Skip to content
Kodvalley

Legal

AI policy

How we develop and use AI in line with the EU AI Act.

Last updated: 3 October 2026

This AI Policy explains how MB Kodvalley develops, uses and supplies artificial intelligence. It reflects Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (the AI Act), as amended by the Digital Omnibus on AI, together with the GDPR and our own principles for responsible AI. As a member of the REFEND Network for ethical AI, we apply these principles to our own products and to the work we do for customers.

1. Principles

  • Human oversight: AI supports people; it does not replace accountable human decisions in matters that significantly affect individuals.
  • Transparency: people know when they interact with AI and when content has been generated by AI.
  • Privacy and confidentiality: personal data and customer data are protected and are not used to train third party models.
  • Safety and security: AI systems are tested, monitored and protected against misuse, including manipulation of prompts and data.
  • Fairness: we assess data and outputs for bias and avoid discriminatory outcomes.
  • Accountability: every AI system has a named owner, documentation and a way to report problems.

2. Our roles under the AI Act

Depending on the situation, Kodvalley acts as:

  • a deployer when we use AI systems in our own work, for example coding assistants, document analysis or support tools;
  • a provider when we place our own AI features on the market, for example the AI assistant in Improj;
  • a development partner when we build AI systems for customers; the proposal then defines whether the customer or Kodvalley is the provider and which obligations each party assumes.

3. Prohibited practices

We do not develop, supply or use AI practices prohibited by Article 5 of the AI Act, including manipulative or deceptive techniques that materially distort behaviour, exploitation of vulnerabilities, social scoring, predicting criminal offences based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education (except for medical or safety reasons), biometric categorisation inferring sensitive characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement. We decline projects that would require such practices.

4. Transparency (Article 50 AI Act)

  • AI systems that interact directly with people, such as chat assistants, clearly inform users that they are interacting with AI, unless this is obvious from the context.
  • Synthetic audio, images, video and text generated by AI systems we provide are marked in a machine-readable format where technically feasible.
  • AI-generated or manipulated images, audio or video that resemble real persons, objects or events (deepfakes) are disclosed as such.
  • AI-generated text published to inform the public on matters of public interest is disclosed as AI-generated, unless it has undergone human review and a person holds editorial responsibility.

The content on kodvalley.com is written and reviewed by our team. Where we use AI tools to assist with drafting, a person reviews and takes editorial responsibility for the result.

5. High-risk AI systems

We currently do not place high-risk AI systems listed in Annex III of the AI Act on the market. If a customer project falls into a high-risk category (for example AI used in employment, education, credit scoring or critical infrastructure), we identify this at the start and agree in writing how the requirements will be met, including risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity, conformity assessment and registration. Under the Digital Omnibus on AI, these requirements apply from December 2027 for Annex III systems; we design such projects to meet them from the outset.

6. General-purpose AI models

When we build on general-purpose AI models from third parties, we select providers that publish the information required for downstream providers, offer contractual data protection commitments and, where possible, process data in the European Union. We document which models are used in each system.

7. Data and confidentiality

  • Customer data is used only for the agreed purpose and is not used to train third party models.
  • We prefer EU-hosted models and private deployments for confidential data.
  • Personal data in AI systems is processed in line with the GDPR, including data minimisation, purpose limitation and, where needed, a data protection impact assessment.

8. AI literacy

In line with Article 4 of the AI Act, everyone at Kodvalley who works with AI systems receives training appropriate to their role on how the systems work, their limitations, risks and the rules in this policy. Training is refreshed at least once a year.

9. Testing and security

Before release, AI features are evaluated against representative test sets for accuracy and harmful outputs. Our security team tests them against prompt injection, data leakage and misuse. After release, we monitor quality and incidents.

10. Use of AI in our services

  • Improj: the AI assistant summarises project status and suggests next steps. Suggestions are labelled as AI-generated and are never applied without a user's action.
  • Software and AI projects: we classify each AI use case under the AI Act at the start of the project and document the result.
  • Security testing: AI tools may assist our testers; every finding is verified manually before it is reported.

11. Reporting concerns

If you believe an AI system provided or used by us causes harm or does not follow this policy, contact legal@kodvalley.com. We investigate every report and respond within 30 days. Serious incidents are reported to the competent authorities where required. In Lithuania, the Communications Regulatory Authority (RRT) is the market surveillance authority for the AI Act.

12. Review

We review this policy at least once a year and when the legal framework changes.

Questions about this document?

MB Kodvalley · Laisvės pr. 60-1107, Vilnius, Lithuania

legal@kodvalley.com