Data Governance, Risk & Compliance Policy
IuVeAI / iuve.eu
Version: 1.0
Effective date: 26 August 2026
Service: https://www.iuve.eu/
Operator
Project Developer: Iurie Verejan
Legal Company / Operator: RECLAMA-VEREJAN I.I.
DNO / Cod: 1003600053323
Address: MD-2042, Moldova, CHISINAU CIOCANA, mun. Chisinau, Alecu Russo, 24/2
Support: hello@iuve.eu
This Data Governance, Risk & Compliance Policy (“DGRC Policy”) complements the Privacy Policy, Terms of Use, Cookie Policy, Acceptable Use Policy, and AI and Model Training Policy. Where a more specific policy establishes stricter protection, the stricter requirement prevails unless prohibited by law. This Policy does not replace the Privacy Policy for data-subject rights procedures.
1. Purpose
This DGRC Policy establishes the governance framework used by IuVeAI to manage user and workspace data; artificial intelligence systems and models; AI model providers; local and cloud inference; API integrations; autonomous and semi-autonomous agents; connected devices; access permissions; security risks; model and operational risks; auditability; and legal and regulatory compliance.
The objective is to ensure that IuVeAI operates according to privacy, security, accountability, transparency, data minimisation, human control, and risk-proportionate AI governance.
2. Scope
This Policy applies to IuVeAI services and components operated through or connected to iuve.eu, including IuVeAI Chat; the Iulia AI assistant; AI model routing and inference; local AI models; external AI providers; API access; files and document processing; voice input and output; STT and TTS; GitHub integrations; repositories and coding tools; IuVe Connect; Desktop Agent; Avatar and local automation; device pairing; Semantic Marketing; Website Agent; Marketplace integrations; Genesis CMS AI integrations; team workspaces; administrative systems; and monitoring and security systems.
It applies to administrators, developers, employees, contractors, service providers, AI agents, and automated processes that access IuVeAI-controlled systems or data.
3. Governance Principles
3.1 Privacy by Default
Private workspace information must remain private by default. Access may occur only where required to provide a user-requested function, maintain system security, comply with law, or perform an explicitly authorised administrative action.
3.2 Data Minimisation
Only information reasonably necessary for the requested operation may be collected, transmitted, or retained.
3.3 Purpose Limitation
Information collected for one purpose must not automatically be reused for an unrelated purpose.
3.4 Least Privilege
Users, services, API keys, agents, and administrators must receive only the permissions required for their task.
3.5 Explicit Authority
An AI agent does not gain authority merely because it can technically perform an action. Authority must derive from user permission, workspace configuration, administrator policy, an approved capability grant, or another documented source of authority.
3.6 Human Control
Actions capable of producing significant financial, legal, security, privacy, or operational consequences must remain subject to appropriate human control.
3.7 Traceability
Security-sensitive and agent-executed operations should be attributable to a user, service, API key, model, agent, or system process.
3.8 Fail Secure
When identity, authority, policy, or execution status cannot be reliably determined, the system should default to the safer state.
4. Data Classification
IuVeAI uses four primary data classifications.
PUBLIC
Information intended for public disclosure (for example public website content, public documentation, public Marketplace listings, and public articles). Public information may be processed by authorised IuVeAI systems without additional confidentiality restrictions.
INTERNAL
Operational information not intended for unrestricted public disclosure (for example internal metrics, system configuration, non-sensitive operational logs, and internal documentation). Access should be limited to authorised systems and personnel.
CONFIDENTIAL
Information associated with a user, workspace, organisation, or private activity (for example conversations, uploaded files, repository content, source code, private notes, project information, voice transcripts, agent execution context, and customer information). Confidential data must not be disclosed to unrelated users or services.
RESTRICTED
Information requiring the highest protection (for example passwords, private keys, authentication secrets, access tokens, API secrets, session credentials, recovery credentials, payment authentication information, and highly sensitive personal information). Restricted information must not be intentionally used as AI training data. Where technically possible, Restricted information should be detected, redacted, masked, or blocked before transmission to an AI model or external provider.
5. Data Lifecycle Governance
IuVeAI governs data throughout: Collection → Classification → Processing → Storage → Access → Transmission → Retention → Deletion.
For every material category of data, IuVeAI should be capable of identifying why the information is processed; which service processes it; its classification; where it is stored; who or what may access it; whether it is sent to a third party; applicable retention rules; and deletion mechanisms.
6. AI Model Governance
Every model integrated into IuVeAI should have an identifiable governance record. The record may include model name, version, provider, deployment location, intended use, capabilities, known limitations, context limits, applicable safety restrictions, data handling characteristics, evaluation results, routing priority, and fallback conditions. Material model changes should be versioned and auditable.
7. Local and Cloud AI Processing
IuVeAI may use local models, self-hosted infrastructure, and external AI providers. Routing decisions may consider user configuration, task type, model capabilities, privacy requirements, latency, availability, cost, safety, context requirements, resource availability, and quality thresholds.
Where local processing is configured or required, IuVeAI should prefer approved local execution before transmitting private information externally. Cloud fallback must not silently override an explicit privacy or local-only restriction.
8. External AI Providers
External AI providers must be treated as third-party processing services. Before production use, IuVeAI should evaluate, where applicable, data processing terms, retention practices, training policies, security controls, geographic processing location, availability, model capabilities, regulatory implications, and incident history.
Sensitive information must not be transmitted to an external AI provider merely because that provider produces a higher-quality response. Privacy and authority requirements take precedence over model quality.
9. Model Training and Continual Learning
Private workspace information must not automatically become training data. IuVeAI distinguishes between inference data, operational telemetry, evaluation data, approved learning examples, and training datasets. Moving information from one category to another requires a defined lawful and technical basis.
Community or product-improvement training based on private user conversations remains opt-in, as specified in the AI and Model Training Policy. Opting out of training must not prevent ordinary inference necessary to provide the requested AI service. Restricted information must not be included in training datasets.
10. Continual Learning Governance
Automated or continual learning systems must not directly modify production behaviour without controlled validation. A learning lifecycle should follow: Capture → Sanitise → Evaluate → Train → Test → Canary → Verify → Approve → Deploy.
Training success alone is not sufficient for production deployment. A new model, adapter, rule, or learned behaviour must pass applicable quality, security, and regression gates before production activation. Production rollback must remain possible.
11. AI Agent Governance
IuVe Connect, Desktop Agent, Avatar, and other agents operate under explicit capabilities. Agents must not assume unrestricted device or account control. Capability categories may include file access, application control, browser interaction, terminal execution, repository access, network actions, system configuration, clipboard access, and external communication. Capabilities must be limited by user or administrator grants. High-impact capabilities should support revocation and audit logging.
12. Agent Action Classification
Tier 0 — Read Only (inspect, search, analyse, summarise): normally executable without additional confirmation when already authorised.
Tier 1 — Reversible (create a draft, create a temporary file, change reversible application state): may execute under an approved capability grant.
Tier 2 — Material Change (modify project files, deploy software, change configuration, update production resources): requires stronger authority verification and appropriate safeguards.
Tier 3 — High Impact (delete important data, send financial transactions, expose credentials, change security policy, grant administrative privileges, perform irreversible operations): must not be executed solely because an AI model recommends the action. Additional human authorisation or an explicitly pre-approved policy is required.
13. Separation of Reasoning and Authority
AI-generated reasoning is advisory. A model response does not itself constitute permission. The execution layer must independently verify actor identity, capability grant, policy, execution scope, environment, and applicable safety restrictions.
14. Human Oversight
IuVeAI must preserve meaningful human oversight for material automated decisions. Users should be able, where technically applicable, to review proposed actions, reject actions, revoke permissions, stop an agent, inspect execution results, and report incorrect behaviour.
15. AI Transparency
Users must be able to understand when they are interacting with an AI system rather than a human. Where required by applicable law and technically appropriate, AI-generated or AI-manipulated content must support appropriate disclosure or machine-readable identification. IuVeAI must not intentionally represent an artificial system as a human individual in circumstances where doing so would materially mislead the user.
16. High-Risk and Prohibited Uses
IuVeAI must apply additional controls to AI uses capable of materially affecting employment, credit, insurance, healthcare, legal rights, biometric identification, public services, critical infrastructure, law enforcement, or financial assets. Functionality falling into regulated or prohibited categories must undergo specific legal and risk assessment before deployment. The availability of a capable model does not automatically authorise such use.
17. Automated Decision Making
Where an AI system assists with consequential decisions, the system should clearly distinguish between information retrieval, recommendation, scoring, automated decision, and execution. Where legally required, users must have access to human review or another appropriate contestability mechanism.
18. Security Governance
IuVeAI applies risk-based security controls including, where appropriate: encryption in transit; secure password hashing; API-key protection; secret separation; authentication; role-based access control; rate limiting; session protection; audit logging; dependency management; vulnerability remediation; backups; recovery controls; and service monitoring. Security controls must be periodically reviewed against changes in architecture and threat models.
19. Secrets Management
Secrets must not be stored directly in public repositories, frontend JavaScript, public logs, training datasets, analytics payloads, or ordinary chat history. API keys and credentials should be scoped, revocable, and separated by purpose. IuVe Marketplace license keys (mp_live_*) and IuVeAI API credentials (kai_live_*) must remain logically separated.
20. Access Governance
Access decisions should be based on authenticated identity and role. Privileged access should follow: Identity → Authentication → Role → Scope → Policy → Action. Administrative access must not be granted solely through possession of a public identifier. Privileged actions should be auditable.
21. Third-Party Integrations
Connected services such as GitHub and external APIs must operate using only permissions required for the requested functionality. Integration credentials must be revocable. Removing an integration should terminate future access wherever technically possible. Third-party integration does not grant IuVeAI ownership of third-party content.
22. Data Transfers
When personal or confidential information is transferred to a third party or another jurisdiction, IuVeAI should assess applicable privacy and contractual requirements. Where required, appropriate safeguards must be established before the transfer.
23. Logging and Audit
IuVeAI may maintain security and operational audit records necessary to establish who performed an action; which service or agent executed it; when it occurred; which capability was used; whether the action succeeded; whether approval was required; and relevant security events. Audit logs themselves must be protected against unauthorised modification and disclosure. Logs should not unnecessarily contain full secrets or confidential payloads.
24. Risk Management
IuVeAI uses a risk-based approach. Risks may include privacy risk, cybersecurity risk, model hallucination, prompt injection, data leakage, privilege escalation, malicious tool use, supply-chain compromise, provider outage, model degradation, incorrect autonomous action, regulatory risk, and reputational risk. Risk is assessed according to Likelihood × Impact × Exposure. Controls should be proportional to the resulting risk.
25. AI Risk Register
Material AI components should be represented in an internal AI Risk Register. Each record may contain system, owner, model, purpose, affected users, data categories, risk classification, known risks, mitigations, evaluation status, deployment status, and review date.
26. Privacy Impact Assessment
A privacy or AI risk assessment should be conducted before deploying functionality likely to create materially increased risk to individuals, including large-scale profiling, biometric processing, sensitive personal information, automated consequential decisions, continuous monitoring, or significant new third-party data transfers.
27. Security Incident Management
A suspected security or privacy incident must be: Detected → Contained → Investigated → Assessed → Remediated → Documented. Where legally required, affected persons or competent authorities must be notified within applicable deadlines. Incident evidence should be preserved sufficiently to support investigation.
28. AI Incident Management
AI incidents include material events involving unsafe autonomous execution, significant confidential-data disclosure, systematic harmful output, security-control bypass, material model malfunction, or unauthorised agent action. AI incidents must be evaluated separately from ordinary application errors when the AI behaviour materially contributed to the event.
29. User Rights and Control
IuVeAI should provide mechanisms required by applicable data protection law for users to exercise relevant rights regarding their personal information, which may include access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Identity verification may be required before fulfilling a request involving private account information. Procedural details are set out in the Privacy Policy.
30. Data Retention
Information should not be retained indefinitely without a defined purpose. Retention periods may vary according to service functionality, account configuration, security requirements, contractual requirements, legal obligations, and user deletion requests. Deletion from active systems may not immediately remove information from protected backups where temporary retention is technically necessary for disaster recovery.
31. Data Deletion
Deletion procedures should address applicable copies in primary databases, file storage, conversation storage, vector or search indexes, caches, derived datasets, training candidate datasets, and backups where technically and legally appropriate. Deleting a user-visible object should not leave an undisclosed active copy used for unrelated processing.
32. Compliance Framework
IuVeAI seeks to operate consistently with applicable requirements and recognised principles including, where relevant: the EU General Data Protection Regulation; the EU Artificial Intelligence Act; applicable Moldovan data protection requirements; contractual data-processing obligations; privacy-by-design and security-by-design principles; and applicable intellectual-property and copyright rules. Applicability depends on the relevant service, processing activity, jurisdiction, and role of IuVeAI.
33. Relationship With Other IuVe Policies
This DGRC Policy should be interpreted together with the Privacy Policy, Terms of Use, Cookie Policy, Acceptable Use Policy, AI and Model Training Policy, applicable Marketplace licensing terms, and product-specific policies.
34. Governance Responsibility
The operator of IuVeAI is responsible for establishing the DGRC governance framework. Technical components may enforce this framework automatically, but governance responsibility cannot be delegated entirely to an AI model. Model providers, infrastructure providers, and third-party services remain responsible for their own obligations under applicable agreements and law.
35. Policy Enforcement
Violation of this Policy may result in request blocking, agent action denial, capability revocation, API-key revocation, account restriction, administrative investigation, service suspension, or incident escalation. Enforcement should be proportionate to severity, intent, and risk.
36. Policy Review
This Policy must be reviewed when significant changes occur to IuVeAI architecture, AI providers, model capabilities, agent permissions, personal-data processing, applicable law, or security threats. A formal review should also occur periodically even if no major change has been identified.
37. Core DGRC Rule
IuVeAI follows one overriding governance principle: Capability does not equal authority.
An AI system may only access data, use tools, or perform actions when the required identity, permission, policy, and risk conditions have been satisfied.
Data → Authority → Policy → AI → Action → Verification → Audit
This control chain forms the basis of accountable AI execution within IuVeAI.
Contact
For questions about this Policy, contact the operator using the details above or email hello@iuve.eu.