AI Policy
This AI policy describes how Netwrkz B.V. handles artificial intelligence (AI) in its own services, in solutions it develops and in the use of AI tools within the organisation. The policy has been drawn up in accordance with the European AI Regulation (Regulation (EU) 2024/1689, the 'AI Act'), the General Data Protection Regulation (GDPR) and relevant NIS2 obligations.
Laatst bijgewerkt: 22 april 2026
1. Purpose and scope
Netwrkz B.V. applies this policy to ensure that AI systems are deployed in a safe, transparent, fair, explainable and human-centred manner. The policy applies to all employees, contracted staff and clients of Netwrkz B.V. and covers both internal use of AI tools and AI functionality in solutions we design, implement or manage for clients.
2. Core principles
We apply the following principles, in line with Article 4 and Annex IV of the AI Act and the European Commission's Ethics Guidelines for Trustworthy AI:
- human agency and human oversight;
- technical robustness and safety;
- privacy and data governance;
- transparency and explainability;
- diversity, non-discrimination and fairness;
- societal and environmental well-being;
- accountability and traceability.
3. Risk classification (AI Act)
For every AI system we deploy internally or develop for clients, we carry out a risk classification in accordance with the AI Act:
- Unacceptable risk (Article 5): not developed, supplied or used by Netwrkz B.V.;
- High risk (Article 6 and Annex III): only deployed with a DPIA, conformity assessment, risk management system and human supervision;
- Limited risk: users are informed that they are interacting with an AI system (transparency obligation, Article 50);
- Minimal risk: deployed in accordance with general duty of care and this policy.
4. Permitted and prohibited use
Employees of Netwrkz B.V. may use approved AI tools for, among other things, code assistance, documentation, translation and analysis, provided this use complies with this policy and the information security policy. The following is prohibited in all cases:
- entering confidential client data, personal data or credentials into public AI services without appropriate safeguards or a data processing agreement;
- fully automating decisions with legal or similarly significant effects, without meaningful human intervention (Article 22 GDPR);
- using AI for manipulation, profiling based on special categories of personal data, or social scoring;
- publishing AI-generated content without review and without adequate controls.
5. Data protection and privacy
AI systems are designed according to the principles of privacy by design and by default (Article 25 GDPR). For processing activities with a potentially high risk — which includes many AI applications — we carry out a Data Protection Impact Assessment (DPIA) in accordance with Article 35 GDPR. Personal data is only processed on the basis of a valid legal ground, with data minimisation, purpose limitation and appropriate security.
When using external AI providers, we enter into a data processing agreement (Article 28 GDPR) and assess where the data is processed. For transfers outside the EEA, additional safeguards such as the Standard Contractual Clauses apply.
6. Transparency and explainability
When end users interact with an AI system — for example a chatbot or generative assistant — we communicate this clearly. AI-generated content (text, image, audio, video) is, where reasonably possible, labelled as such or provided with technical markers, in accordance with Article 50 of the AI Act. We ensure that decisions partly based on AI are traceable and explainable.
7. Human oversight
Human oversight is set up for every relevant AI system, so that a qualified person can monitor, interpret, override or stop its operation. For high-risk AI systems this is a hard requirement, in accordance with Article 14 of the AI Act.
8. Security and reliability
AI systems are developed and managed in accordance with our ISMS principles (derived from ISO 27001 and NIS2). This includes model security, protection against prompt injection and data poisoning, logging, drift monitoring and periodic model reassessment. Incidents involving an AI system are handled through our regular incident and vulnerability procedure.
9. Bias, fairness and non-discrimination
We actively test AI models for bias and discriminatory outcomes, including with regard to special categories of personal data (Article 9 GDPR). In the event of significant risks, mitigating measures are taken, such as rebalancing training data, additional reviews or limiting the scope of application.
10. Intellectual property and input
When using generative AI, we respect the rights of third parties. Content entered into an AI system by Netwrkz B.V. or its clients remains the property of the rights holder. We do not use client data to train models unless explicitly agreed in writing.
11. Suppliers and tooling
Before deploying an AI supplier, we carry out a supplier assessment covering security, privacy, AI governance and compliance with the AI Act. An up-to-date list of approved AI tools is maintained internally.
12. Responsibilities
The management of Netwrkz B.V. bears ultimate responsibility for compliance with this policy. The Data Protection Officer (where applicable) and the security officer advise on privacy and security aspects. Every employee is responsible for complying with this policy in their daily work.
13. Changes
Netwrkz B.V. reviews this AI policy at least annually and whenever there are significant changes in legislation and regulations (such as further implementing acts under the AI Act) or in our services.
14. Contact
Questions, reports or complaints about the use of AI within Netwrkz B.V. can be addressed to: Netwrkz B.V., Nobelstraat 15 BU6, 2693 BC 's-Gravenzande, Netherlands, email legal@netwrkz.io.