AI Employees Notice
Issued by: Vezoft EOOD ("Vezoft", "we", "us"), a single-member limited liability company incorporated in Bulgaria — see the Imprint for our full company details Applies to: AI employees that a TimerOS Customer hires into its workspace, and to every person who works with, chats with, or receives communications from one Companion documents: Terms of Service Section 2B · Privacy Policy · Sub-processors · Acceptable Use Policy
This notice is published under Article 50 of the EU AI Act (Regulation (EU) 2024/1689), Articles 13 and 14 GDPR, and equivalent provisions of US state law. It is written for the people who work alongside an AI employee — staff of a TimerOS Customer, and the Customer's clients — and for anyone evaluating TimerOS.
In one paragraph. A TimerOS Customer may hire an AI employee: a software agent, driven by a third-party AI model, that Vezoft operates on the Customer's behalf on a dedicated virtual computer. It sits in the Customer's team with a name and a job title, works on the tasks it is assigned, and can chat with you. It is always labelled as an AI. It reports to a named human manager, it cannot manage, evaluate or make decisions about any person, and anything consequential it wants to do — send an e-mail, publish something, pay for something — must first be approved by that manager. It never sees anyone's activity-tracking data.
Beta
AI employees are offered as a beta. The feature is new: what it can do, how it behaves, how it is priced and which parts of it exist at all may change, and parts of it may be reworked or withdrawn. Availability is not guaranteed and Vezoft gives no service-level commitment for AI employees — no uptime target, no response time and no service credits apply to them. Nothing an AI employee produces should be relied on, sent onwards or acted upon before a person has reviewed it. The safeguards described in the rest of this notice apply during the beta exactly as they are written here.
1. You may be working with an AI employee
If your employer, or a company you are a client of, uses TimerOS on a Startup or Enterprise plan, it may have added one or more AI employees to its team. You should know that this exists, how to recognise one, what it can and cannot do, and what happens to the information you share with it.
2. What an AI employee is — and who operates it
An AI employee is an entry in the Customer's team of kind "AI". It has a name, a handle, an avatar, a job title, a seniority tier, a team, a human manager, working shifts and a monthly spending cap that the Customer sets.
- Vezoft operates it. Vezoft provides the software agent, the virtual computer it works on (a virtual machine in the European Union), and the connection to the AI model providers, under Vezoft's own accounts. Vezoft is the provider of the AI system.
- The Customer directs it. The Customer decides whether to hire one at all, what it works on, which tools and websites it may use, which accounts it may connect to, who its manager is, and when it is paused or removed. The Customer is the deployer of the AI system and, for personal data, the controller.
- It is driven by third-party AI models, reached through one gateway. Vezoft trains and hosts no model. Every model call an AI employee makes goes through a single routing gateway, OpenRouter, which forwards it to one of several inference providers — all of them named on our Sub-processors page, together with where each one processes and under which safeguards. Which provider handles a given request is not left to the gateway: Vezoft pins the list of providers allowed to serve it, switches off any fallback outside that list, and admits a provider only while its terms say it will not train on this content and will not retain it after answering. Every provider on that list is in the United States. Two of the models are open-weight models published by Chinese companies, and they run on those US providers' computers — which model is being run is a fact about the software, not about where your content goes. There is no EU-region option we can buy through the gateway, so inference happens in the United States, and we say so plainly rather than imply a residency we do not have.
3. How you can tell
- In the TimerOS desktop and web applications, every chat thread with an AI employee and every message it writes carries an "AI" label; its team entry, org-chart node and profile carry an AI badge.
- E-mail it sends on the Customer's behalf identifies it as an AI employee of the Customer, operated by Vezoft.
- If the Customer allows its clients to message an AI employee through the Client Portal, the portal says so before you write to it.
- If you ask it whether it is an AI, it must say yes. Its standing instructions forbid claiming to be human.
4. What it can do, and what it can never do
It can: work on the tasks it is assigned on the projects it is assigned to; post notes, statuses and subtasks on those tasks; prepare drafts, designs, code, tickets, summaries and images; use a browser, an editor and the tools the Customer allows on its own virtual computer; answer your messages; and ask its manager for approval when it wants to do something consequential.
It can never — and TimerOS enforces this on the server, not by instruction to the AI:
- be anyone's manager, or the manager of any team, department or project that includes a person;
- approve anything — leave, overtime, change requests, or any other request — for anyone;
- evaluate, rank, monitor or report on any person's performance, activity or behaviour;
- own a goal over people, or take part in any performance review;
- log, edit or approve anyone's working time, including its own (its hours are recorded by the system that operates it);
- send e-mail, publish anything, make a payment, delete anything outside its own working files, or raise its own spending cap without its human manager approving that specific action first;
- be given access to activity-tracking data, hours, pay, or any financial information about people.
Approval requests go only to its designated manager, who must hold the "Manage AI employees" permission; if that manager does not, the request is refused rather than passed to someone else.
5. What it sees, and where that goes
What it sees. The tasks, notes and files on the projects it is assigned to, including the names of people and clients those tasks mention; the messages you send it; web pages and documents it is told to work with, from websites the Customer has allowed; and screenshots of its own virtual desktop, which it uses to operate programs. It sees only what a human colleague in the same "member" role on the same projects would see, minus anything financial.
What it never sees. Anyone's activity-classification output, hours, activity status, performance, pay, salary, tax identifier, date of birth, home address or emergency contact; anything in another workspace or on a project it is not assigned to; raw passwords or keys (it uses tools; the secrets stay in a vault).
Where it goes. To do its work, the AI employee sends the content it is working with — including your messages to it and the names in its tasks — as prompt content to a model. Those calls go through one routing gateway (OpenRouter, in the United States), which passes the request to one of several inference providers; all of them, and the country each processes in, are named on the Sub-processors page. That processing happens in the United States, outside the European Union. No self-serve EU-region routing is available to us, so we do not claim one. What we do instead is pin the route: only providers on an allow-list may serve a request, every one of them a US company, fallback to anyone else is switched off, and a provider is on that list only while it is bound not to train on this content and not to retain it after answering. Meanwhile the AI employee's virtual computer, the recordings of its screen that its manager can review, and every TimerOS record stay in the European Union. The safeguards for the transfer, and how to object, are on the Sub-processors page and in the Privacy Policy.
Recording. Its manager can watch its screen live and can review recordings of what it did; recordings are kept for 14 days. Everything it does — every approval, every action carried out — is journaled for the Customer.
6. Who is responsible
- Your employer, or the company you are a client of (the Customer), decides to use AI employees, sets their scope and their manager, and is responsible under the Terms of Service Section 2B for how it uses them, for what it lets them read, and for reviewing what they produce. It is the controller of the personal data an AI employee processes about you.
- The manager is a real person who reviews and approves the AI employee's consequential actions, can take over its screen, and can pause, suspend or remove it at any time.
- Vezoft operates the AI employee, keeps the safeguards described here in place, and processes personal data only as the Customer's processor.
- The output of an AI employee is not warranted. Like any AI-generated content, it can be wrong, and the Customer is responsible for reviewing it before relying on it or sending it to anyone.
7. Your rights and how to raise a concern
- Right to know. This notice, the AI label on every surface, and — if you are an employee — your employer's own internal information.
- Right to talk to a human. You may at any time ask that a matter an AI employee raised with you be handled by a person: contact its manager or any human colleague. The AI employee's manager is visible on its profile.
- Right to raise a concern. If you believe an AI employee has done something it should not — contacted you as if it were a person, acted on your data outside its scope, or produced something about you — raise it with the Customer's manager or privacy contact. You can also e-mail Vezoft at [email protected] and we will take it seriously, including by suspending the AI employee while we look.
- Your GDPR rights (access, rectification, erasure, restriction, objection, portability) apply to the personal data an AI employee processes about you exactly as they apply to the rest of TimerOS: exercise them with the Customer as controller, or with Vezoft at [email protected] for anything Vezoft controls. The Privacy Policy explains how.
8. A different system from the activity classifier
TimerOS also contains an on-device activity classifier that labels a worker's current window as "productive" or "idle". That is a separate system — it runs entirely on the worker's own computer, uses no cloud AI service, no model download and no large language model, and is described in its own notice. The AI employee is a cloud-model, opt-in system that never receives anything from the classifier. No data flows between the two.
9. Changes to this notice
We will update this notice when the capabilities, the safeguards or the providers described here change — version 1.3 (2026-09-16) did exactly that, when the providers that run the models were pinned to US-hosted ones and two model vendors dropped off the list altogether. Material changes are announced to Customers through the sub-processor and legal-change notice mechanisms in the Terms of Service, and shown in the applications.
Contact
[email protected] / Vezoft EOOD, Bulgaria (see the Imprint for our full company details)