Key points
- People stay in charge. The AI systems we build keep a person in the loop for decisions that matter and for anything that cannot be undone.
- We check every project against the EU AI Act before we build it, and we do not build uses the Act prohibits.
- We do not use client data to train general-purpose AI models.
- We use AI tools in our own work, and a member of our team reviews what they produce.
- We build on the latest stable models from leading providers such as OpenAI, Anthropic and Google.
01
Why we have this policy
Haystack Ltd (C93790) designs and builds AI and automation systems for businesses. This policy explains the principles we follow in that work, how we apply the EU Artificial Intelligence Act, how we treat the data our clients trust us with, and how we use AI ourselves.
02
Our principles
- Useful before clever: we use AI where it clearly saves time or improves quality, and simpler automation where that does the job better.
- Human oversight: people approve decisions that affect customers, staff or money, and can always override the system.
- Privacy by design: we use the least data needed, and keep it protected and in the European Union wherever we can.
- Honesty: people are told when they are dealing with an AI system, and we are open with clients about what a system can and cannot do.
03
How we apply the EU AI Act
Before we start a project, we look at how the system will be used and where it falls under the AI Act’s risk categories. In practice this means:
- Prohibited practices: we do not build systems the Act bans, such as manipulative techniques that cause harm or social scoring.
- High-risk uses: if a use case falls into a high-risk area, such as recruitment or credit decisions, we tell the client early and design for the Act’s requirements on risk management, data quality, documentation, logging and human oversight.
- Transparency: where people interact with an AI system, or receive content it generates, we build in clear notices and, where required, machine-readable marking.
- AI literacy: we train our own team and help client teams understand the systems they use, including their limits.
Our articles on what the AI Act means for Maltese businesses explain the rules and timetable in more detail.
04
How we treat client data
- We do not use client data to train general-purpose AI models, and we choose AI providers whose business terms do not allow them to train on our clients’ data.
- We process client data only on the client’s instructions, under a data processing agreement.
- Access is limited to the people who need it, and systems log who did what.
- When a project ends, we return or delete client data as agreed.
05
The AI providers and models we use
- We build on AI models from leading providers, such as OpenAI, Anthropic and Google, through their business services rather than their consumer apps.
- We always use the latest stable versions of their models. We do not put experimental or preview versions into client systems.
- When a provider releases a new stable version, we test it on the client’s own examples before switching, so quality never drops without anyone noticing.
- We choose the provider and model for each task based on accuracy, speed, cost and where the data is processed, and we tell each client which providers their system uses.
- Under these providers’ business terms, the data we send is not used to train their models.
06
Accuracy, testing and monitoring
AI systems can make mistakes. We test each system on realistic examples before it goes live, set thresholds so that uncertain cases go to a person, and monitor results after launch. When the underlying AI model changes, we test again before switching.
07
Security
We design AI systems with limited permissions, so they can only reach the data and actions they need. We protect against prompt injection, where instructions hidden in documents or web pages try to take control of an AI agent, and we keep keys and credentials out of the model’s reach.
08
How we use AI ourselves
Our team uses AI tools to help with research, drafting, analysis and writing code. A person reviews and takes responsibility for anything we deliver or publish. Some of the articles on this website are drafted with the help of AI tools and are reviewed and edited by our team before publication. The help panel on this website is a site search and quick links, not an AI chatbot.
09
Raising a concern
If you have a question or concern about an AI system we have built, or about this policy, email hello@haystack.mt. We will look into it and reply.
10
Changes to this policy
We review this policy as the law and technology change. The date at the top of this page shows when it was last updated.