Effective: August 18, 2026

1. Introduction and Scope

MindFire Internet Solutions, Inc. (“MindFire,” “we,” “us,” or “our”) uses artificial intelligence (“AI”) to enhance our products and services and to improve how we work, while treating the data entrusted to us with care. This AI Policy explains how we use and govern AI, the principles that guide that use, and the safeguards we apply.

This Policy describes our approach to AI systems that we develop, configure, procure, deploy, or operate across mindfireinc.com, our platform and personalized microsites (PURLs/GURLs), our AI Voice Agent, and our internal business operations (collectively, the “Services”). MindFire does not train or build its own foundation models; instead, we develop AI-enabled features — such as the AI Voice Agent — on top of enterprise- or business-tier models and services from established third-party providers. AI-enabled features that MindFire develops or deploys are subject to this Policy and to MindFire’s applicable development, security, and change-management controls.

Our use of AI involving personal information is subject to our Privacy Policy and applicable privacy and data-protection requirements. Authorized AI systems are also governed by applicable security and confidentiality controls within MindFire’s information-security program and SOC 2 Type II control environment.

2. Our AI Principles

  • Responsible and lawful use. We use AI for legitimate business purposes and in accordance with applicable laws, regulations, and our contractual commitments.
  • Privacy and data protection. We apply privacy and data-protection safeguards to personal and confidential information used with AI, including data-minimization and access controls appropriate to the use.
  • Transparency. We disclose when a person is interacting directly with an AI system rather than a human.
  • Human oversight. People remain accountable for decisions that produce legal or similarly significant effects on individuals. AI may assist our team, but it does not replace appropriate human judgment for such decisions.
  • Security. Authorized AI systems are governed by applicable controls within MindFire’s information-security program, which is independently examined under SOC 2 Type II.
  • Accountability. We apply accountability and oversight to AI systems based on their purpose, risk, and potential impact.

3. Roles and Responsibilities

As with personal information we handle, our responsibility for AI depends on the capacity in which we act:

  • As a business/controller. When we use AI to operate our own websites and to conduct our own sales, marketing, recruiting, support, and internal operations, we decide how and why AI is used, and this Policy governs that activity.
  • As a service provider/processor. When we provide AI-enabled features (such as the AI Voice Agent) on campaigns and personalized microsite pages we host for our clients, we do so on the client’s instructions and for their purposes. In that case, the client’s own privacy policy governs their end users’ data, and our handling is governed by our agreement with the client. MindFire provides platform capabilities to support AI disclosure, consent, and opt-out mechanisms. Certain controls, including the AI Voice Agent’s disclosure and consent process, are built into the service, while clients are responsible for implementing and managing optional capabilities, such as preferences regarding future AI interactions, as appropriate for their use and applicable legal obligations.

Regardless of which role applies, data that MindFire has access to through AI systems is subject to our applicable information-security and confidentiality controls, including controls within our SOC 2 Type II control environment.

4. How MindFire Uses AI

MindFire uses enterprise- or business-tier AI services from established providers. Examples of our current AI uses include:

4.1 Software Development (Engineering Productivity)

Our engineering teams use AI coding assistants to help write, review, document, and test software more efficiently. Human engineers remain responsible for AI-assisted code before it is deployed to production, and such code is subject to MindFire’s applicable testing, security, and change-management controls. Production credentials, customer data, and other sensitive information may not be shared with AI tools outside our approved, controlled environments.

4.2 Operational and Business Productivity

Across the business, our teams use AI to assist with everyday operational tasks such as drafting and summarizing documentation, preparing internal content, analyzing information, and supporting project work. Employees remain responsible for reviewing AI-generated output as appropriate before relying on it or sharing it externally, and may use MindFire or customer information only with AI tools approved for that purpose. Certain categories of data — for example, human-resources data and other highly sensitive information — are restricted or prohibited from use with AI tools, and use involving personal information is subject to additional controls.

4.3 AI Voice Agent (Customer Engagement)

MindFire provides an AI-enabled Voice Agent that can be configured and deployed on the personalized microsite pages we host to assist visitors and help collect information. Where this feature is enabled, we design it so that visitors are informed they are interacting with an AI assistant and provide consent before the conversation is recorded and transcribed. Visitors who do not wish to interact with the AI Voice Agent may decline consent and end the AI interaction. MindFire also provides clients with tools that can be used to collect and manage preferences regarding future AI interactions; clients are responsible for implementing and managing these preferences as appropriate for their use.

Audio recordings and transcripts generated by the AI Voice Agent are treated as personal information. In all cases, this data is protected by applicable security and confidentiality controls within MindFire’s information-security program and SOC 2 Type II control environment. The privacy terms that govern this data depend on our role: where MindFire operates the AI Voice Agent as a service provider on a client’s behalf, the client’s privacy policy and our agreement with the client govern the handling of their end users’ data; where MindFire acts as the business/controller, our Privacy Policy applies.

5. Data Handling and Privacy in AI

  • Authorized AI services. For work involving MindFire or customer information, we use AI services authorized by MindFire based on appropriate security, privacy, data-handling, and contractual considerations. MindFire or customer information may not be used with unauthorized AI services.
  • Use of data for model training. We do not authorize third-party AI providers to use personal information or confidential customer information to train or improve their general-purpose models, except where expressly permitted under applicable contractual terms and authorized by the party with authority over that information.
  • Data minimization and access controls. We seek to limit AI systems’ access to information reasonably necessary for their intended purpose and restrict access to authorized personnel and approved systems and integrations.
  • Sensitive information. We apply additional restrictions and safeguards to the use of sensitive personal, confidential, or otherwise restricted information with AI systems, based on the nature of the information and the intended use.
  • Retention. Personal information used by or generated through AI systems is retained in accordance with MindFire’s applicable privacy and data-retention practices and, where MindFire processes information on behalf of a client, applicable client instructions and contractual requirements.

6. Transparency and Disclosure

We believe people should know when they are interacting directly with an AI system rather than a human. Where MindFire provides an AI system that communicates directly with an individual — such as the AI Voice Agent — the interaction is identified as AI-driven. For the AI Voice Agent, visitors are informed that they are interacting with an AI assistant, and consent is required before the conversation is recorded and transcribed. Visitors who do not wish to proceed may decline consent and end the AI interaction.

7. Human Oversight and Accountability

AI at MindFire is used to assist people, not to independently make decisions that produce legal or similarly significant effects on individuals. Where AI assists with such decisions, appropriate human review is required before the decision is made. MindFire assigns accountability and oversight for AI systems based on their intended purpose, the sensitivity of the information involved, and their potential impact. Our teams can review, override, suspend, or escalate the use of AI systems where appropriate.

8. Third-Party AI Providers

When selecting third-party AI services for use with MindFire or customer information, we consider appropriate aspects of the provider’s security, privacy, confidentiality, data-retention, and data-handling practices, including the provider’s use of submitted data for model training or improvement and applicable contractual protections. MindFire or customer information may be used only with AI services that MindFire has authorized for that purpose.

9. Security

AI systems and the data they process are governed by applicable security and confidentiality controls within MindFire’s information-security program and SOC 2 Type II control environment. Depending on the system and its use, applicable measures may include encryption of data in transit and at rest, role-based access controls, multi-factor authentication, audit logging, logical isolation of client data, monitoring, and testing. AI-related security incidents and other material AI-related events are addressed through MindFire’s applicable incident-response and escalation processes.

10. Governance and Review

MindFire maintains internal governance for the responsible use of AI, with accountability and oversight appropriate to the nature of the AI use, the sensitivity of the information involved, and the potential impact on customers or individuals. Our AI practices are reviewed periodically to account for changes in our use of AI, technology, security considerations, and applicable legal or regulatory requirements. This Policy is reviewed at least annually and updated as appropriate.

11. Compliance

We use AI consistent with applicable privacy, data-protection, and other laws and regulations, including, where applicable, the California Consumer Privacy Act (CCPA), other U.S. state privacy laws, the EU General Data Protection Regulation (“GDPR”), and the UK GDPR, as well as our contractual obligations to clients.

12. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version with a new “Effective” date and, where required, provide additional notice.

13. How to Contact Us

For questions about this Policy or how MindFire uses AI:

  • Email: compliance@mindfireinc.com
  • Phone: (877) 560-3473
  • Mail: MindFire Internet Solutions, Inc., PO Box 14395, Irvine, CA 92623, USA