1. Purpose and scope
This policy (the Policy) governs the use of artificial intelligence systems by Made in Evolve S.r.l. (Made in Evolve or the Company) in the delivery of its eCommerce agency and system integration services and in the development of the SaaS platform Nucleo Platform, including the AI assistant Atomo.
The Policy is binding on the Company’s staff, external contractors and suppliers who work on behalf of Made in Evolve on client projects or internal systems, and is published for the benefit of clients and website visitors.
The terms AI system, general-purpose AI model (GPAI), provider and deployer have the meaning defined in Article 3 of Regulation (EU) 2024/1689 (the AI Act).
2. Principles
- Human oversight. AI supports people’s work and does not replace them in decision-making. Every output intended for a client or the public is checked by a competent person, who takes responsibility for it.
- Transparency. We disclose the use of AI whenever the law requires it and whenever it is relevant to the recipient.
- Fairness. We do not use AI to discriminate against or covertly profile people, and we check that outputs do not reproduce bias.
- Security. We use only approved tools, with company accounts, under measures aligned with the principles of ISO/IEC 27001:2022.
- Data protection. Personal data enter AI systems only where necessary, in minimised form and with suppliers bound by data processing agreements.
- Accountability. The Company is responsible for the content and services it delivers, whatever tool was used to produce them.
3. Roles under the AI Act and application timeline
3.1 Tools used and role as deployer
Made in Evolve exclusively uses the general-purpose AI systems of OpenAI, Anthropic, Google Gemini and Microsoft Copilot. Other tools, including free services or personal accounts, are not permitted without prior approval (section 10). In relation to these tools the Company acts as a deployer (Article 3(4) AI Act): it uses them under its own authority in the course of its professional activity, without changing their intended purpose or placing them on the market under its own name.
3.2 Role as provider for Nucleo Platform and Atomo
The AI features built into Nucleo Platform (Brain/CRM, Catalog, Commerce and Intelligence modules) and the Atomo assistant are developed by Made in Evolve on the models of the suppliers listed in section 3.1. For these features the Company acts as a provider (Article 3(3) AI Act), since it makes them available to clients under its own name, and takes care of their technical documentation, user information and transparency (section 7).
3.3 Application timeline
The AI Act entered into force on 1 August 2024 and applies in stages:
| Date |
Applicable provisions |
Relevance for Made in Evolve |
| 2 February 2025 |
Prohibited practices (Article 5); AI literacy (Article 4) |
Applicable: review of practices; training (section 11) |
| 2 August 2025 |
Obligations for providers of GPAI models (Chapter V); governance and penalties |
Indirect: concerns the model providers |
| 2 August 2026 |
General application, including transparency (Article 50) and Annex III high-risk systems |
Applicable for Article 50 (section 7); high-risk rules not applicable |
| 2 August 2027 |
High-risk systems embedded in Annex I products |
Not applicable |
4. Risk classification
Made in Evolve has reviewed its use cases under the AI Act’s risk-based approach and concluded that it:
- carries out no prohibited practice (Article 5): no manipulative techniques, social scoring, emotion recognition in the workplace or biometric categorisation;
- neither uses nor develops high-risk systems (Annex III): in particular, AI is not used in candidate selection, in the evaluation of workers or in access to essential services;
- takes no decisions based solely on automated processing with legal or similarly significant effects on individuals (Article 22 GDPR): Nucleo Platform automations produce suggestions and drafts that an operator accepts, edits or rejects.
Our uses therefore fall within limited-risk systems (subject to Article 50) or minimal-risk systems.
5. Permitted use cases
| Use case |
Tools |
Risk level |
Human control required |
| Draft texts (copy, articles, product descriptions) and translations |
OpenAI, Anthropic, Google Gemini, Microsoft Copilot |
Minimal |
Editorial review and source checking before delivery or publication |
| Draft and review of code (Shopify, Laravel, integrations) |
OpenAI, Anthropic, Google Gemini, Microsoft Copilot |
Minimal |
Code review, testing, licence check of dependencies |
| Data analysis and reporting (performance, SEO, CRO, CRM) |
OpenAI, Anthropic, Google Gemini, Microsoft Copilot |
Minimal |
Verification of calculations and conclusions; aggregated or pseudonymised data where possible |
| Product and editorial images generated or edited with AI |
Visual features of the listed suppliers |
Limited (Article 50) |
Client approval; labelling of realistic images; no real person without consent |
| Assisted customer support (draft replies, summaries, classification) |
Listed suppliers; Nucleo Platform features |
Minimal or limited |
Sent by an operator; any chatbot is disclosed |
| Automations and suggestions in Nucleo Platform and Atomo (CRM enrichment, extraction from documents, draft quotes) |
Models of the listed suppliers, integrated by Made in Evolve |
Limited (Article 50) |
Every proposed action is accepted, edited or rejected by a user; Atomo presents itself as an AI assistant |
6. Prohibited uses
The following are prohibited, unless authorised in writing by management after a risk assessment:
- entering into prompts special categories of data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR);
- entering personal data of clients or of their end users into tools that lack a data processing agreement (DPA) and business or enterprise plans that exclude model training;
- entering confidential client information (credentials, API keys, financial data, proprietary code) into unapproved tools or personal accounts;
- using AI to make decisions about people (recruitment, performance evaluation, commercial terms for individual consumers, profiling with legal effects);
- generating or manipulating images, audio or video depicting identifiable real people without documented consent (deepfakes);
- creating deceptive content: fake reviews, untruthful performance data, imitations of protected trademarks or styles, messages that pretend to come from a person;
- publishing or delivering AI outputs without human review.
7. Transparency obligations (Article 50 AI Act)
Made in Evolve already adopts as an operating standard the obligations of Article 50, fully applicable from 2 August 2026:
- Chatbots and assistants. Every system that interacts with natural persons, including Atomo and any assistants built for clients, informs the user that they are interacting with an AI system, unless this is obvious from the context.
- Images, audio and video. Realistic content generated or manipulated with AI carries a clear indication of its artificial origin in the metadata and, where possible, visibly or in the caption. Minor edits (colour correction, background removal) do not require labelling.
- Texts intended for the public. Texts generated with AI and published to inform the public on matters of public interest carry the relevant indication, unless they have undergone human review with editorial responsibility.
- Information to clients. In quotes and contracts we indicate, where relevant, which deliverables involve the use of generative AI (for example images) and with which controls.
8. Intellectual property
- Originality. Outputs intended for publication are checked to rule out substantial reproductions of third-party works, trademarks, logos or styles; in case of doubt they are reworked or replaced.
- Model licences. Tools are used in compliance with the suppliers’ terms, including any limitations on the commercial use of outputs.
- Ownership of outputs. This is governed by the contract with the client. We inform clients that copyright protection presupposes a human creative contribution and that purely automated outputs may not be protected as works of authorship.
- Client and third-party content. It is used with AI within the limits of the rights granted and never to train or fine-tune models.
- Website content. The conditions for reuse of madeinevolve.com content by AI systems are set out in the Website Terms of Use.
9. Personal data protection
Processing by means of AI complies with Regulation (EU) 2016/679 (GDPR), Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the Italian Privacy Code) and our Privacy Policy:
- Minimisation and pseudonymisation. Only the data needed enter prompts; names, contact details and direct identifiers are removed when not essential; where possible, aggregated or anonymous data are used.
- Suppliers with DPA. OpenAI, Anthropic, Google and Microsoft process data as processors under a DPA. Transfers outside the EU are covered by the Standard Contractual Clauses (Decision 2021/914) and, for participating US suppliers, by the EU-US Data Privacy Framework.
- No training on client data. We use business or enterprise plans under which the supplier contractually excludes the use of data to train models; Made in Evolve does not train or fine-tune models on client data.
- Atomo and Nucleo Platform. Atomo operates only on the data of the individual client (tenant), with memory isolated per tenant: one client’s data are never used for another. Hosting at DigitalOcean, Frankfurt data centre.
- Data subject rights. Requests may be submitted through the Privacy requests page or to privacy@madeinevolve.com.
10. Quality, control and use-case register
- Human review. No AI output is delivered or published without review by a competent person, who checks its accuracy, consistency with the brief and compliance with the Policy.
- Testing. AI-generated code is subject to the same tests, code review and security checks as manually written code; Nucleo Platform AI features are tested before release.
- Use-case register. The Company keeps an internal register recording the tool, purpose, data categories, risk level, controls and owner of each use case, reviewed annually.
- Risk assessment. Before adopting a new tool or use case, the area lead assesses its classification under the AI Act, impacts on personal data (including any data protection impact assessment under Article 35 GDPR), intellectual property, security, risks of error or bias and human control.
- Incidents. Significant errors, data leaks or harmful outputs are reported to management and handled under the security procedures, including notification under Articles 33 and 34 GDPR where due.
11. AI literacy (Article 4 AI Act)
In accordance with Article 4 of the AI Act, applicable since 2 February 2025, Made in Evolve ensures that staff and contractors have a sufficient level of AI literacy, taking into account their role and the context of use:
- onboarding training on the Policy, the approved tools and typical risks (hallucinations, bias, intellectual property infringement, data leakage);
- periodic updates, at least annually, on regulatory and technical developments;
- specific training for area leads on risk assessment and transparency;
- documentation of attendance.
12. Suppliers and clients
- Suppliers and contractors. They are bound to the Policy by contractual clauses: prohibition on entering our clients’ data into unapproved tools, obligation to disclose the use of AI in deliverables, intellectual property warranties.
- AI suppliers. We select suppliers that offer adequate technical documentation, compliance with the AI Act obligations for GPAI models, a DPA and exclusion of training.
- Clients. Contracts govern the use of AI in deliverables, ownership of outputs, the processing of personal data (with a DPA where Made in Evolve acts as processor) and, for Nucleo Platform, the terms of use of the AI features and of Atomo. Clients may request at contract stage that generative AI be excluded for specific deliverables.
13. Reporting and review
Anyone who identifies a non-compliant use of AI may report it to hello@madeinevolve.com or, for personal data matters, to privacy@madeinevolve.com. Staff and contractors may also use the channel help@madeinevolve.com, managed by a designated, autonomous and trained person bound by confidentiality, adopted on a voluntary basis in line with the principles of Legislative Decree 24/2023.
The Policy is reviewed at least once a year and whenever new provisions of the AI Act become applicable, new tools are adopted or use cases change significantly. The updated version is published on this page with its update date.
This English version is provided for convenience; in case of discrepancy the Italian version prevails.