Product scope and legal information
Terms, Disclaimer & Privacy Information
Last reviewed: 7 August 2026
The product promise
AI Ledger is an independent software platform. It does not provide certification, legal advice or guarantee compliance with the EU AI Act.
AI Ledger helps organisations centralise AI-use inventories, policies, approvals, training and simulation records, risk and applicability assessments, incidents, supporting documents, and reviewable evidence. It is designed to support a documented, risk-adapted governance programme and traceable proof of the measures an organisation has taken.
AI Ledger does not issue an EU AI Act certification, certify an organisation or individual, guarantee legal compliance, or make a binding legal determination. A status, percentage, recommendation, checklist result, export, learning record, or AI-generated suggestion describes information recorded in the workspace; it is not a legal opinion or authority approval.
Terms of service
The Service is offered to organisations for their internal business use. The person creating or administering a workspace confirms that they are authorised to act for that organisation. The applicable checkout summary, order form, data processing agreement, and any negotiated service terms form part of the agreement and prevail over conflicting product-page text.
Accounts and authorised use
Customers are responsible for account security, member access, role assignment, lawful content, and prompt revocation of access that is no longer required. The Service must not be used unlawfully, to gain unauthorised access, transmit malicious code, or make solely automated consequential decisions about people.
Subscriptions and billing
The checkout screen identifies the final price, billing interval, trial, renewal terms, and tax before purchase. Plan limits enforced by the Service may change only in accordance with the applicable agreement. Contractual support commitments or service levels apply only when they are stated in an executed order form.
Customer content
Customers retain their rights in content submitted to the Service and grant the operator the limited rights needed to host, secure, process, back up, and return that content to provide the Service. Customers must have the rights and lawful basis needed for personal, confidential, employee, customer, and vendor information they submit.
Availability and liability
Unless an order form states otherwise, the Service is provided without a guaranteed service level. To the maximum extent permitted by applicable law, neither templates nor automated outputs are warranted to be complete or suitable for a customer's specific legal situation. Mandatory statutory rights and liabilities that cannot lawfully be excluded remain unaffected.
Customer responsibilities
The customer remains responsible for:
- determining its legal role, applicable duties, deadlines, and national or sector-specific rules;
- verifying source documents, provider instructions, classifications, assessments, and the sufficiency of retained evidence;
- having accountable people review and approve AI-assisted drafts and material decisions;
- making required external submissions or notifications through the correct official channels; and
- obtaining qualified legal, data-protection, employment, security, or sector advice where appropriate.
AI-assisted features
When enabled by the organisation and configured by the operator, AI can help draft purposes and assessments, rewrite or translate text, and surface possible regulatory workflow gaps. AI outputs can be incomplete, inaccurate, or unsuitable. They must be reviewed against authoritative sources and customer evidence before use.
AI suggestions do not determine applicability, legal classification, risk acceptance, employee performance, or compliance. Organisations should not submit secrets, special-category personal data, or other restricted content to an external model unless that use and provider are expressly approved. Provider, location, retention, and training terms must be documented in the applicable data processing information.
Privacy information
Roles and purposes
The operator generally acts as controller for account, authentication, billing, security, support, and essential service-usage data. For workspace content submitted by a customer, the operator generally acts as processor on the customer's documented instructions, subject to the data processing agreement. The exact roles depend on the deployment and processing activity.
Data categories
Data may include account and membership details, authentication and security events, billing references, AI-system and vendor records, policies, evidence files, declarations, acknowledgements, learning and simulation responses, incidents, audit events, and support communications.
Legal bases and rights
Depending on the activity, processing may rely on performance of a contract, compliance with legal obligations, legitimate interests in operating and securing the Service, or consent where required. Individuals may have rights of access, correction, erasure, restriction, portability, objection, and complaint to a supervisory authority, subject to applicable conditions. Workspace users should normally address requests to their organisation; operator-level requests may be sent to the privacy contact below.
Retention, subprocessors, and transfers
Retention follows the customer's configuration, the contract, legal holds, and the operator's documented backup and deletion schedule. An expired or quarantined record is not proof of physical deletion. Hosting location, subprocessors, support-access locations, international transfer safeguards, and provider retention commitments must be identified in the order form, data processing agreement, or current subprocessor notice for the deployed service.
Security and evidence integrity
Security and data-residency claims depend on the production infrastructure actually selected and configured. The workspace reports a data region only when the operator declares it. Customers should verify database, object storage, backup, analytics, support, email, error-monitoring, billing, and optional AI data flows rather than relying on a generic product claim.
Audit events are hash-linked to support tamper detection. Hash linking is not the same as immutability and does not by itself prove that a record is complete, accurate, or legally sufficient. Independent integrity evidence additionally requires the external root-anchoring option to be configured and verified.
EU AI Act context
Product workflows are mapped to selected obligations and controls under Regulation (EU) 2024/1689, as amended, including the current Article 4 approach to measures supporting AI literacy. The law does not require AI Ledger or a particular certificate, and the platform does not promise either.
Scope depends on the organisation's role, system, intended purpose, affected people, sector, and national law. Provider, importer, distributor, product manufacturer, general-purpose AI, data-protection, employment, consumer, accessibility, and sector obligations may require additional work outside the platform. Users should verify material decisions against the current official text and competent-authority guidance.
Official sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744.
Service operator and contacts
ATTACK Simulator SRL
CLUJ-NAPOCA, STR. AUGUSTIN PRESECAN NR. 6, JUD. CLUJ, ROMANIA
Registration: RO43550687
Legal notices: info@attacksimulator.com
Privacy requests: info@attacksimulator.com
© 2026 AI Ledger.