← Back to Master Hub
REVOLUTIONARY EU AI ACT (REGULATION EU 2024/1689) & GDPR COMPLIANCE

Privacy Policy, Data Protection & EU AI Act Governance

Comprehensive legal framework governing data processing, GDPR user rights, and artificial intelligence safety requirements under European Regulation (EU) 2024/1689 across RSK System, RistoFlow, Pritty, and DoctorAI.

AI Governance Network and GDPR Privacy Protection
SEZIONE 1 // CONFORMITÀ REGOLAMENTO EUROPEO AI ACT (UE 2024/1689)

1. EU AI Act Compliance & Human Oversight (Art. 14)

All AI models and automated agents provided under the RSK System infrastructure (including RistoFlow, Pritty, and DoctorAI) strictly comply with Regulation (EU) 2024/1689 (EU AI Act). We enforce Article 14 (Human Oversight by Design), ensuring that no fully automated decision produces binding legal or health consequences without human verification. Furthermore, pursuant to Article 50, all synthetic communications, voice assistants, and text generators explicitly disclose their AI-assisted nature to end users.

SEZIONE 2 // GDPR (UE 2016/679) & RUOLI DEL TRATTAMENTO

2. Data Controller vs. Data Processor Responsibilities

RSK System acts strictly as a Data Processor pursuant to Article 28 of the GDPR (EU 2016/679). Client businesses, medical practices, and venues purchasing our software act as the Data Controller. We process customer bookings, contact details, and operational logs solely under the written instructions of the controller. No personal data is used to train open general-purpose public models, nor is data shared or sold to third-party brokers.

SEZIONE 3 // ISOLAMENTO TENANT & CRITTOGRAFIA

3. Tenant Segregation & Encryption Standards

Each client tenant operates within an isolated partition with dedicated encryption keys. Data at rest is encrypted using AES-256 standards, while data in transit is protected via TLS 1.3 encryption. For specialized verticals like DoctorAI, medical intake records are decoupled into dedicated data isolation vaults.

SEZIONE 4 // DIRITTI DEGLI INTERESSATI (CAPO III GDPR)

4. Data Subject Rights (Access, Erasure & Portability)

Data subjects retain all rights guaranteed under Chapter III of the GDPR: Right of Access (Art. 15), Rectification (Art. 16), Erasure / Right to be Forgotten (Art. 17), Restriction of Processing (Art. 18), and Data Portability (Art. 20). Requests for data extraction or erasure can be submitted to privacy@rsksystem.com or executed via tenant administration tools.

← Return to RSK System Master Platform