AI Policy

Last updated: January 1, 2025

At Symply, we believe that artificial intelligence has the power to transform how small businesses manage payroll, HR, and compliance. We are committed to developing and deploying AI responsibly, ethically, and transparently. This AI Policy outlines our principles, practices, and commitments regarding the use of AI in our products and services.

1. AI-Driven Innovation

Symply integrates artificial intelligence across our platform to help small businesses operate more efficiently and make better decisions. Our AI-powered features include:

  • Ask-HR: An AI assistant that helps employees find answers to HR questions, understand company policies, and complete common tasks without waiting for human intervention.
  • Intelligent Payroll Processing: AI-powered anomaly detection that flags potential errors, inconsistencies, or unusual patterns in payroll data before processing, reducing mistakes and ensuring accuracy.
  • Compliance Monitoring: Automated tracking of regulatory changes across federal, state, and local jurisdictions, with intelligent updates to calculations and filings to maintain compliance.
  • Predictive Analytics: Data-driven insights that help business owners understand workforce trends, predict potential issues, and make informed decisions about their people and operations.
  • Smart Onboarding: AI-guided workflows that adapt to each new hire's situation, ensuring all required documentation is collected and compliance requirements are met.

We continuously invest in research and development to expand our AI capabilities while maintaining the highest standards of accuracy, reliability, and user experience.

2. Ethical AI

Symply is committed to the ethical development and deployment of AI. Our ethical AI principles include:

Fairness and Non-Discrimination

We design our AI systems to treat all users equitably. We actively test for and mitigate bias in our algorithms to ensure that AI-powered features do not discriminate based on race, gender, age, religion, national origin, disability, or any other protected characteristic.

Human Oversight

AI at Symply is designed to assist human decision-making, not replace it. All critical actions — such as payroll processing, tax filings, and employment decisions — require human review and approval. Our AI provides recommendations and flags potential issues, but the final decision always rests with the user.

Accountability

We take responsibility for the AI systems we build and deploy. When errors occur, we investigate promptly, communicate transparently, and implement corrections. Our engineering and data science teams are accountable for the performance and behavior of our AI features.

Continuous Improvement

We regularly audit our AI systems for accuracy, fairness, and reliability. We welcome feedback from our users and use it to improve our AI features and address any concerns.

3. Compliance

Symply's AI systems are designed and operated in compliance with all applicable laws and regulations, including:

  • Data Protection: We comply with the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable privacy laws. AI processing is subject to the same data protection standards as all other data processing in our platform.
  • Employment Law: Our AI features are designed to support compliance with federal and state employment laws, including the Fair Labor Standards Act (FLSA), Equal Employment Opportunity laws, and state-specific labor regulations.
  • AI-Specific Regulations: We monitor and comply with emerging AI-specific regulations at the federal, state, and local levels, including laws governing automated decision-making, algorithmic transparency, and AI in employment.
  • Industry Standards: We adhere to industry best practices and standards for AI development, including guidelines from the National Institute of Standards and Technology (NIST) AI Risk Management Framework.

4. Transparent Use

We believe transparency is essential to building trust in AI. Our commitments to transparency include:

Clear Identification

When you interact with an AI-powered feature, we clearly identify it as such. You will always know when you are receiving AI-generated content or recommendations versus human-generated responses.

Explainability

We strive to make our AI systems as explainable as possible. When our AI makes a recommendation or flags an issue, we provide context about why the recommendation was made and what data informed the decision.

User Control

Users maintain control over AI features in their accounts. You can enable or disable AI-powered features, adjust AI settings, and choose the level of AI assistance you are comfortable with. AI features never take actions without your knowledge and consent.

Documentation

We maintain comprehensive documentation about our AI capabilities, including what data is used, how models are trained, and what limitations exist. This documentation is available to customers upon request.

5. Data Sharing

Our approach to data sharing in the context of AI is governed by strict principles:

  • No Sale of Data: We never sell customer data or employee data to third parties for AI training or any other purpose.
  • Limited Third-Party Sharing: When we use third-party AI services or models, we share only the minimum data necessary and require contractual commitments to data protection, security, and restricted use.
  • Anonymization: When aggregated data is used for model improvement, it is anonymized and de-identified so that individual businesses or employees cannot be identified.
  • Partner Transparency: If an AI feature involves a third-party partner or model provider, we disclose this to users and ensure the partner meets our security and privacy standards.

6. Data Usage and Retention

Regarding how data is used for AI purposes:

Training Data

Our AI models are trained on a combination of proprietary datasets, publicly available data, and anonymized customer data. We never use identifiable customer data for training purposes without explicit consent.

Processing Data

When AI features process your data in real time (such as anomaly detection during payroll processing), the data is processed securely within our infrastructure and is not stored beyond what is necessary for the immediate function.

Retention

AI-related logs and processing records are retained in accordance with our data retention policy. Specifically:

  • AI interaction logs: Retained for up to 12 months for quality improvement and debugging purposes
  • Model training data: Retained for the lifetime of the model plus 12 months
  • AI-generated recommendations: Retained as part of your account history for as long as your account is active

You may request deletion of AI-related data at any time, subject to legal retention requirements.

7. Security

AI systems at Symply are subject to the same rigorous security standards as all other parts of our platform:

  • Encryption: All data processed by AI features is encrypted in transit (TLS 1.3) and at rest (AES-256). AI model weights and configurations are stored securely with access controls.
  • Access Controls: Access to AI systems, training data, and model configurations is restricted to authorized personnel using role-based access controls and multi-factor authentication.
  • Adversarial Testing: We regularly test our AI systems against adversarial attacks, including prompt injection, data poisoning, and model extraction attempts.
  • Monitoring: AI systems are continuously monitored for anomalous behavior, performance degradation, and security incidents. Automated alerts trigger immediate investigation.
  • Incident Response: We maintain a dedicated incident response plan for AI-related security events, including procedures for model rollback, data breach notification, and remediation.
  • Vendor Security: Third-party AI service providers are subject to security assessments, contractual security requirements, and ongoing monitoring.

We are committed to maintaining and continuously improving the security of our AI systems to protect our customers and their employees.

8. Contact Us

If you have questions, concerns, or feedback about our AI policy or AI-powered features, please contact us at:

Symply, Inc.
Email: ai@symply.io
Website: www.symply.io/contact

We welcome and encourage dialogue about responsible AI practices and are committed to addressing any concerns promptly and transparently.