PRIVACY & DATA
HOW WE HANDLE DATA
AND RESPONSIBILITY
AI systems that speak to customers carry a responsibility. This page sets out how data is handled on this website and inside the systems we build.
This page describes our approach in plain language. It is not a substitute for legal advice, and formal data protection review remains the responsibility of the business deploying the system.
THIS WEBSITE
WHAT WE COLLECT ON THIS SITE
When you submit the enquiry form we collect the name, email address and any optional details you choose to provide, together with the time of submission. We use it to respond to your enquiry and to prepare for the strategy call. Nothing else is required from you to use this website.
- The enquiry form is the only place this site asks for personal information
- Optional fields are genuinely optional and can be left empty
- Submissions are stored in a managed database and used to respond to you
- Your details are not sold, shared with advertisers or added to a marketing list
CONNECTED SYSTEMS
DATA INSIDE THE SYSTEMS WE BUILD
For client deployments, the data a system touches belongs to the client. We agree what is stored, where it lives, what it is used for and how long it is kept before anything goes live. The system is given access to the specific records and systems it needs to do its job, and nothing broader.
- A defined purpose for every category of data the system handles
- Minimum access — no blanket permissions to your business
- Agreed retention periods rather than indefinite storage
- Client control over what the AI may say, do and access
PERMISSIONS
WHAT THE AI IS ALLOWED TO DO
Every deployment begins with an agreed boundary: the questions the system may answer, the commitments it may make, the situations that must be escalated, and the data it may look at. The boundary is enforced in configuration rather than left to interpretation.
- Approved answers, agreed in writing before go-live
- Escalation rules for anything outside the approved set
- Human handover defined for sensitive or complex situations
- Conversations reviewable at any time
SECURITY
SECURE INTEGRATIONS
Integrations use the credentials and access methods the connected systems support, scoped to the minimum level required to perform the task. Access can be revoked by the client, and integrations are reviewed as part of ongoing optimisation rather than left unexamined.
- Minimum-scope credentials for each connected system
- Connections that the client can revoke
- Access reviewed as part of ongoing optimisation
GDPR
GDPR-CONSCIOUS IMPLEMENTATION
Where the General Data Protection Regulation applies, implementation is designed around its principles: a lawful basis for processing, transparency about what is automated, data minimisation, and the practical ability to respond to data subject requests. We do not claim certification we do not hold, and we work with your own advisers where formal legal review is required.
- Lawful basis and transparency considered at design stage
- Data minimisation — collect what the task needs
- Practical support for access and deletion requests
- No claim of certification or formal legal advice
YOUR RIGHTS
ACCESS, CORRECTION AND DELETION
If you have submitted an enquiry and want to know what we hold, want it corrected, or want it deleted, contact us through the enquiry form and say so. We will action the request or explain what is required to do so.
- Request a copy of the details we hold about you
- Ask for inaccurate details to be corrected
- Ask for your enquiry details to be deleted
NEXT STEP
QUESTIONS ABOUT DATA BEFORE YOU COMMIT?
Raise them on the strategy call. Data handling, permissions and oversight are part of the design conversation, not an afterthought.