Skip to content

Infordata Sistemi Società Benefit

Use of Artificial Intelligence and Transparency

Last updated: 22 August 2026 Changelog: v1.1: added the AI Act application dates, the Article 50 transparency obligations, the principles applied in projects and the sources. v1.0: first publication of the AI use page.

Infordata Sistemi Srl Società Benefit uses Artificial Intelligence (AI) systems to improve the quality of its services, speed up technical support, assist operators in managing tickets and documents, support research and innovation projects, and develop environmental and risk-prevention tools.

We believe in a responsible, transparent use of AI, always under human control, in line with the GDPR (Regulation (EU) 2016/679), the European Artificial Intelligence Act (AI Act, Regulation (EU) 2024/1689) and our status as a Società Benefit, the Italian benefit corporation form.

Where we use AI

Support portal: Knowledge base search and suggestion of technical articles and answers (RAG system).

SM Admin and internal processes: Email classification, activity summaries, draft replies, and support in managing tickets and documents.

Development and productivity tools: Paid corporate AI assistants for software development, text drafting and technical analysis.

Karst Firewall 5.0: Predictive algorithms, environmental data, sensors, simulations and operational assistants for wildfire prevention, always with human review.

TASC RestoreMed: Natural language search across catalogues of projects, partners and funding opportunities.

Computer vision: Recognition of objects and waste in environmental images, with data minimisation and de-identification measures where applicable.

What we do not do

  • We do not use free AI tools for business activities: only paid corporate accounts.
  • We do not allow passwords, tokens, API keys, credentials or secrets to be entered into AI systems.
  • We do not let AI outputs stand as decisions based solely on automated processing that produce legal effects on individuals or similarly significantly affect them (Article 22 of the GDPR).
  • We do not use sentiment, engagement or meeting metrics for disciplinary decisions or automated staff evaluations without a specific impact assessment, legal basis and dedicated privacy notice.
  • We do not use AI for social scoring, manipulation, emotion recognition in the workplace or any other practices prohibited by the AI Act.

Human oversight

AI outputs are suggestions, not final decisions. Replies to customers, offers, operational decisions, classifications and actions proposed by AI assistants are reviewed by authorised staff. If in doubt, you can always ask for a person to step in.

Data processed and providers

Depending on the service, the data processed may include contact details, tickets, emails, documents, technical logs, search queries and environmental data. Infordata uses paid corporate accounts and enables, where available, the no data sharing and no training options.

AI and cloud providers may include Anthropic, OpenAI, Google/Gemini, Read.ai and other parties listed in our privacy notices and in the list of sub-processors. Where data is transferred to countries outside the EEA, we adopt appropriate safeguards (Standard Contractual Clauses and transfer impact assessments).

Staff training (AI literacy)

In line with Art. 4 of the AI Act, Infordata invests in training its staff on the correct and safe use of AI. In 2026, all company personnel completed a dedicated training programme on Artificial Intelligence, with an instructor, materials and assessments, tailored by role and with periodic updates.

Diagram of the governance of an AI system under the AI Act: documentation, record of processing, compliance, and the cycle of definition, assessment, mitigation, verification, approval and monitoring.

The AI Act: what changes for organisations, and when

The European Artificial Intelligence Act introduces a risk-based framework. Obligations do not follow from “using AI”: they follow from the organisation’s role (provider, deployer or other), the type of system, its capabilities and its context of use.

As of the update date of this page, 22 August 2026, the application timetable is as follows:

DateWhat applies
2 February 2025General provisions and prohibitions on certain AI practices
2 August 2025Rules on general-purpose AI models and part of the governance framework
2 August 2026General application of the Regulation, including the Article 50 transparency obligations where the conditions for them are met
2 December 2027High-risk systems in the Annex III categories
2 August 2028High-risk systems connected to products or safety components covered by EU harmonisation legislation

The high-risk dates differ by category and were revised by Regulation (EU) 2026/1744. ⚠️ These dates do not replace a case-by-case assessment: how a system is classified, and which obligations follow, depend on its actual characteristics rather than on the commercial category it is sold under.

One point causes more confusion than any other: the AI Act does not replace the GDPR. Where a system processes personal data, the data protection rules continue to apply, and the roles do not map onto each other — an AI Act provider or deployer is not automatically a GDPR controller or processor.

Transparency: not one label, but different obligations

Article 50 of the AI Act sets transparency requirements in specific situations, not for every use of AI. They include direct interaction between a person and an AI system, synthetic or manipulated content, emotion-recognition and biometric-categorisation systems, deepfakes, and certain content intended to inform the public on matters of public interest.

This does not mean every AI-assisted item has to carry the same label. It means each organisation has to assess, for its own role and its own scenario, when to inform people, when to make an output detectable and which other measures apply.

The same proportionality principle governs AI literacy: Article 4 asks for measures calibrated to skills, experience, training, context of use and the people affected. It does not automatically impose the same course, or a certification, on every person in every organisation.

The principles we apply in projects

What applies to us applies to the systems we design for customers.

Clear purposes and proportionate use cases. A project starts from a defined problem, identified users and measurable value. Not every activity needs a generative model, and not every automation needs a high degree of autonomy.

Quality, limits and traceability. A reliable system makes inputs, sources, logs and control criteria visible to the extent the use case warrants. For systems built on enterprise knowledge, knowing which version of which document produced an answer is what makes it possible to correct it.

Security and suppliers. Governance includes supplier assessment, roles, access, data transfers, configurations and contractual terms. These are checked project by project: they are not settled by a standard clause or by a supplier’s name.

How we can support your journey

On the customer side, the work we do on these subjects is:

  • mapping systems, suppliers, data and processes;
  • preliminary assessment of use cases and priorities;
  • designing roles, controls, oversight and escalation flows;
  • integrating knowledge bases, logging and technical monitoring;
  • AI training proportionate to job roles;
  • preparing evidence and documentation for review with DPOs, legal advisers, security and business functions.

This does not replace legal advice, privacy assessments or the compliance checks required in a specific case. How we work on an AI project →

Sources

  • Regulation (EU) 2024/1689 (AI Act), consolidated text.
  • Regulation (EU) 2026/1744, amendments to the application timetable.
  • Regulation (EU) 2016/679 (GDPR).
  • Italian Law no. 132 of 23 September 2025 on artificial intelligence.
  • European Commission, guidelines on transparency obligations and AI literacy Q&A.

⚠️ Notice. This section is for information only and does not constitute legal advice. Whether specific obligations apply depends on the organisation’s role, the system’s capabilities, the context of use and sectoral rules. The ten practical rules for the people who use AI every day are in the Golden rules; the longer form is in the responsible AI white paper.

Your rights

Data subjects may exercise the rights under Articles 15 to 22 of the GDPR (access, rectification, erasure, restriction, objection, portability) by writing to the data controller (info@infordata.it) or to the Data Protection Officer (DPO): Cyber365 Srls – dpo@cyber365.it.

For services that Infordata provides as a data processor on behalf of its customers, requests may be forwarded to the relevant data controller.

Contacts

Infordata Sistemi Srl Società Benefit Strada per Vienna 55/1, 34151 Trieste (TS), Italy Email: info@infordata.it – DPO: dpo@cyber365.it