Last updated
September 17, 2026

Ai Transparency Note

1. Purpose of this Note

1.1 This Note explains where Goodface company OÜ, referred to in this Note as Goodface, uses artificial intelligence, what safeguards we apply, and what our clients and website visitors can expect. We publish it because transparency about AI is now both a legal requirement in the EU and a commercial expectation in the fintech market we serve.

1.2 It supplements our Privacy Policy and Terms of Use and does not replace the terms of any engagement contract.

2. Our roles under the AI Act

2.1 The AI Act allocates obligations by role. Goodface may occupy more than one role at the same time:

Role
When it applies to us
Practical consequence
Deployer
When we use a third-party AI tool in our own business — for example a general-purpose assistant used in research, drafting, design ideation or code assistance
We must ensure AI literacy among the staff using it, use the system in line with its instructions, and comply with the applicable Article 50 transparency duties
Provider
If we develop an AI system, or place one on the EU market under our own name or trade mark, or substantially modify one
Provider obligations attach, including the Article 50(2) marking duty for systems generating synthetic content
Provider on behalf of a client
When we build an AI-enabled feature that a client places on the market under its own name
The client is normally the provider. The allocation of roles and of AI Act obligations must be set out expressly in the statement of work

2.2 Goodface does not place any AI system on the market under its own name or trade mark, so the provider row does not apply to us and the Article 50(2) marking obligation does not attach to Goodface. Where we build an AI-enabled feature for a client, the client places it on the market under its own name and is normally the provider; the allocation of roles and of the resulting obligations, including any marking of synthetic output, is set out in the statement of work.

3. Where we use AI

3.1 In running our business and delivering services

We use AI-assisted tools in support of, and never as a substitute for, the work of our team. Approved tools in use: Claude (Anthropic), Fathom (AI meeting notetaker), all on enterprise or zero-retention terms with model-training opt-out.

  • research and synthesis of publicly available market and competitor information;
  • drafting and editing of internal documents, proposals and marketing copy;
  • design ideation, including generation of exploratory visual concepts that are not delivered to clients as final assets;
  • code assistance, including autocompletion, refactoring suggestions and test generation;
  • transcription and summarisation of meetings, where participants have been informed;
  • quality assurance support, including automated review suggestions.

3.2 On this Website

No AI system is deployed on the Website at launch; a Book a call button (Cal) is used instead, so the Article 50(1) disclosure is not engaged. This will be revisited if a chatbot is launched.

3.3 What we do not do

  • We do not use AI for emotion recognition or biometric categorisation, so the disclosure duty in Article 50(3) does not apply to us.
  • We do not use AI to take decisions producing legal or similarly significant effects concerning individuals, including in recruitment.
  • We do not engage in any practice prohibited by Article 5 of the AI Act.
  • We do not generate deep fakes of real people. Where we produce synthetic imagery for marketing purposes, it does not depict identifiable real individuals.

4. Human oversight and editorial control

4.1 AI output is treated as a draft. Every AI-assisted output that reaches a client, is published, or is incorporated into a deliverable is reviewed by a qualified member of our team who takes editorial responsibility for it.

4.2 Article 50(4) of the AI Act requires deployers who publish AI-generated or AI-manipulated text on matters of public interest to disclose that fact, but that duty does not apply where the content has undergone human review and a natural or legal person holds editorial responsibility for its publication. Our review process is designed to meet that condition.

4.3 Where we publish an image, audio or video that has been artificially generated or manipulated, we label it as such.

4.4 Maksym Yakubovych is accountable for editorial review; every published or client-facing output is human-reviewed and approved before release.

5. Client data and confidentiality

5.1 We do not submit client confidential information, client production data or personal data to a public or consumer-tier AI tool.

5.2 Where an AI tool is used on client work, it is used under enterprise or business terms that exclude the use of our inputs and outputs for training the vendor's models, and that provide for limited or zero data retention. Contractors engaged by us are bound by a data protection annex that restricts their use of AI tools on client work to the same standard.

5.3 Where a client instructs us not to use AI tools on its engagement, or restricts which tools may be used, we follow that instruction. Clients can request a statement of which tools were used on their engagement.

5.4 Use of AI tools does not change our confidentiality obligations under the engagement contract or any non-disclosure agreement.

6. Intellectual property in AI-assisted deliverables

6.1 We take account of the fact that material generated wholly by an AI system without sufficient human creative input may not attract copyright protection in some jurisdictions.

6.2 Our delivery process is designed so that deliverables reflect substantial human authorship, and so that we can assign or license rights in them to clients as agreed in the engagement contract.

6.3 We do not knowingly deliver AI-generated material that reproduces a third party's protected work.

6.4 The allocation of AI Act roles, any client restriction on the use of AI tools, and the ownership of AI-assisted deliverables are agreed in the engagement contract or the relevant statement of work. Where an engagement contains no express AI provision, the standards set out in this Note apply, and we will confirm our position in writing on request.

7. Governance

  • AI literacy. Article 4 of the AI Act has required providers and deployers to ensure a sufficient level of AI literacy among their staff since 2 February 2025. We provide regular AI-use and data-handling training to the team members who use AI tools.
  • Approved tool list. AI tools must be approved before use on client work. Approval covers the vendor's data handling terms, training opt-out, retention, hosting location and security posture.
  • Register. We maintain a register of the AI systems we deploy, their purpose, their role classification and their risk classification.
  • Incidents. Issues arising from AI use — including inaccurate output reaching a client, or confidential data being submitted to an unapproved tool — are handled under our incident procedure, and are treated as a personal data breach where personal data is involved.
  • Review. This Note and the underlying practices are reviewed at least annually and whenever the AI Act timetable moves.

8. Accuracy

AI systems can produce output that is plausible but wrong. Nothing produced with AI assistance and published on our Website is advice, and section 9 of our Terms of Use applies to it in full.

9. Changes and contact

We will update this Note as our tools, our practices and the law develop. Questions can be sent to fintech@goodface.agency.