πŸ”’ Investor data room & restricted legal documents available after sign-in
πŸ” Investor Sign-in βœ‰οΈ Request Access
EU AI Act Ready Β· Limited-Risk Certified

Excellent β€” one of the cleaner
"Compliance First" AI climate platforms.

β€” Independent AI regulatory assessment, March 2026

EU AI Act self-classification documented. Article 12 active. Human-in-the-loop by design. Every compliance claim is transparent, auditable, and available for your legal team to verify.

Read the Full Assessment View Sovereignty Options

Lifetime Legal & Compliance Hub

Transparency as a Service.

At Lifetime Oy, we believe that legal clarity is the foundation of industrial trust. Our "Compliance First" architecture is designed to turn complex EU regulationsβ€”such as Fit for 55, the EU AI Act, the Digital Services Act (DSA), the EU Data Act, and GDPRβ€”from liabilities into competitive assets for our clients.

Below you will find our complete legal framework, governing our software, services, and commercial relationships. Each policy carries an explicit effective date, last review, and named escalation channel to simplify vendor-risk assessments.

0. Compliance at a Glance

This overview summarises the key legal and compliance controls for Lifetime Group (Lifetime Oy, Finland & DWS IQ OΓΌ, Estonia), the DWS IQ 6 Platform, the Firehorse product line, Lifetime Consulting & Advisory services, and Lifetime Studios services.

Policy Applies to Effective Last reviewed
πŸ›‘οΈ Digital Sovereignty All EU deployments 28 Jan 2026 01 Apr 2026
⭐ Privacy Policy & GDPR Statement All visitors & data subjects 01 Jan 2023 01 Apr 2026
⭐ Data Security Policy All business partners & clients 13 Dec 2025 01 Apr 2026
⭐ Data Handling Policy Internal team & partners 13 Dec 2025 01 Apr 2026
⭐ Agreement & Project Terms Enterprise & project clients 15 May 2024 01 Apr 2026
⭐ DWS IQ Terms of Service DWS IQ SaaS users 30 Jun 2024 01 Apr 2026
⭐ Firehorse Terms of Service Marketing & reporting automation users 02 Sep 2024 01 Apr 2026
⭐ Lifetime Fleet Terms Robotics, drone & logistics partners 12 Feb 2025 01 Apr 2026
⭐ Professional Services Terms Consulting & advisory engagements 20 Mar 2024 01 Apr 2026
⭐ Regulatory Notice for Investors Prospective & current investors 18 Oct 2024 01 Apr 2026
⭐ Return & Performance Policy Store & subscription customers 05 Jan 2024 01 Apr 2026
⭐ Lifetime Group Legal Notices 2026 Lifetime Oy corporate & group entities 01 Dec 2025 01 Apr 2026
Data Processing Agreement (DPA) All customers processing Personal Data via DWS IQ 05 Feb 2026 01 Apr 2026
KYA Standard v1.5 β€” Know Your Agent BYO agent governance, sandbox isolation, DWS IQ 09 Mar 2026 01 Apr 2026
AI Safety Report 2026 Analysis Security Research β€” all AI deployments 06 Feb 2026 01 Apr 2026
Security & Trust Security architecture, pentest program, responsible disclosure 18 Mar 2026 01 Apr 2026

Dates show when each control entered into force and the most recent audit or legal review. Earlier versions remain available upon request.


1. EU AI Act Self-Classification

Lifetime Oy maintains formal documentation of DWS IQ 6's classification under the EU AI Act (Regulation 2024/1689), enforceable from 2 August 2026.

Classification: Limited-Risk AI System EU AI Act 2024/1689

DWS IQ 6 and Firehorse modules are self-classified as limited-risk AI systems under Article 6 and Annex III. They do not qualify as prohibited AI practices (Article 5) or high-risk systems (Annex III categories: biometrics, employment scoring, law enforcement, safety components of critical infrastructure).

Primary function: automating ESG data into auditable compliance dashboards and 2030 simulation models β€” a decision-support tool, not an autonomous safety-critical actuator.

Documented Compliance Elements

EU AI Act Requirement Our Implementation Status
Technical Documentation (Art. 11) Full system cards, model documentation, and architecture specs maintained in internal governance repository βœ… Active
Record-Keeping & Logging (Art. 12) Automatic immutable logging of all AI events; 7-year retention; SIEM export available βœ… Active
Reasoning Lineage / Explainability Every AI decision includes a traceable input β†’ output chain; provenance metadata embedded in all AI-generated reports βœ… Active
Human-in-the-Loop Oversight No autonomous safety-critical actions; human validation required before any actuation or compliance filing βœ… By design
AI Governance Framework Internal risk assessment, incident audit trails, autonomy tiers (1–5), and quarterly internal review βœ… Active
Data Sovereignty & GDPR Art. 6 Private-cloud deployment; EU data residency (FI/DE); all processing bases documented per GDPR Article 6 βœ… Active
Transparency Obligations (Art. 50) Users are disclosed when interacting with AI-generated compliance reports or automated content βœ… Active
NIS2 Readiness Incident reporting architecture; 24h early warning to Traficom; final report within 72 hours βœ… Compliant
Third-Party Conformity Assessment Not required for limited-risk classification; ISO 27001 audit roadmap active (Q3 2026 target) πŸ”„ Roadmap
Deadline readiness: All limited-risk obligations are met ahead of the 2 August 2026 enforcement date. Preparatory elements for potential future reclassification β€” risk management controls, human oversight architecture, and full audit trails β€” are embedded in the product from day one.

Regulatory Timeline

Date Milestone
Aug 2025 EU AI Act β€” prohibited practices provisions enter force (Article 5)
Aug 2026 EU AI Act full enforcement β€” Article 99 penalty regime active (up to €15M or 3% of global turnover for deployer violations under Art. 99(4); €35M or 7% for prohibited practices under Art. 5)
Q4 2026 First D&O insurance claims on AI governance expected
Q1 2027 Insurers begin pricing “AI governance deficit” into D&O premiums

2. Digital Sovereignty (New)

πŸ›‘οΈ EU-Sovereign by Design

August 2026 EU AI Act: High-risk AI systems require EU data governance. DWS IQ Platform is Article 12 compliant with full reasoning lineage documentation for all AI decisions.

2. Investor Security

⭐ Why Your Investment in Lifetime Oy is Secure


3. Privacy & Data Governance

Data Portability & Sovereignty: Industrial telemetry can be exported in NDJSON/Parquet format. EU-based customers default to Helsinki or Frankfurt regions.

4. Digital Services & Platform Accountability


5. Commercial Agreements


6. Product Terms of Service


7. Investor Relations

SAFE Snapshot Updated Q1 2026


8. Return & Performance Policy


9. Security Research

Independent research and analysis on AI safety, cybersecurity, and enterprise risk management informing our platform security posture and compliance architecture.

Security Research Policy: DWS IQ Platform security architecture is informed by continuous monitoring of international AI safety research, OWASP guidelines, and EU regulatory developments. Research summaries are published as field notes and, when validated, elevated to core compliance artifacts.

10. Security & Trust

Security is not a feature β€” it is the foundation of every DWS IQ deployment. Our security architecture is designed for EU-regulated industries where agent failures have legal, financial, and safety consequences.

Security Architecture

Layer Technology Purpose
Agent Identity KYA Standard (Know Your Agent) Cryptographic agent identity, capability gating, fault attribution
Behavioral Guardrails Leash Snap Protocol (< 5ms) Pre-execution controls enforced before every agent action
Trust Scoring Agent Trust Score (ATS 0–100) Real-time agent reliability scoring with automatic suspension
Forensic Audit Firehorse Suite Immutable audit trails, reasoning lineage, 7-year retention
Tool Isolation MCP Colors Framework (RED/BLUE) Destructive and read-only tools separated to prevent prompt injection escalation
Encryption AES-256 at rest, TLS 1.3 in transit All data encrypted in storage and during transmission
Data Residency EU-only (Finland / Germany) No data leaves EU jurisdiction; CLOUD Act exposure eliminated with EU-sovereign options

Three Evidence Layers for D&O Safe Harbor

D&O insurers require documented governance that proves “reasonable measures” were in place before an AI agent acted. The KYA Standard produces three independent layers of evidence, each mapped to a distinct liability question:

  1. Identity Attribution. Proves which agent produced the output β€” not “our AI.” Every agent carries a cryptographic identity bound to its deployment context, which isolates director decisions from agent failures.
  2. Fault Attribution. Separates LOGIC_FAULT (agent error) from OPERATOR_FAULT (human misconfiguration) from MANIFEST_FAULT (deployment issue). Demonstrates that the board’s governance framework was adequate even when an individual agent fails.
  3. Behavioral Guardrails. Pre-execution controls were active before the agent acted, enforced by the Leash Snap Protocol in < 5 ms per decision. This is the “reasonable measures” standard recognised across EU member-state corporate governance codes for personal-liability safe harbour.

Continuous Security Testing

AI-Specific Security (OWASP LLM Top 10)

Certifications & Compliance Roadmap

Standard Status Target Date
GDPR Compliant Active since 2023
NIS2 Compliant Active β€” 24h early warning to Traficom
EU AI Act Limited-Risk Certified Article 12 active; full enforcement Aug 2026
KYA Standard v1.5 Production-Ready Q2 2026 launch
ISO 27001 In Progress Q4 2026
ISO/IEC 42001 (AI Management System) Preparing AI governance & data protection management roadmap
SOC 2 Type II Planned Q2 2027

Responsible Disclosure

We welcome security researchers who identify vulnerabilities in our platform. Please report findings responsibly:

See our security.txt (RFC 9116) for machine-readable security contact information.

Trust Center: For a visual overview of our security controls and certification status, visit the DWS IQ Trust Center. For KYA governance framework details (agent identity, D&O safe harbor, performance guarantees), see the Board Governance & D&O Safe Harbor below.

11. Customer Risk Disclosures

Lifetime Oy provides the following disclosures in the interest of full transparency. We encourage prospective customers, deployers, and investors to review these with their own legal and compliance teams before integration.

EU AI Act β€” Deployer Responsibility

Our limited-risk self-classification applies to DWS IQ 6 as designed and deployed by Lifetime Oy. Under Article 28 of the EU AI Act, deployers bear independent responsibility for their own use-case risk assessment. If you integrate DWS IQ 6 into operations that may constitute safety-critical infrastructure under Annex III β€” for example, energy grid control, transport critical infrastructure, or employment-decision systems β€” a higher-risk classification may apply to your specific deployment, regardless of our provider-level classification.

We have designed DWS IQ 6 with preparatory controls (human oversight, audit trails, risk management tiers) that ease any such reclassification. Contact [email protected] to discuss your specific integration scenario before go-live.

Product Maturity & Early Commercial Stage

DWS IQ 6 v1.0 launched on 23 February 2026 and is in an active pilot and early commercial phase. Real-world regulatory enforcement of AI Act claims across EU markets will mature after the August 2026 deadline. Enterprise customers should allow for a standard evaluation period. Our SLA (99.5% baseline uptime) and return policy protect your deployment commitment during this phase.

Third-Party Audit Status

As a limited-risk AI system, no notified-body review or CE marking is required or planned. ISO 27001 certification is targeted for Q4 2026. Internal automated penetration testing (OWASP Top 10 + LLM Top 10) was established Q1 2026 and runs continuously. Annual external third-party pentest is planned for H2 2026 (report will be available under NDA upon request). No independent AI conformity assessment has been conducted to date β€” this is consistent with the limited-risk regime.

Regulatory Interpretation Risk

EU AI Act interpretation β€” particularly for Annex III point 1 (critical infrastructure) and cross-sector industrial AI β€” is still evolving as the EU AI Office publishes implementation guidance. Lifetime Oy monitors EU AI Office communications and updates its compliance position accordingly. Our governance framework is designed to accommodate regulatory clarifications without architectural rework.

DPIA Recommendation: If you are evaluating DWS IQ 6 for regulated or safety-sensitive operations, we recommend conducting a Data Protection Impact Assessment (DPIA) for your specific use case. Request our AI Safety & Legal Pack (technical docs, AI governance framework summary, DPA template) at [email protected].

12. Contact & Escalation

Data Protection Officer

Risto Anton PÀÀrni
[email protected]
Requests processed within 30 days.

Legal & DPA Desk

[email protected]
Contract redlines, SCC questions, notice-and-action.

Security / NIS2 Incidents

[email protected]
24/7 hotline for critical vulnerabilities.

Lifetime Oy (Finland)

Y-tunnus: 0772407-9
VAT: FI07724079
Laidunmaanraitti 2 A 25
02330 Espoo, Finland

DWS IQ OΓΌ (Estonia)

DWS IQ Platform provider
Established Q2 2026
Subsidiary of Lifetime Oy

Partner Ecosystem

Digia Hub partner company
NVIDIA Inception Β· Microsoft Founders Hub L1–L4
EU-sovereign delivery partners


13. Board Governance & D&O Safe Harbor

KYA (Know Your Agent) is the governance framework that makes autonomous AI agents court-defensible, insurable, and EU AI Act compliant. It is designed for boards and directors who approve agentic AI deployments in EU-regulated industries.

Board-level exposure. EU AI Act Article 99(4) carries fines up to €15M or 3% of annual global turnover for deployer violations of Articles 8–15 and 26. Prohibited-practice violations under Article 5 reach €35M or 7%. National corporate governance codes add personal exposure for directors who approved AI deployments without documented controls. First enforcement actions are expected Q3–Q4 2026.

KYA Framework: Two Standards

Full specification: KYA Standard v1.5.

D&O Insurance Impact

Metric Value Basis
Indicative D&O Premium Reduction 8–12% Insurer feedback on documented AI-governance frameworks; comparable range to SOC 2 (5–15% cyber-premium reduction). Actual reduction depends on insurer, sector, and coverage limits.
Addressable Enterprises Every KYA-certified deployer EU AI Act applies to all deployers, not just providers (Art. 26)
Commercial Model Included in platform fee D&O savings are a sales accelerator, not a separate SKU

Fines, premiums, and legal defence remain with the customer. KYA produces the Article 12 logging and Article 26 deployer evidence insurers require; it does not underwrite liability.


14. EU-Regulated Industries Coverage

DWS IQ 6 is designed for autonomous-agent governance across the industries most exposed to Fit for 55, CBAM, ETS, CSRD, and the EU AI Act. Coverage is organised in three regulatory-exposure tiers:

Tier Industries Primary Exposure
Tier 1 — Critical Emissions Power & Heat, Iron & Steel, Cement & Lime, Chemicals, Aviation, Maritime, Road Transport, Construction EU ETS, CBAM, Fit for 55
Tier 2 — Important Emissions Agriculture, Waste Management, Aluminium, Pulp & Paper, Petroleum Refining, Food & Beverage, Glass & Ceramics, Mining CSRD, sector emission benchmarks, EU ETS extension
Tier 3 — Wedge Industries Fintech & Trading, Pharma & Biotech, Cybersecurity, Healthcare & MedTech DORA, NIS2, EU AI Act high-risk categories (Annex III)

Industry list maintained in sync with the EU ETS Phase 4 scope, CBAM Regulation 2023/956 Annex I, and CSRD sector-specific ESRS. Contact [email protected] for the current industry-specific controls matrix.