Trust

How we handle your data and our AI.

Clear answers to the questions your security, legal and procurement teams will ask.

Data protection

We process personal data in line with the UK GDPR and EU GDPR. In client work we act as a processor on your instructions unless we agree otherwise in writing.

  • Data minimisation: we ask for and keep only the data a task needs.
  • Purpose limitation: client data is used only for the agreed engagement.
  • Retention and deletion: data is deleted or returned at the end of an engagement, on the schedule set out in the contract [confirm standard retention period].
  • Data processing agreements are put in place where we process personal data for clients.

Where data lives

Your data stays in a secure European environment: either your own tenant or our secure Azure tenant in Europe. For builds in a client environment, data stays in that client's own tenant and region, which you choose and control. For our own website, hosting is provided by Cloudflare.

  • OWL platforms run either in your own tenant or in our secure Azure tenant in Europe.
  • Client-environment builds: hosted in your chosen Microsoft Azure or Microsoft 365 region [confirm available regions].
  • Website hosting regions: [confirm].

AI principles

These principles guide how we design, build and operate AI-enabled systems.

  • Human oversight: people stay accountable for decisions that matter, with review points designed in.
  • No training on client data: we do not use client data to train or fine-tune models for others [confirm against provider terms for each build].
  • Traceable outputs: outputs can be traced back to sources and prompts where the system allows, so they can be checked.
  • Transparency: we tell you where AI is used, what it does and its known limits.

EU AI Act

For each AI system we build, we identify its intended purpose and assess which EU AI Act risk category it is likely to fall into: prohibited, high-risk, limited-risk (transparency duties) or minimal-risk.

We document the assessment, intended use, data sources, human oversight arrangements and known limitations, and give you this record so you can meet your own obligations as deployer. This is not legal advice; classification for high-risk uses should be confirmed with qualified counsel [confirm approach].

Security

We apply practical security controls proportionate to the work.

  • Access control: least-privilege access, individual accounts and multi-factor authentication where supported [confirm].
  • Encryption: data encrypted in transit and, where the platform supports it, at rest [confirm].
  • Incident response: suspected incidents are investigated promptly and affected clients and regulators notified as the law and contract require.
  • Certifications: [confirm certifications]. We do not claim any certification on this page until it is confirmed.

Sub-processors

Providers that may process data on our behalf:

  • Cloudflare — website hosting and content delivery
  • Microsoft Azure / Microsoft 365 — client-environment builds
  • Web3Forms — contact form handling
  • [confirm full list]

Need more detail?

We'll send our security pack and answer questions from your team.