AI data handling

AI automation with defined data boundaries.

We design AI automation around the client’s agreed purpose, data boundaries, operational controls, and risk profile. This page is a high-level overview; the binding terms for each engagement are set out in the signed contract, data-processing agreement, and solution documentation.

Client control and agreed purpose

The client defines the business purpose and approved use of its data. Where we process personal data on a client’s behalf, we do so only as agreed in writing and, where applicable, on the client’s documented instructions.

Provider selection and configuration

Providers are selected for the specific solution and documented before use. We assess relevant controls including data location, transfers, subprocessors, access, security, retention, and the provider’s terms for customer content.

No general-model training by default

Unless expressly agreed otherwise in writing, we select provider configurations intended to prevent customer content from being used to train or improve general-purpose AI models. The applicable provider setting is confirmed in the engagement scope.

Controlled access and security

Access to customer data is limited to authorised people and systems with a need to deliver, operate, or support the agreed solution. Security measures and access arrangements are selected for the solution and documented with the client.

Human oversight and responsible use

AI outputs are designed to support defined workflows. Material decisions remain the responsibility of the client and should be subject to appropriate human review, particularly where outputs could affect people, customers, employees, or access to services.

Retention, return, and deletion

The engagement defines live-data retention, backup treatment, return or deletion on termination, and any lawful exceptions. We keep data only for the period needed to operate and support the agreed solution.

Roles, risk, and compliance

The client remains responsible for determining whether its intended use is lawful and appropriate for its context, including its role as controller where applicable. We assess the technical and operational risks of each solution with the client. Uses involving sensitive personal data, employment, credit, insurance, health, biometric categorisation, emotion recognition, or other potentially high-impact decisions require a dedicated legal and risk assessment before delivery.

Transparency, AI literacy, and oversight

The parties should identify and meet any applicable transparency, human-oversight, AI-literacy, and record-keeping obligations. Where a solution directly interacts with people or generates content requiring disclosure, the implementation should clearly communicate the role of AI and support appropriate review. We do not deploy prohibited AI practices and do not treat this page as a classification or conformity assessment for a specific use case.

Incidents and cooperation

If we confirm a security incident affecting client data in a solution we operate, we notify the client without undue delay and cooperate as set out in the engagement terms. The client and Emz Systems agree the practical contacts, escalation process, and responsibilities before the solution goes live.

For information about this website’s own use of personal data and cookies, see our Privacy Policy and Cookie Policy.