Artificial Intelligence Policy
Effective date: 07 September, 2026
TRAFFIC STARS LTD is a company duly registered in the Republic of Cyprus under registration number HE 335138 having its registered office and head office at Arch. Makariou III, 124, AGROTIS COURT, Floor 1, 3021, Limassol, Cyprus ("we", "us", "our", or "TrafficStars") operates trafficstars.com and the related services described in our Terms and Conditions (the "Services").
This Artificial Intelligence Policy ("AI Policy") explains:
- how we use artificial intelligence ("AI") systems in connection with the Services;
- what data protection and AI Act principles govern that use;
- what happens when we use third-party AI providers to power features on our Services; and
- what rights and responsibilities apply to you as a user.
This AI Policy should be read together with our Privacy Policy and Terms and Conditions.
1. Scope and Definitions
This AI Policy applies to:
- every AI or machine learning system that we design, procure, configure, deploy, or operate in connection with the Services (our "AI Systems");
- every visitor, registered user, and business customer whose data, content, or interactions are processed by our AI Systems; and
- any third-party AI system, model, chatbot, or "Connected AI Agent" (as defined in Section 7) that a user connects to their account or to our API to act on their behalf.
"AI System" means a machine-based system as defined in Article 3(1) of Regulation (EU) 2024/1689 (the "EU AI Act") — broadly, a system that, for explicit or implicit objectives, infers from input how to generate outputs such as predictions, content, recommendations, or decisions that influence physical or virtual environments.
"Personal Data", "Processing", "Controller", and "Processor" have the meanings given in Regulation (EU) 2016/679 (the "GDPR").
"High-Risk AI System" has the meaning in Article 6 and Annex III of the EU AI Act.
"GPAI Model" means a general-purpose AI model as defined in Article 3(63) of the EU AI Act (e.g., the large language models that power our chat and content-generation features).
2. How We Use AI
We currently use AI Systems for the following purposes on the Services:
- Customer support / chatbot
- Content Moderation
- Platform’s features
- Check balance
- Create/update campaigns
- Get statistics
- Optimize campaigns
Based on our current assessment as of the date of this policy, our AI Systems are used for customer engagement, content assistance, and operational efficiency purposes and are not designed or used for automated decision-making producing legal or similarly significant effects on individuals, unless expressly stated otherwise for a specific feature (see Section 4).
Inputs, content, queries, and interactions submitted to our AI-assisted features, together with any resulting outputs, may be processed by us — and, where applicable, by our AI subprocessors, including third-party AI Provider (see Section 7) — to generate responses and deliver the requested feature. We may use aggregated, anonymised, or de-identified information to monitor, maintain, and improve the performance and reliability of our AI Systems, consistent with applicable law and our Privacy Policy.
Where we offer an opt-out from the use of your inputs to improve our AI Systems, exercising that opt-out means we will not use your content for that purpose for as long as the opt-out remains active.
3. Legal Basis Under GDPR
Where our AI Systems process Personal Data, we rely on one or more of the following legal bases under Article 6 GDPR, depending on the specific processing activity:
- Contract (Art. 6(1)(b)) — where AI-assisted processing is necessary to provide a feature you have requested (e.g., an AI support chat you initiate).
- Legitimate interests (Art. 6(1)(f)) — for uses such as fraud detection, service improvement, or analytics, where we have concluded (via a documented legitimate interests assessment) that our interests are not overridden by your rights and freedoms. You have the right to object — see Section 11.
- Consent (Art. 6(1)(a)) — where required by law, for example for certain profiling, targeted advertising, or non-essential cookies used to support AI personalisation. Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — for AI-assisted compliance functions such as fraud or abuse monitoring where mandated by law.
Where Personal Data processed by an AI System falls within a special category under Article 9 GDPR (health, religious or political beliefs, sexual orientation, biometric or genetic data used for identification, etc.), we do not process it for AI-driven profiling, targeting, or automated decision-making, and any such processing outside that context requires an applicable Article 9(2) condition (e.g., explicit consent) plus a documented basis.
Where an AI System processing is likely to result in a high risk to individuals' rights and freedoms, we carry out a Data Protection Impact Assessment (DPIA) under Article 35 GDPR before deployment, and consult our supervisory authority where required under Article 36.
4. AI Act Risk Classification
We assess each AI System we deploy or provide against the EU AI Act's risk tiers:
Tier |
What it means |
Our position |
Unacceptable risk (Art. 5)
|
Banned outright |
We do not deploy these practices — see Section 5.
|
High-risk(Art. 6, Annex III)
|
e.g., AI used in employment, credit scoring, essential services access, law enforcement, biometric identification
|
We do not currently operate any High-Risk AI System
|
Limited risk (transparency obligations)(Art. 50) |
Chatbots, AI-generated content, emotion recognition, biometric categorisation, deepfakes
|
Applies to our AI chat/content features — see Section 6.
|
Minimal risk |
Everything else (spam filters, recommendation engines that aren't high-risk, etc.)
|
Most of our AI Systems fall here; we apply this Policy's baseline commitments to them regardless.
|
We re-assess this classification whenever we materially change an AI System's purpose, training data, or deployment context, and at least annually.
5. Prohibited AI Practices
Consistent with Article 5 of the EU AI Act, the following are strictly prohibited on the Services, by us and by any user or Connected AI Agent:
- Subliminal, manipulative, or deceptive techniques that materially distort a person's behaviour in a way likely to cause them or another person significant harm.
- Exploitation of vulnerabilities due to age, disability, or a specific social or economic situation, in a way likely to cause significant harm.
- Social scoring that leads to detrimental or unfavourable treatment unrelated to, or disproportionate to, the context in which the data was generated.
- Individual criminal-risk prediction based solely on profiling or personality traits.
- Untargeted scraping of facial images from the internet or CCTV to build or expand facial recognition databases.
- Emotion inference in workplaces or educational institutions, except for narrow medical or safety purposes.
- Biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation (with narrow law-enforcement exceptions that do not apply to our Services).
- Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes.
If you become aware of any AI System on the Services engaged in any of the above, notify us immediately at dpo@trafficstars.com .
6. Transparency and Labelling Obligations
In line with Article 50 of the EU AI Act:
- AI interaction disclosure. Where you interact with a chatbot or virtual assistant on the Services, we will inform you that you are interacting with an AI system, clearly and at the latest at the time of first interaction — unless this is obvious to a reasonably well-informed person given the circumstances.
- AI-generated or manipulated content. Where we generate or materially modify image, audio, or video content that could appear to be an authentic depiction of real people, objects, places, or events ("synthetic content"), we label it as AI-generated or manipulated in a way that is detectable, whether by machine-readable marking, watermark, or visible label.
- Deepfakes. Content that constitutes a "deepfake" under the AI Act is disclosed as artificially generated or manipulated, and any exception we rely on (e.g., evidently artistic, satirical, or fictional works, subject to appropriate safeguards) is applied narrowly.
- AI-generated text on matters of public interest. Where AI-generated text is published to inform the public on matters of public interest, we disclose that it is artificially generated, unless it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication.
7. Third-Party AI Providers
Some AI features on the Services are powered by third-party AI providers rather than models we have built ourselves.
7.1 Our obligations as a deployer
When we use Third-Party AI Providers to power a feature of the Services, we act as a "deployer" under the EU AI Act and remain the data controller (or, where applicable, processor on your behalf) for any Personal Data submitted through that feature. We:
- comply with their Usage Policy, which sets out Universal Usage Standards (prohibiting, among other things, the generation of content that facilitates weapons development, malicious cyberattacks, child sexual abuse material, and deceptive political content) as well as additional High-Risk Use Case Requirements;
- where a Third-Party AI Providers-powered feature falls within their High-Risk Use Case categories (for example, legal, medical, financial, employment, housing, or academic-testing contexts with consumer-facing outputs), ensure a qualified human reviews AI-generated advice or decisions before they are relied upon, and disclose to end users that AI is being used to assist, at the start of the relevant interaction;
- do not use Third-Party AI Providers to make solely automated decisions producing legal or similarly significant effects about you without human review, except where permitted by law and disclosed to you; and
- maintain a data processing agreement with Third-Party AI Providers covering the processing of any Personal Data we submit through the API, and rely on Third-Party AI Providers’ standard contractual clauses or equivalent transfer mechanism for any transfer outside the EEA (see Section 9).
7.2 Connected AI Agents (if you offer API/agent access to users)
Where you (a business customer) connect or authorise a third-party AI system, agent, or automated assistant ("Connected AI Agent") to access your account or our API on your behalf, you agree that:
- you are solely responsible for selecting, configuring, instructing, and monitoring the Connected AI Agent, and for all actions and outputs it produces, which are treated as your own;
- you will connect a Connected AI Agent only to your own account using credentials issued to you, and will keep those credentials confidential;
- you will apply meaningful human oversight to material decisions taken by the Connected AI Agent and accept responsibility for any erroneous or unintended action it takes;
- you hold a lawful basis for any Personal Data that you or the Connected AI Agent transmit through our Services, and your use of any third-party AI provider complies with that provider's own terms and applicable law; and
- we are not responsible for, and give no warranty regarding, any Connected AI Agent or third-party AI provider you choose to use, or the outcome of that use.
We may suspend, throttle, or revoke API or Connected AI Agent access at any time if we reasonably believe this Policy or our Terms of Service have been breached.
8. Data Protection and Privacy
- We collect and process only the Personal Data reasonably necessary for each AI System's stated purpose (data minimisation, Art. 5(1)(c) GDPR).
- Where anonymisation or pseudonymisation achieves an equivalent outcome, we prefer it.
- We do not knowingly use special category data (Art. 9 GDPR) for AI-driven profiling or targeting without an applicable legal basis.
-
Full detail on what we collect, why, retention periods, and your choices is in our Privacy Policy — this AI Policy does not replace it.
9. International Data Transfers
Where an AI System (ours or a third-party provider's) processes Personal Data outside the European Economic Area, we ensure an appropriate transfer mechanism is in place under Chapter V GDPR — such as an adequacy decision, the European Commission's Standard Contractual Clauses, or (for UK data) the UK's International Data Transfer Addendum — together with any supplementary measures required following a transfer risk assessment. Details of the specific safeguards applicable to a given processor are available on request to dpo@trafficstars.com .
10. Security and Human Oversight
- Security and data protection considerations are built into our AI Systems from design through deployment (privacy and security by design, Art. 25 GDPR).
- Significant automated decisions with material consequences for you are, where required by law, subject to human review before being finalised.
- Our authorised personnel can intervene in, override, suspend, or deactivate any AI System we operate at any time.
- We log AI System outputs, performance metrics, and anomalies to enable retrospective review and, where applicable under Article 12 AI Act, to meet record-keeping obligations for high-risk systems.
- We periodically review our AI governance, security controls, and this Policy to reflect regulatory and technical developments.
11. Your Rights
Subject to applicable law (principally GDPR Articles 15–22), you have the right to:
- Access — obtain confirmation of, and access to, Personal Data we process about you, including via AI Systems.
- Rectification — correct inaccurate Personal Data.
- Erasure — request deletion of your Personal Data, subject to legal exceptions.
- Restriction — request that we limit processing in certain circumstances.
- Object — object to processing based on legitimate interests, including profiling, at any time.
- Data portability — receive certain data you provided us in a structured, machine-readable format.
- Not be subject to solely automated decision-making producing legal or similarly significant effects concerning you, except in the limited circumstances Article 22 GDPR permits, and to request human intervention, express your point of view, and contest the decision in those cases.
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with a supervisory authority — see Section 16.
To exercise any of these rights, contact dpo@trafficstars.com . We will respond within the timeframes required by GDPR (generally one month, extendable by two further months for complex requests).
12. User and Business-Customer Responsibilities
By using AI-assisted features on the Services, you agree that you will not:
- submit content that is unlawful, deceptive, or manipulative, or use AI outputs to mislead others;
- attempt to use our AI Systems to profile or target individuals using prohibited criteria (Section 5);
- remove, conceal, or falsify AI-identification labels required by Section 6;
- rely on AI-generated output without independently evaluating its accuracy, reliability, and appropriateness before acting on it or publishing it;
- submit Personal Data into an AI System without a valid legal basis for doing so; and
- use the Services' AI features to build or train a competing AI product, except as expressly permitted in writing.
You remain solely responsible for your own compliance with applicable law when using AI-assisted features, and for independently reviewing AI-generated content for accuracy, intellectual property issues, and confidentiality before relying on or publishing it.
13. Children
The Services are available only to individuals who are 18 years of age or older. By accessing or using the Services, you represent and warrant that you are at least 18 years old.
14. Incident Reporting and Breach Notification
Where a Personal Data breach involving an AI System is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR) and, where the risk is high, notify affected individuals without undue delay (Art. 34 GDPR). Where an AI incident meets the AI Act's serious-incident reporting criteria for a high-risk system we operate, we will report it to the relevant market surveillance authority within the statutory timeframe (Art. 73 AI Act).
If you become aware of a security or AI-related incident affecting your data, contact dpo@trafficstars.com ]immediately.
15. Enforcement
We may take one or more of the following actions in response to a breach of this Policy, at our reasonable discretion and proportionate to the breach: (a) suspension or termination of the relevant account or feature access; (b) removal of non-compliant AI-generated content; (c) suspension or revocation of API or Connected AI Agent access; (d) pursuit of available legal remedies where loss or harm results; and (e) reporting to relevant authorities where required by law.
16. Supervisory Authority and Complaints
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. Our lead supervisory authority is [name of DPA, e.g., the Office of the Commissioner for Personal Data Protection, Cyprus], contactable at [DPA contact/website]. This does not affect your right to seek a judicial remedy.
17. Policy Updates
We may update this AI Policy from time to time to reflect changes to our AI Systems, our use of third-party AI providers, or applicable law. Continued use of AI-assisted features after an update constitutes acceptance of the revised Policy, to the extent permitted by law.
18. Contact Us
For questions, complaints, or rights requests relating to this AI Policy, contact:
Data Protection Officer: dpo@trafficstars.com
Legal enquiries: legal@trafficstars.com
This AI Policy forms part of, and should be read together with, our Terms of Service.