Pipefy is recognized by Gartner® for its no-code agent builder capabilities

Learn more

Last updated: August 10, 2026

Annex V – Pipefy AI Terms of Use

This Annex governs access to and use of the Artificial Intelligence (AI) features within the Pipefy Solution (Pipefy AI), taking effect on the date the Customer first uses such features. All provisions of the Agreement not expressly modified by this Annex remain in full force and effect. In the event of a conflict between the provisions of this Annex and the Agreement, the provisions of this Annex will prevail solely with respect to use of Pipefy AI. For all other matters, the Agreement will continue to govern the relationship between the parties. The parties agree as follows:

1. Pipefy AI Features. Pipefy may provide features that use artificial intelligence, machine learning, or similar technologies (“Pipefy AI”). These features may be developed by Pipefy and/or by third-party providers, in accordance with its Privacy Policy and the Sub-processor List. The Customer acknowledges that Pipefy may use Sub-Processors to provide these features, and that Pipefy and its Sub-Processors exclusively hold all rights to Pipefy AI. Whenever a Pipefy feature involves interactions with artificial intelligence, the Customer will be informed through a disclaimer that clearly identifies use of the technology.

1.1 Operating Modes (Pipefy-Intermediated and BYO-LLM)

Pipefy AI may operate under two integration modes:

(a) Pipefy-Intermediated Mode: AI features are provided by providers engaged by Pipefy. These providers are contractually required not to use Customer Inputs or Outputs to train models, observing minimum necessary retention or Zero Data Retention (ZDR) where available.

(b) BYO-LLM Mode (Bring Your Own Large Language Model): the Customer may connect its own account with AI providers (such as OpenAI API, AWS Bedrock, Google Vertex, Azure OpenAI). In this mode, the Customer fully controls the relationship with the provider, including configuration, legal basis, encryption, and training policies, remaining solely responsible for compliance and data privacy.

Pipefy may, upon notice, dynamically route AI requests among providers and model versions (“Model Routing”) without changing the applicable retention and training matrix. The Admin may pin providers, disable dynamic routing, and set regional policies or sensitive-data blocking rules.

2. Personal Data. By entering personal data into Pipefy AI, the Customer authorizes Pipefy and its third-party providers to process such data to provide the contracted features, in accordance with the provisions of the Agreement and Annex I (DPA). The Customer retains ownership of the data entered (“Input”) and the results generated (“Output”), collectively referred to as “Content.”

Pipefy does not use Customer data to train AI models, whether in Pipefy-Intermediated or BYO-LLM mode.

In Pipefy-Intermediated mode, Inputs and Outputs may be retained for up to 30 days only when technically necessary for operation and abuse prevention, and may be anonymized or subject to ZDR, as applicable.

Pipefy undertakes to treat all personal data in accordance with the principles of necessity, purpose limitation, security, and transparency, adopting controls and technical measures equivalent to those provided for under the LGPD, GDPR, and other applicable rules.

3. Security, Monitoring, and Data Processing. Customer data is processed in real time and encrypted in transit (TLS) and at rest (AES-256 or equivalent), ensuring the confidentiality and security of the information. Pipefy adopts security practices consistent with international standards, including ISO/IEC 27001 and ISO/IEC 27701, as well as automatic moderation mechanisms, DLP (Data Loss Prevention), and log auditing. Prompts and responses may be recorded in the Customer’s tenant for audit, quality, and abuse-detection purposes, in accordance with the configured retention mode. Pipefy may monitor use of Pipefy AI to prevent misuse, resolve technical issues, and maintain the platform’s operational security.

4. AI Outputs. The Customer may provide Inputs to be processed by Pipefy AI and receive Outputs based on such data. The Customer retains ownership of its Outputs and is solely responsible for the use of the generated information. Outputs are generated by probabilistic models and may contain inaccuracies, biases, or hallucinations; human review is recommended before use in impactful decisions. Pipefy does not guarantee exclusivity over Outputs, as different Customers may receive identical or similar responses.

5. Customer Use and Responsibilities. The Customer is responsible for ensuring that its use of Pipefy AI complies with applicable law and does not infringe third-party rights. The Customer assumes full responsibility for decisions made based on generated Outputs. In regulated sectors (such as insurance, financial services, or the public sector), AI Outputs do not constitute automated decisions with legal effect; underwriting, coverage, or claim-denial decisions must be reviewed and documented by a human.

5.1. Restrictions. The Customer may not use Pipefy AI to: (a) develop or train competing models; (b) reverse engineer LLMs; (c) deceive third parties as to the origin of the Output; (d) infringe third-party rights, including intellectual property, privacy, or personal data; (d) generate offensive, discriminatory, illegal, or fraudulent content, phishing, spam, or malware; and/or (e) process sensitive data without a legal basis and appropriate controls.

Pipefy may suspend access to Pipefy AI in the event of a breach of these restrictions or a security risk.

6. Use of Content and AI Improvements. Pipefy does not claim ownership of Customer Content and does not use such data to train AI models. Pipefy may compile aggregated and de-identified technical and statistical data (for example, usage volume, latency, tokens, and failures) for operation, billing, and improvement of the solution, without identifying the Customer.

7. Warranties. Pipefy AI is provided “as is” and may contain errors or inconsistencies. Pipefy does not warrant accuracy, reliability, or fitness for particular purposes. The Customer must review and validate Outputs before using them in a production environment or in relevant decisions.

8. Limitation of Liability. Under no circumstances will Pipefy or its third-party providers be liable for any direct, indirect, incidental, special, consequential, or punitive damages, including, but not limited to, loss of profits, data, use, reputation, or other intangible losses. Pipefy’s total liability, where applicable, will be limited to the amount proportional to AI credit consumption during the corresponding contract period.

Pipefy is not responsible for: (i) retention, training, or security policies adopted by LLM providers configured by the Customer (BYO-LLM mode); (ii) automated decisions without human review; (iii) content errors inherent to generative models.

9. Pricing and Availability. Use of Pipefy AI may be managed through AI credits, renewable monthly and non-cumulative. Excess credits will be billed according to the amount set forth in the Order Form or the then-current price table. Pipefy may update the credit consumption and billing policy upon prior notice, maintaining transparency regarding pricing and usage metrics.

9.1 Suspension of Services for Non-Payment. Pipefy may suspend access to Pipefy AI features if amounts owed for excess AI Credit usage are not paid within the stipulated period. The Customer will be duly notified to remedy the situation before any suspension.

10. Updates and Modifications. Pipefy may update this Annex or the AI services as necessary, notifying the Customer at least 30 (thirty) days in advance if there are significant impacts.

11. Term and Termination. The Customer may access Pipefy AI for as long as it complies with these terms. Pipefy may modify or terminate access to the tool in accordance with the provisions of the Agreement.

12. AI Transparency and Governance

Pipefy will maintain a public page (“AI Trust Page”) containing information on: (a) providers and sub-processors used; (b) processing regions, retention, and no-training/ZDR policies; (c) encryption, logging, and administrative controls by plan; (d) audit, DLP, and PII-masking practices; and (e) responsible AI use best practices.

Pipefy maintains an internal AI governance framework, with a committee formed by representatives from Legal, DPO, Information Security, and Product, responsible for approving providers, reviewing risks, overseeing technical and ethical compliance, and documenting decisions related to the adoption and use of AI models.

Internal and external audits may be conducted periodically to ensure compliance with this Annex, the DPA, and applicable data protection and security standards.

13. Intellectual Property in Workflow Intelligence and Proprietary Ontologies

13.1. Pipefy is the exclusive owner of the intellectual property rights in: (i) the proprietary ontologies, blueprints, workflow-intelligence models, knowledge-graph databases, and MCP (Model Context Protocol) servers developed, maintained, or enhanced by Pipefy; (ii) the process patterns, architectures, and best practices identified or derived from aggregated and anonymized use of the platform; and (iii) the process-intelligence models trained or enhanced using Workflow Intelligence Data, as defined in Clause 1.5.1.1 of the Terms.

13.2. The Customer does not acquire, through this Agreement or through use of the Pipefy Solution, any ownership right over the assets listed in Clause 13.1, including blueprints, ontologies, or workflow-intelligence models made available by Pipefy. Access to such assets is granted solely under a limited, non-exclusive, non-transferable, revocable license of use, for purposes of the contracted service.

13.3. Workflow Intelligence Data, to the extent derived from the Customer’s non-identifiable configurations, process patterns, and usage behaviors, may be used by Pipefy to enhance its proprietary models, without generating any right to compensation for the Customer. Pipefy warrants that such use will not compromise the confidentiality of the Customer’s identifiable business data.

14. Customer Responsibilities Regarding Compliance with AI Regulation

14.1. The Customer is solely responsible for: (i) classifying its processes, workflows, automations, and agents that use AI features of the Pipefy Solution in accordance with the categories and risk levels established under applicable AI regulation, including Regulation (EU) 2024/1689 (EU AI Act) and Bill No. 2,338/2023 (PL 2338) or any equivalent legislation that may be enacted; (ii) implementing the specific requirements required for each risk category, including, for high-risk AI systems, human oversight controls, technical documentation, audit logs, impact assessments, and other applicable regulatory obligations; and (iii) ensuring that use of the Pipefy Solution in the context of its regulated processes complies with the sector-specific and regulatory obligations applicable to it.

14.2. For processes classified by the Customer as high-risk under applicable regulation, the Customer must: (a) enable and maintain the audit, logging, and traceability features available in the Pipefy Solution; (b) ensure effective human oversight of decisions or recommendations generated by AI features; (c) document the legal bases, purposes, and impacts of AI use in such processes; and (d) notify Pipefy if it identifies that a Solution feature, alone or in combination with other Customer systems, results in a high-risk or prohibited AI system, for purposes of a joint suitability assessment.

14.3. Pipefy does not perform AI risk classification of the Customer’s processes and is not responsible for determining whether use of the Pipefy Solution, in the specific context of the Customer’s operation, constitutes a high-risk AI system, a prohibited purpose, or any other regulatory category. Responsibility for such classification and for all resulting obligations rests solely with the Customer, as operator or deployer of the AI system, as applicable under the relevant definitions.

14.4. Pipefy will cooperate in good faith with the Customer in providing available technical information and documentation on the Pipefy Solution’s AI features, when necessary for the Customer to comply with its regulatory obligations, provided such cooperation does not require disclosure of confidential information, trade secrets, or Pipefy’s intellectual property.

15. AI Governance in Multi-Tenant and Single Tenant Environments

15.1. In a Multi-Tenant environment, Pipefy may use Workflow Intelligence Data in anonymized, aggregated, and cross-organization form to enhance its proprietary ontologies, blueprints, and workflow-intelligence models. No identifiable business data, Personal Data, or content entered by the Customer in cards, fields, documents, or automations will be used for this purpose without express authorization.

15.2. In a Single Tenant environment, the Customer’s Workflow Intelligence Data will be used exclusively on an intra-organization basis, to enhance the Customer’s own environment (intra-organizational knowledge graph), except with the Customer’s prior, express, and documented authorization to participate in Pipefy’s cross-organization learning model.

15.3. Pipefy will adopt technical and organizational measures to ensure that Workflow Intelligence Data used to enhance cross-organization models is effectively anonymized and does not allow direct or indirect identification of the Customer or its business data.

Book a Demo Book a Demo