About
You came to this page with a question. You want to know what happens to your data, your clients' data, your beneficiaries' records, or your organisation's commercially sensitive information when you work with an AI consultancy.
That question deserves a direct answer, not a policy summary.
Here it is: your data stays in the UK, goes into AI tools only with your explicit agreement, belongs to you from the moment it is produced, and is deleted or returned when the engagement ends. The rest of this page explains exactly how each of those commitments works in practice.
How we handle your data during an engagement
We access only the data necessary for the work you have asked us to do. Nothing else.
All client data is stored in the UK. Project documentation, files, and correspondence use UK-region cloud infrastructure throughout. Client software projects use AWS and Digital Ocean, both configured to UK data centres. No client data is stored or processed outside the UK.
There are no sub-processors. No third parties have access to your data as part of service delivery.
When the engagement ends, personal data processed as part of delivery (such as staff data shared to scope a training session) is deleted or returned to you, whichever comes first. Contractual records and correspondence are retained for six years from engagement end, reflecting the standard limitation period under the Limitation Act 1980. Enquiry data from prospective clients who do not engage us is deleted after 12 months from last contact.
What happens when AI tools are involved
We use Claude, Gemini, ChatGPT, and Perplexity as part of service delivery. Four controls apply as standard whenever client data is involved.
No identifiable personal data goes into an AI tool without your explicit agreement and a documented lawful basis under UK GDPR
(the UK General Data Protection Regulation, the primary data protection law governing how personal information can be processed).
Inputs are limited to what the task requires.
Where the task allows, business context is anonymised or generalised before it is used.
We use enterprise and API versions of these tools.
These operate under data processing agreements and do not use client inputs to train their underlying models. Standard consumer accounts often do. We do not use standard consumer accounts for client work.
Client information is used solely for the engagement it was shared for.
Not for any other purpose.
Charities working with us often ask specifically about beneficiary and service user data. The answer is the same: identifiable personal data about the people your organisation serves does not go into an AI tool without your explicit agreement and a documented lawful basis. If the task can be done without it, it is excluded.
For public sector organisations, data sovereignty is non-negotiable. All client data sits in UK data centres. No exceptions.
Our cyber security certification
Insightful AI holds Cyber Essentials certification. Cyber Essentials is the UK government's baseline cyber security scheme, independently assessed against a defined set of technical controls. Many public sector procurement frameworks, including those operated under the Crown Commercial Service, require it as a condition of supplier approval.
Your IP. Not ours.
The client owns all intellectual property created during an engagement.
Outputs, tools, documentation, and deliverables belong to you from the point they are produced. There are no licensing arrangements, usage rights, or exceptions that qualify this. If we build it for you, it is yours.
Confidentiality agreements and data processing agreements
A non-disclosure agreement (NDA) is available from the start of any engagement and offered as standard. Not every engagement requires one, but it is there from day one for any client who wants it in place before work begins.
Where the engagement involves handling personal data on behalf of your organisation, we also offer a Data Processing Agreement (a contract that sets out exactly how we handle any personal data you share with us, as required under UK GDPR) at the start of the engagement. Under UK GDPR, a data processing agreement is a legal requirement where a supplier acts as a data processor. We do not wait for clients to ask for it.
The regulatory position
The Information Commissioner's Office (ICO) treats any AI system that processes personal data as subject to the full requirements of UK GDPR and the Data Protection Act 2018. Lawful basis, transparency, data minimisation, accuracy, and accountability all apply to how AI tools collect, process, and act on personal data. ICO fines reach £17.5 million or 4% of global annual turnover. The ICO has opened investigations into generative AI tools and is developing a statutory AI code of practice.
The Data (Use and Access) Act 2025 (which received Royal Assent in June 2025) changed how automated decision-making is treated in UK law from February 2026. Where AI drives decisions about individuals, those individuals must be informed, given the ability to make representations, and allowed to request human intervention.
The NCSC (National Cyber Security Centre) warned in December 2025 that prompt injection attacks on AI systems connected to sensitive data may never be fully fixed. This is why the controls above exist. The risk does not disappear because the tool has a good privacy policy.
Our co-founder Ben Sefton spent 18 years as a Senior Forensic Investigator with Greater Manchester Police, working with evidence chains and sensitive material in environments where data handling failures carry serious legal and operational consequences. The standards we apply to client data come from that background, not from a policy document. You can read more at /about/ben-sefton/.
For full detail on the regulatory position and how it affects your organisation's AI adoption, see our Responsible AI page.
What happens if something goes wrong
In the event of a data breach, we contain it immediately and document when it was discovered and what was affected. Where the breach is likely to pose a risk to individuals' rights and freedoms, we notify the ICO within 72 hours as required under UK GDPR Article 33. The affected client is notified promptly, in parallel with any ICO reporting. Where the breach poses a high risk to individuals, those individuals are notified directly. A written account of what happened and the steps taken will go to all affected parties.
Questions we get asked
What happens to our data during an engagement?
Will our client, customer, or beneficiary data be entered into an AI tool?
Do you sign a confidentiality agreement before starting work?
Who owns the work you produce?
Do you hold any cyber security certification?
We are a public sector organisation. What about data sovereignty?
Have a question about how we handle data? Email hello@insightfulai.co.uk.
For formal legal detail on data handling, see our Privacy Policy [/privacy-policy/]. For regulatory context on AI adoption, see our Responsible AI page. If your organisation needs help building its own data governance for AI, we cover that under AI ethics and governance.
