AI and Data Use Addendum
How Dataflag uses customer content with AI systems and model providers.
Effective date: August 16, 2026
1. Scope
This AI and Data Use Addendum explains how Dataflag uses Customer Content with AI systems and model providers. It applies to prompts, uploads, files, source documents, extracted text, document chunks, ratings, evidence artifacts, customer-specific reports, and outputs processed through the Service.
2. No Default Training
Dataflag does not use Customer Content to train, fine-tune, improve, or develop AI/ML models by default. This restriction applies to Customer prompts, uploads, files, documents, source text, outputs, ratings, evidence artifacts, reports, and support-provided Customer Content.
3. Opt-In Training Only
Dataflag may use Customer Content for AI/ML training only if Customer gives prior written opt-in authorization through an agreement or admin-controlled setting that clearly identifies:
- the data categories included;
- the model, feature, or system to be trained or improved;
- the purpose and duration of the training authorization;
- any third-party AI/model provider involved;
- whether outputs or derived artifacts are included; and
- how Customer may revoke the authorization.
Silence, account creation, continued use, support requests, or submission of Customer Content does not constitute opt-in training authorization.
4. Third-Party Model Providers
Dataflag may send Customer Content to third-party AI/model providers only to provide the Service. Dataflag contractually prohibits those providers from using Customer Content to train, fine-tune, improve, or develop their models; from selling or reusing Customer Content; and from retaining Customer Content beyond what is necessary to provide the Service and comply with law.
5. Human Review and Support Access
Dataflag does not routinely review Customer Content for model training. Dataflag personnel may access Customer Content only when necessary to provide support requested by Customer, investigate security or abuse issues, operate or debug the Service, comply with law, or enforce the Agreement. Access is limited to authorized personnel with a need to know.
6. Service Improvement Exclusion
Dataflag may use operational telemetry, error information, and aggregate service metrics to maintain and improve reliability, security, and usability. Dataflag will not use Customer Content, prompts, uploads, files, outputs, or re-identifiable derived artifacts for model training, advertising, sale, or commercialization unless Customer has opted in as described above.
7. Public Vendor Materials
This Addendum does not restrict Dataflag from collecting, analyzing, rating, or commercializing Public Vendor Materials that Dataflag obtains independently from public sources, or from using Dataflag Materials and non-customer-specific methodology. Dataflag will not treat Customer's non-public Customer Content as Public Vendor Materials without Customer authorization.
8. Retention of AI Artifacts
Dataflag stores prompts, model responses, extracted clauses, scores, and audit artifacts to provide explainable ratings, support report generation, troubleshoot errors, and maintain evidence integrity. These artifacts are retained according to the Privacy Notice and deleted or exported according to the Agreement and DPA.
9. Changes
Dataflag will provide advance notice of material changes to this Addendum. Dataflag will not begin using Customer Content for AI/ML training by default, or authorize third-party model-provider training on Customer Content, without Customer's affirmative consent.