virbe.
Dokument prawnyWersja 1

Oświadczenie o przejrzystości AI

Obowiązuje od 16 listopada 2026

This statement explains how the Virbe platform uses artificial intelligence, how Virbe sp. z o.o. ("Virbe") meets its obligations under Regulation (EU) 2024/1689 (the "AI Act"), and what organisations that deploy assistants built with Virbe ("deployers", our customers) need to do. It is provided for information; the binding commitments are in the Terms of Service (https://virbe.ai/terms), the Acceptable Use Policy (https://virbe.ai/legal/acceptable-use-policy) and the Data Processing Agreement (https://virbe.ai/dpa).

1. What the Virbe platform is

1.1. Virbe is a platform for building and running conversational assistants ("virtual beings") that talk with people by text and voice and can be represented by animated avatars, on websites (the Virbe Widget), on kiosks (the Virbe Kiosk Application) and in applications using our APIs.

1.2. Intended purpose. The platform is intended for assistants that provide information, customer service, sales assistance, guidance and engagement, including optional on-device presence detection and audience statistics on kiosks. It is not intended for any practice prohibited by Article 5 of the AI Act, nor for the high-risk uses listed in Annex III of the AI Act (such as recruitment, credit scoring, access to education or essential services). Such uses are not permitted without a specific agreement with Virbe.

1.3. AI components. Assistants use large language models (LLMs), speech-to-text and text-to-speech engines and avatar animation. These models are developed by third-party providers (for example Microsoft/OpenAI, Anthropic, Google and ElevenLabs). Virbe does not develop or place general-purpose AI models on the market; it integrates them into its platform. Customers choose which providers their assistants use, usually with their own accounts.

2. Who is responsible for what

TopicVirbe (provider of the platform)Deployer (our customer)
Telling people they are talking to AI (Art. 50(1))Builds the disclosure into the Widget, Kiosk and voice channels, enabled by defaultKeeps the disclosure enabled and clear; does not present the assistant as human; implements an equivalent disclosure in its own interfaces built on the APIs
Marking AI-generated content (Art. 50(2))Marks text, audio and video delivered through the Widget, Kiosk and APIs in a machine-readable format where technically feasible, whatever engine is used, and preserves marks applied by model providersDoes not remove or tamper with marks
Notices for kiosk camera features (Art. 50(3))Keeps the features off by default, processes images on the device and provides notice templatesDisplays notices before people enter the camera's field of view; carries out a DPIA where required
Deepfakes and digital replicas (Art. 50(4))Provides labelling options and the templates belowLabels avatars or voices that resemble real people as artificially generated; obtains the person's consent
AI literacy (Art. 4)Provides documentation and guidanceTakes measures so that staff operating assistants understand their capabilities and limits
Prohibited and high-risk usesDefines the intended purpose and prohibits misuse in the Acceptable Use PolicyUses the platform within its intended purpose
Data protectionProcesses conversation data as a processor, does not train models on itActs as controller: legal basis, privacy notice, retention settings

3. Transparency features

3.1. AI disclosure. Every assistant delivered through the Widget, the Kiosk Application or voice channels informs people at the start of the interaction that they are talking to an AI system. Deployers can adapt the wording, language and design to their brand, within the limits described in the Documentation, but cannot switch it off.

3.2. Marking of synthetic content. Virbe applies machine-readable marks that identify text, speech and avatar video delivered through the platform as AI-generated, where technically feasible and whatever engine produced them, in line with the EU Code of Practice on transparency of AI-generated content. For platform versions placed on the market before 2 August 2026, marking is rolled out no later than 2 December 2026. Marks applied by model providers are preserved.

3.3. Version history. Changes to the platform are documented in the release changelog available in the Dashboard.

4. Our approach to data and models

4.1. No training on customer data. Virbe does not use conversations, knowledge base content or other customer data to train or fine-tune any AI model, its own or a third party's. AI providers engaged by Virbe are contractually prohibited from doing so.

4.2. Data flows. For each conversation turn, the platform sends to the configured model provider only what is needed to generate the answer: the user's message, relevant conversation history, the deployer's instructions and, if enabled, retrieved knowledge base content. Details: https://docs.virbe.ai and our Sub-processors page (https://virbe.ai/legal/subprocessors).

4.3. Privacy-enhancing options. Deployers can enable detection and removal of personal data from incoming text before it is stored or sent to models, set short retention periods and automatic clean-up of conversations, and keep data in their own Azure tenant.

5. Limitations you should know about

5.1. AI-generated answers are probabilistic. Even when the platform works correctly, assistants can produce answers that are inaccurate, incomplete, outdated or inconsistent with the deployer's knowledge base ("hallucinations"), may reflect biases in the underlying models, and may perform less well in some languages, accents or noisy environments.

5.2. We distinguish platform defects (for example an assistant not responding, executing the wrong flow because of a software defect, or failing to call a configured model), which Virbe fixes under its terms, from model errors (fluent but wrong answers), which are an inherent property of current AI models and must be managed by the deployer's design and oversight.

5.3. Assistants do not provide legal, financial, medical or other professional advice, and their answers should not be relied on as such.

6. Recommended human oversight

We recommend that deployers:

  • ground assistants in a curated knowledge base and instruct them to say when they don't know;
  • test assistants before going live, including with adversarial questions, and re-test after changes to prompts, knowledge base or models;
  • monitor conversations and quality metrics, and keep a record of configuration changes;
  • offer an easy way to reach a human for complaints, sensitive topics and decisions about individuals;
  • warn users not to share sensitive personal data, passwords or account numbers;
  • follow the usage policies and guidance of the model providers they use.

7. Kiosk camera features

7.1. The Kiosk Application can optionally use a camera to detect that someone is in front of the kiosk and to estimate age range and gender for audience statistics. These features are off by default, are enabled by the deployer, process images only on the kiosk and send only aggregated statistics to the platform. They do not identify people, do not recognise emotions and do not store images.

7.2. The deployer must inform people before they enter the camera's field of view and must not use these features in workplaces in relation to employees, in schools, in places primarily intended for children, or to treat individual people differently in ways that significantly affect them.

8. Deployer kit — templates

Adapt the following texts to your situation, language and legal advice.

8.1. AI disclosure (Widget or first message). "Hi! I'm a virtual assistant powered by artificial intelligence. I can make mistakes, so please check important information. Please don't share passwords, account numbers or other sensitive personal data in this chat."

8.2. Kiosk notice (sign placed at the kiosk and visible before the camera's field of view). "This kiosk uses an AI assistant. A camera detects when someone is in front of the kiosk and estimates age range and gender for anonymous statistics. Images are processed only on this device, are not stored and are not used to identify you. Controller: [company name, contact]. More information: [link or QR code to your privacy notice]."

8.3. Label for an avatar or voice based on a real person. "This avatar and voice are artificially generated and represent [name] with their consent."

8.4. Privacy notice paragraph for your website. "Our website uses an AI assistant provided by Virbe sp. z o.o. as our processor. When you chat with it, we process your messages (and your voice, if you use it) to answer your questions [purpose]. Conversations are stored for [period]. The assistant uses AI models of [providers], which process the data on our behalf. [Legal basis, rights and contact details.]"

8.5. DPIA prompts. Consider in particular: the categories of people who will talk to the assistant (including vulnerable persons); whether they may share special categories of data; retention of transcripts and audio; the AI providers and their data locations; the camera features of kiosks and the place where kiosks are installed; human escalation; and how you will handle requests to access or delete conversations.

9. Reporting concerns

Concerns about an assistant built with Virbe, its outputs or suspected misuse can be reported to [email protected]; security vulnerabilities to [email protected]. Deployers should report serious incidents and malfunctions to Virbe without undue delay, as required by the Terms of Service. In Poland, the authority supervising compliance with the AI Act is designated under the Polish Act on Artificial Intelligence Systems.

10. Updates

We update this statement as our platform, the AI Act and related guidance (including the European Commission guidelines on Article 50 and the Code of Practice on transparency of AI-generated content) evolve. Previous versions are available at https://virbe.ai/legal/ai-transparency.