This page explains where there is artificial intelligence inside Ofivia, what each piece does, what content leaves our server and what stays. It is written for the person who has to decide whether to put a team to work on this.
One clarification about scope before you read on. The notice telling you that you are talking to an artificial intelligence system lives in the application, not here: the conversation with the agent is separate from the chat between people and is labelled as AI in the interface itself. That label cannot be switched off, there is no branding option that removes it, and what a client company can customise stops at the logo, the colours and the headline on its login screen. Today that notice is the label and nothing else: there is no sentence stating it at the start of each conversation. This page is the detail behind that notice, not the notice.
1. Where there is artificial intelligence and where there is not
| Function | What runs it | Where it happens |
|---|---|---|
| Agent turns: drafting, reading the vault, carrying out tasks | A third party language model | Leaves the server |
| Scheduled routines | The same agent, fired on a schedule | Leaves the server |
| Image generation | An outside provider | Leaves the server |
| Video generation | An outside provider | Leaves the server |
| Meaning based search inside the vault | An embedding model hosted on our own infrastructure | Stays |
| Transcription of audio and voice notes | A transcription model hosted on our own infrastructure | Stays |
| Keyword search, the link graph, permissions, chat between people | No model at all. It is PostgreSQL and code | Stays |
Two practical consequences follow. Indexing your entire back catalogue sends nothing to any model provider and costs no credit, because indexing and search run on the same machine that holds your vault. And audio recorded inside the application is transcribed on that same machine, without passing through a third party service.
Where there is no artificial intelligence: we do not score or profile people, no model decides promotions, credit, hiring or access to anything, and this public site has no analytics and no visitor tracking, as set out in the cookie policy.
2. What leaves the server and where it goes
When the agent works, what leaves is the slice of content it needs to resolve that request: your department’s instructions, the history of that conversation, and the files it opens to answer. The whole vault does not go out, and neither does a dump of your database.
| Provider | What we use it for | What it receives |
|---|---|---|
| Anthropic, with Claude | Default engine for the agent’s turns | The text of the conversation and the contents of the files the agent opens to answer |
| OpenAI | Alternative agent engine, selectable per conversation, and the free image generator, which works against ChatGPT | For the agent, the same as the row above. For images, the written prompt and any reference images you attach |
| KIE.ai | Bulk image generation and video generation, the latter with Bytedance’s video model | The written prompt and, when there is reference material, a short lived signed link its servers download the file from |
That last row deserves a warning. The reference file is not uploaded: it is published at a signed link that expires after thirty minutes and works for that one file. While the link is alive, anyone holding it downloads the file without signing in, and today we cannot revoke it before it expires. We say so because it is a real difference from the comfortable claim that the file never leaves.
Providers that do not run models, such as infrastructure, storage and email, are in the sub-processor list.
3. The agent gets things wrong
The agent produces text. Sometimes that text is incorrect, incomplete, or states things that are nowhere in your vault. It happens with the best models available today and it happens with ours.
It says both in the same confident tone. The shape of an answer tells you nothing about how much certainty sits behind it, and an invented fact usually reads as well written as a correct one.
It works on what is in your department’s vault. If a document is out of date or wrong, the answer inherits that error without flagging it.
We publish no accuracy percentages, no time saved figures and no productivity numbers. We have no measurement of our own over the kind of content and the kind of company we serve, and publishing a number without that measurement would mean making it up.
Before you decide, publish, hire or communicate anything based on an agent output, review it. That review belongs to your company. We do not review the content the agent produces inside your account and we cannot: we do not read our clients’ vaults passively, and that isolation is precisely what we sell.
Ofivia does not provide legal, accounting, medical, financial or any other regulated professional service. The agent does not replace the professional who does provide it, and it does not take from anyone the responsibility for what they sign.
4. Generated images and video
Ofivia generates synthetic images and video. Every generated file is stored in the company’s vault together with the prompt that produced it, the engine that generated it, who asked for it and when. That record is internal and exists so that later on you can tell what each file is and where it came from.
On machine readable marking we have to be exact. The European AI Regulation requires synthetic content to be marked in a format a machine can detect. Ofivia does not add that marking today. What each provider embeds in the file it returns is the provider’s decision, we do not verify it, and re-encoding the file along the way can strip it, so nothing leaving Ofivia can be claimed to carry it. We would rather say that than announce a watermark that does not exist.
The visible label is your responsibility. If your company distributes an image, an audio file or a video made with Ofivia that resembles real people, places, entities or events, European law requires you, as the deployer, to disclose clearly and perceptibly that the content was artificially generated or manipulated. A technical marking, where a provider adds one, does not replace that label, and we cannot apply the label for you because we do not control where you publish.
On impersonating real people: do not use the generator to pass synthetic content off as genuine where that misleads about an identifiable person. Fabricating someone’s face, voice or statements and presenting them as real exposes your company and may be an offence, and it is not what this product came to do.
5. What cannot be generated
Generating intimate material of an identifiable person without their explicit consent is prohibited on Ofivia, as is child sexual abuse material. There is no exception and no use case that justifies it.
What sits behind that prohibition today, said plainly: the providers that run the generation apply their own input and output filters. Ofivia adds no filter of its own over prompts or over results today. What does exist is the record of what was generated, from what prompt and from which account, and immediate suspension of the account when this material appears, with no notice and no refund.
If you find material like this in something made with Ofivia, write to soporte@ofivia.com with the link or the file. That is handled the same business day and waits for no deadline.
6. Automated decisions
Ofivia’s agents do not, on their own, take decisions producing legal effects on people. They write, search, summarise, prepare drafts and carry out tasks inside the company’s vault. The person deciding works at that company.
If an automated assessment did influence a decision affecting you, article 20 of Ecuador’s data protection law gives you five things: a reasoned explanation, the right to submit observations, the assessment criteria, the types of data used and their source, and the right to challenge the decision. If the General Data Protection Regulation applies to you, its article 22 gives you an equivalent right. How to exercise it is in section 8 and in the privacy policy.
7. Your data and model training
We do not train artificial intelligence models, our own or anyone else’s, on our clients’ content, and we do not use it for any purpose other than providing the service. That is in the data processing agreement and does not depend on this page.
The text we index and the audio we transcribe do not leave our infrastructure, so no model provider sees them. What reaches a provider is only the slice needed to answer the request being handled, as described in section 2.
What each provider may do with what it receives depends on the contract with that provider, not on our goodwill. The detail is in the data processing agreement and in the sub-processor list. Where we do not yet hold that confirmation in writing, we say so instead of assuming it: [written confirmation of no training, per provider].
One specific case worth knowing before you use it. The free image generator works against a ChatGPT account we operate, not against a per company programming interface, and the terms of an account like that are not the terms of a commercial contract. While that route stays as it is, do not send confidential material or photographs of identifiable people through it. For that work there is bulk generation, which goes through a programming interface rather than a consumer account.
8. Oversight, limits and complaints
Who to write to. If an agent output worries you, or you found generated material that should not exist, write to soporte@ofivia.com. If your question is about this document, about your personal data or about human review of a decision, write to hola@ofivia.com.
How fast we answer. We acknowledge receipt within two business days. The substantive answer comes within the fifteen days Ecuadorian law gives for a data subject’s rights; if the General Data Protection Regulation applies to you, the period is one month, extendable by two more when the case requires it, telling you before the first one runs out. The prohibited material in section 5 waits for no deadline.
How to ask for human review of an output that affected a decision. Write to hola@ofivia.com and include the approximate date and time, the company and the project, the agent output exactly as you received it, and what decision was taken or was about to be taken with it. Someone on our team reviews the case and answers with a reasoned explanation, the criteria involved, and the types of data and the sources used. If you are not satisfied, you can challenge the decision and your objection is recorded in writing.
A limit we would rather state up front: when the decision was taken by your company over its own content, the controller is your company and not us. In that case we pass your request to whoever administers that account and support them on the technical side, which is as far as our role as a processor goes.
If you believe we handled your request badly, you can complain to Ecuador’s Superintendencia de Protección de Datos Personales. If you are in the European Union, you can also go to the supervisory authority in your country.
9. Legal framework and date
This document answers Regulation (EU) 2024/1689 on artificial intelligence, as amended by Regulation (EU) 2026/1744, and in particular the transparency obligations in its article 50. It also answers Ecuador’s Ley Orgánica de Protección de Datos Personales, articles 12(17) and 20, and the Superintendencia’s rule on processing personal data with artificial intelligence systems. And it answers the Ecuadorian unfair competition and consumer protection rules, which require any claim about the technology used to be substantiated before it is published, not after somebody challenges it.
Date of this version: 18 August 2026. If what artificial intelligence does inside Ofivia changes, this page changes first.