ACCEPTABLE AI USE POLICY
Last updated: 11 September 2026
This English version is a courtesy translation. In the event of any discrepancy between this text and the Spanish version, the Spanish version is the one that prevails. Read the Spanish version
1. Introduction
This Acceptable AI Use Policy (hereinafter, the "Policy") establishes the rules governing the use of the Gescon service (hereinafter, the "Service" or the "Platform"), owned by NURIA LABS SL, in relation to its artificial intelligence functionalities.
Use of the Service implies full acceptance of this Policy, as well as of the Terms and Conditions, the Privacy Policy and the Data Processing Agreement (DPA). In the event of any contradiction, the Terms and Conditions shall prevail, unless the matter is specifically regulated in this Policy, in which case this Policy shall prevail.
This Policy has been drafted taking into account Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the "AI Regulation" or "AI Act"), as well as Regulation (EU) 2016/679 (GDPR) and other applicable regulations.
2. Scope of application
This Policy applies to:
- The Customer that has contracted the Service.
- All End Users who access the Platform on behalf of the Customer, including employees, collaborators and, where applicable, authorised third parties.
The Customer is responsible for ensuring that its End Users are aware of and comply with this Policy, and shall be liable to NURIA LABS for any breach thereof.
3. How AI works in Gescon
Gescon uses OpenAI models through its API for internal chat, in normal and expert modes. In Open chat you can select OpenAI, Anthropic, Perplexity, xAI or Google AI Studio. Internal chat works as follows:
- The Customer connects its data sources (SharePoint, Google Drive, Microsoft Teams, SQL databases or others) and/or uploads documents to the Platform.
- The Platform indexes this content to allow it to be queried later.
- When an End User submits a query, the Platform retrieves the relevant information and sends it to the AI model together with the query to generate a response based on the Customer's data.
- The response is returned to the End User and is logged in the Customer's Account for traceability purposes and to improve the Service.
It is important for the Customer and the End Users to understand that the responses generated are the output of an automated AI system and, as such, may contain errors, omissions or inaccuracies.
3.1 AI provider and data processing
OpenAI provides the AI for internal chat. Open chat uses the provider selected by the End User. When processing personal data on the Customer's behalf, the provider acts as a sub-processor of NURIA LABS SL under the DPA and the contracted service terms. OpenAI's retention periods do not automatically apply to other providers. The following references concern OpenAI:
- OpenAI API data controls
- OpenAI Data Processing Addendum
- OpenAI usage policies
OpenAI's DPA does not replace the Data Processing Agreement between NURIA LABS SL and the Customer; rather, it documents the terms applicable to the processing carried out by OpenAI as provider/sub-processor.
4. Inherent limitations of AI systems
The Customer and the End Users acknowledge and accept that AI systems, including those used by Gescon, have limitations that must be taken into account before using the responses generated:
- Inaccuracies and "hallucinations": language models may generate responses that appear correct but contain inaccurate, incomplete or fabricated information.
- Outdated information: responses are based on the data available in the connected sources at the time of the query. If the source data is outdated, the response will be too.
- Bias: AI models may reproduce biases present in their training data or in the Customer's data.
- Lack of deep reasoning: AI models generate statistically probable responses, not necessarily the product of qualified legal, medical, financial or professional reasoning.
- Variability: the same query may produce slightly different responses at different times.
Accordingly, the responses generated by Gescon are informative and indicative in nature. The Customer and the End Users are solely responsible for reviewing, validating and, where appropriate, verifying such responses before making decisions based on them, particularly when those decisions have legal, financial, tax, medical or employment-related effects, or affect the rights of third parties.
5. Permitted uses
The Service is designed as a productivity and reference tool within the Customer's organisation. Permitted uses include, by way of example and not limited to:
- Centralising and consulting the company's internal documentation.
- Resolving operational, regulatory or procedural queries among employees.
- Speeding up the onboarding of new employees.
- Generating summaries, extracts or drafts from the Customer's information.
- Handling internal or, where applicable, external queries (through the widget) based on corporate documentation.
- Any other legitimate professional use in accordance with the Terms and Conditions.
6. Prohibited uses
It is expressly prohibited to use the Service to:
6.1 Unlawful or harmful uses
- Carrying out activities contrary to the law, public order, morality or accepted standards of conduct.
- Infringing third parties' fundamental rights, in particular the right to honour, privacy, one's own image, freedom or the dignity of individuals.
- Generating, disseminating or facilitating content that constitutes a criminal offence, including hate speech, incitement to violence, terrorist content or child pornography.
- Carrying out cyberattacks, fraud, phishing or any activity that compromises the security of systems or persons.
6.2 Uses prohibited by the European AI Regulation
Pursuant to Article 5 of Regulation (EU) 2024/1689, it is strictly prohibited to use the Platform to:
- Deploy subliminal or manipulative techniques that materially distort people's behaviour.
- Exploit the vulnerabilities of individuals or groups due to age, disability, or social or economic situation.
- Carry out the social scoring of natural persons.
- Infer the emotions of persons in the workplace or in educational settings, except in legally authorised cases.
- Carry out biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
- Any other use prohibited by the AI Regulation or by applicable law.
6.3 Improper processing of data
- Uploading or processing personal data without an adequate legal basis under the GDPR.
- Uploading special categories of data (health, racial origin, political opinions, biometric data, etc.) without the reinforced safeguards required by Article 9 GDPR.
- Uploading data subject to a duty of professional secrecy without the necessary precautions.
- Using the Service to carry out profiling or automated decisions with legal effects on data subjects without the safeguards of Article 22 GDPR.
6.4 Use for critical decisions without human oversight
It is not permitted to use the responses generated by the Platform as the sole basis for making decisions that produce significant legal effects on individuals, without qualified human review and validation. This includes, without limitation:
- Decisions regarding the hiring, promotion or dismissal of staff.
- Decisions to grant or deny financial products or services.
- Medical or healthcare decisions.
- Judicial or quasi-judicial decisions.
- Decisions affecting access to essential public services.
6.5 Other prohibited uses
- Using the Platform to generate content that infringes third parties' intellectual or industrial property rights.
- Impersonating another person or entity or falsifying one's identity.
- Carrying out security testing, reverse engineering, mass scraping, or using the Platform in a way that could compromise its availability.
- Using the Service to develop products or services that compete with Gescon.
- Circumventing the security measures or the limitations of the contracted Plan.
7. Recommended good practices
NURIA LABS recommends that the Customer and its End Users adopt the following good practices when using the Service:
- Always validate critical responses against the source documentation before making significant decisions.
- Review and keep the connected data sources up to date to avoid responses based on obsolete information.
- Limit access to the Platform and its different spaces through appropriate role and permission policies.
- Inform employees that the responses are generated by an AI system and should be treated as such.
- Periodically review usage logs to detect anomalous queries or improper use.
- Avoid uploading information that is not necessary for the purposes of the Service (data minimisation principle).
- Anonymise or pseudonymise personal data whenever possible and proportionate to the purpose.
8. Transparency towards End Users and third parties
When the Service is used to interact with natural persons (for example, through the chat widget on a website or client portal), the Customer undertakes to inform such persons, clearly and accessibly, that they are interacting with an AI system, in accordance with Article 50 of Regulation (EU) 2024/1689.
Likewise, the Customer must comply with its obligations to inform data subjects under Articles 13 and 14 GDPR regarding the personal data processed through the Service.
9. Ownership and use of the responses generated
The responses generated by the Platform are made available to the Customer for use in accordance with the purposes of the Service. The Customer acknowledges that:
- The responses are generated from the Customer's Data and from third-party AI models, which may limit the ability to claim exclusive rights over them.
- It is the Customer's responsibility to verify that its use of the responses does not infringe third-party rights, in particular intellectual property rights.
- NURIA LABS is not responsible for the use that the Customer makes of the responses generated.
10. No training on Customer data
NURIA LABS SL confirms that Customer Data and queries made through Gescon are not used to train, retrain, fine-tune or improve its own or third-party AI models. This commitment applies to both internal chat and Open chat. NURIA LABS does not enable data-sharing options for training with AI providers.
11. Consequences of non-compliance
Breach of this Policy, by the Customer or by any End User, may result in:
- The immediate suspension of access to the Service, in whole or in part, with no right to a refund of amounts already paid.
- Termination of the contract for serious breach in accordance with the Terms and Conditions.
- A claim for damages caused to NURIA LABS, to other users or to third parties.
- Where applicable, notification to the competent authorities where there is a legal obligation to do so or where the facts may constitute an administrative or criminal offence.
12. Incident notification
The Customer and the End Users undertake to notify NURIA LABS, without undue delay, of any incident, anomaly or suspected misuse of the Service of which they become aware, by writing to gescon@nurialabs.com. NURIA LABS will review the notification and adopt the appropriate measures.
13. Amendments
NURIA LABS reserves the right to amend this Policy to adapt it to regulatory changes, in particular in relation to developments in the European AI Regulation, as well as to technical or commercial developments of the Service. Amendments will be notified to the Customer at least 15 calendar days before they come into effect.
Continued use of the Service after the amendments come into effect implies acceptance thereof. If the Customer does not agree, it may cancel the renewal of its subscription in accordance with the Terms and Conditions.
14. Contact
For any query related to this Policy, you may contact NURIA LABS at:
- Email: gescon@nurialabs.com
- Postal address: NURIA LABS SL, Carrer Sant Miquel, 36, 1.º A, 07002 Palma, Illes Balears, España
- Phone: +34 871 55 71 41