Assessed against UK and European obligations — not just the UK ones.
You remain the data controller throughout. We act as your processor under a written agreement meeting Article 28 of both the UK and EU regimes, with every sub-processor named upfront.
The default regime for UK-established firms, applied as standard to every engagement.
Applied across the EEA, with Standard Contractual Clauses covering any transfer.
Applied where it's relevant, with the Swiss addendum in place for transfers.
Every automation is classified against the Act's risk tiers before anything is built.
Built to be defensible, not just described that way.
Our role, and yours
You remain the data controller. We act as your processor under a written agreement covering purpose, duration, security, sub-processors, breach notification, and return or deletion on termination.
Sub-processors named upfront
Any AI provider or hosting supplier involved is named before work begins, with its own processor agreement in place. You're notified before that list changes, with the right to object.
Where processing happens
Firm data is held on UK or EEA infrastructure according to your jurisdiction. Where an AI provider is involved, processing can be routed through EU-hosted deployments so inference stays within the EEA.
Transfers, properly papered
Any transfer outside the UK or EEA is covered by the correct mechanism — the UK Addendum, the European Commission's Standard Contractual Clauses, or the Swiss addendum — each with a transfer risk assessment.
Never used for training
All AI processing runs on commercial terms under which your data is not used to train or improve a provider's models. Consumer AI accounts are never used for client work.
Minimised and time-limited
Identifiers are stripped or pseudonymised wherever a task doesn't require them. Retention is defined per process, encryption applies in transit and at rest, and data is returned or deleted at the end.
What we hand to your compliance function
A signed data processing agreement, a sub-processor register with change notifications, entries for your record of processing activities, technical input for a DPIA where one's required, transfer risk assessment documentation, suggested privacy notice wording, and — where applicable — the EU AI Act risk classification for each automation.
Common questions
Is our data safe if AI assistants can reach it?
They reach only what you've explicitly approved, on behalf of parties you've explicitly authorised, and every request is logged. In practice this is considerably tighter than the status quo, where the same information is given out over the phone with no record at all.
Can nothing be retained by the AI provider at all?
For the most sensitive workloads, yes — zero-retention arrangements are available, under which prompts and outputs are processed in memory and never stored. We'll tell you when a workload genuinely warrants it rather than applying it by default.
We operate across the UK and the EU — is that a problem?
No. We work to both regimes as standard, and every recommendation flags where it would carry different obligations in each. Where the EU AI Act applies to a proposed use case, we say so before you commit to building anything.
We are not your legal advisers. What we provide is the technical implementation and the documentation your compliance function needs; your own solicitor or data protection officer should review it against your specific obligations. We are registered with the Information Commissioner's Office and, for EEA-facing work where it's required, appoint a representative in the Union under Article 27 of the EU GDPR.