AI Usage and Transparency
How artificial intelligence works within Scoringmy: what it does, what it does not do, what data it receives and where its limits lie. Documentation for compliance, legal and AI governance teams.
Human oversight is mandatory
The platform never publishes automatically. All content passes through user review and validation.
No personal data in prompts
No names, emails or personal identifiers are sent to the models. Context is anonymised.
No model retraining
Neither prompts nor outputs are used to train, retrain or fine-tune AI models.
We do not build models
Scoringmy integrates third-party models via API. It is not a GPAI model provider under the EU AI Act.
Limited risk
A limited-risk system under the EU AI Act: no automated decisions affecting individuals.
Drafts, not truths
Outputs are editable suggestions. The user is responsible for verifying facts before publishing.
Contents
- The role of AI in Scoringmy
- What the AI does
- System architecture
- Model providers
- Data flow
- What data the AI receives
- Human oversight
- Model training policy
- System limitations
- Risk management
- Content safety controls
- Storage of AI outputs
- Responsible use for ambassadors
- Pilot and evaluation
- EU AI Act compliance
- Frequently asked questions
1. The role of artificial intelligence in Scoringmy
Scoringmy integrates generative artificial intelligence through external API services to assist users with professional communication and the improvement of their digital presence.
AI is an assistive component, not an autonomous decision-making system. It generates recommendations and draft content based on anonymised professional context and performance indicators.
The essentials
Scoringmy is not an AI model provider. It does not develop, train, fine-tune or host foundation models. It acts solely as an application layer orchestrating interactions with third-party models through commercial APIs.
2. What the AI does within the platform
AI capabilities fall into four categories:
2.1 Content generation
The system can generate suggested professional posts, draft content and topic ideas for professional communication. Outputs are always presented as editable drafts.
AI-generated content is never published automatically.
2.2 Professional recommendations
Based on the analysis of professional metrics, the AI generates suggestions to improve profile visibility, engagement strategies and tips for professional positioning. These recommendations draw on anonymised contextual information and performance indicators.
2.3 Content analysis
The system can analyse existing content and provide feedback on clarity and structure, tone and professional positioning, and potential engagement effectiveness.
2.4 Industry news and topic suggestions
The platform may suggest publicly available professional news and industry topics relevant to the user's professional context. These suggestions are always editable and require human review before publication.
3. AI system architecture
AI capabilities are implemented through a backend orchestration layer connecting the platform to external model providers.
| Layer | Function |
| Application | Web interface used by the end user. |
| Backend | Business logic, prompt generation and orchestration of AI requests. |
| AI integration | Connection to third-party models through secure API calls. |
| Infrastructure | Application server and database hosted at Hetzner Online GmbH (Germany, EU). |
The architecture ensures that all interactions with AI providers take place from the backend, never directly from the user's browser.
4. Model providers
Scoringmy integrates AI capabilities through external providers accessed via API:
| Provider | Use | Location |
| OpenAI | Language models for AI-assisted content generation and analysis | United States · GDPR safeguards |
| Google Gemini | Language models for AI-assisted content generation and analysis | United States · GDPR safeguards |
These providers act as sub-processors, solely for the purpose of generating the requested outputs, under their respective security and data protection frameworks. They operate under their own licensing terms.
Scoringmy does not modify or train these models. The behaviour and outputs of the AI depend on the capabilities and limitations of the external providers.
Any change of provider will be notified to clients in advance, in line with the Data Processing Agreement.
5. Data flow
The typical flow when an AI feature is used is as follows:
All AI communications take place server-side. API credentials are never exposed to the user.
6. What data the AI receives (and does not receive)
Prompts sent to the models are designed to avoid the inclusion of personally identifiable information (PII).
What is sent
- Professional role or job category
- Sector or industry
- Performance metrics
- Engagement indicators
- Anonymised profile characteristics
- User-defined objectives
What is never sent
- Names and surnames
- Email addresses
- Personal identifiers
- Employee identity information
- Special categories of data (GDPR Art. 9)
- Confidential company information
This separation ensures that prompts are anonymised before processing by external providers, in line with the GDPR principle of data minimisation.
The system is not designed to process special categories of personal data, and users are instructed not to include such data in any interaction with AI features.
7. Human oversight (Human-in-the-Loop)
Scoringmy implements mandatory human oversight for all AI-generated outputs.
The platform does not publish content automatically
Automatic publication of AI-generated content is not enabled within the platform. This is not a setting that has been switched off: it is a capability that does not exist.
Before using or publishing any content, the user must:
- Review the AI-generated output.
- Edit or adapt the content where necessary.
- Decide whether to use or publish it.
The user remains fully responsible for any content generated or published through the platform.
8. Model training policy
Scoringmy does not use prompts or generated outputs for model training. Specifically:
- Prompts are not used to retrain AI models.
- Outputs are not used for fine-tuning models.
- Customer data is not used to improve AI models.
AI providers process prompts solely for the purpose of generating the requested response.
9. System limitations
Like all generative AI technology, the system has inherent limitations. Outputs are provided without guarantees of factual accuracy, completeness or suitability for a specific purpose.
These limitations depend on the behaviour of the external providers (OpenAI, Google Gemini) rather than the platform itself.
9.1 Limitations matrix
| Category | Description | Potential impact | Mitigation |
| Hallucinations | The model may generate plausible but inaccurate statements | Incorrect or misleading content | Human review required before publication |
| Context misinterpretation | The AI may misunderstand limited context | Generic or irrelevant recommendations | Structured prompts and user validation |
| Incomplete knowledge | Models may not reflect the latest information | Outdated references | Users expected to verify factual content |
| Stylistic inconsistency | The tone of generated text may vary | Content may require editing | Draft-based generation |
| Bias | Outputs may reflect biases present in training data | Non-neutral suggestions | Human review and editing |
| Prompt sensitivity | Output depends on prompt structure | Variability in results | Controlled backend prompt templates |
| Overgeneralisation | Recommendations may be generic | Reduced personalisation | Users adapt suggestions |
| Over-reliance on AI | Users may rely too heavily on outputs without validating them | Incorrect or unverified content | Mandatory human review and user responsibility |
10. Risk management and safeguards
10.1 Governance principles
- Human oversight: all outputs require review and validation before use or publication.
- Responsible use: the user is responsible for reviewing outputs, verifying factual accuracy and adapting content before publication.
- Transparency: the system clearly communicates that suggestions are AI-generated and may require editing or verification.
10.2 Mitigation measures
- Human-in-the-loop review: mandatory before any publication.
- Prompt design controls: prompts are structured and generated by backend logic.
- Restricted use of personal data: prompts exclude personally identifiable information.
- Content responsibility: the user verifies outputs.
- Professional context: the system is limited to professional networking and communication scenarios.
- Server-side interactions: all API calls are executed from the backend.
10.3 Identified risk scenarios
- Factual inaccuracies in generated content.
- Incomplete or misleading interpretations.
- Tone or style misalignment with user expectations.
- Potential bias in generated suggestions.
- Over-reliance on AI outputs without proper validation.
These risks are mitigated through mandatory human review, user responsibility and restricted use cases.
11. Content safety controls
The platform incorporates safeguards to prevent the generation of inappropriate or unsafe content:
- Structured prompt templates designed to restrict inappropriate use cases.
- Guidance to users on acceptable content categories.
- Prohibition on generating confidential or personal data in prompts.
- Mandatory human review before publication.
At present these controls are implemented primarily through structured prompting, defined use restrictions and mandatory user review.
Scoringmy is designed exclusively for professional communication scenarios, which significantly limits exposure to harmful or sensitive content categories.
11.1 Integration security
- All AI calls originate from backend services.
- No AI API credentials are exposed to users.
- Prompts are structured and controlled by backend logic.
- Communications with providers are carried out over encrypted HTTPS connections.
Full detail on the architecture and infrastructure controls is available in the Security Centre.
12. Storage of AI outputs
AI-generated outputs may be stored within the platform under controlled conditions:
- Suggested posts are stored only where the user explicitly chooses to save them.
- Generated recommendations may be stored in the user's dashboard for reference.
Stored content remains under the user's control and can be modified or deleted at any time.
Access to AI-related data and outputs is restricted to authorised users within the platform, and protected through authentication and access control mechanisms.
13. Responsible use for ambassadors
Professionals taking part in advocacy programmes using Scoringmy remain fully responsible for reviewing AI-generated content, ensuring the accuracy of the information, and complying with their organisation's communication policies.
13.1 Recommended use
AI suggestions should be used as:
- A source of inspiration for professional posts.
- A starting point for drafting content.
- A way of exploring communication ideas.
- A way of discovering industry news and professional topics of public interest.
13.2 Prohibited uses
Users must avoid using the platform to generate:
- Confidential company information.
- Personal data of third parties.
- Defamatory or misleading content.
- Political or discriminatory content.
13.3 Prompt examples
Prohibited prompts
- "Write a post revealing my company's confidential strategy"
- "Create a post criticising a competitor using internal information"
- "Generate content that includes employees' personal data"
- "Write a post presenting unverified claims as facts"
- "Create content that imitates another person's voice or identity"
Recommended prompts
- "Suggest ideas for a professional LinkedIn post about leadership"
- "Help me draft a post about teamwork in the security sector"
- "Give me tips to improve engagement on professional posts"
13.4 Pre-publication checklist
Before publishing AI-generated content, ambassadors should verify:
- The accuracy of the information.
- That there are no unverified claims or statistics.
- That no confidential or sensitive information is included.
- Compliance with internal communication policies, and that the tone matches company guidelines.
14. Pilot and evaluation
Ahead of a wider rollout, organisations can run a pilot phase of two to four weeks to evaluate the platform with a small group of participants.
14.1 Evaluation criteria
| Criterion | What is assessed |
| Output quality | Accuracy and usefulness of the generated suggestions. |
| Factual reliability | Detection of incorrect or misleading statements. |
| Brand alignment | Consistency of content with the organisation's communication style. |
| Bias and neutrality | Assessment of outputs to detect potential bias. |
| User experience | Ease of use and clarity of the recommendations. |
| Human oversight | Whether users effectively review and validate the suggestions. |
14.2 Pilot governance
The organisation appoints a pilot owner responsible for coordinating the evaluation, collecting feedback and validating the results. At the end of the pilot, the organisation may decide to proceed with full deployment, implement additional safeguards, extend the pilot, or discontinue use of the platform.
15. EU AI Act compliance
Scoringmy is considered a limited-risk AI system under the EU AI Act, as it provides assistive content generation and analytical insights without making automated decisions affecting individuals.
15.1 Regulatory position
Scoringmy is not a provider of General Purpose AI models (GPAI) within the meaning of the EU AI Act. The platform:
- Does not train foundation models.
- Does not distribute AI models.
- Does not provide model access to third parties.
Responsibility for the underlying models lies with the respective providers. Scoringmy functions as an AI-enabled application layer integrating third-party models through APIs.
15.2 No automated decision-making
The system does not perform automated decision-making or profiling with legal or similarly significant effects on individuals, within the meaning of Article 22 of the GDPR.
15.3 Intended use and restrictions
AI functionality is intended exclusively for professional content drafting, professional networking communication support, and digital presence insights.
The system must not be used for:
- Automated publishing.
- Decision-making affecting individuals.
- Generation of confidential or sensitive information.
15.4 Versioning
AI capabilities may evolve as third-party models improve. Significant changes affecting system capabilities, risk profile or functionality will be documented in internal version records.
16. Frequently asked questions
Does Scoringmy train its own AI models?
No. Scoringmy does not develop, train, fine-tune or host models. It integrates OpenAI and Google Gemini models through commercial APIs.
Is personal data sent to the models?
No. Prompts exclude names, email addresses and personal identifiers. Contextual information is anonymised before it is sent.
Is our data used to train models?
No. Neither prompts nor outputs are used to train, retrain or fine-tune models, whether internal or third-party.
Can the platform publish to LinkedIn automatically?
No. Automatic publishing is not enabled within the platform. All content requires user review and validation.
Who is responsible for published content?
The user. AI-generated suggestions are supporting tools, not final content. Ultimate responsibility for anything published externally always rests with the person publishing it.
Is Scoringmy a high-risk system under the EU AI Act?
No. It is a limited-risk system: it provides assistive functionality without automated decisions affecting individuals.
Does the AI make decisions about employees?
No. The system does not perform automated decision-making or profiling with legal or similarly significant effects on individuals.
What happens if the AI generates incorrect information?
Outputs are provided without guarantees of accuracy. This is why human review is mandatory before any publication. Users are expected to independently verify factual claims.
Does your AI committee need more detail?
If your compliance, legal or AI governance teams need any point in this document expanded, or need to complete an impact assessment, write to us at legal@scoringmy.com.
Contact
- Compliance and AI governance: legal@scoringmy.com
- Legal entity: PeopleXBrand Aceleradora S.L.
- Company number (CIF): B-56994916
- Address: C/ Gregorio Benítez 10, 28043 Madrid (Spain)