Use AI with a clear understanding of where your business information goes and how it is used. We design your websites, connected systems and agents around the access, hosting and privacy requirements you choose.
What control means in practice
Four decisions we make with you.
Where it goes
Choose where documents, AI requests and backups are stored and processed.
Who can see it
Give each person and system access only to the information their work needs.
How AI can use it
Set the rules for approved tools, model training, retention and actions.
How you stay independent
Agree account ownership, data export and what happens when a service ends.
The right choice depends on the information involved, the quality you need and the cost of running the system. We compare the options before building.
On your infrastructure
Run a suitable model on your own servers or machines. A useful option when sensitive information must stay within an environment you control.
What we checkPlan hardware, updates, backups and support. Check any external connections separately.
In a private cloud setup
Use a cloud environment configured for your organisation. Choose the region, access rules and who operates each part of the system.
What we checkConfirm the actual countries, administrator access and responsibilities in the provider terms.
With an approved AI provider
Send the information a task needs to a selected AI service. Choose the service and account settings to match your data requirements.
What we checkCheck processing locations, retention, model-training use and any other providers involved.
A project can combine these options. For example, internal document search could run privately while an approved hosted model handles public marketing copy. The routing rules are part of the design.
Example design / internal document assistant
Useful answers. Access stays with the right people.
An employee asks a question about company documents. Here is how we would design the controls around that task.
01
Sign in
The system identifies the person and their access permissions.
02
Search approved files
It searches only the documents that person is allowed to use.
03
Use the chosen model
Only the relevant information goes to the approved model, under the agreed settings.
04
Check the answer
The answer links to its sources. A person checks important decisions and uncertain results.
Before release, we test restricted-document access and incorrect or misleading inputs. Actions such as sending a message, changing a record or approving a payment need their own permissions and review rules.
What your project includes
A setup you can understand and a record you can review.
The proposal identifies the controls and documents included in your project. When your project handles sensitive information, these are the four things we plan with you.
A map of where data goes
The sources, systems and providers involved, with the locations and uses of each data copy.
A list of who can access what
User, administrator, agent and support permissions, plus the actions that need approval.
A plan for keeping and removing data
Retention periods, deletion, backups, data export and the process for ending a service.
Test results and named responsibilities
Evidence of the agreed checks, operating instructions and who handles changes or incidents.
EU hosting and GDPR
Location matters. So does how the data is used.
If your project requires EU-only storage and processing, we document the countries and providers for the whole workflow, including logs, backups and support access.
GDPR also covers why personal data is used, how much is needed, people’s rights and the responsibilities of each organisation. We prepare the technical information for review with your data protection lead or legal adviser.