AI Policy
CORPORATE & OPERATIONAL AI POLICY
Effective Date: August 2026
Updated: 2nd August 2026
Entity: Webtech Solutions – Zoltán Németh EV
Regulatory Framework: Regulation (EU) 2024/1689 (EU Artificial Intelligence Act) & Regulation (EU) 2016/679 (GDPR)
1. PURPOSE & REGULATORY SCOPE
Webtech Solutions ("Company", "We") is committed to delivering enterprise-grade e-commerce solutions, Magento 2/Laravel module development, and cloud infrastructure architecture. To maintain maximum operational velocity while upholding strict data security, data privacy, and software reliability, we integrate Artificial Intelligence (AI) technologies into our engineering workflow.
This Policy governs the internal and external use of AI systems across all operations. Under Regulation (EU) 2024/1689 (EU AI Act), Webtech Solutions operates primarily as a Deployer of third-party AI models for internal workflows and as a Developer/Integrator of AI-assisted capabilities within client deliverables.
2. APPROVED AI TOOLING & PERMITTED USE CASES
Webtech Solutions restricts operational AI usage exclusively to enterprise-grade, commercial-tier tools that provide strict data isolation guarantees.
2.1 Approved Operational AI Stack
GitHub Copilot (GitHub / Microsoft): In-IDE real-time code completion, boilerplate generation, and syntax optimization.
Claude Code / Claude Pro (Anthropic): Architectural planning, complex refactoring, technical documentation, and legacy codebase analysis.
Gemini Enterprise / Advanced (Google): System audits, requirements gathering, unstructured data extraction, multi-modal analysis, and SEO architecture planning.
2.2 Authorized Operational Workflows
AI tools are approved for use strictly within the following operational phases:
Software Engineering & Refactoring: Generation of clean, un-encrypted, PSR-12 compliant PHP, JavaScript (Alpine.js), CSS (Tailwind), and XML structures.
Architectural Planning & Feasibility: Drafting system topology diagrams, microservice workflows, and API payload schemas.
Requirements Assessment & Audits: Analyzing public site performance metrics, server log patterns, and technical SEO structure for client audits.
Technical Documentation & Specifications: Automating internal API references, customer-facing user manuals, inline code comments, and
/llms.txtspecifications.
3. DATA PRIVACY, CONFIDENTIALITY & ANTI-PII DIRECTIVES
Protecting client intellectual property, trade secrets, and end-user data is paramount.
3.1 Strict Anti-PII Directive
Zero PII in Prompts: Personally Identifiable Information (PII)—including customer names, e-mail addresses, payment credentials, phone numbers, or database dumps—must NEVER be entered into, processed by, or transmitted through any AI tool or prompt.
Credential Shielding: Production passwords, private SSH keys, API secrets, database credentials, and production
.envconfiguration files are strictly prohibited from AI input fields.
3.2 Non-Training Data Commitments
All AI tools utilized by Webtech Solutions operate under commercial enterprise licenses where third-party providers (Anthropic, OpenAI, Google, GitHub) explicitly contractually opt out of using input prompts, source code, or generated outputs to train, fine-tune, or improve public foundation models.
4. QUALITY ASSURANCE, CODE REVIEW & "HUMAN-IN-THE-LOOP" (HITL)
Webtech Solutions enforces a strict Human-in-the-Loop (HITL) mandate across all technical operations. AI is an engine for acceleration, not a substitute for senior engineering judgment.
┌─────────────────────────────────────────────────────────────────────────────┐
│ HUMAN-IN-THE-LOOP (HITL) QUALITY ENGINE │
├─────────────────────────────────────────────────────────────────────────────┤
│ [AI Prompt / Generation] ► [Senior Code Review] ► [Staging Sandbox QA] │
│ (Gemini/Claude/Copilot) (Syntax/Security/Logic) (Automated Testing)│
│ │ │
│ [Production Deployment] ◄── [Manual Verification] ◄────────────┘ │
└─────────────────────────────────────────────────────────────────────────────┘
Mandatory Senior Code Review: No AI-generated code snippet, module layout, or configuration script may be merged into production branches without manual line-by-line inspection, static analysis, and verification by a senior engineer.
Verification Against Hallucinations: Technical specifications, library choices, and algorithmic logic produced by AI models must be fact-checked and verified against official vendor documentation (e.g., Adobe Commerce / Magento developer docs) prior to client delivery.
Security Standards: All AI-assisted software outputs must adhere to OWASP Top 10 security standards, ensuring immunity against SQL injection, Cross-Site Scripting (XSS), and insecure direct object references.
5. CLIENT TRANSPARENCY & EU AI ACT COMPLIANCE (ART. 50)
In accordance with Article 50 of the EU AI Act (Transparency Obligations):
Disclosure of AI Assistance: Clients are informed that Webtech Solutions utilizes AI-assisted development tools (such as Claude Code, GitHub Copilot, and Gemini) to optimize engineering timelines, enhance code quality, and maintain competitive pricing structures.
Synthetic Content Transparency: Where a client deliverable includes AI-generated synthetic content (e.g., automated SEO product metadata or synthetic weather risk notifications), Webtech Solutions ensures the output is clearly identified and validated before deployment.
SLA & Warranty: The use of AI tools in the development workflow does not alter, dilute, or diminish Webtech Solutions' 12-month code quality warranty or underlying Service Level Agreements (SLAs).
6. INTELLECTUAL PROPERTY (IP) & OWNERSHIP
Client Ownership: Subject to full payment of applicable project fees, all final source code, custom module architecture, and technical documentation delivered to the client remain the exclusive intellectual property of the client.
Prompt Architecture: Webtech Solutions retains ownership of its proprietary internal prompt libraries, custom agent workflows, and AI optimization scripts developed during internal operations.
Copyright Integrity: AI systems are queried exclusively for original code construction and architectural structuring. Webtech Solutions actively monitors outputs to prevent third-party copyright infringement or unauthorized code GPL bleed.
7. GOVERNANCE & POLICY REVISION
This AI Policy is audited bi-annually by Webtech Solutions management to adapt to evolving European regulatory standards, updates to the EU AI Act, and advancements in Large Language Model capabilities.
Approved by: Zoltán Németh EV (Founder, Webtech Solutions)
Contact for AI Compliance Inquiries: info@webtech-solutions.hu