Institutional document

Artificial Intelligence Governance Policy

Last updated: August 2026.

Identification

This Policy describes how VGrid — a brand operated by Rafael Lotfi Marrocos Leite Ltda., trade name LM Consultoria, CNPJ (Brazilian tax registry) 41.737.358/0001-89, São Paulo, SP, Brazil — governs the use of artificial intelligence in its own operations, including this website, service channels and content production. E-mail: contato@vgrid.com.br.

About this translation

The English and Spanish versions are translations provided for convenience. In the event of any divergence of interpretation, the Portuguese version published at https://vgrid.com.br/politica-governanca-ia/ prevails, without prejudice to applicable mandatory rules.

1. Purpose and scope

This Policy records how VGrid governs the use of artificial intelligence in its own operations, including this website, service channels and content production.

We apply internally the same principles we structure for our clients: governance with an identifiable owner, human oversight, risk proportionality and evidence. This Policy is not a seal or a certification; it is our public, verifiable commitment to how we operate.

2. Principles guiding the use of AI at VGrid

The use of AI at VGrid follows five principles, aligned with the FATE framework (fairness, accountability, transparency, ethics) and the risk-management logic of ISO/IEC 42001 and the NIST AI RMF:

  • Human oversight: no decision with relevant effects on people or clients is made solely by an AI system. Every automated output that influences service or content undergoes human review.
  • Transparency: when you interact with an automated component on this website, that is disclosed — in this Policy, in the Privacy Policy and, where applicable, at the point of interaction itself.
  • Risk proportionality: we use AI only in low-risk activities (organizing the service queue, editorial support, triage of frequently asked questions). We do not use AI for sensitive profiling, credit scoring, hiring decisions or any high-impact purpose.
  • Privacy and security by design: personal data sent to AI services is limited to what is strictly necessary, as described in the Privacy Policy.
  • Evidence and review: we keep a record of the purposes for which AI is used and review this Policy whenever a new use is introduced.

3. Where VGrid uses AI today

The uses currently in operation are:

  • Qualification of contact requests: messages sent through the website forms receive a score and a written justification generated with language-processing support. That score only organizes the human service queue; it does not decide on hiring, pricing or refusal of service. You may request human review at any time.
  • Editorial production support: part of the articles and institutional materials is drafted with the support of generative AI tools. All content undergoes human review, correction and approval before publication, and editorial responsibility always rests with VGrid.
  • Service assistant on the website: the chat available on some pages uses AI to answer initial questions and route the contact. It does not take actions on your behalf and does not replace a conversation with a consultant.

4. What VGrid does not do with AI

To delimit the commitment objectively:

  • We do not make automated decisions with legal or similarly significant effects on data subjects.
  • We do not train models on personal data of visitors, leads or clients, nor do we provide such data for third-party training.
  • We do not use AI for surveillance, employee monitoring or any purpose incompatible with the LGPD and with the ethics declared in this Policy.
  • We do not publish AI-generated content without human review.

5. Roles and responsibilities

AI governance at VGrid has a single, identifiable owner: Rafael Lotfi Marrocos Leite, founding partner, is responsible for approving new uses of AI, reviewing this Policy and handling incidents related to AI systems. In a small, senior-led structure, accountability is not delegated to abstract committees: it has a name and a direct channel (contato@vgrid.com.br).

6. AI vendors and risk management

The AI services used are contracted from internationally operating vendors, selected against criteria of security, confidentiality and contractual compliance. We assess each vendor regarding the purpose of data use, retention, security measures and potential international transfer, as detailed in the Privacy Policy. New vendors or new purposes undergo a risk assessment before activation.

7. Personal data and confidentiality

All processing of personal data associated with the use of AI complies with the LGPD and is described, by purpose and legal basis, in this website's Privacy Policy. Confidential client information obtained in consulting engagements is not entered into external AI tools without express authorization and adequate contractual safeguards.

8. Incidents and dialogue channel

If you identify unexpected, inaccurate or inappropriate behavior in any AI component of this website — including the service assistant — report it to contato@vgrid.com.br. We handle the report with priority, correct the behavior when confirmed and record the learning in the review of this Policy.

9. Review and effectiveness

This Policy is reviewed whenever a new use of AI is introduced into VGrid's operations and, at a minimum, annually. Relevant changes take effect upon publication on this page, with the reference date updated, and the same revision is applied simultaneously to the English and Spanish versions. In the event of divergence, the Portuguese version published at https://vgrid.com.br/politica-governanca-ia/ prevails.

Questions about how we use AI?

Write to contato@vgrid.com.br or use the contact page — we respond directly.