Legal

AI Terms

How agent and model-assisted features work, what leaves the workspace, who owns the output, and what you remain responsible for.

Last updated: 4 September 2026

These AI Terms form part of the Customer Terms of Service and apply whenever you use an AI feature of SalexHub — the assistant, specialised agents, drafting, extraction, classification, search over your workspace, or an automation step that calls a model.

1How AI features work

An AI feature runs when you invoke it — directly, on a schedule you set, or through an automation you enabled. When it runs:

  1. It acts as a principal. An agent runs on behalf of a specific person or API key and inherits exactly that principal's permissions. It cannot read a record, field or file that the principal could not read, and cannot take an action the principal could not take.
  2. It assembles context. The instruction, the records in scope, retrieved documents and prior turns of the conversation are gathered — filtered by those same permissions.
  3. It calls a model provider. That context is sent to a model provider acting as our subprocessor, or to a provider whose key you supplied.
  4. It produces output, and may propose actions. Depending on your configuration, a proposed action is executed immediately or held for human approval.
  5. It is recorded. The run, the tools it called, the records it touched and the credits it consumed are written to your workspace so the work can be audited.

2Model providers and training

Current providers are listed on the Subprocessors page. We may change providers or models, subject to the notice obligations in the DPA.

Our providers are contractually barred from training their models on data we send them on your behalf. We do not use your workspace data to train our own models, and we do not sell it.

Providers may retain content briefly for abuse monitoring under their own terms; retention in our platform is described in the Privacy Policy.

Different providers and models produce different results, cost different amounts of credits, and may have different capability limits. We select defaults for quality and cost, and expose the choice where the product allows it.

3Output

Accuracy. Output is produced by statistical models. It can be plausible and wrong, incomplete, out of date, or unsuitable for your purpose. It may misread a record, invent a detail, or summarise something that is not there. Treat every output as a draft until you have checked it.

Ownership. As between you and us, and to the extent permitted by law, you own the Output generated for your workspace. Output is not unique: similar inputs may produce similar Output for other customers, and we make no claim that Output is protectable or free of third-party rights.

Not professional advice. Output is not legal, tax, accounting, financial, medical, employment or other professional advice, and must not be relied on as such.

Your responsibility. You are responsible for reviewing Output before acting on it or sending it to anyone, and for the consequences of doing so — including messages an agent drafts, records it changes, and commitments made in a document it produced.

4Human oversight and autonomy

The product is built so that agents propose and people decide. You control where that line sits:

  • Actions can require explicit human approval before they execute.
  • Some classes of action are always held for approval and cannot be automated away — including actions that change billing, permissions or people's access.
  • Where you disable approval for a class of action, agents act autonomously within the permissions of their principal, and you accept the consequences.
  • Every action taken by an agent is attributed to it in the audit trail, so a change is never anonymous.

You must keep meaningful human review for decisions that significantly affect individuals — employment, credit, housing, insurance, education, or access to essential services. See the Acceptable Use Policy.

5Untrusted content and prompt injection

Agents read content that neither you nor we wrote: inbound email, web pages, uploaded documents, form submissions, and data returned by connected systems. Such content can contain text crafted to manipulate an agent — instructions to exfiltrate data, to message someone, or to take an action you did not intend.

We design agents to treat that content as data, not instruction, and to act only within the permissions of their principal. No such defence is complete. You reduce the residual risk by granting agents the narrowest permissions that let them work, and by keeping human approval on consequential or irreversible actions.

Report suspected manipulation of an agent to us as a security issue.

6Prohibited and high-risk uses

In addition to the Acceptable Use Policy, you must not use AI features:

  • to generate content that is unlawful, deceptive, defamatory, or that impersonates a specific real person;
  • to produce or distribute bulk unsolicited outreach dressed as individual correspondence;
  • to make automated decisions with legal or similarly significant effects on a person without human review and the disclosures the law requires;
  • in safety-critical settings — medical diagnosis or treatment, control of vehicles or machinery, emergency response, or critical infrastructure;
  • to infer special categories of personal data about individuals, including health, beliefs, sexual orientation or political opinion; or
  • to extract our system prompts, model configuration, another tenant's data, or credentials.

7Customer-supplied provider keys

Where the product allows it, you may configure your own model-provider key. In that case the processing performed under your key is governed by your agreement with that provider; our commitments about training, retention and subprocessing apply to our own providers, not to yours. You are responsible for the cost, limits and compliance of that provider.

Provider keys you supply are encrypted at rest and used only to serve requests from your workspace.

8Credits, limits and availability

AI features are metered in Credits, as set out in the Customer Terms of Service and the Product Specific Terms. Model providers impose their own rate limits and may be temporarily unavailable; an AI feature can therefore fail or slow independently of the rest of the platform.

Where a run fails because of a defect in our service, we re-credit the Credits it consumed on request. We do not re-credit runs whose output you simply did not find useful.