Home / Compliance & Governance – TAOM.AI

Compliance & Governance – TAOM.AI

Scope: TAOM.AI and the TAOM Process Studio, operated by TRANIVA AG, Zimbergstrasse 11, 8335 Hittnau, Switzerland. This policy applies to everyone using the platform and to everyone involved in its operation and development.

1 · Purpose

This policy sets out the principles under which TAOM.AI is operated: how data is handled, how the use of artificial intelligence is governed, which security measures apply and how traceability is established. It supplements the Terms and Conditions and the Privacy Policy. In the event of conflict, mandatory statutory provisions and expressly agreed contractual terms take precedence.

2 · Responsibilities

Overall responsibility for the operation, security and compliance of TAOM.AI lies with the management of TRANIVA AG. Named contact points exist for data protection questions, data subject requests and security incidents; the contact details are given in section 11.

3 · Legal framework

TAOM.AI follows the applicable law, in particular the Swiss Federal Act on Data Protection (revFADP) including its ordinances and – where relevant – the General Data Protection Regulation (GDPR), including the rules on international data transfers. The requirements of the EU AI Act are taken into account as well, in particular regarding transparency and the labelling of AI-generated content.

No formal certification is claimed. Operation and development are guided by recognised standards, in particular ISO/IEC 27001 and 27701 for information security and privacy management.

4 · Responsible use of artificial intelligence

The TAOM Process Studio creates process models and documentation with the help of artificial intelligence. Three principles govern that use:

  • The human decides. Generated models are drafts. They are reviewed in the editor, adjusted and expressly approved. If the agent finds a description ambiguous it asks a question instead of making an assumption; question and answer are kept in the history.
  • Provenance is visible. Every generated diagram carries a provenance seal inside the file itself: origin, tool, version, timestamp, editing status, an indication of AI generation and the licence status. If a value is missing this is stated explicitly rather than passed over in silence.
  • Responsibility stays with the user. Content is reviewed by the responsible people before any external use. Agent output is not adopted unchecked.

5 · Acceptable use

The platform may be used for lawful purposes only. The following are prohibited in particular:

  • processing unlawful content,
  • infringing the copyright or trade secrets of third parties,
  • processing personal data without an appropriate legal basis,
  • creating discriminatory or harmful content,
  • abusive use of automated functions,
  • attempting to circumvent security mechanisms or access restrictions.

In the event of violations, TRANIVA AG reserves the right to refuse or delete content and to restrict access temporarily or permanently.

6 · Data protection

Depending on the constellation, TRANIVA AG acts as controller or as processor. Roles, purposes, recipients, retention periods and protective measures are laid down contractually.

The principles of data minimisation and purpose limitation, accuracy, confidentiality, integrity and availability, storage limitation as well as data protection by design and by default apply.

Data subjects have – depending on the applicable law – the right to information, rectification, erasure, restriction of processing, data portability and objection. Requests are handled and documented within the applicable deadlines.

International data transfers only take place where an adequate level of protection is ensured, in particular through adequacy decisions or standard contractual clauses together with supplementary technical and organisational measures.

7 · User content

Uploaded files, entered descriptions, generated models and attached documents remain within the responsibility of the user. They are stored in separate workspaces assigned to the respective access; there is no access to other people’s workspaces.

For input transmitted to the language models, the contractual assurances of the respective providers apply, in particular regarding the use of input data for training purposes. Sensitive personal data must not be entered unless an express legal basis exists.

AI data retention – configurable in Enterprise

TAOM distinguishes between the standard configuration and individually agreed Enterprise configurations.

In Enterprise, requirements regarding model provider, hosting, processing region and data retention can be laid down contractually. Where technically available and enabled by the respective service provider, this may also include a zero data retention configuration.

Such properties are not claimed across the board. They apply only to the specific customer configuration that has been examined and documented.

What zero data retention means →

8 · Retention and deletion

Workspaces are kept only as long as required for the purpose or by law. Shorter periods apply to demonstration access than to licensed access; the applicable period is stored in the metadata of the workspace and is therefore traceable. Licensed content is not deleted automatically.

9 · Information security

Operation is guided by ISO/IEC 27001 and 27701. The central elements are:

  • access following the principles of least privilege and need-to-know, with separate workspaces per access,
  • encryption in transit and at rest wherever technically possible,
  • logging of security-relevant events including rejected access attempts,
  • regular risk assessment and documented measures,
  • a defined reporting and escalation path for security and data protection incidents, including notification duties towards customers and authorities.

10 · Intellectual property

The rights to the content provided and to the models generated remain with the users or their clients. Trademarks, method designations and software of TAOM.AI and TRANIVA are protected and may only be used within the scope of the contractual agreements. Further details are governed by the Terms and Conditions.

11 · Reporting and contact

Indications of possible violations, security concerns and data protection requests can be reported confidentially. Whistleblowers are protected against disadvantage; reports are documented and investigated.

  • Compliance enquiries: compliance@traniva.com
  • Data protection enquiries: info@traniva.com or the contacts stated in the Privacy Policy
  • Security concerns (information security, technical incidents): security@traniva.com

TRANIVA AG · Zimbergstrasse 11 · 8335 Hittnau · Switzerland

12 · Review of this policy

This policy is stored under version control and reviewed at least annually, and additionally whenever the legal situation, the platform or the organisation changes materially. Changes are documented in a traceable manner.

13 · Relationship to the other documents

Together with the Terms and Conditions, the Privacy Policy and the Legal Notice, this policy forms the legal and organisational framework of TAOM.AI. In case of doubt, mandatory statutory provisions and expressly agreed contractual terms take precedence.

TAOM

Who besides us processes data

Which services process personal data on our behalf in delivering TAOM – with purpose, data types, location and basis – is published openly in the list of sub-processors. The full picture on data, AI, security and responsibility is in the Trust Center.

View sub-processors →  ·  Open the Trust Center →


Related documents