AI Act and GDPR Evidence Pack
for SaaS Teams Shipping
LLM Features
Build your AI feature inventory, AI Act triage record, vendor review, GDPR evidence pack, testing logs and AI literacy proof in 10 days - without starting from a blank page.
Overview
Built for SaaS teams shipping LLM features
AI Act & GDPR Evidence Pack for SaaS is a practical documentation and evidence pack for teams building or deploying AI-powered SaaS features. It helps you create a usable AI governance baseline in 10 days, without buying an enterprise GRC platform or building every template from scratch.
Use it to classify AI features, document decisions, review vendors, train your team, track changes, test LLM behaviour, and prepare evidence for customer, internal, investor, or audit-style governance requests.
AI Act triage
Applicability checks, prohibited practice screening, high-risk flags, transparency triggers, and decision records.
Evidence logs
Approvals, prompt, model and knowledge base change logs, testing and evaluation records, monitoring, incidents, and training evidence.
GDPR AI pack and vendor review
DPIA decision support, DSAR handling, RoPA addendum materials, DPA annex materials, LLM vendor DDQ, and risk scoring.
AI literacy proof
Training decks, quizzes, registers, completion certificates, and role-based materials in Pro.
Scope: focused on EU AI Act and GDPR readiness for SaaS LLM features. This kit is not legal advice, certification, or a full high-risk conformity assessment package.
What You Get
AI Act triage and decision evidence
Classify AI features and keep a clear, reviewable decision trail.
- AI feature intake and approval trail
- AI Act applicability checks
- Prohibited practice screening
- High-risk flagging and escalation notes
- Transparency and disclosure checklist
SaaS operating logs
Track the AI governance evidence customers may ask for.
- Prompt, model and knowledge base change logs
- Testing and evaluation records
- Monitoring and incident log
- Risk acceptance register
- Training completion evidence log
GDPR, vendors and training
Cover privacy, supplier review and AI literacy evidence.
- DPIA decision guide for LLM features
- DSAR intake and response templates
- RoPA AI addendum and DPA annex materials
- Vendor DDQ and LLM risk scoring
- Training decks, quiz and completion records
Designed for practical use: the kit gives SaaS teams working templates, logs, checklists and training materials, not a generic legal theory pack.
What's Inside
30 core files + bonuses
A focused internal baseline with AI intake, AI Act triage, GDPR triggers, vendor checks, evidence logs, AI literacy materials, PDF exports and Starter addenda.
78 files · v1.7 May 2026
A fuller AI Act and GDPR evidence pack for customer, investor, procurement, security and audit-style reviews, including SaaS LLM playbooks, testing records, customer evidence, worked examples and launch readiness materials.
DOCX · XLSX · PPTX · PDF
Editable implementation files plus PDF exports for internal review, customer sharing, procurement responses and audit-style evidence requests.
Choose Starter for a fast internal baseline. Choose Pro if customers, investors, procurement teams or internal stakeholders are already asking how your SaaS product governs AI features.
Why SaaS needs this
SaaS teams shipping LLM features are increasingly asked for AI governance evidence: what the feature does, what data it uses, who approved it, how it was tested, how it is monitored, and whether the team completed AI literacy training.
Customer questions arrive fast
Enterprise customers, procurement teams, investors and security reviewers may ask for proof before you are ready.
- Which AI features exist and what data they use
- Who approved the feature and latest changes
- What AI literacy training the team completed
Policies are not enough
A policy helps, but customers often want practical records showing AI governance runs in the product workflow.
- No prompt, model or knowledge base records
- No testing, evaluation or monitoring evidence
- No structured incident and escalation history
Starting from scratch is slow
Blank-page compliance work often creates scattered documents, inconsistent formats and unclear ownership.
- Documents spread across teams and tools
- No consistent structure for owners and decisions
- Hard to prepare one clear evidence pack
Best fit
For SaaS teams that need practical AI governance evidence.
Built for SaaS teams shipping LLM features such as chatbots, RAG search, summarisation, copilots, AI agents and support automation.
- You need a usable AI Act and GDPR readiness baseline
- You want templates, logs, checklists and training materials
- You need evidence for customers, investors, procurement or security reviews
- You want to document decisions, vendors, testing, changes and AI literacy
Not a fit
For teams that need legal advice, automation or formal certification.
This kit does not replace legal counsel, provide formal legal sign-off, certify your AI system or operate as an integrated GRC platform.
- You need a bespoke legal opinion for a specific AI system
- You expect automated workflows, integrations or live monitoring
- You need a full high-risk conformity assessment package
- You want certification based on templates alone
Positioning: this is a practical implementation kit for documentation, training and evidence building. It helps you prepare a stronger baseline, while legal, technical and conformity reviews may still be needed for regulated or high-risk use cases.
10-Day Plan
A practical 10-day implementation sequence for turning scattered AI work into a structured evidence baseline that product, legal, security, leadership and customer-facing teams can use.
Scope and inventory
List your LLM features, data flows, vendors, owners and responsibilities. Start the evidence trail before decisions scatter across tools.
AI Act triage and approvals
Run applicability checks, screen for prohibited practices, flag possible high-risk use cases and document approval points.
Vendor due diligence
Review LLM and GPAI vendors, record data handling, retention, training use, security evidence, subprocessors and risk scoring.
GDPR decision support
Use the DPIA decision guide, record privacy triggers, update RoPA notes where needed and capture mitigations and approvals.
Changes, testing and evaluation
Set up prompt, model and knowledge base change records. Add evaluation evidence for hallucinations, unsafe outputs and retrieval quality.
Monitoring and incidents
Define monitoring checks, complaint handling, incident categories, escalation owners and review cadence for live AI features.
AI literacy training
Deliver training, run the quiz, record completion evidence and keep attendance or completion records for relevant roles.
Prepare the evidence pack
Assemble the inventory, triage records, vendor review, GDPR notes, logs, training evidence and open actions into one reviewable pack.
Outcome: this sequence is designed to help you establish a practical AI governance baseline, not just a policy document. The pack supports internal reviews, customer questions, procurement checks and audit-style requests.
Pricing
- Selected previews and sample rows
- Useful for checking quality before purchase
- Does not replace the paid Starter or Pro packs
No purchase required.
- 30 core Starter files
- AI intake, AI Act triage and approval records
- Basic prompt, model and knowledge base logs
- GDPR triggers, vendor DDQ and basic risk scoring
- AI literacy starter kit
- 7 bonus Starter addenda
- DOCX, XLSX, PPTX and PDF exports
- 10 days of email support
- Free product file updates for 6 months
Best if you need a fast internal baseline before building a fuller evidence pack.
- 78 files · v1.7 May 2026
- Covers and expands the Starter baseline
- Fuller AI Act and GDPR evidence pack
- SaaS LLM playbooks and testing records
- GDPR AI materials: DPIA, DSAR, RoPA and retention
- Vendor due diligence and risk scoring
- Role-based AI literacy training
- Customer evidence materials
- Worked examples and launch readiness materials
- 10 days of email support
- Free product file updates for 6 months
Best if customers, investors or procurement teams are asking for AI governance evidence.
- Everything in Pro v1.7
- Team and agency licensing
- Multiple internal teams or entities
- Client use option for consultants and agencies
- Priority support option
- Invoice purchase available
Best if you support several teams, entities or client implementations.
FAQ
1. Does this guarantee EU AI Act, GDPR or ISO certification?
No. This is a practical implementation kit with templates, checklists, logs and guidance. You still need to tailor the materials to your company, operate the processes and get legal or technical review where needed. It helps you build a stronger governance and documentation baseline, but it does not guarantee compliance, certification or formal assurance.
2. Is this a software platform?
No. It is a downloadable kit with editable DOCX, XLSX and PPTX files, plus PDF exports. It is designed for teams that want a practical working pack without buying an enterprise GRC or AI governance platform.
3. Who is this for?
It is for SaaS teams shipping LLM features such as chatbots, RAG search, summarisation, copilots, AI agents and support automation. It is especially relevant for founders, product leads, engineering leads, legal and compliance operators, security reviewers and teams preparing customer or internal AI governance evidence.
4. What if our AI system may be high-risk under the AI Act?
You can use the kit as a governance foundation for inventory, approvals, vendor review, training, testing records, monitoring and incident evidence. If a use case may be high-risk, you should get appropriate legal and conformity review. This kit is not a complete high-risk conformity assessment package.
5. We use OpenAI, Anthropic, Azure or another model provider. Do we still need this?
Often, yes. Provider documentation can help, but it does not replace your own internal evidence. SaaS teams still need to document which AI features they operate, what data they use, which vendors are involved, who approved the use case, how prompts and knowledge bases change, how outputs are tested, how incidents are handled and who has been trained.
6. What is included in the AI literacy training?
The kit includes training decks, a quiz, a training register and training completion records. Pro includes role-based versions for product and engineering, support and sales, and leadership or governance stakeholders.
7. What support is included?
Pro includes 10 days of email support for implementation questions during your first 10 days after purchase. Support covers how to use the kit, sequence the rollout and place documents correctly. It does not include legal advice, company-specific compliance determinations or bespoke drafting.
8. What formats will I receive?
You receive editable DOCX files for policies and templates, XLSX files for logs and registers, PPTX files for training materials, plus PDF exports for easier sharing and review.
9. What is the license?
Starter and Pro are single-company licenses for one legal entity. Multiple-entity use, agency use, consultant use and client implementations require the Team and Agency License or a separate written agreement.
10. Do you offer refunds?
This is an instant-access digital product. For business customers, refunds are not generally available after download or access has been provided, except where required by law or where there is a verified delivery or access issue that we cannot resolve.
For EU consumers, the statutory withdrawal right may apply. If you request immediate access to the digital content during the withdrawal period, you will be asked at checkout to expressly consent to immediate delivery and acknowledge that you lose your right of withdrawal once the download or access begins.
11. Are AI Act timelines changing?
The AI Act applies in phases. AI literacy and prohibited AI practice rules started applying in February 2025. GPAI obligations started applying in August 2025. Many general and transparency obligations remain relevant from August 2026, while certain high-risk AI system obligations may be subject to extended timelines under the AI omnibus process.
This kit is designed for practical readiness work that SaaS teams need regardless of a single deadline: inventory, triage, vendor review, testing records, monitoring, incident handling, transparency decisions and AI literacy evidence.
12. How current are the materials?
The kit is updated to v1.7, May 2026. The materials include version dates or last updated notes in the download files. Because AI Act guidance, implementation timelines and GDPR interpretation can evolve, teams should review the materials periodically and seek legal advice where their use case is regulated, high-risk or commercially sensitive.
About

Hi, I’m JUDr. Monika Fegyveres Oravská
ISO/IEC 42001 certified implementerSince 2018, I have helped consulting firms, law offices and companies, including SaaS teams, build practical GDPR programs through audits, implementation support and training.
Before consulting, I spent 14 years in private sector managerial roles, including international environments. That experience helps me translate compliance requirements into operating processes teams can actually use.
I built this kit to give SaaS teams shipping LLM features an evidence-first starting point, so they can move faster without building AI governance documentation from scratch.
Practical focus: the kit is built from implementation experience, not as a legal opinion, certification product or replacement for company-specific legal review.
Terms of Sale and Use
Last updated: May 2026
These Terms govern access to, purchase of and use of the AI Act SaaS digital products available through https://aiactsaas.com.
By purchasing, downloading or using any AI Act SaaS product, you agree to these Terms.
1. Product supplier
AI Act SaaS is a digital product by:
Company ID: 53669665
EU VAT ID: SK2121480592
Gútorská cesta 2733/23A, 931 01 Šamorín, Slovakia
Email: [email protected]
MONIMO, s. r. o. is the product creator, supplier, licensor and support contact for the AI Act SaaS materials.
2. Paddle and payment processing
Self-serve purchases of Starter and Pro may be processed through Paddle. Where Paddle processes the purchase, Paddle may act as Merchant of Record or authorised reseller and may handle payment, tax, receipt, invoice, refund and chargeback processes.
MONIMO, s. r. o. remains the product supplier, licensor and support contact. Team and Agency License purchases may be handled directly by MONIMO, s. r. o. by invoice or written agreement.
3. Product description
AI Act SaaS is a downloadable EU AI Act and GDPR readiness kit for SaaS teams working with LLM features. Depending on the package purchased, it may include DOCX, XLSX, PPTX and PDF files, templates, checklists, logs, playbooks, training materials, worked examples and launch legal readiness materials.
The product helps teams classify AI features, document decisions, review vendors, train relevant roles, track changes, record testing, monitor incidents and prepare governance evidence for internal, customer, investor, procurement, security or audit-style requests.
4. Business and consumer status
The product is intended for business and professional use. By purchasing, you confirm that you are purchasing for business or professional purposes, unless you expressly identify yourself as a consumer before purchase.
If you are a consumer under applicable law, you may have mandatory consumer rights. Nothing in these Terms limits rights that cannot legally be excluded.
5. Product packages
Free Sample Pack: selected previews and sample rows for quality review before purchase.
Starter: a practical internal baseline for one company, including core AI Act, GDPR, vendor, evidence log and AI literacy materials.
Pro: a fuller AI Act and GDPR evidence pack. Version v1.7 includes 78 files, including SaaS LLM playbooks, testing records, customer evidence materials, worked examples and launch legal readiness materials.
Team and Agency License: broader use for multiple teams, entities, agencies, consultants or client implementation work, subject to the applicable license terms or written agreement.
6. What the product is not
The product is not legal advice, a legal opinion, certification, a full high-risk conformity assessment package, a GRC platform, monitoring system or legal service.
The product does not guarantee compliance, regulatory approval, customer acceptance, certification, audit result or procurement outcome. You remain responsible for assessing your own AI systems, data processing, legal obligations, technical controls, vendors and regulatory position.
7. Digital delivery
The products are supplied as digital content. Delivery may be made by immediate download, hosted download page, Paddle checkout delivery, payment success page, email link or another digital method.
You are responsible for providing a valid email address and having software capable of opening DOCX, XLSX, PPTX, PDF and ZIP files. For delivery issues, contact [email protected].
8. Prices, VAT and payment
Prices are shown in EUR unless stated otherwise. For Paddle purchases, taxes, VAT, invoices, receipts and payment processes are handled through Paddle checkout.
For Team and Agency License purchases invoiced directly by MONIMO, s. r. o., prices, VAT treatment, payment method and due date will be stated in the invoice or written agreement.
9. Refunds and withdrawal rights
Because this is an instant-access digital product, refunds are not generally available after download or access has been provided, except where required by law or where there is a verified delivery issue that cannot reasonably be resolved.
For EU consumers, the statutory withdrawal right may apply. If you request immediate access during the withdrawal period, you may be asked to expressly consent to immediate delivery and acknowledge that you lose your right of withdrawal once download or access begins.
See the Refund Policy for more detail.
10. Checkout confirmations
The checkout may ask you to confirm that you purchase for business or professional purposes, consent to immediate digital access, acknowledge withdrawal consequences where applicable, and agree to the Terms, License Terms, Privacy Notice and Refund Policy.
11. License scope
Starter and Pro are single-company licenses for one legal entity. Team and Agency License is required for multiple-entity, agency, consultant or client implementation use.
You may edit the templates for permitted use and use completed outputs for internal governance, customer evidence, procurement responses, investor requests, security reviews and audit-style requests.
You may not resell, redistribute, publish, sublicense, upload publicly or sell the templates as your own product. See the License Terms for full license rules.
12. Restrictions
- You must not resell or redistribute the files as standalone templates or a competing product.
- You must not upload the files to a public template library, marketplace, repository or public shared drive.
- You must not use Starter or Pro for multiple legal entities or client work unless expressly permitted.
- You must not claim that the product gives certification, formal legal compliance, conformity assessment approval or regulatory approval.
13. Support
Starter, Pro and Team and Agency License purchases include 10 days of email support unless otherwise stated or agreed in writing.
Support covers practical product use, file navigation and implementation sequencing. It does not include legal advice, company-specific compliance determinations, bespoke drafting, formal review, DPIA sign-off or conformity assessment.
14. Product updates
Your purchase includes free access to product file updates released within 6 months from your purchase date for the package you purchased.
Updates may include corrected wording, improved templates, additional examples, versioning updates or implementation refinements. Updates do not include bespoke legal advice, custom implementation support, company-specific review, lifetime access or unrelated new products.
Update notices may be sent to the email address used for the original purchase. Updates may be delivered by email, hosted download page, direct download link or another digital delivery method.
15. Service emails
We may send service emails related to your purchase, access, support, license, security, product corrections, update availability within the included update period or legal/administrative matters. These are not marketing newsletters.
16. AI Act and GDPR readiness
The product supports practical readiness work. EU AI Act and GDPR interpretation, guidance, enforcement priorities, standards and timelines may evolve. You are responsible for reviewing suitability for your use case and obtaining professional advice where needed.
17. Intellectual property
All product files, templates, examples, text, design and related materials are owned by MONIMO, s. r. o. or licensed to it, unless stated otherwise. You receive only the limited usage rights granted under the applicable license.
18. User modifications
You may edit the product materials for permitted use. You are responsible for your edits, additions, deletions, implementation decisions, legal conclusions and operational use. MONIMO, s. r. o. is not responsible for modified versions or implementation outcomes.
19. Third-party tools and providers
The website, checkout, payment processing, email delivery, file hosting, analytics, advertising measurement or support process may involve third-party providers. Their own terms and privacy notices may also apply.
20. Availability
We aim to keep the website and download access available, but do not guarantee uninterrupted availability. Access may be affected by maintenance, third-party outages, hosting issues, payment provider issues or technical problems.
21. Limitation of liability
To the maximum extent permitted by law, MONIMO, s. r. o. is not liable for indirect, incidental, consequential, special or punitive damages, loss of profit, loss of business, loss of data, loss of opportunity, regulatory action, failed audit outcome, failed customer review, failed procurement result or compliance failure arising from use of the product.
Nothing in these Terms excludes liability that cannot legally be excluded.
22. Complaints and contact
For complaints, delivery issues or product access issues, contact [email protected] and include your name, order email, product purchased, purchase date and a clear description of the issue.
23. Alternative dispute resolution for consumers
If you are a consumer and are not satisfied with how your complaint has been handled, you may have the right to use alternative dispute resolution under applicable consumer protection rules.
Ústredný inšpektorát
Odbor pre medzinárodné vzťahy a alternatívne riešenie spotrebiteľských sporov
Bajkalská 21/A, p. p. 29
827 99 Bratislava 27, Slovakia
Email: [email protected] or [email protected]
24. Governing law
These Terms are governed by the laws of the Slovak Republic, unless mandatory consumer protection rules provide otherwise. Consumers may also benefit from mandatory protections of the country where they habitually reside, where applicable.
25. Changes to these Terms
We may update these Terms from time to time. The version published on this page applies at the time of purchase or use, unless a newer version is expressly accepted by you or required by law.
26. Contact
Privacy Notice
Last updated: May 2026
This Privacy Notice explains how MONIMO, s. r. o. processes personal data in connection with the AI Act SaaS website, digital products, purchases, downloads, support, service communications and related activities.
1. Controller
The controller of your personal data is:
Company ID: 53669665
EU VAT ID: SK2121480592
Gútorská cesta 2733/23A, 931 01 Šamorín, Slovakia
Email: [email protected]
2. Contact
For privacy questions or data protection requests, contact [email protected]. Where possible, include “Privacy Request” in the subject line.
3. Personal data we may collect
We may process the following categories of personal data:
- Contact details: name, email, company name, billing details, VAT number, address, country and information you provide.
- Purchase and transaction data: product purchased, order date, order value, payment status, invoice or receipt data, refund or access issue records, checkout records and update eligibility period.
- Communication data: emails, support requests, contact form submissions, customer questions, feedback and related correspondence.
- Technical and usage data: IP address, browser type, device information, approximate location, pages visited, referral source, link clicks, download activity and website interaction data.
- Consent data: cookie choices, analytics consent, advertising consent, digital content access consent, business-purpose confirmation and records of withdrawal or refusal of consent.
- Business customer data: role, company, team, use case context and information voluntarily provided for implementation, licensing, invoice purchase or support.
4. Purposes of processing
We process personal data to operate the website, provide free samples and paid digital products, process orders, payments, invoices, receipts and VAT-related information, deliver product access, confirm update eligibility, provide support, manage refunds, administer licenses and respond to customer communications.
We may also process personal data to improve the product and website, measure website performance and advertising effectiveness where consent is required and obtained, maintain security, prevent abuse, protect legal rights and comply with accounting, tax, consumer protection and legal obligations.
5. Legal bases
- Performance of a contract: used to sell, deliver and support products, manage purchases, provide downloads, send service communications and provide included updates.
- Legal obligation: used for tax, accounting, consumer protection, recordkeeping and legal compliance.
- Legitimate interests: used for website security, business administration, fraud prevention, customer support, product improvement, internal records and legal claims, where your rights do not override those interests.
- Consent: used for non-essential cookies, analytics, advertising measurement, remarketing or similar technologies where consent is required.
6. Paddle payment processing
Self-serve purchases of Starter and Pro may be processed through Paddle. Where Paddle processes a purchase, Paddle may act as Merchant of Record or authorised reseller and may process personal data for payment, tax, invoicing, fraud prevention, chargeback, refund and customer transaction purposes.
MONIMO, s. r. o. may receive order-related data from Paddle, such as name, email, product purchased, order date, transaction status, country, VAT-related data and information needed to deliver the product, provide support, manage updates and administer the license. Paddle processes personal data according to its own privacy terms.
7. Team and Agency License invoicing
Team and Agency License purchases may be handled directly by MONIMO, s. r. o. by invoice or separate written agreement. In that case, we may process billing contact details, company details, VAT details, invoice details, payment records, correspondence and license information.
8. File hosting and digital delivery
Digital files may be delivered through checkout delivery, download links, email delivery, hosted download pages, file hosting or similar tools. We may process your email address, order reference, product purchased and access records to provide and troubleshoot delivery.
9. Email and support communications
If you contact us, request support, ask about a product or make a purchase, we may process your communication data to respond and keep a record of the communication.
Support communications are not intended for sensitive personal data. Please do not send confidential customer data, special category data, trade secrets or regulated information unless specifically agreed and protected by appropriate measures.
10. Service and product update emails
If you purchase a product, we may send service emails related to that purchase. These may include product access emails, support replies, license information, important product corrections, security or administrative notices, and product update notices within the included 6-month update period.
These service emails are not a marketing newsletter. Product update notices may be sent to the email address used for the original purchase.
11. No newsletter
We do not currently operate a general marketing newsletter through the website. If this changes, we will update this Privacy Notice and collect consent where required.
12. Cookies, analytics and advertising measurement
The website may use cookies and similar technologies. Strictly necessary cookies may be used to operate the website, maintain security, remember consent choices or enable checkout functionality.
The website may use Google Analytics, Google Tag Manager, Google Ads conversion tracking or similar tools for analytics and advertising measurement. Analytics or marketing cookies and related tracking technologies will only be used where required consent has been obtained. For more information, see the Cookie Policy.
13. International transfers
Some service providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards where required, such as adequacy decisions, standard contractual clauses or other legally recognized transfer mechanisms.
This may be relevant to payment processors, hosting providers, analytics providers, advertising technology providers or email and communication tools.
14. Recipients of personal data
We may share personal data with payment and checkout providers, including Paddle where used; file hosting and digital delivery providers; email and communication providers; accounting, tax and invoicing providers; website hosting and technical providers; analytics and advertising measurement providers where applicable and subject to consent where required; legal, tax or compliance advisers; and public authorities where required by law.
We do not sell your personal data.
15. Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Notice.
- Order, invoice, receipt and tax records: for the period required by accounting and tax law.
- Purchase and license records: for as long as needed to administer the license, support the product, evidence the transaction and handle disputes.
- Product update eligibility records: normally for the included update period and a reasonable administrative period afterwards.
- Support and customer communications: normally up to 3 years after the last interaction, unless longer retention is needed for legal claims or business records.
- Cookie consent records: for the period needed to demonstrate consent and manage preferences.
- Website security logs: for a limited period necessary for security and troubleshooting.
16. Your GDPR rights
Subject to applicable conditions and limitations, you may have the right to access your personal data, correct inaccurate data, request deletion, restrict processing, object to processing based on legitimate interests, receive your data in a portable format where applicable, withdraw consent and lodge a complaint with a supervisory authority.
17. Data protection authority
You may lodge a complaint with the Slovak data protection authority:
Námestie 1. mája 18
811 06 Bratislava
Slovak Republic
Website: dataprotection.gov.sk
You may also contact the supervisory authority in your EU Member State of residence, where applicable.
18. Obligation to provide data
You are not legally required to provide personal data to browse the website. However, some data is necessary to complete a purchase, deliver a digital product, issue an invoice or receipt, respond to support requests, provide product updates or comply with legal obligations.
If you do not provide required purchase or contact data, we may not be able to complete the transaction or provide the product.
19. Automated decision-making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
20. Security
We use reasonable organizational and technical measures to protect personal data against unauthorized access, loss, misuse or alteration. No website or digital service can guarantee absolute security.
21. Children
The website and products are not intended for children. We do not knowingly sell products to or collect personal data from children.
22. Changes to this Privacy Notice
We may update this Privacy Notice from time to time. The updated version will be posted on this page with a revised “Last updated” date.
23. Contact
Cookie Policy
Last updated: May 2026
This Cookie Policy explains how AI Act SaaS uses cookies and similar technologies on https://aiactsaas.com.
1. What cookies are
Cookies are small text files stored on your device when you visit a website. They can help a website work, remember your preferences, support security, measure website use or support advertising and conversion measurement.
2. Types of cookies we may use
Strictly necessary cookies: required for the website to function, maintain security, remember cookie choices, enable checkout or deliver requested services. These do not require consent where they are strictly necessary.
Analytics cookies: help us understand how visitors use the website, which pages are viewed, which links are clicked and how visitors interact with the website. These are used only where required consent has been obtained.
Marketing and advertising cookies: may be used to measure advertising campaigns, track conversions, personalize advertising or support remarketing. These are used only where required consent has been obtained.
3. Consent
When you first visit the website, you may be asked to accept or reject non-essential cookies.
Non-essential cookies, such as analytics, marketing or advertising cookies, should not be set before you give consent where consent is required.
You can refuse non-essential cookies and still use the website, although some optional features or measurement functions may be limited.
4. Managing cookie choices
You can manage your cookie choices through the cookie banner or cookie settings tool, where available.
You can also control or delete cookies through your browser settings. If you block or delete cookies, some website functions may not work correctly.
5. Google Analytics, Google Tag Manager and Google Ads
The website may use Google Analytics, Google Tag Manager and Google Ads conversion tracking or similar Google tools.
These tools may help us measure website traffic, understand page performance, evaluate product interest, measure advertising campaigns and improve the website.
Where required, analytics and advertising tags are activated only after you provide the relevant consent.
6. Google Consent Mode
The website may use Google Consent Mode or a consent management platform to communicate your consent choices to Google tags.
Consent signals may include analytics storage, ad storage, ad user data and ad personalization settings.
7. Cookie categories
Necessary: used for website operation, security, checkout, consent storage and technical delivery. Consent is not required where they are strictly necessary.
Analytics: used for website performance measurement, page views, click tracking and product interest measurement. Consent is required where applicable.
Marketing and advertising: used for campaign tracking, advertising measurement, conversion tracking or remarketing. Consent is required where applicable.
8. Cookie table
The exact cookies may depend on the active website setup, checkout provider, consent tool and advertising configuration.
Provider: website or consent management platform
Purpose: stores your cookie choices
Category: Necessary
Duration: usually 6 to 12 months, depending on configuration
Consent required: No, where strictly necessary
Provider: Google
Purpose: analytics and website usage measurement
Category: Analytics
Duration: depends on Google configuration
Consent required: Yes, where applicable
Provider: Google
Purpose: advertising measurement, conversion tracking or remarketing
Category: Marketing and advertising
Duration: depends on Google configuration
Consent required: Yes, where applicable
Provider: Paddle or other checkout/payment provider
Purpose: payment processing, fraud prevention, checkout operation and transaction security
Category: Necessary or payment-related
Duration: depends on provider configuration
Consent required: usually no where strictly necessary for checkout, but provider terms may apply
9. Third-party cookies
Some cookies may be placed by third-party providers, such as checkout providers, analytics providers, advertising technology providers, embedded tools, payment processors or hosting services.
These may include Paddle, Google Analytics, Google Tag Manager, Google Ads, website hosting providers, file hosting providers or consent management tools, depending on the final website setup.
10. Rejecting non-essential cookies
If you reject non-essential cookies, analytics and marketing cookies should not be activated where consent is required.
Necessary cookies may still be used to operate the website, remember your choice, maintain security or enable checkout.
11. Changes to this Cookie Policy
We may update this Cookie Policy when we change cookies, providers, consent settings or website tools.
12. Contact
Refund Policy
Last updated: May 2026
This Refund Policy applies to purchases of AI Act SaaS digital products from https://aiactsaas.com.
1. Digital product nature
AI Act SaaS products are digital content supplied by download, hosted access link, checkout delivery, email delivery or similar digital delivery method.
Because digital content can be accessed, downloaded, copied and used immediately after purchase, refunds are limited as described below.
2. Business customers
The product is intended primarily for business and professional use.
For business customers, refunds are not generally available once access to the digital product has been provided or the product has been downloaded.
A refund or replacement access may be provided where:
- There is a verified technical delivery issue that prevents access and cannot reasonably be resolved.
- You were charged incorrectly.
- You purchased the same product twice by mistake and contact us promptly.
- A refund is required by applicable law.
- Paddle, where acting as Merchant of Record, determines that a refund is required or appropriate under its payment process.
3. Paddle purchases
Self-serve Starter and Pro purchases may be processed through Paddle.
Where Paddle acts as Merchant of Record or authorised reseller, payment-related refunds, chargebacks, receipts and tax-related processes may be handled through Paddle.
MONIMO, s. r. o. may assist with product access issues, delivery issues, support questions and product-related review requests.
4. EU consumers and right of withdrawal
If you purchase as an EU consumer, you may have a statutory right to withdraw from an online purchase within 14 days without giving a reason.
For digital content supplied immediately, you may lose your right of withdrawal once the download or access begins, if:
- You expressly consent to immediate access to the digital content before the end of the withdrawal period.
- You acknowledge that you lose your right of withdrawal once the download or access begins.
- The required confirmation is provided under applicable law.
Where required, the checkout may ask you to confirm wording substantially equivalent to:
If you do not provide this consent, immediate access may not be available.
5. Before download or access
If you are an EU consumer and you have not yet accessed or downloaded the digital content, and your statutory withdrawal right has not been lost, you may contact us within the applicable withdrawal period at [email protected].
Please include your name, order email, product purchased, purchase date, order reference if available, and a clear statement that you wish to withdraw.
If the purchase was processed through Paddle, the withdrawal or refund process may need to be completed through Paddle.
6. Access or delivery issues
If you cannot access your purchased product, contact [email protected].
We will make reasonable efforts to verify your purchase, resend the download link, provide an alternative download method, resolve hosting or delivery issues, and coordinate with Paddle where needed for payment or order verification.
A delivery issue does not automatically entitle you to a refund if access can be restored within a reasonable time.
7. No refund for change of mind after access
Unless required by applicable law, we do not provide refunds after access or download simply because:
- You changed your mind.
- You no longer need the product.
- You expected legal advice or certification.
- You expected a software platform.
- You did not read the product description, scope or disclaimers.
- Your company decided not to use the materials.
- Your legal, procurement or customer team requested different documents.
- You require a bespoke legal opinion, high-risk conformity assessment or custom drafting.
8. Product scope
The product is a template, documentation and evidence pack.
It is not legal advice, certification, a full high-risk conformity assessment package, an automated compliance platform or a guarantee of compliance.
Refunds are not provided because the product does not create certification, formal legal sign-off, regulatory approval or guaranteed customer acceptance.
9. Duplicate purchase
If you accidentally purchase the same product twice, contact us promptly at [email protected].
If the purchase was processed through Paddle, the duplicate purchase review and refund may be handled through Paddle.
If the duplicate purchase is verified, a refund of the duplicate order may be issued where appropriate.
10. Upgrade from Starter to Pro
If the website offers an upgrade credit from Starter to Pro, the applicable upgrade terms will apply.
For example, if you buy Starter and upgrade to Pro within the stated upgrade period, the Starter purchase price may be credited toward the Pro purchase price, as stated on the pricing page at the time of purchase.
The upgrade credit is not a cash refund unless expressly stated.
11. Product updates
Your purchase includes free access to product file updates released within 6 months from your purchase date for the package you purchased.
Updates are provided as part of the original product license and do not require a separate purchase.
Updates may be delivered by email, hosted download page, direct download link or another digital delivery method.
Failure to download or use an available update does not create a refund right.
12. Refund method
Approved refunds are normally returned through the original payment method, unless another method is required or agreed.
If the purchase was processed through Paddle, the refund method and timing may be handled according to Paddle’s payment process.
Processing time may depend on the payment provider and your bank.
13. How to request support or refund review
Contact [email protected] and include:
- Your full name.
- Order email.
- Product purchased.
- Purchase date.
- Order reference, if available.
- Description of the issue.
- Screenshot or error message, if relevant.
14. Mandatory rights
Nothing in this Refund Policy limits mandatory consumer rights that cannot be excluded under applicable law.
15. Contact
License Terms
Last updated: May 2026
These License Terms explain how you may use AI Act SaaS digital products. By purchasing, downloading or using the product, you agree to the license terms applicable to the package you purchased.
1. Ownership
The AI Act SaaS files, templates, examples, checklists, logs, training materials, structure, text, design and related materials are owned by MONIMO, s. r. o. or licensed to MONIMO, s. r. o., unless stated otherwise.
Your purchase gives you a limited usage license. It does not transfer ownership of the product or intellectual property rights to you.
2. General permitted use
Subject to your package license, you may:
- Download and store the product files.
- Edit the templates for your permitted use.
- Complete the templates using your own company or client information, where permitted.
- Use completed outputs for internal governance, customer evidence, procurement responses, investor requests, security reviews and audit-style requests.
- Share completed outputs internally within your licensed scope.
- Export completed outputs to PDF or similar format for permitted use.
- Use reasonable excerpts in internal presentations, implementation workshops or customer evidence responses.
3. General restrictions
Unless expressly permitted in writing, you must not:
- Resell the product.
- Redistribute the source templates.
- Publish the files publicly.
- Upload the files to a public repository, marketplace, template library or open shared drive.
- Sublicense the files.
- Give the files to another company outside your licensed scope.
- Use the product to create a competing template pack or similar commercial product.
- Remove copyright, attribution, license, version or ownership notices from the original files.
- Use the product in a way that suggests MONIMO, s. r. o. has certified, approved or legally reviewed your AI system.
- Claim that the product gives you AI Act, GDPR, ISO or other certification.
- Use Starter or Pro for client implementation work unless expressly permitted.
- Use Starter or Pro across multiple legal entities unless expressly permitted.
4. Starter License
The Starter License is a single-company license for one legal entity.
Permitted use:
- Use by one legal entity.
- Internal use by employees, contractors and advisers working for that legal entity.
- Editing templates for that legal entity’s own internal AI governance documentation.
- Use of completed outputs for that legal entity’s internal review, customer questions, procurement responses and evidence preparation.
Included support and updates:
- 10 days of email support from the purchase date.
- Free product file updates released within 6 months from the purchase date for the Starter package.
Not permitted:
- Use by multiple legal entities.
- Agency or consultant use for clients.
- Redistribution to customers as editable source templates.
- Use as a template library for third parties.
- Resale or commercial repackaging.
5. Pro License
The Pro License is a single-company license for one legal entity.
Permitted use:
- Use by one legal entity.
- Internal use by employees, contractors and advisers working for that legal entity.
- Editing templates for that legal entity’s own internal AI governance documentation.
- Use of completed outputs for that legal entity’s internal review, customer questions, procurement responses, investor requests, security reviews and audit-style evidence preparation.
- Use of worked examples as reference material for that legal entity’s internal implementation.
Included support and updates:
- 10 days of email support from the purchase date.
- Free product file updates released within 6 months from the purchase date for the Pro package.
Not permitted:
- Use by multiple legal entities.
- Agency or consultant use for clients.
- Redistribution to customers as editable source templates.
- Use as a template library for third parties.
- Resale or commercial repackaging.
- White-label resale.
- Public posting of the source files.
6. Team and Agency License
The Team and Agency License is intended for broader usage, subject to the specific terms agreed at purchase or in writing.
Depending on the purchased scope, it may allow:
- Use across multiple internal teams.
- Use across multiple entities within the same corporate group.
- Use by agencies or consultants for client implementation work.
- Internal workshops using the materials.
- Adaptation of the materials for permitted client implementation outputs.
- Provision of client-specific editable working documents to named clients as part of a paid implementation project, where expressly permitted.
Included support and updates:
- 10 days of email support unless otherwise agreed in writing.
- Free product file updates released within 6 months from the purchase date for the purchased Team and Agency package, unless otherwise agreed in writing.
Unless expressly permitted in writing, the Team and Agency License does not allow resale of the source templates as a standalone product, public distribution, marketplace listing, white-label resale, unlimited sublicensing, public client portal upload, use outside the agreed scope, or giving clients unrestricted access to the full source template library.
7. Client implementation use
Client implementation use means using the product materials to help a client build its own AI governance documentation or evidence baseline.
Client implementation use requires the Team and Agency License or a separate written agreement.
Where client implementation use is permitted, you may create client-specific completed outputs. Where expressly permitted, you may provide client-specific editable working documents to named clients as part of a paid implementation project.
This does not permit resale of the full source template library, public distribution, marketplace listing, standalone template resale, sublicensing or use by unrelated third parties outside the agreed client scope.
8. Contractors and advisers
Employees, contractors, external lawyers, consultants, security advisers or compliance advisers may access the materials only where they are supporting the licensed organization and only within the licensed scope.
You are responsible for ensuring that such persons comply with these License Terms.
9. Customer evidence use
You may use completed outputs, summaries, extracts and customer-facing evidence documents created from the materials for your own customer, investor, procurement, security or audit-style responses.
You should not provide customers with the full editable source templates unless this is expressly permitted by your license.
10. Product updates
Your license includes free access to product file updates released within 6 months from your purchase date for the package you purchased.
Updates may include corrected wording, improved templates, additional examples, versioning updates, implementation refinements or updated product files.
Updates do not include bespoke legal advice, custom implementation support, company-specific review, one-to-one legal review, lifetime access to all future products or access to unrelated new products.
Product update notices may be sent to the email address used for the original purchase. Updates may be delivered by email, hosted download page, direct download link or another digital delivery method.
11. No certification or legal opinion
The product does not certify your company, AI system, GDPR compliance, AI Act compliance, ISO compliance or vendor compliance.
Use of the product does not create a legal opinion, formal assurance, regulatory approval or conformity assessment.
12. Attribution
You may remove or adapt product branding in internal completed documents where reasonably necessary for your internal implementation, unless a specific file states otherwise.
You must not remove copyright, ownership or license notices from the original product files.
13. Derivative materials
If you modify the templates for your permitted use, you may use those modified documents within your licensed scope.
You may not use modified versions to create a competing product, commercial template pack or public library.
14. Breach of license
If you breach these License Terms, your license may be terminated.
Upon termination, you must stop using the product files and delete or return unauthorized copies, except to the extent retention is legally required for your internal records.
15. Written exceptions
Any exception to these License Terms must be agreed in writing by MONIMO, s. r. o.
16. Contact
AI Act SaaS — Full Product Contents
Last updated: May 2026 · Version 1.7
Practical AI Act and GDPR evidence pack for SaaS teams shipping LLM features. Product by MONIMO, s. r. o.
Package overview
Best for: checking quality before purchase.
Includes: read me, file index preview, inventory sample, intake preview, vendor checklist preview, evidence log sample, AI literacy preview and website readiness preview.
Best for: fast internal baseline.
Includes: 30 core files, Starter addenda, launch readiness materials and PDF exports.
Best for: customer, investor, procurement, security and audit-style evidence.
Includes: 70 core files plus Pro addenda 71–78, worked examples, launch readiness materials and PDF exports.
Free Sample Pack
00 Read Me and How to Use Free Sample Pack
01 Full Product File Index Preview
02 AI Feature Inventory Sample
03 AI Use Case Intake Form Preview
04 Vendor Due Diligence Checklist Preview
05 Prompt or Evidence Log Sample
06 AI Literacy Training Preview
07 Website Readiness Preview
Starter — 30 core files
Folder 01 — Start Here
1 Read Me and How to Use This Kit
2 10-Day Implementation Plan, Starter Version
3 File Index, Starter
4 Evidence Folder Structure
5 Roles and Responsibilities Matrix
Folder 02 — AI Feature Intake and AI Act Triage
6 AI Feature Inventory
7 AI Use Case Intake Form
8 AI Act Applicability Checklist
9 Prohibited Practice Screening
10 High-Risk Flagging Checklist
11 Transparency and Disclosure Checklist
12 AI Feature Approval Memo
Folder 03 — Basic SaaS Evidence Logs
13 AI Approval Log
14 Prompt Change Log
15 Model and Vendor Register
16 Testing and Evaluation Log, Basic
17 Monitoring and Incident Log, Basic
18 Training Completion Register
Folder 04 — GDPR AI Starter Pack
19 GDPR Trigger Checklist for AI Features
20 DPIA Decision Guide, Short Version
21 RoPA AI Addendum, Simple Template
22 DSAR AI Intake Form
23 Prompt Personal Data Rules
Folder 05 — Vendor Due Diligence Starter
24 LLM Vendor DDQ, Short Version
25 Vendor Risk Scorecard, Basic
26 Vendor Approval Note
Folder 06 — AI Literacy Starter
27 AI Literacy Training Deck, Core
28 AI Literacy Quiz
29 Training Register
30 Training Completion Certificate Template
Starter — addenda and PDF exports
31 Risk Acceptance Register
32 AI DPA Annex and Subprocessor Checklist
33 Worked Example AI-001 — Support Chatbot RAG
34 Compliance Source Map — AI Act / GDPR
35 Customer Evidence Pack Checklist
36 Web Claims and Public Sample Boundary Note
37 RAG Knowledge Base Change Log
38 Website Readiness Checklist
39 Checkout, Refund and Digital Content Delivery Wording
40 Privacy and Cookie Notice Checklist
PDF exports — PDF versions of relevant editable materials for review and sharing.
Pro — files 1–25
Folder 01 — Start Here and Implementation
1 Read Me, Pro
2 Full File Index
3 10-Day Implementation Plan
4 Evidence Folder Structure
5 Roles and Responsibilities Matrix
6 SaaS AI Governance Operating Model
7 Implementation Checklist
8 Customer and Audit Evidence Map
Folder 02 — AI Feature Intake and Inventory
9 AI Feature Inventory
10 AI Use Case Intake Form
11 AI Feature Owner Assignment
12 AI Data Flow Worksheet
13 AI System Description Template
14 Product Area AI Register
15 AI Feature Review and Retirement Form
Folder 03 — AI Act Triage
16 AI System Definition Checklist
17 Provider, Deployer and Vendor Role Mapping
18 Prohibited Practice Screening
19 High-Risk Triage Checklist
20 Limited Risk and Transparency Checklist
21 AI Generated Content Disclosure Checklist
22 Human Oversight Checklist
23 Non-High-Risk Rationale Memo
24 High-Risk Escalation Memo
25 AI Feature Approval Memo
Pro — files 26–54
Folder 04 — SaaS LLM Playbooks
26 Customer Support Chatbot Playbook
27 RAG and Knowledge Base Search Playbook
28 Summarization Feature Playbook
29 Copilot Feature Playbook
30 AI Agent Playbook
31 Ticket Classification and Routing Playbook
32 Response Generation Playbook
33 Internal AI Assistant Playbook
Folder 05 — SaaS Evidence Logs
34 AI Approval Log
35 Model and Vendor Register
36 Prompt Change Log
37 Model Version Change Log
38 Knowledge Base Change Log
39 RAG Source Review Log
40 Testing and Evaluation Log
41 Monitoring Log
42 Incident and Escalation Log
43 Risk Acceptance Register
44 Customer AI Request Log
45 Audit Evidence Index
Folder 06 — Testing and Evaluation
46 Evaluation Plan Template
47 LLM Test Case Library
48 Hallucination Test Log
49 Prompt Injection Test Log
50 Privacy Leakage Test Log
51 Bias and Fairness Review Sheet
52 RAG Evaluation Sheet
53 Agent Safety Checklist
54 Release Readiness Sign Off
Pro — files 55–78
Folder 07 — GDPR AI Pack
55 GDPR AI Trigger Checklist
56 DPIA Decision Guide for LLM Features
57 DPIA Template for AI Features
58 RoPA AI Addendum
59 DSAR AI Playbook
60 DPA Annex for AI Processing
61 Prompt Personal Data Policy
62 Retention and Logging Checklist
Folder 08 — Vendor Due Diligence
63 Full LLM Vendor DDQ
64 Vendor Risk Scorecard
65 Vendor Approval Memo
66 GPAI Dependency Map
Folder 09 — AI Literacy and Customer Evidence
67 Role-Based AI Literacy Decks
68 Quiz, Register and Completion Materials
69 Customer AI Governance Summary
70 Enterprise DDQ Answer Bank
Pro Addenda — Worked Examples and Launch Readiness
71 Worked Example AI-001 — Customer Support RAG Chatbot
72 Worked Example AI-002 — RAG Search and Summarization
73 Worked Example AI-003 — Sales Response Copilot
74 Worked Example — Customer AI Evidence Response
75 Website Readiness Checklist
76 Checkout, Refund and Digital Content Delivery Wording
77 Privacy and Cookie Notice Checklist
78 Product Changelog and Update Policy Template
PDF exports — PDF versions of relevant Pro DOCX/PPTX materials for review and sharing.
Team and Agency License
1 Everything in Pro v1.7
2 Team and Agency License Terms
3 Multiple Entity Use Guide
4 Client Use Guide for Consultants and Agencies
5 Internal Rollout Workshop Agenda
6 Consultant Implementation Checklist
7 Priority Support Option
8 Invoice Purchase Option
Usage note: Starter and Pro are single-company licenses. Team and Agency License is required for multiple-entity, agency, consultant or client use. Exact rights are governed by the purchase terms or written agreement.
How to use the kit
Assign an owner, complete the relevant fields, attach supporting evidence and review outputs with legal, security, product or leadership stakeholders where needed.
Purpose: each document should explain why it exists and when to use it. Owner: each register or template should identify the responsible role or team. Evidence: logs should link to decisions, tests, vendor documents or supporting records. Review: key records should include review date, status and next action. Escalation: high-risk, regulated, sensitive or uncertain cases should be escalated.
What this kit is not
This kit is not legal advice, certification, a platform, a full high-risk conformity assessment package, a global law tracker or vendor assurance. It provides practical materials and guidance that must be adapted to the buyer’s SaaS product, AI features, data flows, vendors, contracts and applicable law.

Temporary referral tracking test
Referral Tracking Test — €1
