Flex Applications AI policy - EU AI Act
The purpose of this policy
The purpose of this policy is to:
-
explain how our AI capabilities are intended to be used,
-
describe how we work to meet the relevant requirements of the AI Act
-
be transparent about how the AI features work, their limitations and what safeguards are in place.
Your rights
When you use our AI features, it should be clear that you are interacting with AI. You should also be able to get support if something goes wrong or is unclear.
In practice, this means that you can:
-
get information on when a feature uses AI and what it is intended for
-
get guidance on how to interpret results and when you should verify
-
contact us to report issues, get help or ask questions.
In the future, if an AI feature can suggest or initiate actions in Flex HRM, there should be clear human control before anything is executed.
What data do we process in our AI functions, how do we process it and why?
Flexie (chatbot)
Flexie is an AI assistant for users of Flex HRM. It provides answers and guidance on the use, configuration and troubleshooting of Flex HRM and can use predefined tools to retrieve information or perform limited user-initiated tasks.
Activity:
Answer questions, provide guidance and assist users with selected tasks in Flex HRM Payroll, Time, Plan, Employee, Pay Equity Compass and Travel via chat.
Purpose:
Streamline support and self-service for users and help them find the right workflow and information faster.
How Flexie works (overall):
Flexie uses a Retrieval-Augmented Generation (RAG) architecture. This means that Flexie retrieves relevant information from approved sources, such as manuals, guides and release notes, and generates answers based on these documents.
In addition to approved source material, Flexie can use predefined tools to retrieve or update information in Flex HRM. Each tool determines which actions can be performed, which information can be accessed and which information is returned to Flexie.
Flexie does not have unrestricted access to the underlying database and cannot independently extend the scope of a tool based on how a user formulates a request. Access is limited by the current customer context, the logged-in user's existing permissions and the predefined scope of each tool.
Available tools may vary depending on the customer's licences and configuration.
AI type:
Generative AI (LLM) with RAG and predefined tools.
Risk level and transparency:
Flexie is a chatbot and AI assistant where transparency is central.
According to our internal assessment under the EU AI Act, Flexie is classified as limited risk based on the function's intended use.
- Flexie is clearly identified as an AI assistant.
- Users are informed that responses are AI-generated and should be verified.
Human oversight (human-in-the-loop):
Flexie does not make independent decisions about individuals and does not make changes without the user's approval.
- Actions that create or modify information require explicit confirmation from the user before they are carried out.
- Flexie does not perform actions independently in the background.
- All access and actions are limited by the logged-in user's existing permissions and the predefined scope of the relevant tool.
Data that may be processed:
- Text and other content provided by the user as part of the conversation.
- Information returned by the predefined tools used for the current request. For tools that retrieve employment-related personal data, this information is limited to the logged-in user's own employment and is further restricted by the user's permissions.
- Depending on the tool and the user's request, the information processed may contain personal data and, in some cases, special categories of personal data, such as reasons for absence.
Information returned by these tools is processed by Flexie solely to respond to the user's request or perform an action explicitly requested by the user. Flexie does not use this information to make decisions about individuals.
Users should not provide more personal data in free-text fields or attachments than is necessary for the task. Information entered or attached by users may be processed as part of the conversation, including information relating to other individuals.
Data storage and customer separation:
- Flexie runs in Microsoft Azure (Microsoft Foundry) within the EU.
- Customer data is logically separated using Tenant ID.
- Access to information is limited to the current customer context, the logged-in user's permissions and the predefined scope of the relevant tool.
Confidentiality and model training:
Customer data, prompts and information returned by Flexie's tools are not used to train or improve the underlying foundation models.
Microsoft uses safety filters and abuse monitoring to detect potential misuse of the AI service. Content flagged by these security features may, in some cases, be stored separately for security review by specifically authorised Microsoft personnel. This processing is separate from model training, and the content is not used to train or improve the underlying foundation models.
Risk management and testing:
- An internal AI assessment has been conducted.
- Internal assessments under the EU AI Act have been conducted.
- A penetration test has been conducted within Visma.
Support and documentation:
Support for Flexie follows the standard support process for Flex HRM. Documentation and user support are provided through the Knowledge Base.
SmartScan (receipt and document interpretation)
SmartScan is an AI-based service that automatically extracts and interprets information from receipt images and other documents related to expenses and travel expense claims.
Activity:
Automatically read and suggest relevant information (e.g. date, amount and supplier) based on receipt images/documents.
Purpose:
Streamline expense management by reducing manual data entry, reducing errors and saving time.
How SmartScan works (overall):
SmartScan analyses uploaded receipt images/documents and returns structured fields as suggestions. The user can review and, if necessary, correct the information before the report is submitted.
AI type:
AI-based document analysis (image and text interpretation/OCR) and machine learning.
Risk level and transparency:
SmartScan is designed as a support function.
According to our internal assessment under the EU AI Act, SmartScan is classified as minimal risk based on the function's intended use.
- SmartScan should be clearly communicated as an AI function that performs automated interpretations.
- Extracted values should be regarded as suggestions and may need to be verified/corrected.
- The function should not replace the user's review of supporting documentation.
Risk management and testing:
- An internal AI assessment has been conducted.
- An internal EU AI Act assessment has been conducted.
Human oversight (human-in-the-loop):
The user (and, where applicable, the approver) is responsible for reviewing and correcting information before it is saved or submitted further in the process.
Data that may be processed:
- Receipt images/documents uploaded by the user.
- Expense- and travel-related information that is extracted or supplemented.
We recommend that users avoid uploading documents containing sensitive personal data unless explicitly required for the task.
Data location and subprocessors:
The SmartScan service is hosted within the EU/EEA.
More information about the service's hosting, subprocessors and security practices is available in Visma Trust Centre – ML Assets.
Confidentiality and model training:
Customers' receipt images, documents and interpretation results are not used for model training as part of Flex HRM's use of SmartScan.
Flex HRM does not use SmartScan's feedback functionality, which could otherwise be used to send information back as input for continued model training.
Storage and deletion:
Customer data is stored for a limited period and automatically deleted in accordance with the service's deletion policy (currently 365 days from receipt). Deletion can also be initiated earlier when necessary.
Support and documentation:
Support for SmartScan follows the standard Flex HRM support process.
SmartDetect (payroll anomaly detection)
SmartDetect is a function in Flex HRM Payroll that helps payroll administrators identify anomalies in payroll data and payments. The function is based on the underlying PayrollDetect (Visma Resolve) service.
Activity:
Flags anomalous payroll entries and displays explanations/indicators to support review before payroll is submitted for payment.
Purpose:
Reduce the risk of incorrect payments, streamline review processes and strengthen quality in the payroll process.
How SmartDetect works (overall):
Historical, approved payroll data is uploaded per customer/tenant. The service trains customer-specific machine learning models that learn normal patterns and calculate anomaly scores for new/current payroll entries. Results are presented as flags with explanations.
AI type:
Machine learning (anomaly detection) with customer-specific models.
Risk level and transparency:
SmartDetect is a decision-support tool. Flags are indicators and do not in themselves mean that something is incorrect.
According to our internal assessment under the EU AI Act, SmartDetect is classified as minimal risk based on the function's intended use.
- We indicate that results are AI-generated and should be verified.
- Flags are used to prioritise review – not as automated decisions.
Risk management and testing:
- An internal AI assessment has been conducted.
- An internal EU AI Act assessment has been conducted.
Human oversight (human-in-the-loop):
SmartDetect is "human-led with automation support". This means that the user retains control and responsibility.
- The payroll administrator reviews flags and decides whether any action is required.
- SmartDetect does not modify payroll payments or make decisions without human review.
Data that may be processed:
- Pseudonymised payroll entries and pseudonymised historical payroll data.
Data location and subprocessors:
SmartDetect is hosted within the EU/EEA. Customer data is logically separated per tenant and is not mixed between companies.
More information about the service's hosting, subprocessors and security practices is available in Visma Trust Centre – PayrollDetect.
Confidentiality and model training:
- The models are customer-specific, i.e. they are trained and used for the relevant customer/tenant.
- Data is used to provide the service and for necessary troubleshooting/service improvement in accordance with the provider's procedures.
Storage and deletion:
Customer data is stored for a limited period and automatically deleted in accordance with the service's deletion policy (currently 365 days from receipt). Deletion can also be initiated earlier when necessary (e.g. when the integration is terminated).
Support and documentation:
Support for SmartDetect follows the standard Flex HRM support process.
Security and privacy
The privacy and security of information that may be processed in our AI capabilities is important to us. Flex Applications therefore takes appropriate technical and organizational measures to protect information from unauthorized access, improper use or disclosure, unauthorized modification, and unlawful destruction or accidental loss.
Only individuals who need access to perform their job duties shall have access.
Transfer of data
Flex Applications may use technology suppliers and other Visma companies to assist with the operation and protection of our service environments.
Which data location applies is stated under the respective AI function. At the moment:
- Flexie runs in Azure within the EU.
- SmartScan is operated within the EU/EEA via Visma ML Assets (hosting provider: Google Cloud EMEA Ltd).
- SmartDetect (based on PayrollDetect) is hosted in the EU/EEA via AWS (Ireland).
How to contact us?
If you have any questions about our AI features, this policy or how we work with the AI Act, you can contact us by:
- Calling us on our switchboard +46 (0) 19 10 39 15; or
- Sending a message to info@flexapplications.se
If the question concerns personal data, you can also contact GDPR@flexapplications.se.
Changes to this policy
Flex Applications will update this policy to reflect any changes in our AI capabilities and/or changes in applicable law.
This version of the policy is established on 2026-05-22.