Versione 1.0 — in vigore dal 31 luglio 2026
Fabbricante e titolare del servizio: FD CONSULTING S.R.L. — Via Giuseppe di Vittorio, 9 — 40018 San Pietro in Casale (BO), Italia — P.IVA 04157171200 — info@fdconsultingsrl.com — PEC: fd.consulting.srl@pec.it
La presente policy definisce le condizioni di uso accettabile delle funzioni di intelligenza artificiale («funzioni AI») di OPDesk, il gestionale operativo conversazionale di FD Consulting S.R.L. disponibile come web app (app.opdesk.it, installabile come PWA) e come app iOS su Apple App Store. La policy integra i Termini di servizio di OPDesk (https://app.opdesk.it/termini.html) e si applica a ogni utente che utilizza le funzioni AI, su qualunque piattaforma e con qualunque configurazione (piano con AI inclusa oppure chiave API propria — «BYO key»).
1. Assistente conversazionale («Assistente OP», il cui nome e stile sono personalizzabili dall'utente): assistente con capacità agentiche (esecuzione di azioni sui dati dell'utente tramite strumenti interni), soggetto a conferma esplicita dell'utente per le creazioni e per tutte le operazioni distruttive o massive.
2. Classificazione automatica dell'intento delle richieste rivolte all'assistente.
3. Trascrizione degli appunti vocali: l'audio è inviato al provider di trascrizione e non è conservato sui server di OPDesk; viene salvato soltanto il testo.
4. Riassunto degli appunti vocali a partire dalla trascrizione.
5. Generazione di titoli per le attività ricorrenti.
Le funzioni AI si basano su modelli linguistici di fornitori terzi raggiunti via API (OpenRouter per il piano incluso; OpenAI o Anthropic con chiave propria dell'utente; OpenAI o Groq per la trascrizione vocale). FD Consulting non sviluppa né addestra modelli propri e non utilizza i contenuti degli utenti per addestrare modelli.
In conformità all'art. 50, paragrafi 1 e 5, del Regolamento (UE) 2024/1689 (AI Act), l'utente è informato, in maniera chiara e al più tardi al momento della prima interazione, che sta interagendo con un sistema di intelligenza artificiale, tramite apposito avviso in app.
Le funzioni AI di OPDesk sono destinate esclusivamente alla gestione operativa dei dati propri dell'utente all'interno del suo spazio di lavoro. In particolare è consentito usare l'assistente per:
- creare, consultare, aggiornare e organizzare task e scadenze (anche ricorrenti e con orario);
- gestire le anagrafiche dei propri clienti e progetti e le informazioni operative a essi collegate;
- registrare e consultare le attività svolte (registro attività, vista Oggi);
- prendere e rielaborare appunti, inclusi gli appunti vocali (trascrizione e riassunto);
- porre domande sui propri dati presenti in OPDesk e ottenere riepiloghi, promemoria e bozze di testi operativi a uso proprio.
L'uso è consentito nei limiti del piano sottoscritto (inclusi i limiti giornalieri di utilizzo delle funzioni AI del piano con AI inclusa) e nel rispetto della normativa applicabile, dei Termini di servizio e della presente policy.
È vietato utilizzare le funzioni AI di OPDesk per le finalità e con le modalità che seguono. L'elenco è esemplificativo delle categorie indicate e non esclude altri usi contrari alla legge o ai Termini di servizio.
- Qualsiasi uso che violi leggi o regolamenti applicabili (dell'Unione europea, nazionali o del Paese da cui l'utente opera).
- Generare, elaborare o diffondere contenuti che violino diritti di terzi: diritti di proprietà intellettuale e industriale, riservatezza, onore e reputazione (contenuti diffamatori), segreti commerciali.
- Usare le funzioni AI per attività fraudolente, ingannevoli o moleste, incluse le comunicazioni non richieste (spam) e i tentativi di phishing o ingegneria sociale.
- Tentare di aggirare le istruzioni, i filtri o le misure di sicurezza dell'assistente, incluse le tecniche di prompt injection e di jailbreak.
- Tentare di estrarre i prompt di sistema, le istruzioni interne, le configurazioni o altre informazioni riservate sul funzionamento dell'assistente.
- Tentare di indurre l'assistente a eseguire azioni al di fuori del perimetro consentito o a eludere i meccanismi di conferma umana previsti per le operazioni di creazione, modifica massiva o cancellazione.
3.3 Decisioni automatizzate con effetti giuridici o similmente significativi
È vietato usare l'assistente come strumento di decisione automatizzata che produca effetti giuridici o effetti similmente significativi su persone fisiche, tra cui, a titolo esemplificativo: attribuzione di punteggi a persone (scoring), selezione o valutazione del personale e dei candidati, valutazione dell'affidabilità creditizia o accesso a servizi essenziali.
OPDesk non è progettato, destinato né autorizzato per questi impieghi, che possono rientrare tra i casi d'uso ad alto rischio ai sensi dell'art. 6, paragrafo 2, e dell'allegato III del Regolamento (UE) 2024/1689. L'output dell'assistente è un supporto operativo sui dati dell'utente e non sostituisce la valutazione umana.
- È vietato inserire nei contenuti trattati dalle funzioni AI categorie particolari di dati personali ai sensi dell'art. 9 del Regolamento (UE) 2016/679 (GDPR) — ad esempio dati relativi alla salute, all'origine etnica, alle opinioni politiche, alle convinzioni religiose, alla vita sessuale, dati biometrici o genetici — quando non strettamente necessarie alla finalità operativa perseguita.
- È vietato inserire dati personali di terzi oltre quanto necessario alla gestione operativa consentita (punto 2) e, in ogni caso, in violazione della normativa in materia di protezione dei dati personali. L'utente che tratta dati di terzi tramite OPDesk lo fa sotto la propria responsabilità di titolare del trattamento.
È vietato qualsiasi tentativo di impiegare le funzioni AI di OPDesk per pratiche vietate dall'art. 5, paragrafo 1, lettere a)–h), del Regolamento (UE) 2024/1689 (divieti applicabili dal 2 febbraio 2025), tra cui: tecniche subliminali o volutamente manipolative o ingannevoli; sfruttamento delle vulnerabilità di persone dovute a età, disabilità o situazione socio-economica; punteggio sociale; previsione del rischio di reato basata unicamente su profilazione o tratti della personalità; scraping non mirato di immagini facciali; inferenza delle emozioni sul luogo di lavoro o negli istituti di istruzione; categorizzazione biometrica per dedurre dati sensibili; identificazione biometrica remota «in tempo reale» in spazi pubblici a fini di contrasto.
Nessuna di tali pratiche corrisponde a una funzione di OPDesk: ogni tentativo in tal senso costituisce violazione grave della presente policy.
È inoltre vietato — già in forza della presente policy e, dal 2 dicembre 2026, dei nuovi divieti dell'art. 5, paragrafo 1, punti (ba) e (bb), introdotti dal regolamento «Digital Omnibus» sull'AI (PE-CONS 30/26, adottato il 29 giugno 2026, in attesa di pubblicazione in GUUE) — qualsiasi uso volto a generare o manipolare immagini, video o audio realistici a contenuto intimo o sessualmente esplicito di persone identificabili senza il loro consenso esplicito, nonché materiale pedopornografico.
- Aggirare o tentare di aggirare i limiti di utilizzo del piano con AI inclusa (ad esempio i limiti giornalieri di utilizzo delle funzioni AI), anche mediante creazione di account multipli, condivisione abusiva di account o automazione delle richieste.
- Usare le funzioni AI in modo da degradare il servizio per gli altri utenti o da generare carichi anomali e ingiustificati.
- Rivendere o mettere a disposizione di terzi le funzioni AI di OPDesk al di fuori di quanto previsto dai Termini di servizio.
Le funzioni AI di OPDesk si appoggiano a modelli di fornitori terzi. L'uso delle funzioni AI è pertanto soggetto anche alle condizioni d'uso e alle usage policy dei provider dei modelli, secondo la configurazione scelta:
- Piano con AI inclusa: le richieste transitano tramite OpenRouter con credenziali di FD Consulting; la trascrizione vocale transita tramite il provider di trascrizione configurato (OpenAI o Groq). L'utente è tenuto a un uso conforme alla presente policy e alle policy di tali provider; gli abusi espongono FD Consulting verso i propri fornitori e sono trattati come violazioni gravi.
- Chiave API propria (BYO key): l'utente che configura una propria chiave OpenAI o Anthropic è parte diretta del contratto con il rispettivo provider ed è tenuto anche alle condizioni d'uso e alle usage policy del proprio provider, oltre che alla presente policy.
La violazione delle condizioni o delle usage policy del provider dei modelli utilizzato costituisce violazione anche della presente policy. I riferimenti aggiornati alle policy dei provider sono disponibili sui rispettivi siti: OpenAI (openai.com/policies/usage-policies) · Anthropic (anthropic.com/legal/aup) · OpenRouter (openrouter.ai/terms) · Groq (groq.com/terms-of-use).
- Gli output delle funzioni AI possono contenere errori, imprecisioni od omissioni. Le risposte dell'assistente sono ancorate ai dati reali presenti nello spazio di lavoro dell'utente, ma questo riduce — non elimina — la possibilità di errore.
- L'utente è tenuto a verificare gli output prima di farvi affidamento o di utilizzarli, in particolare per date, scadenze, importi, riferimenti a clienti e ogni informazione rilevante.
- Le operazioni di creazione e tutte le operazioni distruttive o massive proposte dall'assistente richiedono la conferma esplicita dell'utente: con la conferma, l'utente si assume la responsabilità dell'azione eseguita.
- L'utente è responsabile dei contenuti che inserisce (prompt, appunti, dati) e dell'uso che fa dei contenuti generati, incluse le decisioni assunte sulla loro base e l'eventuale comunicazione a terzi.
In caso di violazione della presente policy, FD Consulting può, in proporzione alla gravità e alla reiterazione della condotta e secondo quanto previsto dai Termini di servizio (https://app.opdesk.it/termini.html):
1. avvisare l'utente e richiedere la cessazione della condotta;
2. limitare o sospendere le funzioni AI dell'account;
3. sospendere o chiudere l'account nei casi gravi o reiterati;
4. segnalare alle autorità competenti le condotte che integrino illeciti.
Chiunque può segnalare usi delle funzioni AI di OPDesk contrari alla presente policy scrivendo a info@fdconsultingsrl.com, indicando una descrizione della condotta e, ove disponibili, gli elementi utili alla verifica.
Le segnalazioni di vulnerabilità di sicurezza del prodotto non rientrano in questa policy e seguono la Politica di divulgazione coordinata delle vulnerabilità (CVD) di FD Consulting: punto di contatto security@fdconsultingsrl.com, politica pubblicata su https://fdconsultingsrl.com/cvd.html e file /.well-known/security.txt su app.opdesk.it e fdconsultingsrl.com.
FD Consulting può aggiornare la presente policy per adeguarla all'evoluzione del prodotto, dei fornitori o della normativa. La versione vigente, con numero di versione e data, è pubblicata in questa pagina (https://app.opdesk.it/uso-accettabile.html). Le modifiche sostanziali sono comunicate agli utenti tramite l'app o via email prima della loro efficacia. L'uso delle funzioni AI dopo l'efficacia delle modifiche comporta l'accettazione della versione aggiornata.
Version 1.0 — effective from 31 July 2026. In the event of any discrepancy, the Italian version prevails.
Manufacturer and service provider: FD CONSULTING S.R.L. — Via Giuseppe di Vittorio, 9 — 40018 San Pietro in Casale (BO), Italy — VAT no. IT04157171200 — info@fdconsultingsrl.com — Certified email (PEC): fd.consulting.srl@pec.it
A.1 Purpose and scope
This policy sets out the conditions for acceptable use of the artificial intelligence features ("AI features") of OPDesk, the conversational operations manager by FD Consulting S.R.L., available as a web app (app.opdesk.it, installable as a PWA) and as an iOS app on the Apple App Store. This policy supplements the OPDesk Terms of Service (https://app.opdesk.it/termini.html) and applies to every user of the AI features, on any platform and under any configuration (plan with AI included, or bring-your-own API key — "BYO key").
AI features covered:
1. Conversational assistant ("Assistente OP", whose name and style can be customised by the user): an assistant with agentic capabilities (execution of actions on the user's data through internal tools), subject to the user's explicit confirmation for creations and for all destructive or bulk operations.
2. Automatic intent classification of requests addressed to the assistant.
3. Voice note transcription: audio is sent to the transcription provider and is not stored on OPDesk servers; only the text is saved.
4. Voice note summarisation based on the transcript.
5. Title generation for recurring tasks.
The AI features rely on large language models of third-party providers accessed via API (OpenRouter for the included plan; OpenAI or Anthropic with the user's own key; OpenAI or Groq for voice transcription). FD Consulting does not develop or train its own models and does not use user content to train models.
Transparency. In accordance with Article 50(1) and (5) of Regulation (EU) 2024/1689 (AI Act), the user is informed, clearly and at the latest at the time of the first interaction, that they are interacting with an artificial intelligence system, through a dedicated in-app notice.
A.2 Permitted uses
The OPDesk AI features are intended exclusively for the operational management of the user's own data within their workspace. In particular, users may use the assistant to:
- create, view, update and organise tasks and deadlines (including recurring and time-based ones);
- manage the records of their own clients and projects and the related operational information;
- record and review activities carried out (activity log, Today view);
- take and rework notes, including voice notes (transcription and summary);
- ask questions about their own data in OPDesk and obtain summaries, reminders and drafts of operational texts for their own use.
Use is permitted within the limits of the subscribed plan (including the daily usage limits of the AI features under the plan with AI included) and in compliance with applicable law, the Terms of Service and this policy.
A.3 Prohibited uses
It is prohibited to use the OPDesk AI features for the purposes and in the ways set out below. The list illustrates the categories indicated and does not exclude other uses contrary to law or to the Terms of Service.
- Any use that breaches applicable laws or regulations (of the European Union, national law, or the law of the country from which the user operates).
- Generating, processing or distributing content that infringes third-party rights: intellectual and industrial property rights, privacy, honour and reputation (defamatory content), trade secrets.
- Using the AI features for fraudulent, deceptive or harassing activities, including unsolicited communications (spam) and phishing or social engineering attempts.
- Attempting to bypass the assistant's instructions, filters or safety measures, including prompt injection and jailbreak techniques.
- Attempting to extract system prompts, internal instructions, configurations or other confidential information about how the assistant works.
- Attempting to induce the assistant to perform actions outside the permitted perimeter or to bypass the human confirmation mechanisms required for creation, bulk modification or deletion operations.
It is prohibited to use the assistant as a tool for automated decision-making producing legal or similarly significant effects on natural persons, including, by way of example: scoring of individuals, recruitment or evaluation of staff and candidates, creditworthiness assessment or access to essential services.
OPDesk is not designed, intended or authorised for such uses, which may fall within the high-risk use cases under Article 6(2) of, and Annex III to, Regulation (EU) 2024/1689. The assistant's output is operational support on the user's data and does not replace human judgement.
- It is prohibited to enter into content processed by the AI features special categories of personal data within the meaning of Article 9 of Regulation (EU) 2016/679 (GDPR) — for example data concerning health, ethnic origin, political opinions, religious beliefs, sex life, biometric or genetic data — where not strictly necessary for the operational purpose pursued.
- It is prohibited to enter third parties' personal data beyond what is necessary for the permitted operational management (Section A.2) and, in any event, in breach of data protection law. A user who processes third-party data through OPDesk does so under their own responsibility as data controller.
Any attempt to use the OPDesk AI features for practices prohibited by Article 5(1), points (a)–(h), of Regulation (EU) 2024/1689 (prohibitions applicable since 2 February 2025) is forbidden, including: subliminal or purposefully manipulative or deceptive techniques; exploitation of vulnerabilities due to age, disability or socio-economic situation; social scoring; prediction of criminal offence risk based solely on profiling or personality traits; untargeted scraping of facial images; emotion inference in the workplace or in education institutions; biometric categorisation to infer sensitive data; "real-time" remote biometric identification in publicly accessible spaces for law enforcement purposes.
None of these practices corresponds to an OPDesk feature: any attempt of this kind is a serious breach of this policy.
It is also prohibited — under this policy already and, from 2 December 2026, under the new prohibitions in Article 5(1), points (ba) and (bb), introduced by the "Digital Omnibus" regulation on AI (PE-CONS 30/26, adopted on 29 June 2026, awaiting publication in the Official Journal of the EU) — to attempt any use aimed at generating or manipulating realistic images, videos or audio of an identifiable person's intimate parts or sexually explicit activity without that person's explicit consent, as well as child sexual abuse material.
- Circumventing or attempting to circumvent the usage limits of the plan with AI included (for example the daily AI usage limits), including by creating multiple accounts, improperly sharing accounts or automating requests.
- Using the AI features in a way that degrades the service for other users or generates abnormal, unjustified loads.
- Reselling or making the OPDesk AI features available to third parties outside what is permitted by the Terms of Service.
A.4 Model providers' terms (flow-down)
The OPDesk AI features rely on third-party models. Use of the AI features is therefore also subject to the terms of use and usage policies of the model providers, depending on the chosen configuration:
- Plan with AI included: requests transit through OpenRouter under FD Consulting's credentials; voice transcription transits through the configured transcription provider (OpenAI or Groq). The user must use the features in compliance with this policy and with those providers' policies; abuse exposes FD Consulting towards its suppliers and is treated as a serious breach.
- Bring-your-own key (BYO key): a user who configures their own OpenAI or Anthropic key is a direct party to the contract with the respective provider and is also bound by their own provider's terms of use and usage policies, in addition to this policy.
A breach of the terms or usage policies of the model provider in use also constitutes a breach of this policy. Up-to-date references to the providers' policies are available on their websites: OpenAI (openai.com/policies/usage-policies) · Anthropic (anthropic.com/legal/aup) · OpenRouter (openrouter.ai/terms) · Groq (groq.com/terms-of-use).
A.5 User responsibility for generated content
- The outputs of the AI features may contain errors, inaccuracies or omissions. The assistant's responses are grounded in the real data in the user's workspace, but this reduces — it does not eliminate — the possibility of error.
- Users must verify outputs before relying on or using them, in particular dates, deadlines, amounts, client references and any material information.
- Creation operations and all destructive or bulk operations proposed by the assistant require the user's explicit confirmation: by confirming, the user takes responsibility for the action performed.
- Users are responsible for the content they enter (prompts, notes, data) and for their use of generated content, including decisions taken on its basis and any communication to third parties.
A.6 Consequences of breaches and reports
Consequences. In the event of a breach of this policy, FD Consulting may, in proportion to the seriousness and repetition of the conduct and as provided in the Terms of Service (https://app.opdesk.it/termini.html):
1. warn the user and require the conduct to cease;
2. limit or suspend the AI features of the account;
3. suspend or terminate the account in serious or repeated cases;
4. report conduct amounting to an offence to the competent authorities.
Abuse reports. Anyone may report uses of the OPDesk AI features contrary to this policy by writing to info@fdconsultingsrl.com, providing a description of the conduct and, where available, any elements useful for verification.
Security vulnerability reports. Reports of product security vulnerabilities are outside the scope of this policy and follow FD Consulting's Coordinated Vulnerability Disclosure (CVD) policy: contact point security@fdconsultingsrl.com, policy published at https://fdconsultingsrl.com/cvd.html, and the /.well-known/security.txt file on app.opdesk.it and fdconsultingsrl.com.
A.7 Updates to this policy
FD Consulting may update this policy to reflect changes in the product, its suppliers or the applicable law. The current version, with version number and date, is published on this page (https://app.opdesk.it/uso-accettabile.html). Material changes are communicated to users through the app or by email before they take effect. Use of the AI features after the changes take effect constitutes acceptance of the updated version.