Last updated: 29 July 2026
AutomateIQ builds AI systems that talk to your customers, handle your quotes and hold your business data. This page sets out plainly how we think about the rules that govern that — the EU AI Act and data protection law — what we commit to, and where the responsibility sits between us and you.
This page describes our understanding of our obligations and the commitments we make to customers. It is written to be useful, not to be legal advice, and it does not create rights beyond our Terms & Conditions. If you need a formal position for your own compliance file, email hello@automateiq.ie and we will put it in writing.
Both the EU AI Act and the GDPR assign duties by role, and we sit in more than one:
| Regime | Our role | What that means here |
|---|---|---|
| EU AI Act | Provider of the AI systems we build | We put the review agent, quote agent, AI receptionist, assistants and lead-capture systems on the market under our own name, so the provider duties for those systems are ours. |
| EU AI Act | Deployer of third-party models | Our systems are built on general-purpose models from Anthropic and Google. We do not train or fine-tune foundation models, so we are not a GPAI model provider. |
| EU AI Act | You are usually a deployer | When you switch on an agent that speaks to your customers, you decide the purpose it is used for — which carries deployer duties, including telling people they are dealing with AI where that isn't obvious. |
| GDPR | Controller for our own data | Your account details, our enquiry and sales records. |
| GDPR | Processor for your customers' data | When AutomateIQ emails your customers or captures your leads, that is your data and your decision. We process it on your instructions to deliver the service. See our Privacy Policy. |
The AI Act works in tiers of risk rather than a single standard. Our honest assessment of our current products:
Prohibited practices — we don't do any of them. No social scoring, no emotion inference in workplaces or education, no biometric categorisation, no untargeted scraping of faces, no manipulative techniques designed to exploit vulnerability. This isn't a close call for us; nothing in our catalogue goes near it.
Limited-risk / transparency obligations — this is where most of our products sit. An AI receptionist, a chat assistant, an automated quote or a drafted review request is an AI system interacting with a person or generating content. The duty attached to that tier is disclosure, not certification: people should be able to tell they are dealing with an AI, and AI-generated content should be identifiable as such. Section 3 sets out what we do about that.
Minimal risk. Internal tooling that doesn't interact with the public or make decisions about people — scheduling, document handling, routing, our own sales workspace — carries no specific AI Act obligation beyond general product and data law. We still hold it to the same transparency standards.
High-risk — where we would tell you. The high-risk tier is defined by use, not technology. Certain uses in employment (recruitment, task allocation, monitoring, evaluation of workers), creditworthiness, education, essential public or private services, and safety components of regulated products carry substantially heavier obligations — risk management, data governance, logging, human oversight, technical documentation, conformity assessment.
Our workforce and asset management systems are built as operational tools: rotas, jobs, assets, compliance records. If you intend to use any AutomateIQ system to evaluate, rank, monitor or make decisions about workers, or to assess a person's access to credit or an essential service, tell us before you do. That changes the classification, it changes what both of us must have in place, and we would rather scope it properly with you than discover it later.
The AI Act expects the people operating AI systems to understand them well enough to use them sensibly. In practice, for a small business, that means: knowing what the system does, knowing what it can get wrong, and knowing who checks it. When we set up an agent for you we walk through what it will and won't do, what it drafts versus what it sends, and where you review. If that briefing hasn't happened for a system you're running, ask us and we will do it — it is part of the service, not an extra.
The AI Act is being applied in stages rather than all at once. Broadly: the prohibitions and the AI-literacy expectations came first, general-purpose model obligations followed, and the bulk of the high-risk regime lands later, with some product-embedded cases later still. Our own products sit predominantly in the transparency tier, whose duties we treat as already live — waiting for a deadline to disclose that a chatbot is a chatbot would be a strange way to run a business.
We track changes to the timeline and to the guidance. If an obligation begins to apply to something you run with us, we contact you rather than leave you to find out.
Our processing is governed by the GDPR and the Irish Data Protection Act 2018, supervised by the Irish Data Protection Commission. The detail — what we collect, why, the legal bases, retention, your rights and our sub-processors — is in the Privacy Policy, and the specific points that matter for AI features are:
Some data protection laws outside Europe — the Personal Data Protection Laws of Saudi Arabia, the UAE, Bahrain and similar regimes — impose their own requirements on consent, data localisation, cross-border transfer approvals and breach notification, which can differ materially from the GDPR.
AutomateIQ currently operates from Ireland and serves customers principally in Ireland and the EU, and our infrastructure is configured for that. If you are established outside the EEA, or you process the personal data of people who are, contact us before onboarding so we can confirm honestly whether we can meet your local requirements — particularly any data-residency obligation. We would rather tell you we need to make a change than assert a compliance position we haven't verified.
Data is encrypted in transit and at rest, access is role-based and enforced at the database layer, and administrative actions are logged. If a personal data breach occurs we will notify affected controllers without undue delay and support your own notification duties. Full detail sits in the Privacy Policy.
For a data processing agreement, a sub-processor list, a security questionnaire, or a written statement of our AI Act position for your compliance file, email hello@automateiq.ie. We would rather answer a hard question early than have it surface after you have gone live.