XXcellerate
AI transparency

AI proposes. A named person decides. Every step is logged.

Last updated: 2 August 2026 · Version 1.0

1

Scope

This statement discloses how RMM Labs Ltd uses artificial-intelligence features inside Xcellerate OPS and on rmmlabs.io. It is published in fulfilment of the transparency duties applicable under Regulation (EU) 2024/1689 (the EU AI Act) and to ensure that Xcellerate customers and their end users understand how AI is, and is not, used in respect of their data.

2

The single rule

AI proposes. A named person decides.

Xcellerate’s AI reads, classifies, summarises, compares, drafts and proposes. It does not autonomously send a customer reply, apply a triage decision, route a ticket or accept a risk. Every action that produces a legal or similar significant effect on the customer, on the customer’s end users, or on a third party routes to a named, authenticated technician, who applies, edits or dismisses it before it becomes the record of truth. The single, deliberate exception is the optional AI Gatekeeper, which may reply to a requester to ask for missing information; it makes no binding decision, is clearly and machine-readably marked as AI, and can be switched off for the whole workspace or per team.

3

Where AI acts inside Xcellerate

FunctionAI roleHuman approval required?
Ticket triage (priority and product)ProposesYes — applied by the named technician
Team and member routingProposesYes — auto-assign is off by default
Draft replyDraftsYes — edited and sent by the named technician
Conversation summarySummarisesNo decision — read-only aid
Sentiment badgeClassifiesNo decision — read-only aid
QA check on outgoing repliesReviewsYes — applied by the named technician
Conversation and knowledge-base translationTranslatesYes — reviewed by the author
Intake gatekeeper (completeness check on new requests)Screens & asksNo — autonomous, AI-marked reply asking the requester for missing details; off by default
4

Where AI does not act

  • AI never sends a customer reply automatically.
  • AI never applies a triage or routing decision without a technician confirming it.
  • Internal notes are never sent to the AI.
  • Secrets-vault entries, IT documentation and cost or profitability figures are never included in AI prompts.
  • AI does not execute transactions or instructions outside Xcellerate.
  • The AI Gatekeeper only asks requesters for missing information; it never resolves a ticket, sends a solution, or makes a routing or priority decision.
5

Models and infrastructure

  • AI features run on the platform operator’s configured providers (Anthropic Claude or an OpenAI-compatible endpoint) and, for translation, a dedicated translation provider.
  • Provider API keys are stored encrypted and are never echoed back in the interface.
  • Customer content is not used to train foundation models, and foundation-model parameters are not modified on the basis of customer content.
  • Every AI action bills a transparent per-technician credit ledger, and technicians can be excluded from all AI assistance with a per-user toggle.
  • Before any prompt leaves the platform, a deterministic, always-on layer replaces personal and secret data — email addresses, phone numbers, IP and MAC addresses, IBANs, card and VAT numbers, and API or bearer tokens — with stable placeholders that are restored in the answer. No AI is involved in this scrubbing, so it cannot leak.
6

Limitations and known risks

  • AI-generated triage suggestions, summaries and drafts may contain errors and must be reviewed.
  • AI outputs are reproducible for a given input and model version; customers may request a logged copy of the relevant inputs and outputs in respect of a specific decision.
  • AI is not used to detect minors or other special-category data subjects unless the customer explicitly enables such a feature and meets the relevant GDPR Art. 9 obligations.
7

Automated decisions under GDPR Art. 22

RMM Labs Ltd does not make automated decisions producing legal effects on natural persons on the basis of Xcellerate data. Where a customer uses Xcellerate outputs in a context that itself produces a legal or similarly significant effect on a data subject, the customer is the controller and remains responsible for GDPR Art. 22 compliance.

8

EU AI Act — roles, dates and obligations

Xcellerate OPS integrates third-party general-purpose AI models (Anthropic Claude or an OpenAI-compatible endpoint) into product features and places them on the EU market under our name. RMM Labs Ltd is therefore a provider of these AI systems under Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744); our customers are deployers and their end users are affected persons. We are not a general-purpose AI model provider — those model obligations sit with the model makers.

  • From 2 August 2026, the Act's transparency duties under Art. 50 apply: people are told when they interact with AI, and AI-generated content is disclosed. The optional AI Gatekeeper carries a fixed, human-written transparency disclaimer in all 25 supported languages.
  • AI-generated messages that reach a person are machine-readably marked and visibly labelled as AI-generated, ahead of the 2 December 2026 deadline for machine-readable marking under Art. 50(2).
  • No AI feature in Xcellerate is currently classified as high-risk. Team routing stays outside the high-risk category because the person is chosen by a deterministic, rule-based strategy — never by AI profiling of individuals — and the QA check stays advisory and is never aggregated per technician. The high-risk regime for stand-alone Annex III systems applies from 2 December 2027.
  • For our deployer-customers, the in-product AI Act compliance center provides the AI registry, action log, oversight reporting, worker information, AI-literacy tracking and FRIA/DPIA material needed to meet their own duties under Arts. 4, 13, 14, 26 and 27.
9

Logging and audit

Every AI action is recorded in a unified AI action log — the feature, provider and model, the initiating user or system, the related record, redaction counts by type, credits billed, the outcome and the human decision applied, dismissed or edited, each with a timestamp and request identifier. Prompt and response contents are never stored. Logs are retained for a configurable period of at least six months and are exportable as CSV or JSON and via a read-only API, in addition to the schedule in the security statement.

10

Updates

Material changes to model usage or to the human-approval boundary are notified per the change-notice period on the trust center index page.

In one line

Xcellerate's AI reads, classifies, summarises, compares, drafts and proposes — it does not apply routing, accept risk or send a resolving reply on its own. The one deliberate exception is the optional AI Gatekeeper, which may reply to a requester to ask for missing details and is always clearly marked as AI. Every AI action is logged; every decision carries the name of the technician who reviewed and approved it.