Effective date: 3 August 2026
Organisation: Hamblett Consultancy Ltd
1. About This Policy
Hamblett Consultancy may use artificial intelligence tools to support parts of our work, including drafting documents, summarising information, researching public material, improving internal processes, supporting cyber security analysis, helping with Microsoft 365 and IT consultancy work, and improving business administration.
This policy explains how we approach AI privacy, what information we protect, and the limits we place on AI tools. It should be read alongside our main Privacy Policy.
Our position is simple: AI can help us work more efficiently, but it must not compromise client confidentiality, personal information, security, or human accountability.
2. What We Mean By AI
In this policy, AI means tools or systems that can generate, summarise, analyse, classify, automate, or assist with content, data, code, documents, images, messages, or technical work. This may include AI features built into third-party products, cloud services, productivity tools, security platforms, automation tools, or standalone AI services.
3. How We May Use AI
We may use AI to assist with low-risk or controlled business tasks such as:
- Drafting and improving business documents, website copy, proposals, process notes, and internal material.
- Summarising non-sensitive information or already-approved business content.
- Researching public information, vendor documentation, and general technical topics.
- Creating marketing drafts, social media ideas, images, and campaign outlines.
- Supporting technical troubleshooting, coding, automation, documentation, and security review where appropriate controls are in place.
- Helping organise internal workflows, reminders, notes, and administrative tasks.
AI is used as an assistance tool. It does not replace human review, professional judgement, or our responsibility for the work we provide.
4. Client Data Is Not Shared With AI By Default
We do not give AI tools unrestricted access to client data by default.
Client data may include emails, support tickets, Teams messages, SharePoint or OneDrive files, Microsoft 365 tenant information, device information, user account details, security settings, logs, contracts, invoices, commercial records, network information, audit findings, vulnerability results, screenshots, call recordings, and any information a client would reasonably expect us to treat as confidential.
Where AI is used in connection with client work, we aim to use the minimum amount of information necessary. Wherever practical, information is summarised, anonymised, pseudonymised, or redacted before it is used with an AI tool.
5. Personal Information
We do not knowingly enter personal information into public or unapproved AI tools where it is not necessary or appropriate.
Personal information may include names, email addresses, phone numbers, addresses, job roles, employment details, user account details, device ownership details, financial information, identity information, and any other information that can identify a person.
If personal information is involved in an AI-assisted process, we consider the purpose, lawful basis, data minimisation, provider controls, retention, security, and whether the processing is appropriate for the type of information involved.
6. Information We Do Not Put Into AI Tools
Unless there is a specific approved reason and suitable controls are in place, we do not put the following into AI tools:
- Passwords, MFA codes, recovery codes, API keys, private keys, certificates, session tokens, or other secrets.
- Raw client mailboxes, file libraries, support ticket histories, logs, backups, or tenant exports.
- Unredacted security incident details, vulnerability reports, audit packs, or sensitive technical diagrams.
- Client contractual information, financial records, pricing details, or commercially sensitive material where it is not needed for the task.
- Special category personal data or sensitive personal information unless there is a clear lawful basis and approved processing route.
- Information that would breach a client agreement, confidentiality obligation, privacy duty, or security requirement.
7. AI Tool Selection And Approval
We assess AI tools before using them with business or client information. Depending on the use case, we may consider:
- Whether the provider offers suitable business or enterprise privacy terms.
- Whether prompts, files, or outputs may be used to train models.
- Where data is processed and stored.
- Retention and deletion controls.
- Access controls, audit logs, encryption, and administration features.
- Whether the tool is suitable for the type of data involved.
- Whether client approval or a data protection assessment is required.
Free, personal, consumer, trial, or unknown AI tools are not treated as suitable for client confidential information or personal information.
8. Human Review
AI-generated output is not automatically trusted. We review AI-assisted work before it is used where it could affect a client, a technical decision, a security recommendation, a Microsoft 365 configuration, a proposal, a quote, a contract, a public statement, an incident response, or a client communication.
AI does not make final decisions for us on legal, financial, contractual, employment, security, compliance, or client-impacting matters. A human remains accountable for the final output, action, or recommendation.
9. Communications And Impersonation
AI may help draft or organise emails and messages, but it must not be used to mislead people about who they are communicating with.
If an assistant or automation replies directly where transparency is appropriate, it should be clear that the response is from the assistant. AI must not be used to impersonate a client, supplier, member of staff, Darren Hamblett, or any other person.
Client-facing communications involving pricing, contracts, complaints, disputes, security incidents, data protection matters, technical changes, or commitments require appropriate human review or approval.
10. Website Visitors And Enquiries
If you contact us through the website, email, telephone, or another channel, we may use AI to help summarise, organise, or draft a response to your enquiry. We do not use AI to make solely automated decisions about you that have legal, financial, contractual, or similarly significant effects.
We will not intentionally upload your enquiry into a public or unapproved AI tool if it contains sensitive personal information, confidential client information, credentials, or security-sensitive material.
11. Security And Access Controls
AI tools and AI-assisted workflows must not be given broad or unnecessary access to systems. Where AI tools are connected to business systems, access should be limited to what is needed, monitored where practical, and removed when no longer required.
We do not give AI tools access to passwords, admin credentials, MFA details, private keys, or unrestricted client systems.
12. Data Retention
AI-assisted drafts, notes, prompts, and outputs should not be kept for longer than needed. Where AI outputs contain client information or personal information, they must be stored only in appropriate business systems and deleted from temporary locations where practical.
Retention may vary depending on the tool used, the type of information involved, and our legal, contractual, operational, or security requirements.
13. Accuracy And Limitations
AI tools can produce inaccurate, incomplete, outdated, or misleading results. We do not rely on AI alone for final technical, security, legal, financial, contractual, or compliance decisions.
Where AI contributes to work we provide, we remain responsible for reviewing the output and deciding whether it is suitable.
14. Your Rights
Your data protection rights are set out in our main Privacy Policy. Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to, or request portability of your personal data.
If you have questions about whether AI has been used in connection with your information, or if you want to raise a concern, you can contact us using the details below.
15. Contact
If you have questions about this AI Privacy Policy or how Hamblett Consultancy uses AI, contact:
Hamblett Consultancy Ltd
Email: [email protected]
Phone: 0113 484 2010
16. Changes To This Policy
We may update this policy as AI tools, business processes, client requirements, or legal guidance changes. The latest version will be published on this page.
Summary
Hamblett Consultancy may use AI to improve efficiency and support service delivery, but AI does not get unrestricted access to client data or personal information. Sensitive data must be protected, AI outputs must be reviewed, and human accountability remains in place.