Human Capital CXO
HumanCapital CXO® — HCV Model
humancapitalcxo.com  •  Patent Pending USPTO 2026
Responsible Use Policy
Human Capital Value (HCV) Model — E(RVBER)  •  Data Governance & Ethics Framework
Document
RUP-HCV-001
Version
1.2
Effective date
2026-06-01
Review cycle
Annual
🚫 Absolute Prohibition — Read Before Use
The E(RVBER) output of the HCV Model must never be the sole or automated basis for any adverse employment decision — including but not limited to termination, demotion, pay reduction, redundancy selection, or refusal of promotion. Every deployment affecting named individuals requires a qualified human decision-maker, corroborating evidence, documented rationale, employee notification, and a right of appeal. Violation of this prohibition may constitute an unlawful automated decision under GDPR Article 22 and / or Swiss nDSG Art. 21.

1. Purpose and Scope

This Responsible Use Policy (RUP) governs all professional, commercial, and research use of the Human Capital Value (HCV) Model and its E(RVBER) computational output. It applies to:

  1. All users of the HCV Model platform at humancapitalcxo.com
  2. All API consumers and ERP / SAP integration deployments
  3. All organisations using HCV Model outputs in M&A, HR analytics, or workforce planning
  4. All advisory engagements delivered by or in collaboration with the inventor (Andreas C. Keller)
  5. All academic, research, and educational uses of the model or its methodology

This policy operates alongside applicable law and does not limit any rights or obligations arising under GDPR, Swiss nDSG, the EU AI Act 2024/1689 (fully in force August 2026), or national employment law.

2. What the Model Is and Is Not

2.1 Decision-Support Tool — Not a Decision-Making System

The HCV Model computes an indicative monetary present-value estimate of the human capital contribution of an employee or group of employees. It is a quantitative decision-support instrument — analogous to a financial valuation model — not an automated decision system. The output is one input among many that a qualified professional uses to form a judgement.

2.2 What E(RVBER) Represents

E(RVBER) is the expected present value of an employee's future service contributions, adjusted by external market conditions (EI(cf)) and internal organisational quality (IM(cf)). It reflects estimated economic contribution value under specified assumptions — not the intrinsic worth, dignity, or potential of any person. It is sensitive to its inputs and can be materially wrong if inputs are miscalibrated or if the underlying assumptions do not hold.

3. Permitted and Prohibited Uses

✓ Permitted
  • M&A due diligence — aggregate HC valuation of target
  • Strategic workforce planning and HC budgeting
  • Organisational design and restructuring modelling
  • Compensation benchmarking (informing, not determining)
  • HR analytics research and board reporting
  • ERP / SAP integration for HC reporting dashboards
  • Academic research and educational demonstration
  • Expert witness valuation in transaction disputes
  • Departmental HC value tracking over time
  • Attrition cost analysis (aggregate)
✗ Prohibited
  • Automated or sole-basis termination of employment
  • Automated pay reduction without human review
  • Automated demotion or role reassignment
  • Sole criterion for redundancy selection
  • Hiring rejection based solely on predicted E(RVBER)
  • Inputs using protected characteristics (age, gender, ethnicity)
  • Real-time automated individual performance monitoring
  • Profiling for credit, insurance, or loan decisions
  • Any use without employee notification where legally required
  • Deployment without DPIA where legally required

4. Mandatory Human Oversight

Any use of E(RVBER) output that informs a decision affecting a named individual requires all of the following:

  1. Qualified reviewer: A qualified HR professional, manager, or external adviser must independently review the model output before any action is taken.
  2. Corroborating evidence: The model output must be accompanied by at least two independent sources of evidence (e.g. performance reviews, market data, line manager assessment).
  3. Documented rationale: The human reviewer must document their assessment, including: their name, role, date, the factors they considered, and their independent conclusion — held separately from the model output.
  4. Employee notification: The employee must be informed that algorithmic processing contributed to the analysis of their employment situation, consistent with GDPR Art. 13/14 and nDSG Art. 19.
  5. Right of appeal: The employee must have a clear, accessible mechanism to contest the decision and request human re-evaluation.
  6. DPIA: Where the deployment involves systematic processing of employee data, a Data Protection Impact Assessment must be completed and held on file.

5. Bias Risk Obligations

ObligationRequirementFrequency
Input validationNo protected characteristics (age, gender, ethnicity, disability) as direct or proxy inputs to EI(cf) or IM(cf)Before every deployment
Cross-group auditTest for systematic output variance (>10% mean difference) by gender, age band, and ethnicity before any employment-affecting useAnnually + on material change
Culture fit reviewIM(cf) "culture fit" dimension must be grounded in documented, objective criteria and reviewed by legal counselBefore first use; annually
Service state validationService state definitions must include ≥3 documented, observable criteria and be reviewed by HR and employment lawAnnually
Mobility data auditProbability matrices derived from historical data must be audited for demographic biasBefore use; after major org change
Calibration registerAll calibration inputs, sources, dates, and reviewer names must be recorded in a calibration registerOngoing; retain 5 years

6. Privacy-by-Design Requirements

  1. Pseudonymisation: Employee names must be replaced with internal IDs before data enters the calculation engine. The ID-to-name mapping table must be held separately with restricted, logged access.
  2. Data minimisation: Collect only: annual base salary, service state assignment, probability estimates, EI(cf) and IM(cf) sub-scores, and time horizon. No health data, family status, or other sensitive categories.
  3. Encryption: All stored valuation data must be encrypted at rest (AES-256 minimum) and in transit (TLS 1.3 minimum).
  4. Retention limits: Individual valuations: 24 months maximum. M&A transaction records: 10 years (legal obligation). All data: deleted on written request unless legal hold applies.
  5. Access control: Individual valuations accessible only to authorised HR staff and deal team members. Role-based access control. All access logged with timestamp and user ID.
  6. Cross-border transfers: No transfer of personal data outside the EEA / Switzerland without adequate protection (adequacy decision, standard contractual clauses, or equivalent).
  7. Breach notification: Personal data breaches involving HCV valuation data must be assessed within 24 hours and notified to the supervisory authority within 72 hours where required under GDPR Art. 33 / nDSG Art. 24.

7. API and ERP / SAP Integration

Organisations embedding the HCV Model via API or ERP integration accept the following additional obligations:

  1. Complete a DPIA before any live deployment processing identified employee data.
  2. Ensure the integration does not enable automated adverse employment decisions (technical guardrails required — e.g. no API endpoint that directly triggers HR system actions based on E(RVBER) output).
  3. Conduct works council consultation where required under national co-determination law before deployment.
  4. Register the system as a high-risk AI system in the EU AI database per EU AI Act Art. 49 (mandatory for EU commercial deployments from August 2026). Designate an EU authorised representative under Art. 22 where required.
  5. Implement role-based access controls and audit logging at the integration layer.
  6. Contractually bind sub-processors to the data protection and bias control obligations in this policy.

8. Legal Basis for Processing

Use CaseLawful Basis (GDPR)Swiss nDSG Equivalent
M&A due diligence (aggregate)Art. 6(1)(f) Legitimate interestsArt. 31(1) Overriding private interest
Workforce planning (internal)Art. 6(1)(b) Contract performance; or (f) Legitimate interestsArt. 31(1)
Individual employment decisionsArt. 6(1)(b) or (c) — explicit consent not sufficient alone for automated decisionsArt. 31(1)(2)
Research / academic useArt. 6(1)(e) Public task; or (f) Legitimate interests with anonymisationArt. 31(2)(a)
Expert witness / legal proceedingsArt. 6(1)(c) Legal obligation; or (f) Legitimate interestsArt. 31(2)(b)

9. Accountability and Contacts

Questions regarding this policy, data subject rights, or compliance obligations should be directed to:

ContactResponsibilityEmail
Model inventorTechnical and methodology questions; expert witness and advisoryadvisory@humancapitalcxo.com
Data ControllerGDPR / nDSG data subject rights; DPIA coordinationprivacy@humancapitalcxo.com
Enterprise & APIIntegration compliance; API terms; ERP deploymentsenterprise@humancapitalcxo.com
CompliancePolicy questions; AI Act; Works council documentationcompliance@humancapitalcxo.com

10. Acknowledgement of Policy

By accessing or deploying the HCV Model, subscribing to the platform, consuming the API, or integrating the model into any system, the user / organisation confirms they have read, understood, and agree to comply with this Responsible Use Policy in full, including all bias risk controls, privacy-by-design requirements, and the absolute prohibition on automated adverse employment decisions.

Authorised signatory name
Signature & date
Organisation / company
Role / title