Go Testify – AI & Data Usage Policy
1. Overview
This policy explains how Go Testify Limited ("Go Testify", "we", "us") uses artificial intelligence and machine learning technologies in the delivery of our services, and the commitments we make to our customers about how their data is handled in connection with AI systems.
Go Testify provides playtesting and player research services to the video games industry. As part of the continuous improvement of these services, we may use AI and machine learning technologies to enhance analysis, reporting, and the quality of insights delivered to customers.
This policy should be read alongside our Data Processing Addendum, our Sub-Processor List, and any customer-specific contractual terms. Where a customer-specific agreement varies these commitments, that agreement governs for that customer.
2. How we use AI
We may use AI technologies in the following areas:
- Sentiment and thematic analysis — automated analysis of playtester feedback to identify patterns, sentiment, and recurring themes.
- Reporting — AI-assisted summarisation, pattern identification and categorisation of related observations and themes.
- Transcription and language processing — automated transcription of playtesting sessions and natural language processing of open-ended responses.
- Vision processing — capture, embedding and labelling of visual data for real-time search.
- Workflow optimisation — AI-assisted solutions developed by Go Testify to help streamline test preparation, setup, analysis and reporting.
- Internal productivity — AI tools for internal operations such as documentation, scheduling, and workflow optimisation (not involving customer data).
We will not use AI to:
- Process customer data through AI systems without a lawful basis and a contractual purpose.
- Share customer data with AI providers in a manner that permits those providers to use the data for their own purposes, including model training.
3. Our core commitments
- Purpose limitation — customer data is only processed through AI systems for the specific purpose of delivering the contracted services to that customer.
- Data minimisation — only the minimum data necessary is provided to AI systems. Where possible, data is anonymised or pseudonymised before processing.
- Isolation — customer data processed through AI systems is logically isolated. Data from one customer is never combined with data from another customer for AI processing.
- No cross-customer learning — insights, models, or outputs generated from one customer's data are not applied to or shared with other customers.
- Confidentiality — all customer data processed through AI systems remains subject to the confidentiality obligations in the applicable Data Processing Addendum and service contract.
- Human oversight — AI-generated outputs are subject to human review. We do not make decisions producing legal or similarly significant effects about individuals by solely automated means.
4. Model training and data usage
- Zero data retention with AI providers — we maintain zero data retention agreements with all third-party LLM providers. Customer data submitted for AI processing is not stored, cached, or retained by the provider beyond the immediate API request/response cycle.
- No third-party model training — customer data is never used by our AI providers to train, fine-tune, retrain, or otherwise improve their models or services. This is contractually enforced through our zero-retention and data processing agreements with each provider.
- API-tier agreements — we use API-tier service agreements (not consumer-tier) with all AI providers to ensure contractual protections around data usage, retention, and training exclusions are in place.
- No custom model training on customer data — we do not train or fine-tune custom AI models using customer data. If we introduce this capability in the future, customers will be notified in advance, no customer data will be used without explicit written consent, and any such arrangement will be documented through a separate addendum to the Data Processing Addendum.
5. Service improvement and your opt-out
We may use customer data internally to test, evaluate, and improve our own AI analysis logic, workflows, and service quality — for example, benchmarking AI analysis accuracy against human-reviewed outputs, or testing updated workflows and prompt configurations. This work is conducted internally by Go Testify and does not involve sharing customer data with third parties for their benefit.
You may opt out of having your data used for service improvement at any time by notifying us in writing at infosec@gotestify.com. Opting out will not affect the quality or scope of the services delivered to you.
6. AI sub-processors
AI providers used to process customer data are sub-processors under our Data Processing Addendum. Our current AI sub-processors are:
| Provider | Purpose | Data location |
|---|---|---|
| OpenAI | AI processing of video/audio/transcript data; automated summaries and insights (zero data retention) | Global |
| Anthropic | AI processing of video/audio/transcript data; automated summaries and insights (zero data retention) | Global |
| Pinecone | AI vector database for image embeddings and visual search | US |
The full sub-processor list, including non-AI providers, is maintained at https://www.gotestify.com/sub-processors, where you can subscribe to receive notice of changes.
We evaluate all third-party AI providers before use with customer data. Providers must support zero data retention agreements, contractually prohibit the use of inputs/outputs for model training, offer enterprise-grade or API-tier data processing terms, process data within the EEA or under appropriate safeguards (such as Standard Contractual Clauses), maintain appropriate security certifications (e.g. SOC 2, ISO 27001), and document enforceable retention and deletion practices.
7. Data retention and deletion
- AI-generated outputs (e.g. analysis reports, categorised data) are retained as part of the project deliverables and subject to the same retention terms as other customer data.
- Raw customer data used for service improvement is retained only for as long as necessary for the improvement activity and is then deleted or anonymised.
- Customers may request deletion of their data (including AI-processed derivatives) in accordance with the Data Processing Addendum. We will confirm deletion in writing within 10 business days.
8. Security
AI systems processing customer data are subject to the same security controls as the rest of our platform, including role-based access controls for AI tools and API keys, encryption in transit (TLS 1.2+), encrypted credential storage, and logging of AI service usage (retained for 12 months). We do not input customer credentials, API keys, or sensitive personal identifiers into AI systems.
9. Incidents and contact
In the event of a security incident involving AI systems that process customer data, we follow our Security Incident Response Plan, including immediate suspension of the affected AI service pending investigation and notification to affected customers within the timeframes specified in their Data Processing Addendum.
This policy is reviewed at least annually. Questions or concerns can be raised with our Data Protection Officer at infosec@gotestify.com.
Go Testify Limited | Unit 17, 8 Cromac Avenue, Belfast, BT7 2JA