Trust Center

Data & AI Governance

What we do with client material and assessment answers — what is kept, what is anonymised, and what is never used for training.

Last updated August 2026

In plain language

This is our own position on how we handle client material and assessment answers, and where AI is and is not allowed near them. It covers what we keep, for how long, what we never put into a model, and what we ask of clients before we build anything AI-driven for them. It does not cover data this website collects about visitors generally — the Privacy Policy covers that — and it is not a substitute for the specific terms in a signed engagement agreement.

This covers data we hold because of work we do: client material during an engagement, and the answers people give in our assessments. For data this website collects about visitors, see the Privacy Policy.

We advise organisations on AI governance. It would be difficult to take that seriously without stating our own position, so this page is more specific than a policy of this kind usually is.

Client material

During an engagement we see things organisations do not publish — decisions, disagreements, numbers, people. All of it is treated as confidential by default, whether or not an NDA is in place. An NDA changes what is enforceable; it does not change how we behave.

  • Held only for as long as the engagement and any agreed retention period require.
  • Never used as a case study, an example or a talking point without written permission. This is why there are no case studies on this website.
  • Never used to train any model, ours or anyone else’s.
  • Returned or destroyed on request, with written confirmation when it is done.

Assessment answers

When you complete an assessment, your answers produce your report. They are also added to an anonymised benchmark, so that later reports can say how a pattern compares across organisations rather than simply asserting it.

Anonymised means the organisation cannot be identified from the benchmark — not that a name was removed from a row. Where a combination of answers would make an organisation identifiable, that combination is excluded rather than published.

  • Never sold, and never shared with a third party for their own purposes.
  • Never used to train a model.
  • Deleted on request, including from the benchmark, with confirmation when it is done.
  • Retained for three years otherwise.

Where AI is used, and where it is not

A model scores assessment answers against a rubric we wrote, and produces first drafts of descriptive sections and chart data. A person reads every answer, writes the diagnosis and the recommendations, checks that nothing has been invented, and signs the report. Nothing reaches a client unread by a human.

That is why a paid report takes days rather than seconds, and it is not a bottleneck we are trying to remove.

What we will not put into a model

  • Confidential client material, into any consumer AI tool or any service whose terms permit training on inputs.
  • Personal data, where the processing has no lawful basis.
  • Anything that would let a model make a decision affecting someone’s employment, credit or access to a service.

Sub-processors

Where a third party is involved — hosting, email, payment, model inference — we name them on request. We do not use a provider whose terms permit training on our inputs, and we review that when terms change rather than when someone asks.

Where the data sits

Assessment answers and client material are held in systems we control. Where data crosses a border we apply appropriate contractual and technical safeguards in line with applicable data protection law.

Governance we ask of clients

Where we build AI workflows for you, we will not hand over a workspace without three things settled in writing: who owns each workflow, where a person signs off, and what happens when the output is wrong.

We have declined work over this. It is not a formality — an agent acting on your systems with nobody accountable for what it did is a liability with better formatting.

If something goes wrong

If data we hold is exposed, we will tell affected clients directly and quickly: what happened, what was involved, and what we are doing about it. We will not wait for a complete picture before telling you there is a problem.

Changes to this policy

This field moves. When our practice changes, this page changes first and the date moves with it. Ask what changed and we will tell you plainly.

Contact us

If you have questions about how we handle data, or want to know what we hold about your organisation:

We aim to reply within three working days.

What this does not cover

This page does not cover general website visitor data — see the Privacy Policy for that. It does not cover the specific data-processing terms of an individual client agreement, which take precedence where they say something different. And it describes our own practice, not a certification we hold or a framework we are audited against.

Questions we get asked

Questions about this policy

Do you use client material to train models?

No. Never, and not in an anonymised form either.

What does anonymised actually mean here?

That the organisation cannot be identified from the benchmark. Where a combination of answers would make one identifiable, that combination is excluded rather than published.

Can I have my assessment answers deleted?

Yes, including from the benchmark. Ask and we will confirm in writing when it is done.

Who else sees our data?

Only the people working on your engagement, plus the infrastructure providers required to run our systems. We name them on request.

Do you use AI on our material?

For assembly and drafting, against rubrics we wrote, inside systems we control. Not in consumer tools, and never in a service whose terms permit training on inputs.

Something here unclear?

These pages are meant to be readable rather than defensible. If a clause does not make sense, tell us — that is usually our fault.