treXis AI & External Tool Privacy Policy

1. PurposeThis Policy establishes requirements governing the use of external Artificial Intelligence (“AI”) tools and services by treXis personnel. Its purpose is to protect confidential, proprietary, and client-related information from unauthorized disclosure and to ensure alignment with treXis information security and data protection obligations.

2. ScopeThis Policy applies to all employees, contractors, and authorized users (“Users”) of treXis systems and accounts who access or utilize external AI tools, including but not limited to ChatGPT, Claude, Microsoft AI services, and similar platforms, whether through web interfaces, APIs, integrations, or embedded applications.

3. Policy RequirementsUsers shall not enter, upload, transmit, or otherwise disclose sensitive, confidential, or client-related information into external AI tools unless such use is explicitly approved and governed under a controlled and authorized integration.External AI tools shall be treated as third-party systems. Information submitted to such tools may be stored, processed, or used by the provider in accordance with their respective terms and privacy practices. treXis does not control third-party data handling outside of approved enterprise configurations.

4. Prohibited InformationThe following information must not be entered into external AI tools under any circumstances:

  • Client data, including any non-public or production information
  • Personally identifiable information (PII)
  • Credentials, secrets, API keys, tokens, or authentication data
  • Internal system architecture, security controls, or design documentation
  • Financial, contractual, or proprietary business information
  • Any information classified as confidential or restricted

5. Permitted UseExternal AI tools may be used solely for non-sensitive, business-related purposes, including general knowledge queries, non-sensitive code assistance, and content drafting that does not include restricted information.All AI-generated outputs must be reviewed and validated prior to use. AI outputs shall not be treated as authoritative and must not be relied upon without appropriate verification.

6. AI Integration and Data HandlingWhere AI capabilities are integrated into treXis solutions:

  • Only approved providers and configurations may be used
  • Client data shall not be used for model training
  • AI shall not perform autonomous or regulated decision-making
  • Data handling must comply with treXis data protection requirements

treXis does not develop, host, or control third-party AI models or their training processes.

7. User ResponsibilitiesUsers are responsible for:

  • Ensuring that no prohibited information is entered into AI tools
  • Understanding that inputs and outputs may be logged by providers
  • Validating all AI-generated outputs prior to use
  • Reporting any suspected or actual data exposure immediately

Failure to comply with this Policy constitutes a violation of treXis security and data protection requirements.

8. Monitoring and EnforcementUse of AI tools may be monitored where technically feasible. treXis reserves the right to restrict or revoke access to AI tools at its discretion.Violations of this Policy may result in disciplinary action, including termination of access, contractual penalties, or termination of employment or engagement.

9. Policy AlignmentThis Policy operates in conjunction with and reinforces:

  • Information Security Policy
  • Data Protection and Classification Policy
  • Artificial Intelligence Usage Policy

All Users are required to comply with these policies in full.

10. AcknowledgementUse of treXis-managed accounts or systems to access AI tools constitutes acknowledgement of and agreement to comply with this Policy.