified text when requested

4. Accessibility in Our Development Process. Accessibility is integrated into:

  1. product planning
  2. UX/UI design
  3. code development
  4. internal QA testing
  5. automated accessibility scanning
  6. manual review by trained accessibility testers

We strive to “shift left” accessibility—considering it early and often.

5. Known Limitations. Although we aim for full WCAG 2.2 AA compliance, some parts of the website or platform may not yet meet the standard due to:

  1. third-party integrations
  2. legacy components still being upgraded
  3. dynamic AI-generated content with unpredictable structure

We are actively monitoring, reviewing, and improving these areas.

6. Feedback & Reporting Issues. We welcome user feedback on accessibility and strive to respond quickly. If you encounter barriers, accessibility issues, or need accommodations, contact us at: compliance@ugenticai.com

Please include:

  1. Description of the issue
  2. Device, browser, operating system
  3. URL or location where the issue occurred
  4. Any assistive technology used

We typically respond within 5–10 business days.

7. Reasonable Accommodations. Users may request reasonable accommodations, such as:

  1. alternate formats (PDF, plain text, large print)
  2. verbal explanation of content
  3. assistance with navigation
  4. customized accessibility support

Submit accommodation requests to: compliane@ugetnicai.com

8. Third-Party Content & Integrations. Some areas of UgenticAI’s services may rely on third-party providers whose accessibility we do not control. However, we require partners to:

  1. meet accessibility standards where feasible
  2. fix any confirmed accessibility violations
  3. avoid creating barriers for UgenticAI users

9. Ongoing Improvement. UgenticAI performs periodic:

  1. accessibility audits
  2. automated scans
  3. manual testing
  4. user testing with people with disabilities

We continuously work to:

  1. update our components
  2. fix issues quickly
  3. improve accessibility training internally

10. Compliance & Governance. UgenticAI maintains an internal Accessibility Compliance Program, including:

  1. Accessibility Lead(s) or committee
  2. documented accessibility roadmap
  3. integration with DEI, ethics, and product teams
  4. alignment with legal and regulatory requirements

We incorporate accessibility into procurement, vendor evaluation, and product updates.

11. Updates to This Statement. We may update this Accessibility Statement as standards evolve or improvements are made. The “Last Updated” date reflects the latest version.

B. AI TRANSPARENCY & MODEL EXPLANATION POLICY

This AI Transparency & Model Explanation Policy (“Policy”) describes how UgenticAI, Inc., including subsidiaries, affiliates, and business units (“UgenticAI,” “we,” “our”), provides information about how our artificial intelligence systems (“AI Systems”) operate, generate outputs, make predictions, and support user decision-making. This Policy is designed to comply with:

  1. The EU AI Act (transparency + explainability requirements)
  2. U.S. FTC and CFPB responsible AI expectations
  3. NIST AI RMF (Explainability & Interpretability)
  4. ISO/IEC AI transparency principles
  5. Consumer protection and privacy laws

1. Purpose of This Policy. UgenticAI is committed to:

  1. transparency in how AI systems function
  2. providing meaningful, understandable information to users
  3. enabling informed decision-making
  4. complying with applicable laws
  5. mitigating risks associated with AI-assisted outputs

This Policy explains:

  1. what our AI systems do
  2. how they work at a high level
  3. their limitations and risks
  4. user responsibilities
  5. how to request additional information

2. Overview of UgenticAI AI Systems. AI systems used by UgenticAI include:

  1. large language models (LLMs)
  2. predictive analytics models
  3. recommendation and optimization engines
  4. classification, scoring, or parsing models
  5. natural language processing (NLP) tools
  6. AI-driven workflow automation
  7. embeddings and semantic search systems
  8. multimodal models (text, image, document analysis)

Where applicable, outputs may involve:

  1. generative AI
  2. pattern recognition
  3. statistical inference
  4. algorithmic decision-support

AI Systems assist in decision-making but do not replace human judgment.

3. Intended Use Cases. UgenticAI AI Systems are designed for:

  1. productivity enhancement
  2. workflow automation
  3. content generation
  4. contextual search
  5. document analysis and summarization
  6. business intelligence insights
  7. task routing and optimization
  8. social media integration and analytics (with permission)
  9. predictive and analytical modeling

They are not intended for:

  1. fully autonomous decision-making
  2. biometric identification (without approval)
  3. legal, medical, or financial determinations
  4. high-risk, safety-critical contexts
  5. surveillance or law-enforcement applications

High-risk use cases require written approval from:complaince@ugenticai.com.

4. AI System Transparency. UgenticAI provides high-level descriptions of:

4.1 How the AI Works

  1. Models generate outputs by analyzing patterns in training data
  2. Outputs are probabilistic, not deterministic
  3. Models do not possess consciousness, opinions, or personal beliefs
  4. Models may generate errors, inconsistencies, or missing context

4.2 Data Sources Used to Train Models. UgenticAI may use:

  1. licensed datasets
  2. publicly available information
  3. synthetic data
  4. de-identified internal data (unless otherwise agreed)

We do not use Customer Personal Data to train third-party models.

4.3 Model Behavior. Models may:

  1. generalize from patterns
  2. summarize content
  3. identify trends
  4. perform classification
  5. produce novel content based on context

We disclose:

  1. major limitations
  2. scenarios where outputs may be inaccurate
  3. appropriate use contexts

4.4 Automated Decision-Making. If any feature involves algorithmic scoring or automated decision recommendations, we disclose:

  1. what factors influence the recommendation
  2. whether humans review the result
  3. how users may challenge or override outputs

5. AI Limitations & Known Risks. UgenticAI AI Systems may:

  1. generate inaccurate or outdated information
  2. misinterpret ambiguous queries
  3. reflect biases present in training data
  4. hallucinate or fabricate details
  5. produce non-deterministic outputs
  6. misunderstand sensitive context
  7. respond inconsistently across similar prompts

We strongly encourage:

  1. human oversight
  2. independent verification
  3. cautious reliance in critical contexts

6. User Responsibilities. Users of UgenticAI AI Systems must:

  1. validate outputs before relying on them
  2. ensure compliance with local laws
  3. avoid using AI for disallowed or high-risk purposes
  4. not present AI outputs as professional advice
  5. disclose AI involvement when legally required (e.g., political content, automated messaging)
  6. maintain accurate and lawful inputs

Users remain responsible for any actions taken based on AI outputs.

7. User Notifications & Disclosures. Where required, UgenticAI will notify users when:

  1. content is generated or significantly influenced by AI
  2. they are interacting with an automated system
  3. automated decision-support is used in a workflow
  4. sensitive data is analyzed by an AI system
  5. a feature uses profiling or pattern-based predictions

When interacting with AI, users will see clear indicators such as:

  1. “Generated by UgenticAI”
  2. “AI-assisted output”
  3. “Automated response”

8. Explainability & Interpretability. Depending on the product, UgenticAI provides:

8.1 Explanation Summaries. High-level explanations describing:

  1. how the model generated a result
  2. what data categories were used
  3. which factors influenced the output
  4. potential limitations or uncertainty

8.2 Feature-Level Insights. Where feasible and relevant:

  1. feature importance descriptions
  2. influence scores
  3. rationale summaries

8.3 Error Messages & Warnings. If a model lacks sufficient data or confidence:

  1. users may see confidence-level indicators
  2. disclaimers
  3. uncertainty warnings

8.4 AI Model Cards. For applicable models, UgenticAI provides standardized Model Cards describing:

  1. intended purpose
  2. limitations
  3. risks
  4. safety mitigations
  5. evaluation benchmarks

9. Human Oversight. UgenticAI encourages and, where legally required, mandates human-in-the-loop processes for:

  1. decisions with legal or financial impact
  2. sensitive or high-risk processing
  3. model escalations
  4. exception handling

Users must not use AI outputs as the sole basis for:

  1. employment decisions
  2. creditworthiness assessments
  3. insurance determinations
  4. legal conclusions
  5. healthcare decisions

10. Complaints & Human Review Requests. Users who believe an AI decision or output is:

  1. incorrect
  2. biased
  3. harmful
  4. misleading
  5. incomplete

You may request a human review at: compliance@ugenticai.com

Provide:

  1. description of the content
  2. context of use
  3. reason for concern
  4. any evidence or examples

UgenticAI will respond within 15 business days.

11. Transparency for Third-Party AI Providers. When UgenticAI uses third-party models or infrastructure (e.g., OpenAI, Anthropic, AWS):

  1. we disclose the use of such models where relevant
  2. we ensure subprocessors comply with the same privacy and security standards
  3. we do not allow third-party AI services to use Customer Personal Data for training without explicit agreement

12. Updates to This Policy. We may update this Policy periodically to:

  1. comply with legal changes
  2. reflect model updates
  3. improve transparency
  4. enhance user understanding

The “Last Updated” date reflects the latest version.

C. API TERMS OF SERVICE

These API Terms of Service (“API Terms”) govern access to and use of application programming interfaces (“APIs”) provided by UgenticAI, Inc., including all subsidiaries, affiliates, business units, and partners (“UgenticAI,” “we,” “our,” or “us”). By accessing or using UgenticAI APIs, you (“Developer,” “you”) agree to be bound by these API Terms, the UgenticAI Terms of Use, Privacy Policy, Acceptable Use Policy, Data Processing Addendum (where applicable), and all applicable laws and regulations.

If you are accessing the API on behalf of an organization, you represent and warrant that you have the authority to bind the organization to these API Terms.

1. Definitions

1.1 API. Any UgenticAI application programming interface, SDK, webhook, developer tool, endpoint, library, or integration service.

1.2 Developer Application. Any software, product, integration, model, script, or service created by you that uses or interacts with the UgenticAI API.

1.3 Customer Data. Data submitted to or processed by the API, including text, inputs, files, metadata, outputs, and system-generated content.

1.4 API Key. A unique credential used to authenticate and authorize API access.

1.5 Output / AI Output. Structured or unstructured content generated by UgenticAI models in response to API inputs.

2. License to Use the API. Subject to these API Terms, UgenticAI grants you a:

  1. revocable
  2. non-exclusive
  3. non-transferable
  4. non-sublicensable
  5. limited license to access and use the UgenticAI API solely to develop compatible applications or integrations.

You may not use the API for any purpose not explicitly authorized by UgenticAI.

3. API Keys & Authentication

3.1 API Key Security. You must:

  1. keep API keys secure and confidential
  2. not embed keys in client-side code
  3. not share keys publicly or with unauthorized users
  4. rotate keys immediately if compromised

3.2 Key Usage. Each API key is exclusive to a single Developer account and application.

3.3 Revocation. UgenticAI may suspend or revoke API keys without notice if:

  1. misuse is detected
  2. suspicious activity occurs
  3. legal or safety concerns arise
  4. violations of these API Terms occur

4. Developer Responsibilities. Developers must:

  1. comply with all applicable laws
  2. adhere to UgenticAI’s Acceptable Use Policy
  3. maintain security and integrity of their applications
  4. disclose AI usage to end users when required
  5. obtain valid consent before collecting personal data
  6. implement rate-limit handling
  7. provide accurate contact information

Developers are fully responsible for:

  1. User onboarding
  2. User support
  3. User data handling
  4. Compliance with privacy regulations

5. Prohibited API Uses. You may not use the API to:

5.1 Illegal or Harmful Activities

  1. conduct fraud
  2. distribute malware
  3. scrape or harvest personal data
  4. engage in unauthorized surveillance
  5. violate export control regulations

5.2 Abuse of AI Models

  1. generate harmful or disallowed content
  2. bypass safety filters
  3. perform prompt injection attacks
  4. reverse-engineer model behavior
  5. create impersonation or deepfake systems without consent

5.3 Misleading or Deceptive Practices

  1. misrepresent AI as human
  2. deceive end users
  3. manipulate public opinion
  4. automate actions that violate third-party policies

5.4 Security Violations

  1. circumvent rate limits
  2. overload infrastructure
  3. attempt unauthorized access
  4. interfere with API functionality

6. Rate Limits & Usage Restrictions. UgenticAI enforces rate limits to maintain system stability. Limits may vary based on:

  1. subscription plan
  2. endpoint
  3. traffic patterns
  4. safety risk
  5. abuse detection

If you exceed limits, UgenticAI may:

  1. throttle requests
  2. return error codes
  3. temporarily block traffic
  4. permanently disable your key

7. Data Handling & Privacy

7.1 Customer Data Protection. Developers must:

  1. process data lawfully and fairly
  2. inform users how AI is being used
  3. delete data upon user request
  4. secure personal data using industry best practices

7.2 API Data Retention. UgenticAI applies retention periods outlined in the:

  1. Data Retention & Deletion Policy
  2. Privacy Policy

7.3 Prohibition on Using Data for Model Training. Unless explicitly agreed in writing:

UgenticAI does not use Customer Personal Data submitted via API to train public or third-party foundation models. Aggregated and anonymized data may be used to:

  1. improve system performance
  2. enhance safety
  3. detect abuse patterns
  4. optimize infrastructure

7.4 Sensitive Data. You must not send:

  1. protected health information (HIPAA)
  2. biometric identifiers
  3. government-issued IDs
  4. children’s data
  5. financial account credentials

unless explicitly permitted under contract.

8. Intellectual Property

8.1 UgenticAI IP. UgenticAI retains all rights to:

  1. APIs
  2. models
  3. documentation
  4. tools
  5. outputs

Developers receive no ownership rights.

8.2 Developer IP. Developers retain ownership of:

  1. their applications
  2. integration logic
  3. original code
  4. non-UgenticAI intellectual property

8.3 Output Rights. Unless stated otherwise in contract:

  1. Developers own the Output generated by the API
  2. Subject only to UgenticAI’s rights to use Output for safety, security, and operational purposes

9. Attribution Requirements. Unless otherwise contractually permitted:

  1. Developers must not imply partnership or endorsement
  2. Public-facing apps must disclose: “Powered by UgenticAI”
  3. UgenticAI logos require written permission

10. Security Requirements. Developers must implement:

  1. HTTPS/TLS encryption
  2. secure key storage
  3. access controls
  4. logging and monitoring
  5. protection against injection and replay attacks
  6. secure error handling
  7. vulnerability disclosure processes

UgenticAI may require a security audit for high-risk implementations.

11. Monitoring & Enforcement. UgenticAI may monitor:

  1. API requests
  2. usage patterns
  3. abusive behaviors
  4. compliance signals

If violations are detected, we may:

  1. restrict access
  2. enforce stricter rate limits
  3. disable API keys
  4. report illegal behavior to authorities
  5. terminate accounts

12. Modifications to the API. UgenticAI may update, deprecate, or discontinue API features with notice where reasonable. For high-impact changes, we aim to provide:

  1. 30–90 days notice
  2. migration guidance
  3. documentation updates

13. Termination. Either party may terminate access at any time. Upon termination:

  1. all API calls must stop immediately
  2. cached data must be securely deleted
  3. API keys must be removed from all active systems

14. Warranties, Disclaimers & Limitation of Liability. The API is provided “as-is”, without warranties of any kind. UgenticAI is not liable for:

  1. outages
  2. delays
  3. inaccuracies
  4. loss of data
  5. indirect or consequential damages

Developer agrees to indemnify UgenticAI for:

  1. misuse
  2. violations of law
  3. unauthorized data processing
  4. breach of these API Terms

15. Law & Jurisdiction. Except where prohibited:

  1. These API Terms are governed by the laws of Delaware, USA
  2. Disputes must be resolved in Delaware courts
  3. Arbitration provisions in the Terms of Use may apply

16. Changes to These API Terms. We may update these API Terms as needed. The “Last Updated” date reflects the latest version.

D. COMMUNITY GUIDELINES

These Community Guidelines (“Guidelines”) describe the expectations, rules, and standards for interacting on platforms, tools, communities, and services operated by UgenticAI, Inc., including subsidiaries, affiliates, and partners (“UgenticAI,” “we,” “our,” or “us”). Our goal is to maintain safe, respectful environments where users can collaborate, learn, and build using UgenticAI technologies. These Guidelines apply to:

  1. online communities
  2. forums and discussion spaces
  3. AI interactions
  4. comments, posts, and messages
  5. shared content, prompts, and outputs
  6. tickets, submissions, and support communications

By using UgenticAI platforms, you agree to follow these Guidelines.
1. Be Respectful and Professional. We expect all users to behave respectfully toward:

  1. other users
  2. UgenticAI staff and moderators
  3. third parties and partners

Prohibited behaviors include:

  1. harassment, bullying, or personal attacks
  2. hate speech, slurs, or discriminatory content
  3. threats or encouragement of self-harm or violence
  4. targeted harassment or doxxing (“revealing private information”)
  5. overly aggressive, obscene, or hostile behavior

Disagreements are acceptable; disrespect is not.
2. No Illegal, Harmful, or Dangerous Activities. Do not use UgenticAI platforms to:

  1. engage in illegal conduct
  2. promote violence or dangerous behavior
  3. distribute harmful instructions
  4. coordinate criminal activity
  5. facilitate fraud, scams, or deception

We follow all applicable laws and may report illegal activity when required.
3. No Misinformation or Deceptive Content. Content or activity that is misleading or deceptive is prohibited, including:

  1. knowingly false claims
  2. impersonation of individuals or organizations
  3. misrepresenting identity, credentials, or affiliations
  4. spreading misinformation or harmful rumors
  5. generating deceptive deepfakes without consent

Be truthful and transparent in all interactions.
4. Protect Privacy — Yours and Others’. Do not post or share:

  1. personal information (yours or others’)
  2. confidential or proprietary data
  3. financial or sensitive information
  4. passwords, security keys, or credentials
  5. private communications without permission

If you encounter exposed private data, report it immediately.
5. Follow IP & Copyright Rules. You may not post or use content that:

  1. violates copyright, trademarks, or other IP rights
  2. includes unauthorized use of proprietary documents, code, or data
  3. infringes someone else’s work without permission

If you believe content infringes your rights, follow our DMCA Policy.
6. No Spam, Unsolicited Promotion, or Manipulation. We prohibit:

  1. excessive posting, flooding, or disruptive behavior
  2. spam or mass advertising
  3. fake engagement, review manipulation, or referral abuse
  4. scraping community content without permission

Self-promotion must be relevant, honest, and non-disruptive.
7. Use AI Responsibly. When interacting with UgenticAI AI tools, users must:

  1. avoid generating harmful, dangerous, or disallowed content
  2. avoid attempting to bypass safety filters
  3. not use AI outputs for impersonation, harassment, or fraud
  4. recognize that AI-generated content may contain errors

For specific rules, see the AI Use & Safety Policy.
8. No Exploiting Technical Loopholes. Prohibited actions include:

  1. reverse engineering UgenticAI systems
  2. attempting to bypass rate limits, filters, or security
  3. exploiting bugs, vulnerabilities, or logic flaws
  4. using bots to mimic human activity

If you discover a vulnerability, follow our Responsible Disclosure Policy.
9. Respect Moderators & Enforcement Decisions. UgenticAI moderators may:

  1. remove content
  2. issue warnings
  3. restrict privileges
  4. suspend or terminate accounts

Moderator decisions exist to protect the community. Disagreements should be raised respectfully and through proper channels.
10. User-Generated Content Responsibility. Users are solely responsible for:

  1. the content they create
  2. the content they share
  3. the AI-generated outputs they choose to publish
  4. ensuring laws and rights are respected

UgenticAI may remove content at its discretion, with or without notice.
11. Reporting Violations. If you see harmful, unsafe, or inappropriate content, report it to: Compliance@ugenticai.com. Reports are confidential.
12. Consequences for Violations. Depending on severity, consequences may include:

  1. content removal
  2. temporary restrictions
  3. permanent account suspension
  4. API key revocation
  5. reporting to authorities (where required)

Repeated or severe violations may lead to permanent removal from UgenticAI platforms.
13. Updates to These Guidelines. We may update these Guidelines periodically. The “Last Updated” date reflects the current version.

E. CONTENT MODERATION POLICY

This Content Moderation Policy (“Policy”) explains how UgenticAI, Inc., including its subsidiaries, affiliates, and partners (“UgenticAI,” “we,” “us,” or “our”), manages, evaluates, moderates, and enforces rules related to content created, posted, shared, submitted, or generated through UgenticAI platforms (“Content”). This Policy applies to:

  1. user-generated content (UGC)
  2. AI-generated content
  3. posts, messages, comments, and uploads
  4. API-generated outputs
  5. account behaviors and signals
  6. automated workflows or integrations

Our goal is to maintain safe, lawful, transparent, and respectful environments for all users.

1. Moderation Principles. UgenticAI’s content moderation is guided by the following principles:

1.1 Safety First. Protect users from harmful, illegal, or abusive content.

1.2 Transparency. Explain policies, decisions, and enforcement actions clearly.

1.3 Fairness & Non-Discrimination. Ensure moderation decisions do not target individuals based on protected attributes.

1.4 Respect for User Rights. Balance safety with freedom of expression where possible.

1.5 Compliance With Law. Follow global laws, including DMCA, GDPR, DSA, and jurisdiction-specific requirements.

2. What Content We Moderate. We moderate all content that appears on or is transmitted through UgenticAI systems, including:

  1. public posts and comments
  2. private messages (if flagged for abuse or reported)
  3. profile data
  4. images, text, audio, and video
  5. AI-generated outputs
  6. API-generated content
  7. integrated third-party content

Automation and human review are both used.

3. Types of Prohibited Content. Content that violates UgenticAI’s rules includes (but is not limited to):

3.1 Illegal Content

  1. criminal activity
  2. child sexual abuse material (CSAM)
  3. threats or incitement of violence
  4. unlawful discrimination
  5. copyright-infringing content
  6. unauthorized access instructions (hacking, malware)
  7. human trafficking or exploitation

3.2 Harmful or Dangerous Content

  1. self-harm encouragement
  2. violent extremism
  3. dangerous instructions
  4. biological, chemical, or weapons content
  5. doxxing or invasion of privacy
  6. targeted harassment

3.3 Hate Speech. Content attacking a protected group based on:

  1. race
  2. ethnicity
  3. national origin
  4. gender or gender identity
  5. sexual orientation
  6. disability
  7. religion

3.4 Fraud & Deceptive Practices

  1. impersonation
  2. scams
  3. phishing
  4. AI-assisted fraud
  5. manipulated media without disclosure

3.5 Spam & Malicious Behavior

  1. bulk unsolicited messages
  2. link farms
  3. bot manipulation
  4. inauthentic engagement
  5. scraping or data harvesting

3.6 Disallowed AI Content

  1. bypassing AI safety
  2. generating harmful outputs
  3. attempts to extract model internals
  4. prohibited surveillance
  5. high-risk uses without approval

(See the AI Use & Safety Policy for details.)

4. Moderation Methods. UgenticAI uses a combination of:

4.1 Automated Systems. AI classifiers and automated detection tools for:

  1. spam
  2. hate speech
  3. violence
  4. self-harm
  5. identity abuse
  6. prompt-injection attempts
  7. regulatory compliance flags

4.2 Human Reviewers. Trained moderation teams evaluate:

  1. edge cases
  2. appeals
  3. context-sensitive decisions
  4. AI-flagged content requiring verification

4.3 Hybrid Moderation. Most decisions involve at least one automated assessment followed by optional or required human review.

5. User Reporting. Users may report:

  1. harmful content
  2. harassment
  3. impersonation
  4. illegal behavior
  5. safety issues
  6. violations of Community Guidelines

Reports can be submitted to: compliance@ugenticai.com. All reports are reviewed confidentially.

6. Enforcement Actions. Depending on severity and context, UgenticAI may take one or more actions:

  1. Content removal
  2. Content editing or restriction
  3. Warning notices
  4. Feature limits
  5. Temporary suspension
  6. Permanent account termination
  7. API key revocation
  8. IP address blocking
  9. Referral to law enforcement (in severe/legal cases)

UgenticAI reserves the right to enforce policy violations proactively.

7. Notification of Enforcement. Except in rare cases involving:

  1. security threats
  2. imminent harm
  3. legal restrictions

UgenticAI will:

  1. notify users of actions taken against their accounts
  2. provide a general explanation of the violation
  3. explain next steps (appeal, restoration, etc.)

8. Appeals Process. If you believe a moderation decision is incorrect, you may submit an appeal. Submit appeals to: compliance@ugenticai.com.

Include:

  1. explanation of why you believe the decision was incorrect
  2. any supporting evidence
  3. links or screenshots

Appeals are reviewed by a human reviewer, not automated systems. Decisions are typically issued within 7–14 business days.

9. Handling of AI-Generated Content. AI-generated outputs may be moderated for:

  1. harmful content
  2. hallucinations
  3. personal data leakage
  4. copyright issues
  5. policy violations

Users are responsible for any AI outputs they choose to publish externally. If flagged, UgenticAI may:

  1. block the output
  2. present safety warnings
  3. limit access or usage
  4. review for misuse of the AI system

10. Handling of User Privacy in Moderation. UgenticAI respects user privacy and:

  1. limits access to content to authorized moderation staff
  2. restricts review of private messages to flagged or reported cases
  3. minimizes retention of moderated content except for compliance or appeal recordkeeping
  4. follows GDPR, CCPA, and other applicable privacy laws

11. Special Protections for Vulnerable Individuals. UgenticAI prioritizes safety for:

  1. minors
  2. survivors of harassment or abuse
  3. whistleblowers
  4. individuals facing real-world threats

Content involving minors is handled with strict, immediate escalation procedures.

12. Repeat Violations. Users who repeatedly violate policies are subject to:

  1. escalating penalties
  2. long-term restrictions
  3. permanent removal
  4. reporting to external partners or platforms if policies require it

UgenticAI enforces a three-strike escalation for most violations, except severe cases which may result in immediate removal.

13. Transparency Reporting. UgenticAI may publish periodic transparency reports including:

  1. volume of removed content
  2. categories of violations
  3. government or legal requests
  4. appeal outcomes

This supports compliance with the EU Digital Services Act and similar regulations.

14. Updates to This Policy. We may update this Policy periodically. The “Last Updated” date reflects the current version.

F. DATA RETENTION & DELETION POLICY

This Data Retention & Deletion Policy (“Policy”) explains how UgenticAI, Inc., including its subsidiaries, affiliates, and partners (“UgenticAI,” “we,” “us,” or “our”), retains, stores, archives, and deletes information processed through our products, platforms, websites, APIs, and AI Systems (“Services”). This Policy complements and works in conjunction with:

  1. UgenticAI’s Privacy Policy
  2. Data Processing Addendum (DPA)
  3. Security Policy
  4. Subprocessor List
  5. AI Use & Safety Policy

1. Purpose of This Policy. This Policy is designed to:

  1. ensure data is retained only as long as necessary
  2. support compliance with applicable laws and regulations
  3. describe how deletion works for various data types
  4. outline retention periods for operational, legal, and safety purposes
  5. ensure secure, irreversible deletion when data is no longer needed

2. Categories of Data Covered. This Policy applies to:

2.1 Customer Account Data

  1. name, email, phone
  2. authentication credentials
  3. preferences and settings

2.2 Customer Content. Data uploaded, imported, generated, or created by the user, including:

  1. files, documents, text, images
  2. prompts, API inputs, API outputs
  3. embeddings, generated summaries
  4. UGC (user-generated content)

2.3 AI System Data

  1. logs
  2. model interactions
  3. safety flags
  4. metadata associated with usage
  5. anonymized or aggregated analytical data

2.4 Transaction & Billing Data

  1. invoices
  2. payment confirmations
  3. subscription and usage logs

2.5 Compliance & Security Data

  1. KYC/AML/ATF verification data
  2. audit logs
  3. security logs
  4. moderation actions
  5. incident reports

2.6 Communications

  1. support tickets
  2. email correspondence
  3. recorded consent or opt-in confirmations
  4. SMS logs (for consent verification)

3. Retention Principles. UgenticAI follows these core principles:

3.1 Data Minimization. We retain only what is needed for:

  1. account functionality
  2. legal compliance
  3. security
  4. fraud prevention
  5. contractual obligations

3.2 Purpose Limitation. Data is not retained for unrelated or secondary purposes unless legally allowed and explicitly disclosed.

3.3 Storage Limitation. Data is stored for the shortest period necessary to fulfill:

  1. operational needs
  2. billing needs
  3. legal retention requirements
  4. safety and abuse prevention obligations

3.4 Secure Destruction. Once retention periods expire, data is irreversibly deleted using NIST 800-88–aligned methods.

4. Retention Periods. Retention periods vary depending on data type and legal requirements.

4.1 Customer Account Data. Retained while the account is active, and:

  1. deleted or anonymized within 30–90 days after account closure
  2. minimal metadata may be retained for legal compliance (e.g., fraud prevention)

4.2 Customer Content (User Files, Inputs, Outputs). Unless otherwise stated in product features or contracts:

  1. retained only as necessary to provide the Services
  2. deletable by user request or through account controls
  3. fully deleted within 30–90 days after account deletion

UgenticAI does not use Customer Content to train third-party foundation models.

4.3 AI Logs & Interaction Metadata

  1. short-term logs: typically up to 30 days for operational stability
  2. security/audit logs: 12–24 months
  3. anonymized analytics: retained indefinitely (non-identifiable)

4.4 Billing & Financial Records

Required by law for:

  1. 7 years (U.S. IRS)
  2. 6 years (UK/EU financial regulations)

Includes invoices, payments, and refund records.

4.5 KYC/AML/ATF Data

For regulated workflows:

  1. retained for 5–7 years (FinCEN / FATF-aligned)
  2. then securely deleted

4.6 Support & Communications Logs

  1. retained for 12–24 months
  2. used for training staff, fraud prevention, and improving service experience

4.7 Moderation, Safety & Abuse Logs

  1. retained for 1–3 years
  2. duration may extend if needed for legal or safety purposes

4.8 Backup Data

Backups are:

  1. encrypted
  2. retained for 30–90 days depending on backup tier
  3. deleted automatically on rotation

Backups are not used to restore deleted individual user files unless part of full-system recovery.

5. User-Initiated Deletion Requests. Users may request deletion of:

  1. account information
  2. content and files
  3. API logs (where technically possible)
  4. personal data stored in marketing systems
  5. Requests should be submitted to: compliance@ugenticai.com

5.1 Verification. We verify identity to prevent unauthorized deletion.

5.2 Timelines. We process deletion requests typically within:

  1. 30 days (standard)
  2. 45 days (CCPA/CPRA allowed extension)

5.3 Exceptions. We may retain limited data where required by:

  1. law
  2. audits
  3. fraud monitoring
  4. ongoing contract
  5. security investigations

Users will be informed of exceptions.

6. Account Deletion. When a user deletes their account:

  1. The account enters a pending deactivation state (7–14 days).
  2. Customer content is queued for deletion.
  3. Personal data is deleted or anonymized within 30–90 days.
  4. Legal, billing, and compliance data may be retained as required by law.
  5. Backups containing deleted data are purged on their next scheduled rotation.

7. Deletion of AI-Generated Data. AI inputs, outputs, and embedding vectors are deleted when:

  1. the user deletes the source content
  2. the user deletes their account
  3. the retention period expires
  4. the contract or use case requires immediate deletion

AI logs used for safety (e.g., detecting abuse patterns) may be retained for longer under Section 4.7.

8. Data Stored by Subprocessors. UgenticAI requires all subprocessors to:

  1. follow equivalent or stronger retention limits
  2. delete data within agreed timelines
  3. comply with DPA and global privacy laws
  4. maintain secure destruction processes

See our Subprocessor List & Change Notification Policy for details.

9. Data Deletion Methods. We use secure deletion practices aligned with NIST SP 800-88, including:

  1. cryptographic erasure
  2. deletion from active databases
  3. secure overwriting where applicable
  4. removal from caches and temporary storage
  5. deletion from logs where technically feasible

Physical storage destruction is performed by certified partners when required.

10. Special Rules for Regulated Data. Certain data types require extended retention, including:

  1. tax records
  2. financial records
  3. AML documentation
  4. consent logs (e.g., SMS marketing)
  5. legal holds

If a legal hold is placed on data:

  1. deletion is paused until the hold is cleared
  2. users will be notified if permitted by law

11. Children’s Data. UgenticAI does not knowingly store data from children under the legal minimum age per jurisdiction. If discovered:

  1. content is immediately flagged
  2. deleted as soon as feasibly possible
  3. reviewed for legal reporting obligations

12. Changes to This Policy. We may update this Policy periodically to reflect:

  1. changes in regulations
  2. improvements in retention practices
  3. product changes
  4. compliance requirements

The “Last Updated” date reflects the current version.

G. ETHICS & SOCIAL IMPACT POLICY

UgenticAI, Inc., including its subsidiaries, affiliates, partners, and business units (“UgenticAI,” “we,” “our”), is committed to building artificial intelligence technologies that are safe, fair, ethical, sustainable, and beneficial to society. This Ethics & Social Impact Policy (“Policy”) describes the principles, commitments, and governance systems that guide the development, deployment, and use of UgenticAI technologies.

1. Purpose of This Policy. This Policy outlines our commitment to:

  1. human-centered technology
  2. fairness, equity, and non-discrimination
  3. transparency and accountability
  4. sustainable and socially responsible innovation
  5. minimizing harm while maximizing public benefit
  6. ethical practices in AI, data, and automation
  7. responsible corporate citizenship

These commitments apply across all UgenticAI teams, products, and partnerships.

2. Core Ethical Principles. UgenticAI follows internationally recognized AI ethics principles:

2.1 Human-Centric Design. AI should augment human capabilities, not replace or diminish human agency.

2.2 Safety & Non-Maleficence. Systems must be designed to prevent harm, avoid misuse, and include safeguards.

2.3 Fairness & Non-Discrimination. Our AI systems must not:

  1. discriminate based on protected attributes
  2. generate biased or harmful outputs
  3. disproportionately impact vulnerable communities

We actively work to identify, measure, and reduce algorithmic bias.

2.4 Transparency & Explainability. We provide:

  1. clear explanations of how AI systems work
  2. disclosure when AI is used
  3. model limitations and uncertainty indicators

(See our AI Transparency & Model Explanation Policy.)

2.5 Accountability. UgenticAI takes responsibility for:

  1. model behavior
  2. safety mechanisms
  3. content moderation
  4. compliance with global laws

Users must also act responsibly and comply with all policies.

2.6 Privacy & Data Protection. We respect:

  1. user autonomy
  2. user consent
  3. privacy and security requirements
  4. data minimization and purpose limitation

(Aligned with our Privacy Policy and Data Processing Addendum.)

2.7 Security & Resilience. We protect our systems from:

  1. misuse
  2. vulnerabilities
  3. adversarial attacks
  4. exploitation

By implementing robust security controls and governance systems.

3. Ethical Safeguards in AI Development. To ensure ethical outcomes, UgenticAI implements:

3.1 Ethical Review for High-Risk Features. Any feature involving:

  1. personalization
  2. profiling
  3. predictive scoring
  4. high-impact AI decisions
  5. automation affecting individuals
  6. sensitive categories of data

undergoes an internal ethics review by:

  1. Safety team
  2. Legal team
  3. AI Governance Committee

3.2 Dataset Governance. We use data that is:

  1. ethically sourced
  2. licensed or permissioned
  3. de-identified where appropriate
  4. free of unauthorized personal data
  5. regularly audited for bias and representational imbalance

3.3 Model Evaluation & Testing. We perform:

  1. safety evaluations
  2. bias testing
  3. red-teaming
  4. adversarial testing
  5. fairness audits
  6. scenario testing
  7. model performance analysis

3.4 Human-in-the-Loop Controls. Where appropriate, human oversight is required for:

  1. sensitive predictions
  2. high-risk workflows
  3. AI-supported decision-making
  4. complex, ambiguous, or high-impact decisions

4. Social Impact Commitments
4.1 Positive Societal Benefit. We design products to:

  1. increase productivity
  2. democratize access to advanced technology
  3. support education and innovation
  4. empower responsible automation

4.2 Minimizing Harm. We actively mitigate risks related to:

  1. misinformation
  2. manipulation
  3. deepfakes
  4. structural bias
  5. overreliance on automated systems
  6. unsafe content generation

4.3 Responsible Integrations. For integrations such as social media, CRM, or business intelligence tools, we ensure:

  1. transparent data sourcing
  2. user control over permissions
  3. respect for platform terms and API rules
  4. clear opt-outs

4.4 Accessibility & Inclusive Design. We create technology that is inclusive of people with:

  1. disabilities
  2. language barriers
  3. different technical skill levels

(Aligned with our Accessibility Statement.)

5. Environmental & Sustainability Considerations

UgenticAI works to reduce environmental impact by:

  1. using energy-efficient compute infrastructure
  2. selecting cloud providers with renewable energy commitments
  3. optimizing model training and inference for efficiency
  4. minimizing unnecessary data storage
  5. reducing redundant compute cycles

We commit to annual sustainability evaluation and improvement cycles.

6. Ethical Use by Customers. UgenticAI customers must:

  1. avoid harmful or unethical use of AI
  2. comply with our Acceptable Use Policy
  3. respect privacy, consent, and data protection laws
  4. not use AI to deceive, manipulate, or impersonate
  5. disclose AI involvement when required
  6. ensure human oversight for impactful decisions

Violations may result in:

  1. account suspension
  2. feature limitations
  3. full platform access termination

7. Governance Structure. UgenticAI maintains an internal AI Ethics & Governance Committee responsible for:

  1. setting ethical standards
  2. evaluating high-risk features
  3. overseeing safety audits
  4. advising on sensitive use cases
  5. implementing mitigation strategies
  6. ensuring compliance with the EU AI Act and global regulations

The committee includes representatives from:

  1. Legal
  2. Compliance
  3. Engineering
  4. AI Safety
  5. Product Management
  6. Ethics & Social Responsibility

8. Whistleblowing & Reporting Ethical Concerns. Anyone (employee, contractor, partner, or customer) may report:

  1. unethical behavior
  2. harmful AI outcomes
  3. misuse of data
  4. bias concerns
  5. safety issues
  6. potential rights violations

Reports may be submitted confidentially to: Complaince@ugenticai.com. UgenticAI prohibits retaliation against individuals who make good-faith reports.

9. Accountability & Enforcement. Violations of this Policy may result in:

  1. internal disciplinary actions
  2. removal of platform access
  3. product limitations
  4. contract termination
  5. legal action, if required

UgenticAI reserves the right to take appropriate measures to ensure compliance.

10. Updates to This Policy. UgenticAI may update this Policy periodically to reflect:

  1. regulatory changes
  2. technological developments
  3. safety improvements
  4. ethical advancements

The “Last Updated” date reflects the current version.

© 2026 Complily, All Rights Reserved | Privacy Policy | Terms Of Use | Earnings Disclaimer | Cancellation and Refund Policy | DMCA Policy | Anti Spam Policy | Web Policy