Responsible AI Policy
Responsible AI Policy Version 1.1, effective as of March 1, 2024. Last reviewed September 1, 2026.
Special Note on Personal Data: This policy covers how Draup designs, develops, deploys, and governs artificial intelligence. It does not replace our privacy documentation. For how Draup collects, uses, shares, and protects personal information, see the Privacy Policy, the EU User Privacy Policy, and our GDPR information.
Special Note for Clients and Users: Questions about this policy, and any concern about an AI system operated by Draup, can be raised through the contacts in Section 9.
Please read this policy carefully. It sets out the principles Draup applies to artificial intelligence, the framework we use to put those principles into practice, and the channels available to raise a concern. It is maintained by the Responsible AI Committee and reviewed at least annually.
Policy summary
1. Introduction and Purpose
1.1 Draup’s commitment to Responsible AI
Draup is committed to developing and deploying artificial intelligence in a manner that is ethical, transparent, fair, and aligned with human values. We recognize the transformative potential of AI in talent and sales intelligence, and we build our systems to empower users, respect individual rights, and contribute positively to society.
1.2 Policy objectives
This policy aims to:
- Establish clear principles and guidelines for the responsible design, development, deployment, and use of AI systems at Draup.
- Mitigate potential risks associated with AI, including bias, lack of transparency, and privacy infringement.
- Foster a culture of responsibility and ethical consideration across all AI-related activities.
- Ensure compliance with relevant legal and regulatory frameworks.
- Build and maintain trust with our employees, clients, users, and the wider community.
1.3 Scope of this policy
This policy applies to:
- All employees, contractors, and third-party partners involved in the design, development, testing, deployment, operation, or sale of AI-powered products, services, and internal tools at Draup.
- All AI systems developed or procured by Draup, including machine learning models, natural language processing tools, and other AI-driven analytics.
1.4 Definitions
Artificial Intelligence (AI): Systems that display intelligent behavior by analyzing their environment and taking actions, with some degree of autonomy, to achieve specific goals.
Bias (in AI): Systematic errors or prejudices in AI systems that can lead to unfair or discriminatory outcomes, often stemming from biased data or flawed algorithms.
Explainability: The ability to describe, in understandable terms, how an AI model arrives at its decisions or predictions.
Transparency: Openness about how AI systems are designed, trained, and deployed, including the data used and the limitations of the system.
Responsible AI (RAI): An approach to developing, deploying, and using AI systems in a way that aligns with ethical principles and societal values, aiming for beneficial outcomes while mitigating risks.
2. Guiding Principles for Responsible AI
2.1 Fairness and non-discrimination
Draup AI systems are designed and operated to avoid unfair bias and discrimination against individuals or groups on the basis of protected characteristics, including race, gender, age, and disability, or other unjust factors. This applies with particular force in talent acquisition and sales opportunity identification. We work actively to identify and mitigate bias in both data and models.
2.2 Transparency and explainability
Draup strives for transparency in its AI systems. Where feasible and appropriate, we provide users and affected individuals with understandable explanations of how AI-driven decisions or recommendations are made, the data influencing them, and the capabilities and limitations of the system.
2.3 Accountability and governance
Draup establishes clear lines of responsibility and oversight for its AI systems, and maintains governance structures to ensure that development and deployment align with this policy and with ethical best practice. Decisions made by AI systems carry human accountability.
2.4 Privacy and data security
Draup is committed to protecting the privacy and security of data used in its AI systems, in compliance with applicable data protection regulation including GDPR and CCPA. We implement appropriate technical and organizational measures to safeguard personal and confidential information. Our Privacy Policy sets out how personal information is collected, used, and shared.
2.5 Reliability, robustness, and safety
Draup AI systems are developed to be reliable, to perform as intended, and to be resilient to manipulation and unexpected inputs. We test rigorously for accuracy, robustness, and safety before deployment, and monitor continuously after it.
2.6 Human-centricity and oversight
Draup AI systems are designed to augment human capabilities, not to replace human judgment in critical decisions. We maintain appropriate levels of human oversight, particularly in applications with significant impact on individuals such as hiring recommendations and performance assessment.
2.7 Beneficence and societal impact
Draup works to create AI systems that deliver tangible benefit to our clients, users, and society. We consider the broader societal and ethical implications of our applications and aim at positive outcomes, including fairer hiring practices and more efficient business operations.
Where each principle is operationalized
3. Operationalizing Responsible AI: Framework and Practices
3.1 AI governance framework
3.1.1 Responsible AI Committee (RAIC). Draup establishes a committee composed of cross-functional representatives drawn from legal, engineering, product, data science, ethics, and HR. The committee oversees implementation of this policy, reviews AI Impact Assessments, advises on ethical dilemmas, promotes awareness of responsible AI across the company, and reports to executive leadership.
3.1.2 Roles and responsibilities. Responsible AI duties are defined clearly for data scientists, engineers, product managers, legal counsel, and other relevant roles.
3.2 Risk assessment and management
3.2.1 AI Impact Assessments (AIIA). An assessment is mandatory for every new AI project and for significant updates to existing systems. Each assessment identifies potential ethical risks, biases, privacy concerns, and societal impacts, and evaluates data sources, model purpose, potential for misuse, and impact on affected individuals. Systems are assigned a risk tier of high, medium, or low, with a corresponding level of scrutiny.
3.2.2 Continuous risk monitoring. Processes are in place to monitor AI systems after deployment for emerging risks and unintended consequences.
3.3 Data governance for AI
3.3.1 Data quality, provenance, and integrity. Protocols govern the accuracy, completeness, and relevance of data used to train AI models. Data sources and transformations are documented.
3.3.2 Bias detection and mitigation in data. Datasets are proactively assessed for bias related to protected characteristics and other unfair factors. Where bias is identified, we apply mitigation techniques such as re-sampling, data augmentation, and algorithmic adjustment, as appropriate.
3.3.3 Data minimization and anonymization. We collect and use only the data necessary for the intended purpose of the AI system, and apply anonymization or pseudonymization techniques where feasible to protect privacy.
3.3.4 Secure data handling and storage. Data used in AI systems is collected, stored, processed, and transmitted in accordance with Draup data security policies.
3.4 AI model development and validation
3.4.1 Bias testing and mitigation in models. Fairness metrics and bias testing are integrated throughout the model development lifecycle. We explore and apply algorithmic fairness techniques to mitigate identified bias in model outputs, and document mitigation strategies and their effectiveness.
3.4.2 Robustness and adversarial testing. Models are tested against adversarial attacks and unexpected inputs to confirm stability and reliability, and performance is evaluated across diverse subgroups.
3.4.3 Explainability techniques and documentation. We employ appropriate explainability methods such as SHAP, LIME, and feature importance to understand model behavior, and document model architecture, training data, assumptions, limitations, and performance metrics.
3.4.4 Model versioning and lifecycle management. Models and datasets are placed under version control, with established processes for retraining, updating, and decommissioning.
3.5 Deployment and monitoring
3.5.1 Phased rollouts and pilot programs. New AI systems are released through phased rollouts or pilot programs so that issues surface and are addressed in a controlled environment.
3.5.2 Continuous monitoring for performance, drift, and bias. Production systems are monitored for model performance, data drift, concept drift, and the re-emergence of bias, with thresholds set for alerts and intervention.
3.5.3 Feedback mechanisms for users and clients. Channels are available for users and clients to give feedback on AI system performance, report issues, and raise concerns.
3.6 Human oversight and intervention
3.6.1 Defining human roles in AI-assisted decisions. We delineate clearly where AI provides a recommendation and where a decision is automated, and identify the decision points that require mandatory human review and approval.
3.6.2 Human-in-the-loop and human-on-the-loop for critical decisions. Applications with high impact on individuals or business outcomes, such as final hiring decisions and significant sales strategies, operate under human-in-the-loop or human-on-the-loop mechanisms. Reviewers are given sufficient information and context to make an informed judgment.
3.6.3 User training on AI capabilities and limitations. Internal staff and clients are educated on how to interpret AI outputs, understand their limitations, and recognize when to seek human expertise.
3.7 Incident response and remediation
3.7.1 Reporting AI-related incidents and ethical concerns. A clear process exists for reporting AI-related incidents, errors, biases, and ethical concerns. See Section 9.
3.7.2 Investigation and root cause analysis. Reported incidents are investigated promptly to determine root causes.
3.7.3 Remediation and continuous improvement. Corrective action is taken to address identified issues and prevent recurrence, and what we learn from an incident is used to improve our AI systems and processes.
4. Specific Considerations for Draup’s AI Applications
4.1 Talent intelligence, including resumes, skills, and workforce planning
Applies to our talent intelligence and AI workforce transformation products.
4.1.1 Mitigating bias in candidate sourcing and matching. We actively audit and mitigate bias related to gender, ethnicity, age, and similar attributes in algorithms that screen resumes, match candidates to roles, or predict success, with emphasis on skills-based matching and objective criteria.
4.1.2 Transparency in skills assessment and recommendation. Clients receive insight into how skills are inferred and why particular candidates or development paths are recommended.
4.1.3 Protecting candidate privacy. Sensitive candidate information is protected through robust data protection, adhering to consent and purpose limitation principles.
4.2 Sales intelligence, including lead scoring and market insights
Applies to our sales intelligence and AI sales agent products.
4.2.1 Ensuring accuracy and fairness in lead scoring. Lead scoring models are validated for accuracy on a regular cycle, and scoring is designed not to unfairly disadvantage certain types of prospects without justifiable business reasons.
4.2.2 Transparency in data sources for insights. We are transparent with clients about the data sources and methodologies used to generate sales and market insights.
4.2.3 Protecting prospect and client data. Data processed for sales intelligence purposes is handled in accordance with applicable data privacy regulation.
5. Training and Awareness
5.1 Mandatory RAI training for all employees. Every employee completes responsible AI awareness training covering the core principles, an overview of this policy, and the mechanisms for reporting a concern.
5.2 Specialized training for technical and product teams. Data scientists, engineers, and product managers receive in-depth training in bias detection and mitigation, explainability techniques, AI Impact Assessments, and secure AI development practices.
5.3 Continuous learning and knowledge sharing. We foster a culture of continuous learning by sharing best practices, case studies, and updates on responsible AI developments.
6. Stakeholder Engagement and Communication
6.1 Transparency with clients and users. We communicate clearly with clients about how AI is used in Draup products, what it delivers, and where its limits lie, and we provide documentation and support to help users work with AI-powered features effectively.
6.2 Collaboration with industry and academia. We engage with industry peers, research institutions, and ethical bodies to stay informed about best practice and contribute to the advancement of responsible AI.
6.3 Public reporting. Draup may publish periodic reports on its responsible AI efforts, challenges, and progress, as appropriate.
7. Compliance and Auditing
7.1 Adherence to applicable laws and regulations. Draup stays current with, and complies with, the local, national, and international laws and regulations that apply to AI, data privacy, and non-discrimination. These include GDPR, CCPA, and the principles of the EU AI Act. Our Privacy Policy and GDPR information set out our data protection commitments in detail.
7.2 Internal and external audits of AI systems. We conduct regular internal audits of AI systems, processes, and documentation to confirm adherence to this policy. For critical AI systems, Draup may also commission periodic external audits by independent third parties.
8. Policy Review and Updates
8.1 Regular review cycle. This policy is reviewed and updated at least annually by the Responsible AI Committee, and sooner where circumstances require it.
8.2 Triggers for an update. A review may be triggered by significant change in AI technology, new regulatory requirements, a major incident, evolving ethical norms, or feedback from stakeholders.
9. Contact and Reporting Concerns
9.1 Designated point of contact. The Chair of the Responsible AI Committee is the primary point of contact for questions or concerns about this policy and about responsible AI at Draup. Write to support@draup.com.
9.2 Whistleblower protection. Draup protects employees who report responsible AI concerns in good faith against retaliation. Concerns may be raised through Draup’s internal reporting channel or by writing to support@draup.com.
PLEASE CHECK THIS PAGE PERIODICALLY FOR UPDATES TO THIS POLICY.