AI Terms of Use
Effective Date: 16 September 2026
Phocas Group (Phocas or We or our) uses artificial intelligence (AI) in Phocas products and services to enhance functionality, improve efficiency, and deliver meaningful value to our customers. Phocas believes AI should be deployed in a manner that is responsible, transparent, and aligned with our customers’ expectations for security, reliability, and control.
These AI Terms supplement the Phocas End User License Agreement, or such other agreement entered between customer and Phocas.
While AI can improve outcomes, it also introduces new and evolving risks, including risks related to accuracy, bias, security, and unintended outputs. Phocas has implemented technical, contractual, and organisational controls to manage these risks as part of our broader trust, security, and governance framework.
These AI Terms govern: (i) how we use AI in our products and services; (ii) how we protect customer data in connection with AI; and (iii) the rules governing the use of AI-enabled features. They are also intended to provide customers with clear, accurate, and practical information about how AI operates within our products and the safeguards that apply.
Customers remain responsible for evaluating and validating AI-generated outputs before relying on them, particularly in connection with business critical, legal, financial, or operational decisions.
Design and Deployment. We design and deploy AI in accordance with the following principles:
(a) Transparency: Customers are informed when AI is used in a material way.
(b) Human Accountability: AI augments, but does not replace, human judgment in high impact scenarios.
(c) Privacy and Security: Customer data is protected through strict technical and contractual safeguards.
(d) Fairness and Non Discrimination: AI systems are designed and monitored to reduce bias and harmful outcomes.
(e) Reliability and Safety: AI outputs are tested, monitored, and continuously improved.
(f) Governance: AI use is subject to cross functional governance, risk based approvals, and periodic review.
(g) Risk Based Approach: AI systems are classified and governed based on their potential impact and risk profile.
(h) Security and Privacy by Design. AI systems are developed with embedded security and privacy safeguards throughout their lifecycle.
(i) External validation and standards alignment. We align, where applicable, with industry best practices and applicable laws (e.g. EU AI Act).
These principles are implemented through internal controls and oversight designed to ensure that AI systems are appropriate for their intended use and risk profile.
How We Use & Incorporate AI In Phocas Products and Services. We primarily use AI for assistive, augmentative, or advisory purposes, designed to enhance, not replace, human decision making. AI is not used for fully autonomous decision making that produces legal, financial, employment, or similarly significant effects unless explicitly disclosed and subject to appropriate safeguards. Examples of our use cases include:
(a) content generation, summarisation, and recommendations;
(b) data analysis, forecasting, and insights;
(c) workflow automation and decision support;
(d) customer support and conversational interfaces; and
(e) other domain specific capabilities as described in applicable product documentation.
AI may generate outputs, recommend outcomes or actions, prioritise or rank information, assist with decision making, or automate certain processes depending on the feature or functionality.
Monitoring and Continuous Improvement. We monitor AI systems for accuracy and performance, bias and unintended outcomes, incident response triggers, and misuse. We maintain processes to detect, respond to, and remediate AI-related incidents, including unintended outputs, bias, or security vulnerabilities. We use customer feedback, human review cycles, testing, and monitoring to improve AI systems over time. Customers may report concerns, errors, or unexpected outputs through our support channels, which are incorporated into our monitoring and improvement processes.
We Are Committed to Transparency & Disclosure
(a) We provide clear and conspicuous disclosure when users interact with AI systems where such use is not reasonably apparent.
(b) AI-generated outputs may be labelled, annotated, or otherwise identified, including through user interface indicators or contextual disclosures, where appropriate.
(c) We do not misrepresent AI-generated content as human generated.
(d) Representations regarding AI capabilities are accurate, substantiated, and not misleading, consistent with regulatory expectations.
AI Limitations. Innovation concerning AI is occurring quickly and providing significant benefits to our customers.
(a) Although AI can improve productivity and insights, it does not replace human judgment. All AI has limitations and hallucination risks, and its accuracy and reliability should be considered accordingly given that AI outputs are probabilistic and may be inaccurate, incomplete, misleading or otherwise unsuitable for any particular purpose, and Phocas makes no warranty or representation as to the accuracy, reliability, completeness or fitness for purpose of any Output. Further, AI-generated content should not be relied upon without appropriate review, particularly for business critical, legal, financial, or operational decisions.
(b) For higher risk use cases of AI in our product, we implement enhanced controls, including:
(i) testing and validation;
(ii) monitoring and performance review; and
(iii) human oversight where appropriate.
(c) We do not guarantee that AI outputs are error free or suitable for all use cases.
When used appropriately and with human oversight, AI can enhance productivity, insight generation, and decision support. Our approach is designed to enable responsible innovation where we leverage the benefits of AI while implementing enterprise grade safeguards that support trust, reliability, and accountability.
AI outputs are provided for informational and assistive purposes only and are not intended to constitute legal, financial, or professional advice.
We design AI systems to include appropriate human-in-the-loop mechanisms, particularly for higher risk use cases. Where applicable, customers may:
(a) review, edit, or override AI-generated outputs;
(b) request human assistance; or
(c) escalate or challenge AI-generated outcomes.
Certain safeguards may be enabled by default, while others may be configurable depending on the specific feature and product design.
AI systems are not intended to replace human decision making in contexts involving material risk (financial, legal, employment, pricing, and other regulated data).
Customers are responsible for determining whether and how to enable features that utilise AI within their environment, including configuring settings, access controls, and review processes consistent with their internal policies and risk tolerance.
Where technically feasible, we maintain documentation and governance processes that support traceability and auditability of AI systems.
Where appropriate or required by law, we provide customers with meaningful information regarding:
(a) how AI-generated outputs are produced;
(b) key factors influencing outputs; and
(c) known limitations of the system.
At an appropriate level of abstraction, we maintain internal documentation describing AI system design, intended use limitations, and evaluation metrics.
We implement controls to support appropriate oversight and auditability of AI system behaviour in a manner consistent with data minimisation and security requirements.
Subject to applicable agreements, we may provide customers with information reasonably necessary to support their compliance, audit, or risk assessment requirements related to AI features.
We may process customer data as inputs to AI systems to generate outputs requested by the customer. We do not use customer data, inputs, or outputs to train or fine tune AI models unless explicitly permitted by our contract with the customer. Where applicable, we apply controls to limit the reuse of customer derived data and outputs for model improvement, including technical and contractual restrictions designed to prevent unauthorised use.
We apply data minimisation principles and limit data use to what is necessary for the functionality provided.
Customers are responsible for ensuring that data they input complies with applicable laws and their own internal policies.
We do not sell customer data, including data processed in connection with AI features. We do not disclose customer data to third parties for their independent marketing, advertising, or data monetisation purposes. Any sharing of data with service providers is performed solely to deliver and support our products and services, subject to contractual data protection obligations.
Phocas’ processing of Customer Data in connection with the product features that utilise AI is governed by the Phocas’ Data Processing Addendum.
We may use third party AI technologies as part of our products. AI vendors are subject to internal security, privacy, and compliance review appropriate to the role they play in delivering the service.
We also implement contractual safeguards to ensure vendors do not use customer data for unauthorised purposes, provide appropriate data protection commitments, and comply with applicable laws.
If any AI vendor is a sub-processor under applicable data protection law, we will disclose them to you.
We will evaluate material changes to vendor AI technologies, including changes to models, features, or data handling practices, to ensure continued alignment with our security, privacy, and compliance requirements.
AI features embedded in our products are designed to be transparent, reliable, and subject to appropriate controls. Where AI outputs may materially impact customers, outputs are subject to validation or oversight and human review mechanisms are available.
Certain features that utilise AI may be optional or configurable, while others may be embedded within core product functionality. Where feasible, we provide customers with the ability to enable, disable, or configure AI-driven features.
Customer agreements, product documentation, and disclosures (e.g. labelling, user interface indicators, disclaimers at point of use) accurately reflect the role of AI in the product, limitations of AI outputs, and our data usage practices.
AI capabilities within our products may include different types of systems, such as generative AI (e.g., content generation), predictive or analytical models (e.g., forecasting), and automation tools (e.g., workflow assistance). These systems may operate differently and present different risk profiles. We apply controls appropriate to the nature, purpose, and impact of each type of AI functionality.
AI-related data is retained only as necessary for functionality, compliance, and improvement.
We implement controls that may include: data retention and deletion, anonymisation and aggregation, and monitoring appropriate to the feature and risk profile.
We maintain safeguards to prevent unauthorised access, misuse, or disclosure of data.
We ensure that our AI-related practices are aligned with and governed by our broader information security and data protection programs, which includes SOC2 compliance.
We maintain processes to detect, investigate, and respond to AI-related incidents, including those involving data security, unintended outputs, or system misuse. Where required by applicable law or contract, we will notify affected customers of material incidents involving their data or use of AI features, consistent with our incident response and data breach notification obligations.
Customers are responsible for using features that utilise AI in a lawful and responsible manner. Misuse may expose customers to legal/regulatory risk and/or may impact system integrity.
Customers may not use AI features to:
(a) engage in unlawful, harmful, or fraudulent activities;
(b) generate or distribute content that is:
(i) abusive, harassing, or discriminatory;
(ii) materially misleading or deceptive;
(iii) infringing on intellectual property rights;
(c) develop or support:
(i) harmful activities;
(ii) exploitation or abuse of individuals;
(iii) unauthorised surveillance or biometric identification;
(d) create or disseminate:
(i) manipulated content intended to mislead;
(ii) profiling or targeting based on protected characteristics;
(e) make or automate decisions that have legal, financial, employment, pricing, or similarly significant effects without appropriate human oversight;
(f) attempt to reverse engineer, extract, or misuse AI models or underlying systems;
(g) attempt to exploit vulnerabilities in AI systems, including prompt injection or adversarial inputs;
(h) input or process data in violation of applicable laws or contractual obligations; or
(i) use AI outputs in a manner that violates applicable laws or regulations.
Customers will ensure that all authorised users and other personnel involved in the operation, oversight or use of AI features maintain a sufficient level of AI literacy, having regard to their technical knowledge, experience and the context in which the AI features are used, as required by applicable law.
Phocas will have no liability, howsoever arising, whether in contract, tort, negligence or otherwise, for any loss or damage arising from the Customer’s or reliance on, or use of, any AI-generated output.
AI Features are not subject to any service level commitments that may apply to other Phocas products or services.
The customers use of Phocas AI is subject to the liability provisions in the End User License Agreement. Phocas is not responsible for decisions the customer makes on the basis of output generated by any AI features, or for customer’s failure to comply with its obligations under applicable law in connection with customer’s deployment or use of those services.
Violations of these AI Terms may result in:
(a) suspension or termination of access to AI features;
(b) restriction of functionality; or
(c) other actions consistent with applicable agreements.
We reserve the right to investigate suspected violations and take reasonable and proportionate action to protect Phocas systems, customers, and users. Customers agree to cooperate in reasonable investigations of violations.
Violations may constitute a breach of applicable customer agreements.
AI is subject to evolving legal and regulatory requirements. We monitor applicable laws, regulations, and industry standards and will update Phocas practices and these AI Terms as necessary to maintain compliance and reflect emerging expectations.
We may update these AI Terms periodically to reflect changes in technology, applicable law, or Phocas practices. Where required by law or where changes are material, we will provide notice to customers in accordance with applicable agreements. Updates will be posted on the Phocas website and become effective as specified in the notice.
For questions regarding this Policy or Phocas’ use of AI, contact us at legal@phocassoftware.com.
Understand the past, operate better today, and plan well for the future