OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.
This Policy applies to every account, trial, workspace, integration, prompt, scenario, voice input, export and attempt to access DIRI AI. Customers are responsible for users they invite.
1. Lawful training use
DIRI AI is designed for simulated communication practice and human-reviewed coaching. You must use it lawfully, transparently and with all rights, notices and permissions required for submitted material. A simulation must not be presented as a real person's call or statement.
2. Harmful and unlawful conduct
You may not use the service to create, facilitate, promote or conceal:
- fraud, phishing, scams, unlawful impersonation, deceptive commercial practices or identity theft;
- threats, stalking, harassment, coercion, hate, unlawful discrimination or targeted humiliation;
- sexual exploitation, sexual content involving minors, grooming or trafficking;
- instructions whose primary purpose is violent wrongdoing, self-harm encouragement, illegal drug trade, weapons crime or evasion of lawful safeguards;
- infringement of privacy, confidentiality, publicity, copyright, trademark or other rights;
- spam, unlawful direct marketing, robocalling or contact-list exploitation; or
- sanctions, export-control, anti-bribery, competition, employment or consumer-law violations.
3. People, voices and workplace use
You may not:
- clone, imitate or use a real person's identity or voice without all required rights and clear disclosure;
- secretly record or upload a real conversation, employee or customer;
- use DIRI AI for workplace emotion recognition, biometric identification or categorisation;
- covertly monitor workers or bypass a required employee, union or works-council notice;
- use a score or AI output as the sole basis for hiring, firing, discipline, pay, promotion or another legally significant employment decision; or
- infer protected or highly sensitive traits about a person.
Organisations must use the Employee Training and Monitoring Notice template as a starting point, customise it for local law and preserve meaningful human review.
4. High-stakes and regulated uses
Standard self-service plans are not approved for diagnosis, treatment, emergency response, credit, insurance eligibility, legal adjudication, law-enforcement decisions, critical infrastructure, weapons, border control or another high-stakes determination. Public authorities and regulated customers require a separate written scope, assessment, procurement, security, DPA and human- oversight review.
You may use general communication training in a regulated industry only if the simulation contains no unnecessary regulated real-person data and qualified humans remain responsible for real-world advice and decisions.
5. Sensitive and restricted data
Do not submit full payment-card numbers, security codes, passwords, API keys, government identifiers, health records, biometric templates, criminal records, children's data, trade secrets or real- customer special-category data to a standard training session. Use fictional or anonymised scenarios wherever possible.
A business customer may submit personal data only with a valid purpose, legal basis, notice, retention choice and DPA. “Publicly available” does not automatically make reuse lawful.
6. Security and platform integrity
You may not:
- probe, scan, exploit, disrupt, overload or bypass authentication, tenant, rate, seat, payment, trial, usage or provider controls;
- introduce malware, destructive code or instructions designed to extract system prompts, secrets or another customer's content;
- access, test or infer another account's data;
- automate requests beyond documented limits, scrape the service or evade a suspension;
- share an individual seat, sell access, sublicense or resell without a permitted plan; or
- reverse engineer except to the limited extent mandatory law expressly permits.
Good-faith vulnerability research requires the boundaries in the Security Overview. It does not authorise access to another person's data or service disruption.
7. Content and intellectual property
You must have the rights to every scenario, script, recording, logo, voice and other submitted material. Do not remove provenance or AI disclosures, create misleading synthetic evidence, or use exports to violate another person's rights. DIRI AI may remove or restrict content after a valid rights notice or binding legal request.
8. Enforcement
DIRI AI may investigate using proportionate account, audit and provider evidence. Depending on severity, we may warn, restrict content, reset credentials, suspend a feature or terminate an account. Immediate action is permitted for urgent security, safety, legal or third-party risk.
Where safe and legally permitted, we will explain the material reason and allow correction or appeal through support@diriai.com. Enforcement must be proportionate and must not remove mandatory consumer remedies or data-protection rights. We may preserve narrowly relevant evidence under a legal hold and report conduct where law requires.
9. Contact and version
Abuse reports: support@diriai.com. Security reports: security@diriai.com. Effective version: 1.0.0. Effective date: 26 August 2026.