1. Off by default, and you choose where the model runs
The artificial-intelligence features of Omega People are switched off by default. An owner or administrator switches them on in the workspace settings and, at that moment, chooses where the model runs. There are two modes, and the difference matters.
- In the browser. The language model is downloaded to the device of the person using it and runs there. Questions and answers do not go to any AI provider. The model’s files are downloaded once from the public repositories that distribute them and kept in the browser’s cache. It needs a recent computer, and the models that fit in a browser are less capable.
- With an external provider. The customer enters its own API key for a provider it has chosen — Anthropic, OpenAI or Google. Requests pass through our server only to be forwarded to that provider; we do not use them for any other purpose. The key is stored encrypted in the workspace’s own database, is never shown again after it is entered, and is sent to the provider only in a request header. Only owners, administrators and team members can use the assistant (not employee accounts), and the number of requests per person is limited.
We do not operate a model of our own and we have no AI provider at platform level: if you do not switch a mode on, no data from your workspace reaches any model.
2. What the features do and which data they receive
| Feature | What it does | What the model receives |
|---|---|---|
| Assistant | Answers questions asked in plain language by the users of the management area — for example who is absent on a given day, which requests are waiting, who has not clocked in, how much was spent on expenses — and, on request, prepares two actions: a reminder to people who have not clocked in, and a proposal to cover open shifts. | The question, the conversation so far, and the result of the look-ups it makes to answer: names of employees with their job title, department and site, and data about their attendance, absences, requests, shifts, expenses, pay totals and upcoming deadlines (for example medical checks, training, contracts), limited to the modules and the people that the user asking is allowed to see. Absence reasons that the company has marked as confidential are hidden from users who may not see them. It also receives the name of the workspace and of its modules, and a short summary of the country’s general employment rules. |
| Reading a receipt | Reads the photograph of a receipt and proposes the amount, date, merchant and category of an expense claim, which the person confirms or corrects. Available only with an external provider. | The image of the receipt and the list of the company’s expense categories. |
| Text of automatic messages | If a rule in Automations asks for it, writes the text of the notification or of the email that the rule sends. Available only with an external provider. | The instruction written in the rule and the data of the event that triggered it — for example the name of the employee and the dates concerned or, for a rule triggered by the contact form of a website you have published, the name, contact details and message of the visitor. |
The assistant never queries the database freely: it can only call a fixed set of look-ups that we wrote, each of which applies the same permissions as the screens of the application. An assistant in one workspace cannot reach another workspace’s data, which lives in a different database.
3. No automated decisions about people
No AI feature of Omega People takes a decision about an employee or a candidate. In particular, and this page will change before any of this does:
- AI does not screen or rank candidates and does not read CVs;
- AI does not assess performance, does not write or score reviews, and does not suggest disciplinary measures or dismissals;
- AI does not approve or refuse leave, expenses, overtime or any other request;
- AI is not used on the reports received through the speak-up channel;
- AI does not recognise faces, infer emotions or categorise people by biometric data.
The two actions the assistant can prepare always need a person’s explicit confirmation, and only users with management permission on that module can ask for them. The reminder is sent only after the user has seen the list of recipients and said yes. The shift proposal — which is built by the scheduling rules of the application (rest periods, absences, availability, contracted hours), not by the language model — is saved as drafts that a manager checks and publishes from Shift planning.
There is therefore no decision based solely on automated processing that produces legal or similarly significant effects on a person (GDPR art. 22). If you use the output of AI features as one of the inputs to a decision about someone, the decision — and the duty to explain it — is yours.
4. How these features are classified
- No prohibited practice under art. 5 of the AI Act: no social scoring, no manipulation, no emotion recognition in the workplace, no biometric categorisation.
- Not designed as a high-risk system. Annex III of the AI Act treats as high-risk the AI systems intended to recruit or select people, to take decisions on promotion, termination or the allocation of tasks based on individual behaviour or traits, or to monitor and evaluate workers. The features above are not intended for those purposes and must not be used for them (see the Acceptable Use Policy).
- Transparency (art. 50). The assistant is presented as an AI assistant, and what it produces is shown as its output. When you send people a text written with AI, transparency towards them remains your duty as the user.
Under the AI Act, the Provider supplies the AI features built into the application; the customer that switches them on is their deployer; the provider of the model the customer chooses is the provider of that general-purpose model. If you are not established in the European Union, the AI rules of your own country may also apply to you — in the United States, for example, New York City’s rules on automated employment decision tools.
5. Your data and model training
OutLine Digital Agency does not use customer data to train artificial-intelligence models, neither its own nor anyone else’s, and does not give it to anyone for that purpose. Whether your chosen provider does so with what you send it depends on your contract with that provider.
6. Using AI responsibly with staff data
- Tell your staff. If you switch AI features on, say so in your staff privacy notice — including the provider you chose and where it processes data — and, where your law requires it, inform or consult employee representatives first.
- Always check. Models produce plausible text even when it is wrong: an invented date or figure goes unnoticed precisely because it is well written. The figures that count are the ones on the screens of the application.
- It is not legal advice. What the assistant says about leave, notice, overtime or pay is general guidance drawn from the country rule packs, with the limits set out in article 10 of the Terms of Service.
- Keep health data out of external models. Do not type diagnoses, the content of medical certificates or the content of a speak-up report into the assistant. If your staff’s data is particularly sensitive, prefer the in-the-browser mode.
- No decisions about people. A generated text must not decide a hiring, a dismissal, a sanction or an assessment: that decision belongs to a person.
- Train the people who use it (AI Act art. 4): what it does, where it goes wrong, when not to trust it.
7. Contact
For questions about the AI features, or to find out how to switch them off, write to amministrazione@outlinedigital.it.