Security & Compliance
Protecting Your Data and Your Customers’ Data to the Highest Standards
At Cari AI, security is not an add-on—it is a core pillar of our platform. Our infrastructure runs on AWS and is supported by advanced cybersecurity protocols, strict data protection policies, and ISO 27001 and ISO 9001 certifications, helping your organization operate with confidence.
Cloud Security Architecture and Controls
🔐 Robust and Secure Cloud Architecture
Cari AI operates on AWS infrastructure and leverages advanced cloud security capabilities and internationally recognized standards.
Cari AI Certifications
We hold ISO 9001 and ISO 27001 certifications, demonstrating our commitment to service quality and information security management.
🛡️ Business Continuity and Resilience
Our AWS-powered architecture is designed for high availability, resilience, advanced data encryption, and horizontal scalability.
🔒 End-to-End Encryption
Data is protected both at rest and in transit. Cari AI uses AES-256 encryption for databases and logs, while WhatsApp communications leverage Meta’s end-to-end encryption capabilities.
🏢Secure Multi-Tenant Architecture
Multiple organizations can operate securely within the platform while maintaining logical data isolation, independent configurations, reporting, users, and controls.
📊Hardened Databases
Our database infrastructure uses technologies such as Amazon Aurora MySQL, with replication, encryption, isolation, and availability controls.
🔍 Continuous Auditing
Cari AI uses AWS monitoring and auditing capabilities, including CloudWatch, CloudTrail, and SOC reports, alongside regular internal audits.
🤖 Ethical and Transparent Generative AI
Our Generative AI capabilities incorporate controls and human oversight to promote secure, transparent, and responsible AI use.
👥 Secure Authentication
Cari AI supports role-based access control (RBAC) and OTP authentication, with flexible user management and options for customized authentication integrations.
🛡️ Secure Development
Our development practices incorporate security controls and methodologies such as OWASP to reduce vulnerabilities and risks associated with applications and LLM-based solutions.
We Are Committed to Protecting Your Data and Your Customers’ Data
- Global regulatory compliance, including GDPR, HIPAA, Mexico’s LFPDPPP, and Colombia’s Law 1581
- AES-256 and TLS 1.2+ encryption
- Secure multi-tenant architecture and data isolation
Security and governance for generative AI
🔐 Protection Against LLM Attacks
We incorporate guardrails, prompt sanitization, and input/output controls to reduce the risk of prompt injection, jailbreaks, and malicious inputs intended to alter the defined behavior of the AI Agent.
Response Control and Information Exposure
We use content filters, contextual controls, and data protection mechanisms to reduce unwanted responses, bias, information leakage, and exposure of sensitive data.
🛡️ Grounding and Hallucination Reduction
AI Agents can operate within restricted contexts and controlled knowledge sources, limiting the context used by the model and reducing the risk of responses outside the authorized domain.
🔒 Continuous Evaluation and Red Teaming
Cari AI incorporates test suites, prompt and response evaluation, adversarial testing, continuous risk reviews, and Red Teaming to identify vulnerabilities and unwanted changes in model behavior.
Cari AI incorporates security controls specifically designed for solutions based on language models and AI agents. The platform implements guardrails, prompt sanitization, and input/output controls to mitigate risks such as prompt injection, jailbreaks, information exposure, and unintended model behavior.
Content filtering and context control mechanisms limit the information used by AI agents, while the use of grounding and controlled knowledge sources helps reduce responses outside the authorized domain and the risk of hallucinations.
The solution development and evolution lifecycle includes test suites, prompt and response evaluation, risk analysis, adversarial testing, and Red Teaming activities aimed at identifying vulnerabilities specific to LLM-based applications.
These controls are complemented by access management, encryption, and information isolation mechanisms, as well as secure development practices aligned with frameworks such as OWASP for generative AI applications.
Guardrails & Prompt Security
Prompt sanitization, input/output controls, and prompt injection mitigation.
Content & Data Protection
Content filtering, RBAC, data isolation, and sensitive data protection.
Grounding & Hallucination Reduction
Restricted context and controlled knowledge sources to reduce out-of-domain responses.
Red Teaming & Continuous Evaluation
Restricted context and controlled knowledge sources to reduce out-of-domain responses.
Legal & Regulatory Compliance
PERSONAL DATA PROCESSING POLICY
1. Introduction
DEFYTEK SAS / DEFYTEK S.A. de C.V., operating under the registered trade name CARI AI, hereinafter referred to as CARI AI, is legally incorporated in Colombia under Tax ID (NIT) No. 900723497-4 and in Mexico under Federal Taxpayer Registry (RFC) No. DEF200421D84. Its website is https://www.cariai.com, and its email address for personal data matters is datospersonales@cariai.com.
CARI AI will act as the Data Controller and Data Processor responsible for the processing and safeguarding of personal data and hereby states that:
The collection and processing of personal data carried out by CARI AI is performed responsibly and lawfully, in compliance with the rights to privacy, habeas data and personal data protection, in accordance with the policies, procedures and guidelines adopted by CARI AI, as well as with applicable regulations.
CARI AI properly manages the personal data required to provide its services. For this purpose, it has established this policy to ensure that such data is handled appropriately and in accordance with the law. This policy is available to CARI AI’s entire internal and external community.
For the purposes of this Personal Data Processing Policy, and in accordance with the definitions established under Colombian Law 1581 of 2012, the following terms shall have the meanings set forth below:
Authorization: Prior, express and informed consent given by the Data Subject for the Processing of their Personal Data.
Privacy Notice: Verbal or written communication issued by the Data Controller and addressed to the Data Subject regarding the Processing of their Personal Data, through which the Data Subject is informed of the existence of the applicable information Processing policies, how to access them, and the purposes for which their Personal Data will be processed.
Database: An organized collection of Personal Data subject to Processing.
Personal Data: Any information linked or that may be associated with one or more identified or identifiable natural persons.
General Data: Contact information such as full name, address, landline telephone number, mobile telephone number and email address.
Specific Data: Depending on the type of relationship, this may include income level, financial information, borrowing capacity, gross assets, dependents, family composition, hobbies or interests, owned assets, employment information and marital status.
Public Data: Public Data includes, among other information, data relating to an individual’s civil status, profession or occupation, and their status as a merchant or public official.
Sensitive Data: Sensitive Data means Personal Data that affects the privacy of the Data Subject or whose improper use may result in discrimination. This includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, social organizations, human rights organizations or organizations promoting the interests of political parties or safeguarding the rights and guarantees of opposition political parties, as well as health-related data, information concerning sexual life, biometric data and medical records.
Such information will only be collected, incorporated and/or stored with the prior authorization of the Data Subject and when necessary for the performance of the contractual relationship with the Data Subject, provided that applicable law permits access to such information.
Accordingly, access to, circulation and Processing of Sensitive Data will be restricted and limited to the Data Subject’s authorization and the provisions of applicable law.
Data Processor: A natural or legal person, public or private, that independently or jointly with others processes Personal Data on behalf of the Data Controller.
Data Controller: A natural or legal person, public or private, that independently or jointly with others makes decisions regarding a Database and/or the Processing of Personal Data.
Data Subject: The natural person whose Personal Data is subject to Processing.
Processing: Any operation or set of operations performed on Personal Data, including collection, storage, use, circulation or deletion.
Transfer: A Data Transfer occurs when the Data Controller and/or Data Processor sends information or Personal Data to a recipient located inside or outside the country.
Transmission: Processing of Personal Data involving its communication within or outside the territory of the Republic of Colombia for the purpose of carrying out Processing activities.
CARI AI has also assessed the obligations arising from this legislation in the document “CARI AI — Obligations of CARI AI as Data Processor.”
PRIVACY NOTICE
Your Personal Data will be protected in accordance with Colombian Law 1581 on Personal Data Protection and other applicable Colombian regulatory decrees, as well as Mexico’s Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations, under the principles of lawfulness, purpose, fairness, consent, quality, proportionality, information and accountability, together with the appropriate security measures.
The Processing of Personal Data by DEFYTEK SAS and DEFYTEK S.A. DE C.V. requires the free, prior, express and informed consent of the Data Subjects.
Your Personal Data may be used to respond to requests, petitions and requirements submitted by you as a user, as well as to maintain control data, statistics and reports concerning the services provided.
To fulfill the purposes described above, DEFYTEK SAS and DEFYTEK S.A. DE C.V. request only the Personal Data collected through their digital platforms.
The Processing of users’ Personal Data is carried out pursuant to Law 1581 of 2012, as well as Article 3, Sections II, VII, IX, XI and XX, and Articles 26, 27 and 28 of Mexico’s General Law on Protection of Personal Data Held by Obligated Subjects.
For further information, please refer to:
UP-PL-GI-Privacy Notice, Website Terms of Use-v5-5Jan2026
2. Principles
CARI AI shall comprehensively apply the following principles, which constitute the rules for interpreting and applying this Policy, in accordance with Law 1581 of 2012 in Colombia and the Federal Law on Protection of Personal Data Held by Private Parties in Mexico:
- Principle of Legality and Lawfulness: Data Processing is a regulated activity that must comply with applicable law. CARI AI shall process Personal Data lawfully, and the collection of information through deceptive or fraudulent means is prohibited under the Principle of Fairness.
- Principle of Purpose: Processing must serve a legitimate, specific and lawful purpose, which must be disclosed to the Data Subject through the Privacy Notice.
- Principle of Freedom and Consent: Processing may only be carried out with the prior, express and informed consent of the Data Subject.
- Principle of Accuracy or Quality: Information must be truthful, complete, accurate, up to date and verifiable. Appropriate measures shall be adopted to delete or correct inaccurate information.
- Principle of Transparency and Information: Data Subjects are guaranteed the right to obtain clear information at any time regarding the existence and Processing of their Personal Data.
- Principle of Proportionality: CARI AI shall only process Personal Data that is necessary, appropriate and relevant to the purposes for which it was collected.
- Principle of Restricted Access and Circulation: Processing is subject to limitations arising from the nature of the Personal Data. Personal Data may only be processed by authorized individuals or under circumstances permitted by applicable law.
- Principle of Security: The technical, human and administrative measures necessary to safeguard records shall be implemented in order to prevent loss, unauthorized consultation, unauthorized use or fraudulent access.
- Principle of Confidentiality: The confidentiality of information shall be guaranteed even after termination of the relationship associated with the activities involving its Processing.
- Principle of Accountability: CARI AI shall ensure compliance with the principles described above and shall adopt the measures necessary for their implementation. CARI AI shall also be capable of demonstrating such compliance before the relevant supervisory authorities, including the SIC in Colombia and INAI in Mexico.
3. Purpose of Personal Data Processing
CARI AI shall process information provided and previously authorized by users as follows:
General Purposes
For all users, students, employees, collaborators, suppliers and customers, Personal Data will be used to:
- Prospectively identify the needs of CARI AI’s stakeholders in order to innovate in the provision of its services.
- Fulfill obligations arising from existing contractual relationships with its stakeholders.
- Protect visitors, employees and the general community present at CARI AI facilities.
- Provide users registered in our systems, website and/or social media channels with information about new services, news, events, academic opportunities, publications, updates, business innovation, special programs, user education campaigns, commercial events and advertising, provided that such communications are related to the company’s objectives.
- Continuously understand the needs of users registered on our web portals in order to strengthen relationships and promote business innovation.
- Develop corporate social responsibility programs in accordance with the company’s bylaws and internal regulations.
- Allow data provided by employees or collaborators to be shared with other companies for contractual purposes and/or commercial proposals or agreements, unless the Data Subject expressly revokes such authorization.
- Enable efficient communication regarding our services and partnerships.
- Support the ongoing development of CARI AI’s services and products.
- Communicate marketing activities and/or promote CARI AI’s own services or those offered through commercial partnerships.
- Analyze Personal Data in studies related to artificial intelligence.
- Assess satisfaction levels and the quality of services provided.
- Conduct statistical studies and analyze market trends.
- Control and prevent fraud and money laundering.
- Exchange or transmit information pursuant to international agreements or treaties.
- Inform Data Subjects of changes to the Personal Data Processing Policy.
Users and Customers
The information will be used to:
- Perform the company’s core business activities.
- Provide users registered in our systems, website and/or social media channels with information regarding new services, news, events, academic opportunities, publications, updates, business innovation, special programs, user education campaigns, commercial events and advertising, provided that such communications are related to the company’s objectives.
- Continuously understand the needs of users registered on our web portals in order to strengthen relationships and promote business innovation.
- Communicate marketing activities and/or promote CARI AI’s own services or services offered through commercial partnerships.
Contractors and Suppliers
Personal Data will be used to support the performance of service agreements and civil and/or commercial relationships, including monitoring and managing the commercial conduct of contractors and suppliers.
The information may also be used to verify their suitability, periodically exchange information to facilitate their understanding of the services offered by CARI AI, and invite them to participate in activities or commercial campaigns that may be of interest to them.
Information contained in our current or future Databases will be used to enable CARI AI to develop both an objective and subjective understanding of such service providers.
Information will only be transferred and/or transmitted to other entities when necessary to comply with applicable legal requirements, when requested by public or administrative authorities and/or labor supervisory entities acting within their legal authority, or pursuant to a court order.
Corporate email addresses belonging to service providers and/or suppliers may be used to facilitate communication with employees, send relevant internal communications, invite them to participate in corporate activities, and comply with laws applicable to suppliers.
Employees
Information contained in our Databases regarding former employees, current employees and prospective job candidates will be used to enable CARI AI to develop both an objective and subjective understanding of its personnel.
Such information will only be transferred and/or transmitted to other entities when necessary to comply with applicable legal requirements, when requested by public or administrative authorities and/or labor supervisory entities acting within their legal authority, or pursuant to a court order.
Corporate email addresses will be used to facilitate communication between employees and stakeholders, send internal communications and invite employees to participate in corporate activities.
For employees and collaborators, in addition to the purposes described above, their Personal Data may be transmitted to companies requesting employment verification, financial or commercial credit authorization, background or security studies, provided that the source and use of the Personal Data have been previously verified and applicable legal confidentiality requirements are observed.
Personal Data may also be used for internal promotion processes, verification of academic credentials, requests for information from other companies or educational institutions, training activities, direct contact where necessary, and generally for all administrative and financial activities directly related to the role for which the individual is or will be hired.
Personal Data may also be used to provide employee wellness programs and organize corporate activities for employees and their beneficiaries.
3.1 Processing of Sensitive Data
Because Sensitive Data and Personal Data concerning minors require special protection, Data Subjects shall be explicitly informed in advance that they are not required to authorize the Processing of such information.
Sensitive Data may only be processed when:
- The Data Subject has explicitly authorized such Processing, except where authorization is not legally required.
- Processing is necessary to protect the vital interests of the Data Subject and the Data Subject is physically or legally incapable of providing consent.
- Processing concerns information necessary for the recognition, exercise or defense of a legal right in judicial proceedings.
- Processing is carried out for historical, statistical or scientific purposes. In such cases, appropriate measures shall be implemented to remove the identity of the Data Subjects.
The Processing of Personal Data concerning children and adolescents shall be performed in accordance with the parameters described above in this Policy.
3.2 Video Surveillance
The Processing of Personal Data has been defined as “any operation or set of operations performed on Personal Data, including collection, storage, use, circulation or deletion.”
In the case of images of identified or identifiable individuals, activities such as capturing, recording, transmitting, storing, retaining or reproducing images, whether in real time or at a later time, among others, constitute Personal Data Processing and are therefore subject to the General Personal Data Protection Framework.
CARI AI does not collect Personal Data through video surveillance on the basis of legitimate interest.
CARI AI does not maintain physical infrastructure for the performance of its operations and, therefore, does not conduct video surveillance.
3.3 Cases Where Authorization Is Not Required
Authorization from the Data Subject shall not be required when the Processing falls within the legal exceptions applicable in each jurisdiction.
Colombia
In accordance with Article 10 of Law 1581 of 2012, authorization is not required in the following cases:
- Information requested by a public or administrative authority acting within its legal powers or pursuant to a court order.
- Public Data.
- Cases involving a medical or health emergency.
- Processing authorized by law for historical, statistical or scientific purposes.
- Data relating to individuals’ Civil Registry records.
Anyone accessing Personal Data without prior authorization must nevertheless comply with the provisions of applicable law.
Mexico
In accordance with Articles 10 and 37 of the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), consent will not be required for the Processing of Personal Data when:
- Processing is provided for by law.
- The Personal Data is available from publicly accessible sources.
- The Personal Data has undergone a prior dissociation or anonymization process.
- Processing is intended to fulfill obligations arising from a legal relationship between the Data Subject and the Data Controller, such as the performance of a service agreement with CARI AI.
- An emergency exists that could potentially cause harm to an individual or their property.
- Processing is essential for medical care, prevention, diagnosis, provision of healthcare services, medical treatment or management of healthcare services, when the Data Subject is unable to provide consent.
- Processing is ordered by a competent authority.
3.4 Lawful Bases for Processing
Lawful Bases: CARI AI processes Personal Data on the basis of:
- The Data Subject’s prior and express Consent.
- The Performance of a Contract for services with the Data Subject or their employer.
- Compliance with Legal Obligations, including accounting, employment and tax obligations.
- CARI AI’s Legitimate Interest in improving its Artificial Intelligence models through anonymization processes and ensuring network security.
4. Authorization to Exercise Data Subject Rights
The rights of Data Subjects, including Access, Rectification, Cancellation, Objection or deletion, and revocation of authorization, may be exercised by the following individuals, in accordance with Article 20 of Decree 1377 of 2013 in Colombia and Article 28 of Mexico’s Federal Law on Protection of Personal Data Held by Private Parties:
- The Data Subject: The Data Subject must sufficiently verify their identity using the mechanisms made available by the Data Controller, CARI AI.
- Successors in Interest in Colombia / Heirs or Persons with a Legal Interest in Mexico: Such individuals must establish their status through the appropriate legal documentation, such as a civil registry certificate, death certificate, succession judgment or will.
- The Data Subject’s Representative and/or Attorney-in-Fact: The representative must provide evidence of their authority through a duly granted power of attorney. In Mexico, depending on the procedure, this may require a simple power-of-attorney letter signed before two witnesses or a notarized power of attorney.
- By Stipulation in Favor of or on Behalf of Another Person: Provided that the legal authority to act on behalf of the Data Subject is demonstrated.
- Rights of Children and Adolescents: Such rights shall be exercised by individuals legally authorized to represent them, including parents or guardians, always safeguarding the best interests of the minor and their right to be heard.
5. Persons to Whom Information May Be Disclosed
Information meeting the conditions established in this Policy may be disclosed by CARI AI to:
- Data Subjects, their successors in interest or legal representatives.
- Public or administrative authorities acting within their legal powers or pursuant to a court order.
- Third parties authorized by the Data Subject or by law.
- Suppliers for purposes authorized by the Data Subject or permitted by law. For this purpose, CARI AI shall ensure that conditions are established requiring suppliers to comply with applicable privacy policies so that users’ Personal Data remains protected. Confidentiality agreements and Data Controller–Data Processor obligations shall also be established where appropriate based on the nature of the disclosure.
6. Joint Duties of CARI AI as DATA CONTROLLER and of DATA PROCESSORS
- Establish simple and efficient mechanisms that remain permanently available to Data Subjects so they can access their Personal Data and exercise their rights.
- Adopt reasonable measures to ensure that Personal Data contained in Databases is accurate and sufficient and, when requested by the Data Subject or identified by the Data Controller, is updated, corrected or deleted so that it remains consistent with the purposes of the Processing.
- Designate an individual or department responsible for Personal Data protection to process Data Subject requests relating to the exercise of rights under Colombian Law 1581 of 2012, Decree 1377 of 2013 and Mexico’s Federal Law on Protection of Personal Data Held by Private Parties.
- Guarantee Data Subjects, at all times, the full and effective exercise of their right to habeas data.
- Store information under appropriate security conditions to prevent alteration, loss, unauthorized consultation, unauthorized use or fraudulent access.
- Adopt information security and privacy policies and procedures to ensure proper compliance with applicable law, particularly with respect to Data Subject inquiries and complaints.
- Properly inform Data Subjects of the purpose for which information is collected and the rights available to them as a result of the authorization provided.
- Inform Data Subjects that responses to questions involving Sensitive Data or Personal Data concerning children and adolescents are optional.
- Make available the contact information required to resolve requests related to Personal Data Processing.
- Maintain evidence of compliance with their obligations and provide a copy of such evidence to the Data Subject upon request.
- Request and retain, under the conditions established by applicable law, a copy or evidence of the authorization granted by the Data Subject.
- Process inquiries and complaints within the timeframes established by applicable law.
- Adopt policies and procedures in applicable departments and processes to ensure compliance with applicable law, particularly with respect to Data Subject inquiries and complaints.
- Comply with instructions and requirements issued by regulatory authorities and other government regulations.
- Maintain evidence of publication of the Privacy Notice and information Processing policies when published online.
- Update, correct or delete Personal Data within the timeframes established by applicable law.
- Process inquiries and complaints submitted by Data Subjects within the timeframes established by applicable law.
- Add the notation “claim in progress” to records in the manner prescribed by law and add the notation “information subject to judicial proceedings” once notified by the competent authority of judicial proceedings relating to the quality or accuracy of Personal Data.
- Refrain from circulating information disputed by the Data Subject when its blocking has been ordered by a regulatory authority.
- Allow access to information only to individuals authorized to access it.
- Notify the relevant regulatory authorities when security breaches occur and risks arise in connection with the management of Data Subjects’ information, and comply with instructions and requirements issued by such regulatory authorities.
6.1 Duties of CARI AI
As Data Controller, when requesting authorization from a Data Subject, CARI AI shall clearly and expressly inform the Data Subject as required and shall:
- Comply with the provisions of Section 6 of this Policy.
- Ensure that information provided to the Data Processor is truthful, complete, accurate, up to date, verifiable and understandable.
- Update information and promptly notify the Data Processor of any changes relating to Personal Data previously provided, adopting any additional measures necessary to ensure the information remains current.
- Correct inaccurate information and notify the Data Processor accordingly.
- Provide the Data Processor, as applicable, only with Personal Data whose Processing has been previously authorized in accordance with applicable law.
- Require the Data Processor at all times to comply with the security and privacy conditions applicable to Data Subjects’ information.
- Inform the Data Processor when certain information is being disputed by the Data Subject after a complaint has been filed and while the respective proceeding remains pending.
- Maintain evidence of the authorization granted by Data Subjects for the Processing of their Personal Data. For this purpose, CARI AI shall implement the physical and electronic mechanisms necessary to preserve evidence of authorization, regardless of the method through which such authorization was obtained.
6.2 Duties of Personal Data Processors
Data Processors shall:
- Comply with Section 6 of this Policy.
- Update information reported by CARI AI within five (5) business days of receiving it.
- Inform CARI AI of any update or modification to their Personal Data Protection Policy and Privacy Notice.
- Inform CARI AI where the Personal Data Protection Policy and Privacy Notice may be accessed.
- Provide CARI AI with contact channels for handling Personal Data protection inquiries and complaints.
- Immediately notify CARI AI of any information security or privacy incident at support@cariai.com.
7. Rights of Personal Data Subjects
Data Subjects shall have the following rights:
- To access, update and rectify their Personal Data before Data Controllers or Data Processors. This right may be exercised, among other circumstances, in relation to partial, inaccurate, incomplete, fragmented or misleading information, or Personal Data whose Processing is expressly prohibited or has not been authorized.
- To request evidence of the authorization granted to the company, except where authorization is expressly exempted as a requirement for Processing pursuant to Article 10 of Colombian Law 1581 of 2012 and Chapter III, Articles 21 through 36, of Mexico’s Federal Law on Protection of Personal Data Held by Private Parties.
- Any individual exercising their habeas data rights must accurately provide the requested contact information so that their request can be properly processed and answered, and must comply with the requirements applicable to the exercise of those rights.
- To be informed by CARI AI, upon request, of the manner in which their Personal Data has been used.
- To file complaints before competent authorities and regulatory bodies for violations of applicable laws and any regulations that amend, supplement or replace them.
- To access Personal Data that has been subject to Processing free of charge.
- Right to Restriction of Processing: The Data Subject has the right to request the suspension or restriction of Processing when the accuracy of the Personal Data is disputed, when Processing is unlawful, or when CARI AI no longer requires the information but the Data Subject needs it for the establishment, exercise or defense of legal claims.
- Right to Data Portability: Where Processing is based on consent or a contract and is carried out through automated means, the Data Subject shall have the right to receive their Personal Data in a structured, commonly used and machine-readable format and to transmit such information to another Data Controller.
Automated Decision-Making: Where CARI AI uses algorithms to make decisions that produce legal effects or otherwise significantly affect a Data Subject, the Data Subject shall have the right to obtain human intervention from CARI AI, express their point of view and challenge the decision.
8. Special Requirements for Processing Personal Data of Children and Adolescents
In compliance with Law 1098 of 2006, Law 1581 of 2012 and constitutional rights, CARI AI recognizes that it may receive Personal Data concerning minors, which may be provided by employees or collaborators who are their parents or legal representatives.
CARI AI undertakes to respect and provide appropriate safeguards so that minors can exercise their rights to freedom of expression, free development of personality and access to information, as established by Law 1098 of 2006.
In accordance with Colombian regulations regarding minors and CARI AI’s duty to act responsibly, CARI AI assumes the following commitments:
- Remove from its information systems any minor who falsely stated that they were above the required age when registering as a user.
- Ensure that all Processing respects and protects the best interests of children and adolescents.
- Ensure respect for their fundamental rights.
- Notify the authorities of any criminal conduct of which CARI AI becomes aware that could place the integrity of a minor at risk and provide all cooperation required by State security authorities.
- Minors interested in acquiring our services using electronic payment methods must complete the electronic financial transaction through their parents, guardians or legal representatives, following registration and contracting by such representatives.
- When Processing Personal Data concerning children and adolescents provided by our employees or collaborators, CARI AI shall ensure its appropriate use.
9. International Transfer and Transmission of Personal Data
In order to provide better service and fulfill the purposes described in this Privacy Policy, your Personal Data may be transmitted and/or transferred to foreign entities and/or servers hosted in foreign countries under security conditions designed to ensure compliance with Colombian Law 1581 of 2012 and its implementing regulations, as well as Mexico’s Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations.
CARI AI uses cloud infrastructure services, such as AWS, whose servers may be located outside the country where Personal Data is collected.
The Data Subject expressly authorizes such international transfer and transmission.
To protect information, CARI AI ensures that these providers maintain internationally recognized security certifications, such as ISO 27001. For Personal Data subject to the GDPR, CARI AI relies on the EU-U.S. Privacy Shield, the AWS Data Processing Addendum and the CISPE Data Protection Code of Conduct, thereby providing a level of protection equivalent to the standard required by applicable law.
The following rules shall apply to the transmission and transfer of Personal Data:
- International transfers of Personal Data must comply with Article 26 of Colombian Law 1581 of 2012 and Article 36 of Mexico’s LFPDPPP, including restrictions on transferring Personal Data to countries that do not provide adequate levels of data protection, together with the legal exceptions to those restrictions.
- International transmissions of Personal Data between a Data Controller and a Data Processor, for the purpose of allowing the Data Processor to process Personal Data on behalf of the Data Controller, shall not require separate notification to or consent from the Data Subject where an appropriate agreement exists under the terms of Article 25 of Law 1581 of 2012 and Mexico’s Federal Law on Protection of Personal Data Held by Private Parties.
A country shall be considered to provide an adequate level of data protection where it complies with the standards established by Colombian regulatory authorities.
As an exception, CARI AI may transfer Personal Data in the following circumstances:
a. Where the Data Subject has provided express and unequivocal authorization for the transfer.
b. Where the transfer is agreed under an international treaty to which the Republic of Colombia is a party, based on the principle of reciprocity.
- Transfers and/or transmissions necessary for the performance of a contract between the Data Subject and CARI AI, or for the implementation of pre-contractual measures, provided that authorization has been obtained from the Data Subject.
- Transfers legally required to safeguard the public interest or for the establishment, exercise or defense of legal claims in judicial proceedings.
10. Contact Through the Website
To provide security to individuals requesting demos, joining our community or requesting additional information about our products and services through our contact form or Chatbot, CARI AI requests certain Personal Data from users.
Such information is also necessary for contacting users, providing information, preventing fraud and responding to security incidents.
As administrator of the website www.cariai.com, CARI AI will not maintain the registration of a user who has failed to provide truthful information, who uses information in a manner inconsistent with honest and lawful practices, or who violates the policies contained herein or any obligations, duties and responsibilities assumed when registering or contacting us through the website.
Users registering on this website are responsible for any inaccurate, false or misleading information they provide. Accordingly, information supplied must be truthful and reliable.
Failure to provide accurate information may result in liability for any damages caused to CARI AI and/or third parties.
Any person who uses Personal Data that does not belong to them in violation of this Policy or applicable law shall be responsible for the penalties established under Colombian and/or applicable international legislation regarding Personal Data violations.
CARI AI therefore assumes in good faith that information provided by registered users is truthful, accurate and reliable and disclaims responsibility for inaccuracies in information supplied by such users.
This document forms an integral part of the Terms and Conditions applicable to the website www.cariai.com and of the legal agreement governing CARI AI corporate web portals that provide services to external and/or internal users.
11. Handling of Requests for Access, Consultation, Updating, Rectification and Deletion of Personal Data
The continuous improvement process is responsible for handling Data Subject requests and ensuring the effective exercise of their rights.
This Policy applies to all Databases managed by CARI AI across all of its departments and business areas.
CARI AI informs users, customers, service providers, employees, collaborators, suppliers, users of its web portals and users of its other tools that any dispute will, whenever possible, be resolved amicably through consensual dispute resolution mechanisms such as negotiation or conciliation in the city of Bogotá.
12. Procedure for Exercising Habeas Data and ARCO Rights
12.1 Inquiries
Requests for information shall be submitted through the channels provided by CARI AI and shall be answered within a maximum of:
- Ten (10) business days in Colombia.
- Twenty (20) business days in Mexico.
The applicable period shall be calculated from the date the request is received.
When it is not possible to respond within the applicable period, the interested party shall be informed of the reasons for the delay and the date on which the request will be answered.
In Colombia, such additional period shall in no event exceed five (5) business days following expiration of the initial period.
12.2 Complaints
The Data Subject or other persons authorized by law who believe that information contained in CARI AI’s Databases should be corrected, updated or deleted, or who identify an alleged breach of any obligations established by applicable law, may submit a complaint to CARI AI.
The complaint shall be processed according to the following rules:
The complaint must be submitted to CARI AI and include identification of the Data Subject, a description of the facts giving rise to the complaint, the Data Subject’s address, and any supporting documentation the complainant wishes to submit.
If the complaint is incomplete, CARI AI shall request the missing information within five (5) days following receipt of the complaint.
- If two (2) months have elapsed from the date of such request without the complainant providing the required information, the complaint shall be deemed withdrawn.
- If the person within CARI AI who receives the complaint is not authorized to resolve it, the complaint shall be forwarded to the appropriate person within a maximum of two (2) business days, and the interested party shall be informed accordingly.
- Once a complete complaint has been received, the relevant Database shall include a notation stating “claim in progress”, together with the reason for the claim, within no more than two (2) business days. This notation shall remain in place until the complaint has been resolved.
The maximum period for resolving a complaint shall be fifteen (15) business days, calculated from the day following receipt of the complaint.
Where it is not possible to respond within this period, the interested party shall be informed of the reasons for the delay and the date on which the complaint will be resolved, which shall in no event exceed eight (8) business days following expiration of the initial period.
12.3 Contact for Handling Requests
Data Subjects may exercise their rights to access, know, update, rectify and delete their Personal Data by sending a request to:
or through:
https://site.cariai.com/#contacto/
Requests will be processed in accordance with Articles 14 and 15 of Colombian Law 1581 of 2012, Articles 20 through 23 of Decree 1377 of 2013, and Article 29 of Mexico’s LFPDPPP.
At a minimum, the request must contain:
- Full first and last name.
- Contact information, including physical and/or email address and telephone numbers.
- Preferred method for receiving a response.
- The reasons and/or facts giving rise to the request and a brief description of the right the Data Subject wishes to exercise, including access, updating, rectification, requesting evidence of authorization, revocation of authorization, deletion or access to information.
- Signature, where applicable.
- Identification number.
- Signature of the individual requesting the information.
12.4 Controls
Through its Personal Data Protection Policy, CARI AI informs all users and Data Subjects whose information is contained in its Databases and/or files that technical, human and administrative security measures have been implemented to protect records against alteration, loss, unauthorized consultation, unauthorized use or fraudulent access.
Such controls are implemented taking into account the nature of the Personal Data stored and the risks to which such information may be exposed.
13. Processing of Personal Data in Services Contracted by Customers
Companies that contract CARI AI services are considered CUSTOMERS of the service.
The CUSTOMER contracting each CARI AI service is the DATA CONTROLLER responsible for its Personal Data.
CARI AI acts as the DATA PROCESSOR for Personal Data processed on behalf of CUSTOMERS using its products and/or services.
Natural persons who use the products or services contracted by CUSTOMERS are end users and may be considered the DATA SUBJECTS for the processes defined by each CUSTOMER.
CARI AI shall implement the security conditions determined by the DATA CONTROLLER for the relevant Processing activities, based on the requirements communicated through the channels and roles agreed upon during the project.
CARI AI shall only perform actions involving Personal Data that have been officially instructed by the DATA CONTROLLER.
CARI AI shall forward any request relating to Personal Data to the DATA CONTROLLER so that the DATA CONTROLLER may verify the relevance, admissibility, validity and authenticity of the request, together with any other factors required to determine whether the requested action should be performed.
CARI AI shall provide access to information relating to DATA SUBJECTS where such access has been validated by the DATA CONTROLLER.
CARI AI shall perform the agreed actions within the parameters established by applicable law and in accordance with the service level agreements entered into with each CUSTOMER.
CARI AI shall implement internal awareness and training processes so that its personnel act in accordance with the requirements of applicable law.
CARI AI has established contact points as described in Section C of the procedures and inquiries section.
CARI AI’s DATA PROTECTION OFFICER shall be responsible for managing all CARI AI requests covered by this Policy.
Information Transfer Considerations for Each Service
Although CARI AI operates its technological infrastructure on AWS using IaaS and PaaS services hosted in U.S. data centers, CARI AI never transfers control of the information to another Data Processor or Data Controller.
The AWS services used by CARI AI maintain CARI AI’s full responsibility for the control of the Personal Data and technology.
The responsibilities associated with the AWS IaaS and SaaS services used by CARI AI are described in the corresponding chart, where BLUE represents components managed by CARI AI and RED represents components managed by the service provider (QSS in the case of IaaS and PaaS).
Accordingly, CARI AI provides its services to customers as a Software as a Service (SaaS) provider and uses Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) services to deliver those services.
This technical configuration does not change the fact that CARI AI acts as the Data Processor and that control of the Personal Data has not been transferred to a third party, even where the Personal Data has been transmitted to the United States.
“When using the applications, information received from Google APIs will comply with the Google API Services User Data Policy, including Limited Use requirements.”
“When using the applications, information received from Meta APIs will comply with the Meta API Services User Data Policy, including Limited Use requirements.”
CARI AI reads and stores public comments obtained through Google and Meta applications. Such Personal Data is used for reporting, analytics and other purposes defined by our Customers according to the applicable service.
14. Effective Date and Retention Period
This Policy was approved on February 10, 2026, supersedes the previous version, and shall become effective as of the date of its publication on CARI AI’s intranet and website.
CARI AI shall retain Personal Data only for the period strictly necessary to fulfill the purpose for which it was collected.
Once the contractual relationship has ended or the applicable Processing purpose has been fulfilled, Personal Data shall be blocked or securely deleted, unless a legal obligation requires it to be retained for an additional period.
CARI AI reserves the right to modify this Policy at any time.
Any modification shall be communicated and published in a timely manner on the website https://www.cariai.com.
Purpose of Personal Data Processing
Cari AI will process the information provided by users and previously authorized by them as follows:
a. General Purposes
For all users, students, employees, collaborators, suppliers, and customers, Personal Data will be used to:
- Prospectively identify the needs of Cari AI’s stakeholders in order to innovate in the provision of its services.
- Fulfill obligations arising from existing contractual relationships with its stakeholders.
- Ensure the safety of visitors, employees, collaborators, and the general community present at Cari AI facilities.
- Communicate with users registered in our systems, website, and/or social media channels regarding new services, news, events, academic opportunities, publications, updates, business innovation, special programs, user education campaigns, commercial events, and advertising, provided that such communications are related to the company’s objectives.
- Continuously understand the needs of users registered on our web portals in order to strengthen relationships and promote business innovation.
- Develop corporate social responsibility programs in accordance with the company’s bylaws and internal regulations.
- Allow data provided by collaborators to be shared with other companies for contractual purposes and/or for commercial proposals or agreements, unless the Data Subject expressly revokes such authorization.
- Enable efficient communication regarding our services and partnerships.
- Support the ongoing development and improvement of Cari AI’s services and products.
- Communicate marketing activities and/or promote Cari AI’s own services or those offered through commercial partnerships.
- Analyze Personal Data for studies related to artificial intelligence.
- Assess satisfaction levels and the quality of services provided.
- Conduct statistical studies and analyze market trends.
- Control and prevent fraud and money laundering.
- Exchange or submit information pursuant to international agreements or treaties.
- Inform Data Subjects of changes to the Personal Data Processing Policy.
b. Users and Customers
The information will be used to:
- Carry out the company’s core business activities.
- Communicate with users registered in our systems, website, and/or social media channels regarding new services, news, events, academic opportunities, publications, updates, business innovation, special programs, user education campaigns, commercial events, and advertising, provided that such communications are related to the company’s objectives.
- Continuously understand the needs of users registered on our web portals in order to strengthen relationships and promote business innovation.
- Communicate marketing activities and/or promote Cari AI’s own services or those offered through commercial partnerships.
c. Contractors and Suppliers
Personal Data will be used to support the performance of service agreements and civil and/or commercial relationships, including the monitoring and management of contractors’ and suppliers’ commercial performance.
The information may also be used to verify their suitability and periodically exchange information to facilitate their understanding of the services offered by Cari AI, as well as to invite them to participate in activities or commercial campaigns that may be of interest to them.
Information contained in our current or future databases will be used to enable Cari AI to develop both an objective and subjective understanding of such service providers.
Such information will only be transferred and/or transmitted to other entities when necessary to comply with applicable legal requirements, when requested by public or administrative authorities and/or labor supervisory entities acting within their legal authority, or pursuant to a court order.
Corporate email addresses belonging to service providers and/or suppliers may be used to facilitate communication with employees, send relevant internal communications, invite them to participate in corporate activities, and comply with applicable laws governing suppliers.
d. Employees
Information contained in our databases regarding former employees, current employees, and prospective job candidates will be used to enable Cari AI to develop both an objective and subjective understanding of its personnel.
Such information will only be transferred and/or transmitted to other entities when necessary to comply with applicable legal requirements, when requested by public or administrative authorities and/or labor supervisory entities acting within their legal authority, or pursuant to a court order.
Corporate email addresses may be used to facilitate communication between employees and stakeholders, send internal communications, and invite employees to participate in corporate activities.
In the case of collaborators, in addition to the purposes described above, their Personal Data may be transmitted to companies requesting employment verification, financial or commercial credit authorization, background checks, or security studies, provided that the source and intended use of the information have been verified and applicable legal confidentiality requirements are observed.
Personal Data may also be used for internal promotion processes, verification of academic credentials, requests for information from other companies or educational institutions, training activities, direct contact when required, and, in general, all administrative and financial activities directly related to the position for which the individual is or will be hired.
Personal Data may also be used to provide employee wellness programs and to plan corporate activities for employees and their beneficiaries.
Processing of Sensitive Data
Because this involves Sensitive Data and Personal Data concerning minors, the Data Subject will be explicitly informed in advance that they are not required to authorize the Processing of such information.
Sensitive Data may only be processed when:
- The Data Subject has expressly authorized such Processing, except in cases where authorization is not required by law.
- Processing is necessary to safeguard the vital interests of the Data Subject and the Data Subject is physically or legally incapable of providing consent.
- Processing relates to information required for the recognition, exercise, or defense of a legal right in judicial proceedings.
- Processing is carried out for historical, statistical, or scientific purposes. In such cases, appropriate measures must be adopted to remove or anonymize the identity of the Data Subjects.
The Processing of Personal Data concerning children and adolescents will be carried out in accordance with the parameters established above in this Policy.
Video Surveillance
Personal Data Processing has been defined as “any operation or set of operations performed on Personal Data, including collection, storage, use, circulation, or deletion.”
In the case of images of identified or identifiable individuals, activities such as capturing, recording, transmitting, storing, retaining, or reproducing images, whether in real time or at a later time, among others, are considered Personal Data Processing and are therefore subject to the General Personal Data Protection Framework.
Cari AI does not collect Personal Data through video surveillance on the basis of legitimate interest.
Cari AI does not maintain physical infrastructure for the performance of its operations and, therefore, does not conduct video surveillance.
Cases Where Authorization Is Not Required
In accordance with Article 10 of Law 1581 of 2013, authorization from the Data Subject will not be required in the following cases:
a) Information requested by a public or administrative authority acting within its legal powers or pursuant to a court order.
b) Data of a public nature.
c) Cases involving a medical or health emergency.
d) Processing of information authorized by law for historical, statistical, or scientific purposes.
e) Data related to individuals’ Civil Registry records.
Any person who accesses Personal Data without prior authorization must, in all cases, comply with the provisions established by law.
Processing of Personal Data in Services Contracted by Customers
Companies that contract Cari AI services are considered CUSTOMERS of the service.
The CUSTOMER that contracts each Cari AI service is the DATA CONTROLLER responsible for its Personal Data.
Cari AI acts as the DATA PROCESSOR for the Personal Data of CUSTOMERS using its products and/or services.
Natural persons who use the products and services contracted by CUSTOMERS are end users and may be considered the DATA SUBJECTS for the processes defined by each CUSTOMER.
Cari AI will implement the security conditions determined by the DATA CONTROLLER for the relevant Processing activities, based on the requirements communicated through the channels and roles agreed upon during the project.
Cari AI will only perform actions involving Personal Data that have been officially instructed by the DATA CONTROLLER.
Cari AI will forward any request relating to Personal Data to the DATA CONTROLLER so that the DATA CONTROLLER may assess the relevance, admissibility, validity, authenticity, and any other element required to determine whether the request should be fulfilled.
Cari AI will provide access to information relating to DATA SUBJECTS where such access has been validated by the DATA CONTROLLER.
Cari AI will perform the agreed actions within the parameters established by applicable law and in accordance with the service level agreements entered into with each CUSTOMER.
Cari AI will implement internal awareness and training processes so that its personnel act in accordance with the requirements of applicable law.
Cari AI has established contact points as described in subsection C of the Procedures and Inquiries section.
Cari AI’s DATA PROTECTION OFFICER will be responsible for managing all requests defined in this Policy.
Information Transfer Considerations for Each Service
Although Cari AI operates its technological infrastructure on AWS¹ through IaaS² and PaaS³ services hosted in U.S. data centers, Cari AI does not transfer control of the information to another Data Processor or Data Controller.
The AWS services used by Cari AI preserve Cari AI’s full responsibility for control over the data and the technology.
The responsibilities associated with the AWS IaaS and SaaS services are explained in the corresponding chart, where BLUE represents the components managed by Cari AI and RED represents those managed by the service provider (QSS in the case of IaaS and PaaS).
Privacy Notice and Website Terms of Use
It is in CARI AI’s interest to safeguard the privacy of Users’ personal information obtained through the Website. Accordingly, CARI AI undertakes to adopt a confidentiality policy in accordance with the provisions set forth below.
The User acknowledges that any personal information entered on the Website is provided voluntarily and in response to specific requests made by CARI AI for purposes such as carrying out a procedure, submitting a complaint or claim, or accessing interactive features.
The User agrees that, through registration on the Website, CARI AI collects Personal Data, which will not be disclosed to third parties without the User’s knowledge.
The collection and automated Processing of Personal Data resulting from browsing and/or registering on the Website is carried out for the following purposes:
- The proper management and administration of the services offered through the Website that the User chooses to register for, use, or contract.
- Quantitative and qualitative analysis of visits to the Website and Users’ use of its services.
- The delivery, through traditional and electronic means, of information related to CARI AI and any other CARI AI project, its programs, and its affiliated and related entities.
- The processing of online government services.
1.1 Users’ Rights Regarding Their Personal Data
In compliance with applicable regulations, Users are informed of the existence of an automated Personal Data file.
Users are entitled to exercise their rights of access, rectification, cancellation, and objection regarding the Processing of their Personal Data.
These rights may be exercised by submitting a request to:
or through:
https://site.cariai.com/#contacto/
The request will be handled in accordance with Articles 14 and 15 of Law 1581 of 2012 and Articles 20 through 23 of Decree 1377 of 2013.
At a minimum, the request must contain:
- Full first and last name.
- Contact information, including physical and/or email address and telephone numbers.
- Preferred means of receiving a response.
- The reason(s) and/or facts giving rise to the request, together with a brief description of the right the User wishes to exercise, including access, updating, rectification, requesting proof of authorization, revocation of authorization, deletion, or access to information.
- Signature, where applicable.
- Identification number.
- Signature of the person requesting the information.
1.2 Use of Cookies and Activity Logs
Website Monitoring
The Website uses third-party cookies, including cookies provided by Google.
Cookies used by the Website are files sent to a browser through a web server in order to record Users’ activity on the Website and provide a smoother and more personalized browsing experience.
Users may configure their browsers to prevent cookies from being installed, block them, or delete them.
Use of this Website does not require Users to allow cookies to be downloaded or installed.
Likewise, the Website’s servers automatically detect the IP address and network name used by the User.
This information is temporarily recorded in a server activity log, allowing the subsequent Processing of data for statistical purposes, including measurements such as the number of page impressions and visits to the Website.
In addition to its own Website monitoring systems, the Website uses external statistical tools such as Google Analytics, a web analytics service provided by Google, Inc., a Delaware company whose principal office is located at 1600 Amphitheatre Parkway, Mountain View, California 94043, United States.
Google Analytics uses “cookies,” which are text files stored on the User’s computer, to help the Website analyze how Users use the Website.
Information generated by the cookie regarding the User’s use of the Website, including the User’s IP address, will be transmitted directly to and stored by Google on servers located in the United States.
Google will use this information on behalf of CARI AI for the purpose of tracking the User’s use of the Website, compiling Website activity reports, and providing other services related to Website activity and Internet usage.
Google may transfer such information to third parties where required by law or where such third parties process the information on Google’s behalf.
Google will not associate the User’s IP address with any other data held by Google.
Users may refuse the Processing of data or information by rejecting the use of cookies through the appropriate browser settings. However, Users should be aware that doing so may prevent them from using the full functionality of the Website.
By using the Website, the User consents to the Processing of information concerning the User by Google in the manner and for the purposes described above.
For additional information, please refer to the COOKIE POLICY.
1.3 Disclosure of Users’ Personal Data to Third Parties
CARI AI will not disclose Users’ Personal Data collected through the Website to third parties without the User’s express consent.
Notwithstanding the foregoing, the User consents to the disclosure of Personal Data when required by competent administrative authorities or pursuant to a court order.
The User also understands that information provided by the User will form part of a file and/or Database that may be used by CARI AI for purposes of carrying out a specific process.
CARI AI shall not be liable for any consequences resulting from unauthorized access by third parties to the Database and/or from any technical failure affecting the operation and/or preservation of data within the system or any section of the Website.
CARI AI has implemented the security levels legally required for the protection of Personal Data, including the technical and organizational measures necessary to prevent the loss, misuse, alteration, unauthorized access, and theft of information provided by Users.
1.4 Amendments to the Terms of Use
CARI AI may modify the Privacy Policies contained herein at its sole discretion and at any time.
Any such modifications will become effective once they are published on the Website.
The User agrees to periodically review this section in order to remain informed of any amendments.
Each new access to the Website by the User will be considered tacit acceptance of the updated terms.
Annex
Terms of Use
Dear User:
The CARI AI website under the .com domain, registered in Colombia as www.cariai.com / site.cariai.com (hereinafter, the Website), has the primary purpose of providing information and services, as well as publishing and promoting CARI AI’s policies and guidelines.
Through the Website, CARI AI publishes, among other matters, topics and activities related to its mission, vision, objectives, and functions.
Additionally, through the Website, CARI AI provides information concerning policies, plans, programs, projects, services, information security news, cybersecurity events, publications, regulations, calls for applications, recommended websites, and, in general, information related to cybersecurity and information security.
CARI AI pursues profit, revenue, and commercial interests through the content and links published on its Website and on the websites of other affiliated or related departments or entities that may be accessed through the Website.
CARI AI requests that Users carefully and thoroughly read these Terms of Use and the Website’s Privacy Policy before browsing or using the Website.
If the User does not agree with these Terms of Use or with any provision of the Privacy Policy, CARI AI recommends that the User refrain from accessing or browsing the Website.
1. Definitions
For purposes of facilitating the understanding of these Website Terms of Use, the following definitions apply:
a. Content
All forms of information or data published on the Website, including text, images, photographs, logos, designs, and animations.
b. Intellectual Property Rights
Includes trademarks, trade names, logos, commercial signs, slogans, domain names, trade secrets, know-how, industrial designs, patents, utility models, and copyrights.
c. Forum
An automated messaging service, often moderated by an owner, through which subscribers receive messages posted by other subscribers concerning a particular topic.
Messages may be sent by email.
d. Internet
A communications network consisting of tens of thousands of interconnected computer networks using the TCP/IP protocol.
Multiple services may operate over this network, including email and the World Wide Web.
e. Web Page
A hypertext or hypermedia document displayed by a web browser after obtaining requested information.
Its content may range from brief text to extensive collections of text, static or animated graphics, sound, and other media.
f. Publish
To make a document visible through the Website.
g. Services
Online resources currently provided, or intended to be provided in the future, by CARI AI to Users through the Website.
These may include publication of news or activities, security-related news and/or events, online procedures, consultations, forums, and complaint and claim submission tools, among others.
h. User
Any person who accesses the Website.
The User may register if required to complete a procedure, receive a service from CARI AI, or submit a complaint through the Complaints and Claims feature created for this purpose.
i. Link
A hypertext pointer that allows a User to navigate from one item of information to another or from one web server to another while browsing the Internet.
2. Acceptance of Terms
When a User accesses the Website, it is presumed that the User does so entirely at their own responsibility and therefore fully and unconditionally accepts the content of these Website Terms and Conditions of Use.
CARI AI reserves the right, in all respects, to update and modify these Terms of Use, Privacy Policies, and Website content at any time, in any manner, unilaterally, and without prior notice.
3. Website Content
The purpose of the Website is to provide Users with information relating to Cari AI’s products and services, as well as information regarding the organization’s management, plans, programs, and advisory activities through newsletters, posts, and news.
Under no circumstances should such information be considered exhaustive, complete, or sufficient to satisfy all of the User’s needs.
The Website may contain links to other websites of interest or documents located on websites owned by entities, individuals, or organizations other than CARI AI.
If the User accesses another website or an individual document located on another web page through a link made available on the Website, the User will be subject to the terms of use and privacy policy applicable to the destination website.
The inclusion of a link to the website of another company, entity, or program does not necessarily imply the existence of a relationship between CARI AI and the owner of the linked website, nor does it imply CARI AI’s approval or endorsement of its content or services.
Persons intending to create a link to the CARI AI Website must ensure that such link provides access only to the Website’s homepage.
Likewise, CARI AI assumes no responsibility for information located outside the Website that is not directly managed by the Website administrator.
Links appearing on the Website are intended to inform Users of other sources that may expand upon the content offered by the Website or that may otherwise be related to such content.
CARI AI does not guarantee or assume responsibility for the operation or accessibility of linked websites, nor does it suggest, invite, or recommend that Users visit them.
Accordingly, CARI AI will not be responsible for any results obtained from accessing those websites.
Accessing such websites through the CARI AI Website does not imply that CARI AI recommends or approves their content.
The Website service is provided to Users free of charge.
The Website may contain articles or literary and scientific works, hereinafter referred to as Information, created by CARI AI or third parties for informational, educational, and dissemination purposes.
CARI AI may modify or remove such Information at any time and without prior notice.
Opinions expressed in comments submitted by Users do not necessarily reflect CARI AI’s views.
Any use of the Website that overloads, damages, disables, or otherwise impairs CARI AI’s or third parties’ networks, servers, computer equipment, software products, or applications is expressly prohibited.
CARI AI does not guarantee uninterrupted or error-free operation of the Website.
CARI AI makes commercially reasonable efforts to ensure that the content provided is of high quality, and the User agrees to use the service subject to these conditions.
Users may not use the content, particularly any information obtained through CARI AI or its Services, for advertising purposes.
Users of the Website may not alter, block, or perform any act that prevents the display of or access to any content, information, or Services on the Website or on linked web pages.
3.3 Responsibility for Information Contained on the Website
Because current technical means do not allow CARI AI to guarantee the complete absence of third-party interference with the Website, CARI AI does not warrant the accuracy and/or truthfulness of all or any portion of the information contained on the Website, its continued accuracy, or that such information has not been altered or modified in whole or in part after publication.
CARI AI also does not guarantee any other aspect or characteristic of the content published on the Website or accessible through external links.
CARI AI does not control or guarantee the absence of viruses or other elements within Website content that may cause changes or damage to the User’s computer systems, including software and hardware, or to electronic documents and files stored on the User’s computer systems.
Nevertheless, CARI AI implements cybersecurity controls throughout its technological infrastructure.
Accordingly, CARI AI shall not be responsible for any damage caused as a result of alterations made to materials or downloadable files provided directly by the company.
Users may not send or transmit through or to the Website, to other Users, or to any other person, information containing obscene, defamatory, insulting, slanderous, or discriminatory content directed against any person or against CARI AI, its subsidiaries or affiliated entities, its employees, or those responsible for managing the Website.
Under no circumstances will content be accepted that may be considered offensive, sexist, racist, discriminatory, or obscene, insofar as such content may violate individuals’ fundamental rights.
4. Intellectual Property
Intellectual Property rights relating to Website content either form part of CARI AI’s assets or, where applicable, are owned by third parties that have authorized their use on the Website, or consist of public information governed by Colombian and international public information access laws.
The text and graphic elements comprising the Website, together with its presentation and layout, are either exclusively owned by CARI AI or CARI AI holds the necessary rights to use them.
Notwithstanding the foregoing, trade names, trademarks, and distinctive signs displayed or referenced on the Website belong to their respective owners and are protected by applicable law.
Any use, transformation, or exploitation of content included on the Website for commercial or promotional purposes is prohibited without CARI AI’s prior authorization.
In all cases, any use contrary to law is prohibited.
Personal, non-commercial use of Website content is permitted provided that express attribution is given to the owner or author of the relevant content.
All logos and trademarks appearing on the Website are owned by CARI AI or are used by CARI AI with authorization from their respective owners.
In all cases, the owners of such trademarks and logos remain responsible for any disputes that may arise concerning them.
Such owners reserve the right to pursue any legal action they deem appropriate to enforce their rights in Colombia or abroad.
The User agrees that content created and uploaded by the User will become the property of CARI AI, while the User retains the moral rights associated with such content.
Any claims submitted by Users or third parties concerning alleged violations of Intellectual Property Rights relating to Website content must be sent to the email address indicated in the source document.
Once CARI AI receives notification, the disputed content will be automatically removed from the Website until the person who posted such content has resolved the dispute with the claimant.
5. Privacy
Personal Information means information provided by the User for registration purposes, including information such as name, identification number, age, gender, address, email address, and telephone number.
The storage and use of Personal Information are governed by the Website’s Privacy Policies.
6. Governing Law and Jurisdiction
a.
These Website Terms of Use shall be governed by the laws of the Republic of Colombia and any applicable international laws.
b.
If any provision of these Terms of Use becomes invalid or unenforceable for any reason, all remaining provisions shall remain valid, binding, and fully effective.
c.
For all legal or judicial purposes, these Terms shall be deemed entered into in the city of Bogotá.
Any dispute arising from their interpretation or application shall be submitted to the competent courts of the Republic of Colombia.
7. Participation on the Website
7.1 General Participation Rules
By accessing the Website, and in order to ensure its proper and appropriate use, the User acknowledges that CARI AI reserves the right to:
- Deny registration to any person at any time and for any reason.
- Decide, at its sole discretion, whether to include material received from Users on the Website. If such material is included, CARI AI may retain it on the Website for the period it considers appropriate or modify it.
- Remove, without being obligated to do so, content that CARI AI considers illegal, offensive, defamatory, or otherwise in violation of these Terms of Use.
- Remove content that infringes Intellectual Property Rights upon request by the applicable rights holder.
- Use Personal Information and/or content provided by Users in accordance with these Website Terms of Use and the Privacy Policy.
7.2 User Registration and Participation
By accessing the Website, and in order to ensure its proper and appropriate use, the User must:
- Be responsible for any activity carried out under the User’s registration.
- Be responsible for maintaining the security of the User’s password.
- Refrain from abusing, harassing, threatening, or intimidating other Website Users through chats, forums, blogs, or any other interactive area.
- Refrain from using the Website as a means of carrying out illegal or unauthorized activities in Colombia or any other country.
- Be solely responsible for their conduct and for the content of any text, graphics, photographs, videos, or other information they use or publish through the Website.
- Refrain from sending unsolicited email or SPAM to other Website Users or transmitting viruses or any other destructive code.
CARI AI shall not be responsible for any User’s failure to comply with the foregoing rules, and the User shall indemnify and hold CARI AI harmless from any liability arising from such violation.
7.3 Forums, Blogs, Chats, Comments, and Other Interactive Areas
The User acknowledges that participation in any forum, chat, comment section, blog, and/or other interactive area of the Website is undertaken entirely at the User’s own responsibility.
Likewise, the opinions, actions, and conduct of other Users in such areas are the sole responsibility of the individuals who express or engage in them.
CARI AI assumes no responsibility for and does not guarantee the quality or appropriateness of such conduct or opinions, or any consequences they may have for or against other Users or third parties.
The design, management, purpose, and characteristics of the Website’s different interactive areas are determined at CARI AI’s discretion.
CARI AI may modify or remove them at any time and/or determine the number of participants permitted in each area.
Participation in forums, chats, comment sections, and other similar interactive areas of the Website, hereinafter referred to as the Interactive Areas, constitutes the User’s acknowledgment and acceptance of these Terms of Use.
Each User irrevocably agrees to comply with these Terms of Use and understands and accepts that CARI AI shall be released from and held harmless against any liability arising from the User’s failure to comply with such obligations, including damages caused to other Users and/or affected third parties.
If a User does not agree with these Website Terms and Conditions, CARI AI recommends that the User refrain from participating in the Website and/or its Interactive Areas.
Each User expressly and irrevocably authorizes CARI AI to review comments or opinions submitted through the Interactive Areas and/or remove any content that does not comply with the standards of conduct established in these Website Terms of Use.
CARI AI may also interrupt communications where it considers such action appropriate for these reasons.
CARI AI reserves the right to exercise this authority at its discretion whenever it considers appropriate.
No liability may be attributed to CARI AI for failing to exercise such authority or for the presence, access, or participation of undesirable Users and/or comments or opinions that fail to comply with these recommendations.
Because comments and opinions posted in forums, comment sections, and blogs are submitted by third parties entirely independent of CARI AI, CARI AI assumes no responsibility for their content.
CARI AI neither endorses nor disputes such comments or opinions, which are understood to originate solely from their authors and remain entirely their responsibility.
It is strictly prohibited to submit comments, messages, opinions, information, or similar content that is:
- Defamatory.
- Abusive.
- Contrary to morality or generally accepted standards of conduct.
- Discriminatory.
- Offensive.
- Obscene.
- Intimidating.
- Slanderous.
- Inappropriate.
- Illegal.
- In violation of any third-party rights.
- In violation of the rights of minors.
- Likely to cause damage or harm.
- Intended to prevent or restrict another person’s right to use the Interactive Areas or other sections of the Website.
- Criminal in nature or supportive of criminal conduct.
- Intended to encourage violence and/or the commission of criminal offenses.
Advertising products and/or services of any kind within the Interactive Areas is also prohibited.
Users may not introduce or distribute viruses or deviate from the topics established for forums.
If comments, messages, opinions, information, or similar content of this nature nevertheless appear within the Interactive Areas, Users expressly and unconditionally agree that CARI AI, its employees, suppliers, or advertisers shall not be liable in any manner for any consequences of any nature or scope that such content may cause to any third party, whether as a result of its inclusion within the Interactive Areas or any matter directly or indirectly related to its use.
Likewise, CARI AI, its employees, suppliers, or advertisers shall not be liable in any manner if comments, information, messages, opinions, or similar content are affected, deleted, altered, or otherwise modified.
Users shall refrain from initiating any action or claim against CARI AI relating to or arising from information, content, opinions, or comments submitted by another User and/or a third party unrelated to CARI AI.
Users acknowledge that any such actions or claims may only be brought against the person directly responsible for the relevant content, through the appropriate legal proceedings established for that purpose.
CARI AI may decline to provide available information regarding an alleged infringer where, in CARI AI’s judgment, such information is protected by confidentiality obligations owed to Users.
In such cases, disclosure shall be subject to a request from a competent authority.
At its sole discretion, CARI AI reserves the right to exclude from the Interactive Areas Users who fail to comply with these rules or the basic principles of appropriate conduct.
CARI AI also reserves the right to interrupt, remove, and/or exclude, in whole or in part, any message, opinion, information, or similar content that does not comply with or violates the rules and principles described above.
Each User must report any violation of these Website Terms of Use by other Users of which they become aware.
Such reports must be sent to:
so that CARI AI may take any measures within its control regarding the Website.
8. Amendments to the Terms of Use
CARI AI may modify these Terms of Use at its sole discretion and at any time.
Any amendments will become effective once they are published on the Website.
The User agrees to periodically review this section to remain informed of any such modifications.
Each new access to the Website by the User will be considered tacit acceptance of the updated Terms of Use.
Cookie Policy
In accordance with applicable Colombian and international regulations governing the use of cookies, we hereby inform you about the cookies used on the Cari AI websites, https://site.cariai.com and cariai.com (hereinafter, the “Website”), as well as the reasons for their use.
Cari AI also informs you that, by browsing the Website, you consent to the use of cookies as described herein.
What Are Cookies and What Are They Used For?
A cookie is a file that is downloaded to your computer, tablet, smartphone, or other device when you access certain websites.
Cookies allow a website, among other things, to store and retrieve information about a User’s browsing habits or device and, depending on the information they contain and the way the User uses their device, may be used to recognize the User.
Cookies cannot damage your device. On the contrary, enabling them helps us identify and resolve potential errors.
Cookie Identification
Cookies are classified below according to several categories.
Please note that the same cookie may fall under more than one category.
Types of Cookies According to the Entity Managing Them
Depending on the entity that manages the equipment or domain from which cookies are sent and processes the data obtained through them, cookies may be classified as follows:
First-Party Cookies
These are cookies sent to the User’s device from equipment or a domain managed by the Website publisher itself and from which the service requested by the User is provided.
Third-Party Cookies
These are cookies sent to the User’s device from equipment or a domain that is not managed by the Website publisher, but rather by another entity that processes the data obtained through the cookies.
If cookies are installed from equipment or a domain managed by the Website publisher but the information collected through them is managed by a third party, such cookies cannot be considered first-party cookies.
Types of Cookies According to How Long They Remain Active
Depending on how long cookies remain active on the User’s device, they may be classified as follows:
Session Cookies
These cookies are designed to collect and store data while the User accesses a website.
They are typically used to store information that is only required for the provision of the service requested by the User on a single occasion, such as a list of purchased products.
Persistent Cookies
These cookies store data on the User’s device and may be accessed and processed for a period established by the party responsible for the cookie.
This period may range from a few minutes to several years.
Types of Cookies According to Their Purpose
Depending on the purpose for which the data collected through cookies is processed, cookies may be classified as follows:
Technical Cookies
These cookies allow the User to browse a website, platform, or application and use the various options or services available therein.
This includes, for example:
- Managing traffic and data communication.
- Identifying a session.
- Accessing restricted areas.
- Remembering items included in an order.
- Completing the purchase process.
- Registering for or participating in an event.
- Using security features while browsing.
- Storing content for video or audio streaming.
- Sharing content through social media.
Personalization Cookies
These cookies allow the User to access the service with certain predefined general characteristics based on criteria stored on the User’s device.
These may include:
- Language.
- Browser type.
- Regional settings from which the User accesses the service.
Analytics Cookies
These cookies allow the party responsible for them to monitor and analyze the behavior of Users on the websites to which they are linked.
The information collected through these cookies is used to measure activity on websites, applications, or platforms and to create browsing profiles for Users, with the purpose of making improvements based on analysis of how Users interact with the service.
Advertising Cookies
These cookies make it possible to manage advertising spaces as effectively as possible where the Website publisher has included such advertising spaces on a website, application, or platform from which the requested service is provided.
Their use may be based on criteria such as the content displayed or how frequently advertisements are shown.
Behavioral Advertising Cookies
These cookies make it possible to manage advertising spaces as effectively as possible where the Website publisher has included such advertising spaces on a website, application, or platform from which the requested service is provided.
These cookies store information about Users’ behavior obtained through continuous monitoring of their browsing habits, allowing a specific profile to be created in order to display advertising based on that profile.
Cookies Used on Our Website
The cookies used on our Website include both first-party and third-party cookies.
They allow us to store and access information relating to:
- Language.
- Browser type.
- Other general characteristics predefined by the User.
- User activity on the Website.
This information enables us to analyze Website activity, make improvements, and provide our services more efficiently and in a more personalized manner.
Cari AI does not use advertising cookies or behavioral advertising cookies.
The use of cookies provides several benefits in connection with information society services, including:
- Making it easier for the User to browse the Website and access the different services it offers.
- Preventing the User from having to configure predefined general settings every time they access the Website.
- Supporting improvements in Website performance and services following analysis of the information collected through installed cookies.
Cari AI does not collect or store Personal Data such as your name or address through these cookies, and therefore this information cannot be used to identify you personally.
However, you may configure your browser to accept or reject all cookies, or select which cookies you wish to allow or block, depending on the browser you use.
Supported browsers and devices include:
- Google Chrome
- Mozilla Firefox
- Internet Explorer
- Safari
- Opera
- Internet Explorer for Windows Phone
- Safari for iOS (iPhone and iPad)
- Chrome for Android
Analytics Cookies
Cari AI uses analytics cookies on its Website.
Specifically, Cari AI stores Google Analytics analytics cookies on the User’s device.
Users may opt out of individual tracking through the opt-out mechanisms provided by Google Analytics.
For additional information, please refer to Google Analytics documentation regarding cookie usage on websites.
Cookies Used on the Website
| Cookie | Provider | Duration | Purpose | Level |
|---|---|---|---|---|
_ga | 2 years or until updated | Cookie set by analytics.js, a JavaScript library owned by Google. analytics.js is part of Google Universal Analytics and uses this first-party cookie containing an anonymous identifier to distinguish Users. | Level 2 | |
_gat | 10 minutes from creation or modification | Cookie set by analytics.js, a JavaScript library owned by Google. It contains an identifier used to distinguish between different tracking objects created during the session. | Level 2 | |
__utma | 2 years or until updated | Keeps a record of how many times a User has visited a website, when the first visit occurred, and when the most recent visit occurred. | Level 2 | |
__utmb | 30 minutes or until updated | Helps calculate how long a User’s visit lasts by storing the time at which the User entered the Website. | Level 2 | |
__utmc | Expires at the end of the session | Helps calculate how long a User’s visit lasts by storing the time at which the User leaves the Website. | Level 2 | |
__utmz | 6 months or until updated | Records the traffic source or campaign and tracks which search engine the visitor used, which links were clicked, which keywords were used, and the location from which the Website was accessed. | Level 2 | |
__utmli | 2 years or until updated | Generates an anonymous User ID used to count how many times a User visits the Website. It also records the first and most recent visits, determines when a session ends, identifies the User’s source, and records keywords used. | Level 2 | |
PREF | 2 years | When a User creates or signs in to a Google account, cookies such as PREF, NID, HSID, APISID, SID, SSID, SAPISID, GAPS, LSID, BEAT, and ULS may be stored on the User’s device to keep the User signed in when using Google services again. While the session remains active and Google plug-ins are used on other websites such as ours, Google may use these cookies to improve the User experience. | Level 2 | |
NID | 6 months | The Google +1 button used on our Website is hosted by Google. The User’s browser sends information from cookies required by Google if the User is signed in to their Google account. Google uses this data to associate activity with the User’s account. | Level 2 | |
SNID | 6 months | Our Website uses Google Maps to display geographic locations. Its use involves the transmission of PREF, NID, SNID, khcookie, and other cookies required by Google when the User remains signed in to their Google account. These cookies are managed entirely by Google. | Level 2 | |
GAPS | Expires at the end of the session | Some pages on our Website contain embedded YouTube videos, a Google service. Use of these videos involves cookies including PREF, NID, LOGIN_INFO, ACTIVITY, dkv, USE_HITBOX, demographics, VISITOR_INFO1_LIVE, YSC, and other Google cookies required when the User is signed in. These cookies support video playback, bandwidth estimation, and view-count tracking. | Level 2 | |
LSID | 2 years | Used by Google services. | Level 2 | |
BEAT | 24 hours | Used by Google services. | Level 2 | |
YSC | Expires at the end of the session | Used in connection with YouTube services. | Level 2 | |
Khcookie | Expires at the end of the session | Used in connection with Google services. | Level 2 | |
demographics | 18 months | Used in connection with Google and YouTube services. | Level 2 | |
dkv | 60 days | Used in connection with Google and YouTube services. | Level 2 | |
APISID | 2 years | Used by Google services. | Level 2 | |
HSID | 2 years | Used by Google services. | Level 2 | |
SID | 2 years | Used by Google services. | Level 2 | |
SAPISID | 2 years | Used by Google services. | Level 2 | |
SSID | 2 years | Used by Google services. | Level 2 | |
LOGIN_INFO | 2 years | Used in connection with YouTube and Google services. | Level 2 | |
ACTIVITY | Expires at the end of the session | Used in connection with Google services. | Level 2 | |
USE_HITBOX | Expires at the end of the session | Used in connection with YouTube services. | Level 2 | |
VISITOR_INFO1_LIVE | 8 months | Used in connection with YouTube services and video playback. | Level 2 |
Cookies Used by Third-Party Content Provider Plug-ins
Cookies used by third-party content provider plug-ins are required to allow Users to access content or services provided by external providers.
Examples include:
- Watching videos hosted on YouTube.
- Viewing geographic locations through Google Maps.
- Viewing information about how many times a Website page has been rated through Google +1.
These cookies are governed by the respective cookie policies of the third-party providers.
Google Plug-in Cookies
Cari AI uses external Google plug-ins.
The use of these plug-ins involves the transmission of cookies.
For more information, please refer to Google’s information regarding how it uses cookies.
Information collected by external Google plug-ins on our Website, including the User’s IP address, may be transmitted to Google and stored on its servers.
This information is managed entirely by Google.
These cookies do not personally identify the User unless the User is signed in to a Google account, in which case the information may be associated with that Google account.
For further information, please refer to Google’s documentation regarding the types of cookies it uses.
Cari AI uses the Google Maps plug-in to display geographic locations, including our offices and other locations.
Certain areas of the Cari AI Website may also contain embedded YouTube videos.
Cookies implemented by Google on pages containing YouTube videos are used to measure the number and behavior of YouTube Users.
This may include information linking a visit to our Website with the User’s Google account where the User has an active Google session.
For additional information, please refer to Google’s Privacy Policy.
Social Media and Third-Party Cookies
These are cookies created by third parties that we use to allow Users to share Website content on social media platforms.
Twitter cookies are introduced through the “Share on Twitter” functionality whenever this module is used.
For additional information, please refer to Twitter’s privacy documentation.
LinkedIn cookies are introduced through the “Share” button.
These may include:
__qcabcookielangIN_HASHX-LI-IDCvisitNSC_MC_WT_FU_IUUQ
These cookies are used to track the pages visited by the User.
For additional information, please refer to LinkedIn’s Privacy Policy.
Google Plus, Google Maps, and YouTube
Google cookies are typically introduced when Google Plus, Google Maps, Street View, or YouTube video widgets are loaded.
These may include:
SIDAPISIDHSIDSAPISIDSSIDNIDPREFULS
For additional information, please refer to Google’s Privacy Policy.
Facebook cookies are introduced through the “Share on Facebook” functionality.
For additional information, please refer to Facebook’s Cookie Policy.
Intrusion Levels Associated with the Cookies We Use
The cookies described above are classified according to an “intrusion level” using a scale from 1 to 3.
Level 1
Cookies used internally that are strictly necessary to provide the service expressly requested by the User.
Level 2
Anonymous cookies used internally that are necessary for maintaining Website content and navigation.
This category also includes cookies managed by third parties in connection with services expressly requested by the User on those websites, such as:
- Facebook or Twitter social plug-ins.
- Embedded videos.
- Maps.
Level 3
Cookies managed by third parties in connection with services not expressly requested by the User and that may allow the User to be tracked across websites not owned by Cari AI, such as display advertising management platforms.
The party responsible for each Level 3 cookie will be identified.
The use of Level 3 cookies is subject to the User’s prior consent through express confirmation.
Review
These lists will be updated as promptly as possible whenever the services offered through the Website change or evolve.
However, during the updating process, the list may occasionally fail to include a specific cookie.
In all cases, any omitted cookie will have purposes identical or substantially similar to those already described in these lists.
End User License Agreement (EULA)
1. Acceptance of the Agreement
This End User License Agreement (“EULA”) is a legal agreement between you (the “User”) and Defytek, SAS and Defytek, S.A. de C.V. (the “Provider”) governing the use of the Cari AI suite software provided as a service (the “Software”).
By using the Software, you agree to be bound by the terms of this EULA.
2. Suite Components
The Cari AI suite consists of several components, including:
- A virtual assistant for building Chatbots, Voicebots, and Mailbots.
- Janus, the agent module.
- ION, which enables information extraction from documents.
- GIK, which uses Generative AI to build copilots or virtual assistants.
- Falcon, a workforce management tool.
Defytek may add new components or modify its product offering from time to time.
3. License
The Provider grants the User a non-exclusive, non-transferable, and revocable license to use the Software in accordance with the terms of this EULA.
This license is valid only while the User maintains an active subscription to the Software and remains current with all applicable contractual obligations.
4. Restrictions
The User may not:
a. Modify, translate, adapt, or create derivative works based on the Software.
b. Decompile, reverse engineer, disassemble, or otherwise attempt to derive the source code of the Software.
c. Rent, lease, lend, sell, sublicense, distribute, or transfer the Software to third parties.
d. Use the Software in any manner that violates applicable law, regulations, or third-party rights.
5. Intellectual Property
The Software is owned by the Provider and is protected by copyright laws and international treaties.
All rights not expressly granted under this EULA are reserved by the Provider.
6. Updates and Support
The Provider may, at its discretion, provide updates, enhancements, or support for the Software.
Any updates or enhancements provided to the User shall be deemed part of the Software and shall be subject to the terms of this EULA.
Support shall be provided in accordance with the applicable Service Level Agreement (SLA) and through the channels and procedures established therein.
7. Limited Warranty
The Software is provided “as is.”
The Provider does not warrant that the Software will be error-free or operate without interruption.
The Provider assumes no responsibility for any damage resulting from the use of the Software.
8. Limitation of Liability
To the maximum extent permitted by applicable law, the Provider shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits or revenue, whether incurred directly or indirectly.
The Provider shall also not be liable for any loss of data, use, goodwill, or other intangible losses resulting from the use of, or inability to use, the Software.
9. Confidentiality
You agree to keep confidential all confidential information belonging to the Provider that you obtain in connection with your use of the Software.
10. Termination
This EULA shall remain in effect until terminated.
The Provider may terminate this EULA at any time if the User breaches any of its terms.
Upon termination of this EULA, the User must cease all use of the Software and destroy all copies of the Software in the User’s possession.
11. Governing Law
This EULA shall be governed by and construed in accordance with the laws of the country in which Defytek has its registered domicile, which may be Colombia or Mexico.
12. Acceptable Use Policy
To ensure that the Services operate securely and without disruption, Users and Customers agree not to misuse them.
In particular, the Customer agrees not to:
- Probe, scan, or test the vulnerability of any system or network used in connection with the Services.
- Tamper with, reverse engineer, hack, or otherwise interfere with the Services.
- Circumvent any security or authentication measures associated with the Services.
- Attempt to gain unauthorized access to the Services, any portion thereof, or any related systems, networks, or data.
- Modify or disable the Services.
- Use the Services in any manner that interferes with or disrupts the integrity or performance of the Services or any related systems, networks, or data.
- Access or search the Services through any means other than our publicly supported interfaces.
- Copy, distribute, or disclose any portion of the Services through any medium, including through automated or non-automated scraping.
- Overload or attempt to overload our infrastructure by imposing an unreasonable burden on the Services that consumes extraordinary resources.
Examples of prohibited conduct include:
- Using robots, spiders, offline readers, or other automated systems to send more request messages to our servers than a human could reasonably send during the same period using a standard web browser.
- Substantially exceeding the usage parameters applicable to any particular Service, as described in the corresponding documentation.
13. Third-Party Tools
If the Services operate with or integrate third-party tools:
a. Defytek/Cari AI may share messaging data with the third-party provider as necessary to enable product interoperability.
b. Defytek/Cari AI shall not be responsible for any acts, omissions, services, applications, technologies, policies, or procedures of third parties, including those of the third-party provider or its tools.
c. The third-party provider may modify or discontinue its tool at any time.
14. Generative AI Terms
Defytek/Cari AI may use third-party Large Language Models (LLMs) to provide Generative AI functionality.
Such third-party technologies may use public cloud environments, APIs, and data centers to process Company Data.
Each third party is solely responsible for matters relating to its own services.
These technologies may generate inaccurate or fabricated outputs, commonly referred to as hallucinations.
Defytek/Cari AI will implement mechanisms designed to reduce or minimize such hallucinations.
15. General Provisions
If any provision of this EULA is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
This EULA constitutes the entire agreement between the User and the Provider regarding the use of the Software and supersedes all prior agreements or understandings, whether written or oral.
Acceptable Use Policy
Effective as of December 2, 2020
This Acceptable Use Policy applies to Cari AI services, including, without limitation, any successor URLs, mobile or localized versions, and related domains and subdomains, as well as communication and messaging products and services (collectively, the “Services”).
To ensure that the Services operate securely and without disruption, we require our Users/Customers to agree not to misuse them.
In particular, the Customer agrees not to:
- Probe, scan, or test the vulnerability of any system or network used in connection with the Services.
- Tamper with, reverse engineer, or hack the Services.
- Circumvent any security or authentication measures associated with the Services.
- Attempt to gain unauthorized access to the Services, any portion thereof, or any related systems, networks, or data.
- Modify or disable the Services.
- Use the Services in any manner that interferes with or disrupts the integrity or performance of the Services or any related systems, networks, or data.
- Access or search the Services through any means other than our publicly supported interfaces.
- Copy, distribute, or disclose any portion of the Services through any medium, including, without limitation, through automated or non-automated scraping.
- Overload or attempt to overload our infrastructure by imposing an unreasonable burden on the Services that consumes extraordinary resources.
Examples of prohibited conduct include:
- Using robots, spiders, offline readers, or other automated systems to send more request messages to our servers than a human could reasonably send during the same period using a standard web browser.
- Substantially exceeding the usage parameters applicable to any particular Service, as described in the corresponding documentation.
If the Customer wishes to evaluate the security of our products and services, Cari AI may, by mutual agreement, provide a dedicated testing environment based on the project currently being carried out with the Customer.
This testing environment may be used to perform authorized vulnerability assessments and penetration testing.
1. Purpose
Establish the principles, commitments, responsibilities, controls, and evidence governing the design, development, acquisition, integration, configuration, implementation, operation, monitoring, use, modification, and retirement of Artificial Intelligence (AI) systems, including Generative Artificial Intelligence (GenAI), at CARI AI.
This Policy consolidates the guidelines for Responsible AI, ethical use, and GenAI transparency, and establishes the specific Artificial Intelligence policy required to support the Integrated Management System aligned with ISO/IEC 42001:2023, without replacing the Integrated Management System Policy, which remains the overarching policy established by Senior Management.
2. Scope
This Policy applies to:
- All systems, functionalities, components, workflows, bots, Voicebots, virtual assistants, copilots, models, integrations, APIs, knowledge bases, prompts, outputs, evaluations, analytics tools, or automations using AI or GenAI that are developed, acquired, integrated, configured, commercialized, operated, or used by CARI AI.
- All CARI AI personnel, including employees, contractors, consultants, third parties, suppliers, subprocessors, and partners involved in any stage of the AI system lifecycle or interacting with AI systems on behalf of CARI AI.
- Customers and service administrators, where applicable under the shared responsibility model for functional configuration, supplied data, workflows, permissions, integrations, knowledge bases, authorized use, and deployment decisions within their instance.
- Internal and external systems, development, QA, and production environments, integrations with LLM providers, cloud services, communication channels, and AI-related support platforms.
- Operations delivered from Colombia and contractual, commercial, documentary, or billing activities associated with the legal entity registered in Mexico, where applicable.
Scope Note
- This Policy covers AI generally as well as GenAI. Where a control applies only to GenAI, LLMs, or generative models, this will be expressly indicated or applied proportionately according to risk.
- This Policy does not replace cybersecurity, privacy, DLP, access control, business continuity, backup, data deletion, or incident management policies. It supplements them specifically within the AI context.
3. Definitions
| Term | Operational Definition for CARI AI |
|---|---|
| AI | A system, component, or functionality capable of generating predictions, content, recommendations, classifications, assisted decisions, or automations based on data, rules, models, or algorithms. |
| GenAI | Generative Artificial Intelligence based on models capable of producing text, voice, images, code, classifications, summaries, or responses based on instructions, prompts, or context. |
| AI System | A combination of models, data, prompts, parameters, integrations, interfaces, guardrails, logs, processes, and responsibilities that enables an AI-based or AI-supported functionality. |
| AIMS | Artificial Intelligence Management System that integrates policies, objectives, processes, roles, risks, controls, evidence, auditing, and continual improvement to responsibly manage AI systems. |
| Prompt | An input, instruction, query, or context sent to an AI model or LLM to generate a response or result. |
| Response or Output | Content generated or returned by an AI system, including text, voice, labels, classifications, recommendations, or suggested actions. |
| Guardrail | A technical, functional, or content control that limits, filters, validates, blocks, alerts on, or corrects undesirable inputs, outputs, or behaviors of an AI system. |
| Human-in-the-loop / Human-on-the-loop | A mechanism for human supervision, intervention, validation, escalation, or monitoring of AI outputs, decisions, or exceptions. |
| AI Impact Assessment | A documented analysis of the potential effects of an AI system on individuals, customers, users, privacy, security, continuity, fairness, compliance, reputation, and rights. |
| External Model | A model, API, platform, service, or AI component provided by a third party and integrated directly or indirectly into CARI AI solutions. |
4. Reference Framework and Related Documents
This Policy is integrated with CARI AI’s Integrated Management System and with the specific policies supporting security, privacy, continuity, backup, access control, data deletion, and incident management.
| Document / Framework | Relationship to this Policy |
|---|---|
| UI-GI-Integrated Management System Policy | Senior Management framework policy declaring the IMS and the commitment to ISO/IEC 42001. |
| UC-PL-GI-Specific Cybersecurity Policy | Security-by-design technical controls, OWASP LLM, guardrails, prompt injection protection, Red Teaming, suppliers, and access controls. |
| PU-PL-GI-Specific Personal Data Protection Policy | Privacy principles and obligations, data Processing, Data Subject rights, and international transfers/transmissions. |
| UC-PP-GI-Data Loss Prevention | Classification, detection, monitoring, and information leakage prevention controls for data at rest, in transit, and in use. |
| UI-PL-GI-Specific Incident Management Policy | Incident management, communication, CSIRT, RCA, digital evidence, containment, eradication, and recovery actions. |
| UC-PP-IN-Cloud Architecture | Cloud architecture, high availability, encryption, monitoring, operational security, and integrations with cloud and LLM providers. |
| ISO/IEC 42001:2023 | Primary framework for establishing, implementing, maintaining, and continually improving the AIMS. |
5. Responsible AI Policy Statement
CARI AI is committed to designing, developing, acquiring, integrating, deploying, operating, and using AI and GenAI systems in a responsible, ethical, transparent, secure, reliable, and risk-proportionate manner, while respecting applicable legal, contractual, regulatory, privacy, information security, continuity, quality, and stakeholder rights requirements.
Senior Management, through the Integrated Management System, assigns responsibilities, resources, and authority to ensure that AI systems are governed throughout their lifecycle, maintain appropriate controls, generate auditable evidence, and are subject to monitoring, review, and continual improvement.
CARI AI prohibits the use of its AI systems for illegal, discriminatory, abusive, manipulative, fraudulent, violent, offensive, unauthorized purposes, or for purposes contrary to contracts, internal policies, individual rights, or valid customer instructions.
6. Responsible AI Principles
Responsibility and Accountability: Every AI system must have clearly defined owners for business, technology, security, privacy, operations, monitoring, changes, and evidence. Relevant decisions must be traceable and justifiable.
Human Oversight: AI is a support tool. It does not replace human responsibility in sensitive, critical, legal, regulatory, contractual, or high-impact matters. Human supervision, intervention, or escalation points must exist in proportion to risk.
Ethical, Lawful, and Non-Malicious Use: AI systems must be used exclusively for authorized and legitimate purposes aligned with CARI AI’s and its customers’ value proposition.
Transparency: Where applicable, users must be clearly informed that they are interacting with AI, of any recordings or logs, the system’s limitations, and the respective roles of CARI AI and the customer.
Proportionate Explainability: CARI AI will seek to explain, within technical and contractual limitations, the operation, criteria, sources, limitations, and results of AI systems according to the use case and risk level.
Fairness and Non-Discrimination: AI systems must be designed, configured, tested, and monitored to prevent, identify, and mitigate bias, discriminatory outcomes, or unjustified adverse impacts.
Privacy and Data Minimization: Data used in AI must be limited to what is necessary for the authorized purpose, protected by appropriate security and privacy controls, and Sensitive Data must not be used unless authorized, necessary, and properly controlled and documented.
Security by Design: AI systems must incorporate controls from the outset, including access control, encryption, environment segregation, guardrails, prompt and output protection, monitoring, and security testing.
Reliability, Robustness, and Continuity: AI systems must be tested and monitored to maintain availability, stability, accuracy, relevance, safe degradation, and recovery capability.
Traceability, Auditability, and Continual Improvement: Relevant activities must generate records and evidence. Findings, incidents, changes, audits, and feedback must contribute to the continual improvement of the AIMS.
7. Governance, Roles, and Responsibilities
CARI AI defines clear responsibilities for AI and GenAI governance. Detailed responsibilities must remain aligned with the specific Roles and Responsibilities Policy and the current RACI matrix.
| Role | Minimum AI/GenAI Responsibilities |
|---|---|
| Senior Management / General Management | Approve the Policy, assign authority and resources, define risk appetite, review AIMS performance, approve high-impact exceptions, and ensure continual improvement. |
| AIMS Manager / IMS Lead | Coordinate integration of the AIMS into the IMS, maintain evidence, objectives, and indicators, and coordinate management reviews, audits, and improvement plans. |
| Process Committee / AI Governance | Review risks, significant changes, impacts, incidents, suppliers, deviations, objectives, and relevant AI-related decisions. |
| Information Security Officer | Define and verify AI security controls, manage InfoSec/CyberSec risks, vulnerabilities, incidents, security guardrails, and customer security requirements. |
| Data Protection and Privacy Officer | Validate Personal Data Processing, lawful bases, minimization, transfers/transmissions, Data Subject rights, DPAs, and AI privacy risks. |
| Product Manager / AI Product Owner | Define purpose, limits, acceptance criteria, roadmap, product risks, AI functionalities, shared responsibility, and usage restrictions. |
| Technical Architect / Technology Lead | Define architecture, integrations, models, suppliers, technical security, environment segregation, monitoring, continuity, and technical operations. |
| Developers / Technical Team | Build, configure, and maintain AI components under secure development, traceability, testing, and version control standards. |
| QA / Tester | Perform functional, security, privacy, robustness, regression, bias, hallucination, relevance, and acceptance testing before production. |
| Cybersecurity Manager | Support adversarial testing, monitoring, threat detection, vulnerability assessment, OWASP LLM, and technical response to AI-related events. |
| Operations / Support | Monitor services, handle events, escalate incidents, preserve evidence, execute continuity procedures, and communicate with customers where applicable. |
| Sales / Presales / Customer Success | Communicate actual AI capabilities and limitations, document customer requirements, avoid promising unverified functionality, and manage expectations. |
| Customer / Service Administrator | Define workflows, data and classification, users, permissions, integrations, configurations, knowledge bases, and use of AI tools within its instance according to contract. |
| AI Suppliers and Subprocessors | Comply with contractual requirements, confidentiality, security, privacy, availability, training restrictions, and transparency regarding subprocessors. |
Governance and Compliance Framework
- Commitment to Responsible AI: CARI AI is in the process of obtaining ISO 42001:2023 certification, reinforcing our commitment to responsible Artificial Intelligence management standards.
- Two-Level Risk Management: Risk management is addressed at the Platform level, which operates under an ISO 27001-certified Information Security Management System (ISMS), and at the Application level, through an assessment module for periodic risk reviews specific to each implementation.
- Infrastructure and Global Compliance: Our infrastructure is hosted on AWS in the United States region, allowing us to inherit extensive compliance standards such as GDPR and CCPA through AWS Data Processing Agreements (DPAs). Third-party and supplier management follows rigorous processes under the ISO 27001 ISMS.
- Commitment to Responsible AI: CARI AI is in the process of obtaining ISO 42001:2023 certification, reinforcing our commitment to responsible Artificial Intelligence management standards.
- Two-Level Risk Management: Risk management is addressed at the Platform level, which operates under an ISO 27001-certified Information Security Management System (ISMS), and at the Application level, through an assessment module for periodic risk reviews specific to each implementation.
- Infrastructure and Global Compliance: Our infrastructure is hosted on AWS in the United States region, allowing us to inherit extensive compliance standards such as GDPR and CCPA through AWS Data Processing Agreements (DPAs). Third-party and supplier management follows rigorous processes under the ISO 27001 ISMS.
Shared Responsibility Model and Artificial Intelligence Controls
CARI AI’s commitment to Responsible Artificial Intelligence is based on a Shared Responsibility Model.
Because our platform allows customers to develop and deploy their own AI-powered bots, the role of Application Developer applies both to CARI AI, for the core development of the platform, and to the Customer, for the configuration and deployment of specific applications using AI tools.
Our controls and commitments are designed to support this model and provide a robust security and regulatory compliance framework at every level.
Application Developer Responsibilities and Controls — CARI AI and Customer
The decision to include available AI tools—AI Question Box with Options, AI Extractor, and GIK v2—within a workflow rests exclusively with the Application Developer.
The Application Developer is responsible for implementing and using the available control mechanisms.
- Control and Mitigation Mechanisms: CARI AI implements Guardrails and Evaluations to identify and control illegal, discriminatory, or harmful outcomes. The Application Developer is responsible for applying these mechanisms to prevent such situations.
- Immediate Interruption — Kill Switch: All applications include immediate interruption capabilities that may be activated through the administration interface by authorized users or through automatic rules designed to detect anomalies and trigger interruption.
- Remediation Plans: Tools such as Guardrails, Evaluations, and Conversation Logs are provided to detect AI-related incidents, allowing the Application Developer to activate the remediation plans considered appropriate.
- Code Integrity: We mitigate the risk of malicious code through periodic security scans, including SAST/DAST, and annual Ethical Hacking processes.
8. AI System Lifecycle Management
Every AI system or functionality must be managed throughout its lifecycle using controls proportionate to its risk, criticality, processed data, impact, and contractual or regulatory obligations.
| Stage | Minimum Controls and Evidence |
|---|---|
| Ideation / Opportunity | Define purpose, business need, stakeholders, intended use, restrictions, required data, expected benefits, and preliminary risks. |
| Design | Document architecture, data flows, model/provider, controls, guardrails, acceptance criteria, usage limits, shared responsibility, and transparency requirements. |
| Acquisition or Supplier Selection | Assess security, privacy, continuity, subprocessors, DPA, data location, use of prompts/outputs, training restrictions, and contractual terms. |
| Development / Configuration | Apply secure development, version control, environment segregation, RBAC, least privilege, sanitization, validations, and secrets protection. |
| Testing | Perform functional, integration, security, privacy, bias, robustness, hallucination, relevance, regression, Red Teaming, jailbreak, prompt injection, and acceptance testing. |
| Pre-Production Approval | Retain documented approval from product, security, privacy, and customer owners where applicable; record accepted residual risks. |
| Deployment and Operation | Monitor performance, quality, availability, deviations, incidents, complaints, costs, usage, logs, guardrails, and compliance with defined limits. |
| Significant Changes | Manage changes to models, prompts, knowledge bases, parameters, suppliers, integrations, data, guardrails, or architecture through the change management procedure. |
| Retirement or Deactivation | Define retirement, blocking, deletion, or migration criteria; revoke access, retain or delete data according to contract and applicable policy, and document closure. |
9. AI Risk, Impact, and System Classification Management
CARI AI identifies, assesses, treats, accepts, communicates, monitors, and reviews AI-related risks.
The depth of analysis depends on the potential impact on customers, end users, Personal Data, security, continuity, assisted decisions, reputation, compliance, and individual rights.
- Every AI system must be recorded in an inventory that includes its purpose, owner, AI type, provider/model, data processed, environment, applicable customers, criticality, controls, and status.
- An AI risk assessment must be performed before production deployment or significant changes and, where applicable, an AI Impact Assessment.
- Assessments must consider confidentiality, integrity, availability, privacy, bias, discrimination, hallucinations, harmful outputs, prompt injection, jailbreaks, data leakage, third-party dependency, misuse, and continuity.
- Residual risks must be accepted by the appropriate authority according to criticality and documented in the matrix or tool defined by CARI AI.
- Controls must be periodically reviewed and whenever relevant changes occur in technology, regulation, contracts, data, models, system behavior, or customer feedback.
| Classification Criterion | Examples of Factors to Evaluate |
|---|---|
| Impact on Individuals | End users, vulnerable populations, Sensitive Data, bias, discriminatory treatment, economic or reputational effects. |
| Impact on Customers | Critical customer processes, service channels, integrations, operational dependencies, service agreements. |
| Impact on CARI AI | Security, continuity, compliance, confidentiality, brand, costs, contractual obligations, auditing. |
| Level of Autonomy | Suggestion, decision support, partial automation, automatic execution, need for human oversight. |
| Data Processed | Personal Data, Sensitive Data, financial information, trade secrets, logs, recordings, historical data, knowledge bases, test data. |
| Model / Provider | Proprietary model, external model, LLM API, cloud provider, subprocessors, usage restrictions, data location, and retention. |
10. Data Management, Privacy, and DLP in AI
Our Data Processing Policy is clear: we do not share data with unauthorized third parties.
This Policy is the foundation of all our operations and applies to the use of any technology, including Generative AI.
All customer information is securely stored on Amazon Web Services (AWS) servers located in the United States, which comply with leading international data security and privacy standards.
When we use Generative AI models, whether proprietary or provided by third parties, we implement multiple layers of controls to ensure that customer data is not compromised:
- Data Subject Rights: Users may fully exercise their rights of access, rectification, deletion, and any other applicable rights regarding Personal Data collected through the virtual agent, in accordance with applicable data protection laws.
- Ethical Use of Voice and Language: We ensure that voice scripts and AI Agent-generated responses avoid aggressive, manipulative, offensive, or inappropriate language. Content guardrails are fundamental to this approach.
- No Use for Malicious Purposes: Our GenAI systems shall not be used to generate illegal content, promote misinformation, discrimination, violence, or any other harmful activity.
- Data Processing Agreements (DPAs): Before integrating technology from an external provider, we validate that robust Data Processing Agreements are in place, ensuring that the provider’s policies and contracted services prohibit the use of customer data to train models or for any other unauthorized purpose.
- Data Anonymization and Minimization: Where possible, we apply anonymization and pseudonymization techniques before data is processed by an AI model. This means removing or masking Personally Identifiable Information (PII) so that the processed data cannot be associated with a specific individual or organization.
- Implementation of Guardrails: We implement technical and content Guardrails. These controls operate in real time to:
- Prevent Data Leakage: Block Sensitive Data such as Personal Data, financial information, or trade secrets from being included in prompts sent to models or in model-generated responses.
- Ensure Relevance: Keep AI within the topics and functions defined for its business purpose, preventing inappropriate, out-of-context, or unauthorized responses.
- Subprocessor Control: Maintain strict oversight of subprocessors used by AI providers. We require full transparency and ensure that any third party involved complies with our security and privacy standards.
Use of Internal Knowledge Bases
Our Generative AI Copilot is designed to operate primarily using internal knowledge bases jointly developed and maintained by Cari AI and its customers.
This reduces the need to send large volumes of data to external systems because responses are generated from documentation and data that are internally provided and controlled.
For more detailed information, please refer to the Data Processing Policy and Privacy Notice published on our website.
11. Transparency, Explainability, and User Communication
- Explainability Mechanisms: CARI AI incorporates functionality that enables AI models to be asked for detailed explanations of the reasoning behind their responses. Please note that this capability requires specific reasoning models and may generate additional costs.
- Statement on AI Use at CARI AI: CARI AI provides a limited set of development tools that integrate Artificial Intelligence. These tools are the AI Question Box with Options, AI Extractor, and GIK v2. Accordingly, any application incorporating one or more of these tools is considered to be using AI. The decision to include any of these tools within a specific workflow rests exclusively with the Application Developer. None of these tools can be integrated into a particular workflow without the Developer’s explicit knowledge.
- Technical Confidentiality of Models:
- Public Models, e.g. OpenAI and Gemini: Model Cards are available in the official documentation of each provider.
- Internal Models Designed by CARI AI: Corresponding Model Cards may be provided to Developers upon direct request.
- Contractual Responsibility: Liability and indemnification matters are governed strictly by the clauses defined in the service agreement executed between the parties.
12. Security, Robustness, Guardrails, and Adversarial Testing
AI systems incorporate security by design and defense in depth.
Controls shall be applied according to system criticality, architecture, provider, processed data, and exposure to end users.
| Control Domain | Minimum Guidelines |
|---|---|
| Access Control | RBAC, least privilege, MFA for administrative access, traceability, periodic access reviews, and segregation of duties. |
| Prompt and Output Protection | Input sanitization, input/output guarding, Sensitive Data filtering, blocking of unauthorized content, and controlled logging. |
| Behavioral Guardrails | Domain restrictions, content policies, blocking of malicious instructions, toxicity controls, and prevention of illegal or discriminatory responses. |
| Robustness and Hallucinations | Relevance, accuracy, consistency, regression testing, confidence thresholds, safe degradation, and human escalation where applicable. |
| Adversarial Testing | Evaluations against prompt injection, jailbreaks, evasion, model denial of service, information leakage, instruction or data extraction, and tool abuse. |
| Vulnerabilities | Periodic security assessments, SAST/DAST where applicable, Ethical Hacking, remediation of findings, and remediation traceability. |
| Continuity | Business continuity and recovery plans, alternative providers, or safe degradation mechanisms according to service criticality. |
13. AI Suppliers, External Models, and Subprocessors
Every AI supplier, external model, API, library, channel, subprocessor, or AI service must be assessed before production use and periodically thereafter or whenever significant changes occur.
The assessment must include security, privacy, confidentiality, continuity, data location, subprocessors, certifications, incident history, terms of service, training restrictions, and available audit rights or evidence.
Contracts, DPAs, or equivalent terms must prohibit the use of customer data, prompts, responses, or knowledge bases for model training or other unauthorized purposes unless expressly and formally approved.
CARI AI must maintain traceability of AI suppliers used, their purpose, associated services, responsible owners, controls, and supporting documentation.
When a supplier changes relevant conditions, models, regions, subprocessors, or controls, the impact on customers, security, privacy, and continuity must be evaluated.
Below are the information security commitments provided by our LLM suppliers:
Google: Service Specific Terms | Google Cloud
AWS: AWS Service Terms
Azure: Microsoft Products and Services Data Protection Addendum (DPA)
14. Shared Responsibility Model with Customers
CARI AI provides the platform, controls, tools, documentation, and support services for AI management.
However, the Customer retains responsibility for functional configuration, data and its classifications, workflows, users, integrations, and usage decisions within its instance, according to the contract and service scope.
| Activity / Control | CARI AI Responsibility | Customer Responsibility |
|---|---|---|
| Platform and Infrastructure | Operate and protect the platform, cloud infrastructure, baseline controls, availability, and technical security within the contracted scope. | Use the platform in accordance with the contract, policies, security recommendations, and authorized configurations. |
| Workflow and Use Case Definition | Provide functionality, recommendations, and technical limits. | Define the purpose, content, workflows, rules, channels, and final use of the instance. |
| Data and Knowledge Bases | Protect information under the security, privacy, and DLP controls applicable to the service. | Classify, authorize, and provide appropriate, minimized, lawful, current, and relevant data for the use case. |
| Users and Permissions | Provide role, profile, administration, and traceability mechanisms. | Manage users, permissions, and internal responsibilities under the principle of least privilege. |
| Use of AI Tools | Implement available tools, guardrails, logs, evaluations, and controls. | Decide whether to incorporate AI tools into workflows, review results, and apply functional controls according to the Customer’s context. |
| End-User Transparency | Provide capabilities, documentation, and recommendations. | Define messages, notices, consent mechanisms, and communications to end users according to the Customer’s relationship with the Data Subject and applicable law. |
| Incidents and Deviations | Manage platform-related incidents and support analysis where applicable. | Promptly report events, errors, inappropriate responses, or incidents detected within the Customer’s operation. |
15. Monitoring, Incidents, Deviations, and Remediation
AI systems in production are monitored according to risk and criticality, including response quality, availability, errors, deviations, guardrail alerts, complaints, costs, behavioral changes, and security events.
Any AI-related incident, event, or deviation must be reported through the defined channels and managed in accordance with the Incident Management Policy.
AI incidents may include:
- Data leakage through prompts or responses.
- Discriminatory content.
- Harmful responses.
- High-impact hallucinations.
- Prompt injection.
- Jailbreaks.
- Unauthorized use.
- Availability impact.
- Tool abuse.
- Supplier failures.
- Guardrail deviations.
The response must document:
- Impact.
- Scope.
- Root cause.
- Containment.
- Eradication.
- Recovery.
- Communications.
- Evidence.
- Corrective actions.
- Lessons learned.
- Risk updates.
Where a deviation represents an unacceptable risk, CARI AI may activate interruption, blocking, safe degradation, rollback, guardrail adjustment, temporary withdrawal, or deactivation of AI functionality.
16. Auditable Evidence of the AIMS
To demonstrate compliance, CARI AI retains evidence proportionate to the scope, criticality, and risk of its AI systems.
At a minimum, where applicable, the following evidence will be maintained:
| Evidence | Expected Content |
|---|---|
| AI System Inventory | Name, purpose, owner, status, provider/model, data, customers, criticality, controls, review date. |
| AI Risk Assessment | Threats, vulnerabilities, impacts, likelihood, controls, residual risk, approval, and treatment plan. |
| AI Impact Assessment | Impact on individuals, privacy, security, fairness, continuity, customers, legal/contractual obligations, and mitigations. |
| AI Supplier Register | Security/privacy assessment, DPA, terms of use, training restrictions, subprocessors, and approvals. |
| Test Plan and Results | Functional, security, privacy, bias, hallucination, robustness, Red Teaming, acceptance testing, and findings. |
| Production Release Approval | Responsible parties, date, scope, accepted residual risks, version, implemented controls, and restrictions. |
| AI Change Log | Changes to models, prompts, knowledge bases, integrations, parameters, guardrails, suppliers, or architecture. |
| Monitoring and Indicators | Performance, quality, availability, alerts, deviations, complaints, incidents, and actions taken. |
| Incidents and RCA | Report, impact, root cause, actions, evidence, communications, closure, and lessons learned. |
| Training and Awareness | Attendance, content, assessments, campaigns, communications, and acknowledgment of responsibilities. |
| Management Review | AIMS results, risks, opportunities, objectives, audits, incidents, resources, and continual improvement. |
17. Training, Awareness, and Internal Use of AI
- CARI AI trains and raises awareness among employees and relevant third parties regarding responsible AI use, prompt security, privacy, confidentiality, bias, limitations, incidents, responsibilities, and prohibited uses.
- Employees must not enter confidential information, Personal Data, secrets, credentials, sensitive code, customer data, or unauthorized information into public or unapproved AI tools.
- Internal use of AI tools must be limited to approved tools, authorized business purposes, appropriate security controls, human review of outputs, and respect for Intellectual Property, confidentiality, and data protection requirements.
- AI-generated outputs must be validated before being used for decisions, external communications, customer deliverables, production code, contractual documents, or responses with significant impact.
- Responsible teams must promote good practices for secure prompting, source validation, output verification, use of authorized knowledge bases, and error reporting.
18. Non-Compliance and Exceptions
- Failure to comply with this Policy may result in corrective, disciplinary, contractual, or legal action according to the relationship of the individual or third party involved and the severity of the event.
- Any exception to this Policy must be documented, justified, risk-assessed, supported by compensating controls, assigned to a responsible owner, given a defined validity period, and approved by the appropriate authority.
- Tacit, permanent, or untraceable exceptions are not permitted for matters involving Data Processing, supplier use, security controls, customer authorizations, legal responsibilities, or protection of Sensitive Data.
- Exceptions must be periodically reviewed and closed once the underlying cause no longer exists or the associated risk is no longer acceptable.
Therefore, Cari AI provides its services to customers as a Software as a Service (SaaS) provider and uses Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) services to deliver those services.
This technical configuration does not change the fact that Cari AI acts as the Data Processor and that the data has not been transferred to a third party, even where it has been transmitted to the United States.
“When using the applications, information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.”
“When using the applications, information received from Meta APIs will comply with the Meta API Services User Data Policy, including the Limited Use requirements.”
Cari AI reads and stores public comments from Google and Meta applications. This data is used for reporting, analytics, and other purposes defined by our customers according to the services they use.