Data & AI policy
The safeguards Relaymere uses when AI systems process business information or take workflow actions.
Last updated: 11 October 2026Purpose and scope
This policy explains the standards Relaymere applies when designing AI-assisted workflows and connected business systems. A project agreement, data-processing terms and documented solution design turn these principles into specific obligations for each client.
Start with a defined business purpose
Every automation has a named owner, a clear purpose, permitted inputs, expected outputs and a way to measure whether it is useful. We do not collect or process information merely because a tool can do so.
The client remains responsible for confirming that the intended use is lawful, fair and appropriate for its sector, customers, employees and internal policies.
Human control and escalation
AI supports people at clearly defined points. Workflows involving important commitments, unusual requests, complaints, vulnerable people, financial decisions, employment decisions, legal rights or high-impact outcomes include suitable human review and an escalation route.
Where transparency is appropriate, users can understand when an automated system is involved, reach a person when needed and correct important errors.
Accuracy, testing and monitoring
AI output can be wrong or inconsistent. Before release, each system is tested against realistic and difficult examples, including failure cases. The project defines acceptance criteria, fallback behaviour, logging, review frequency and who can pause the automation.
Performance is monitored after launch. Material changes to prompts, models, data sources or connected actions are assessed and tested before wider use.
Client data boundaries
Client data is used only for the agreed purpose and through approved systems. Access follows least-privilege principles. Credentials and production data are not copied into personal accounts or unapproved tools.
The project documents data categories, sources, destinations, retention, deletion, exports and the responsibilities of Relaymere, the client and each provider. Sensitive data is excluded unless there is a justified need and suitable safeguards.
Model providers and training
Before using an AI provider, we review its business terms, privacy and security information, data location, retention controls and position on provider training. The selected configuration and any opt-out or zero-retention setting are recorded.
Client information is not reused to train a general model or create unrelated products unless the client has expressly authorised it and legal requirements are met.
Security and incidents
Systems use proportionate authentication, access control, encryption where appropriate, secret management, activity logging, backups and tested recovery. Connections expose only the data and actions needed for the workflow.
Suspected loss, unauthorised access, harmful output or unexpected automated action is contained, investigated and documented promptly. Contractual and legal notification duties are followed.
Fairness, privacy and higher-risk uses
Projects consider whether data or automation could disadvantage a person or group. Uses involving monitoring, profiling, biometrics, children, health, employment, credit or other high-impact contexts require specialist assessment and may be declined.
Where required, the client and Relaymere complete a data-protection impact assessment and obtain sector-specific legal or compliance advice before deployment.
Ownership, transparency and exit
The project agreement identifies ownership and permitted use of prompts, code, workflow logic, client materials, documentation and third-party components. The client receives practical operating information, known limitations and a route to request changes.
Offboarding covers access removal, credential rotation, exports, deletion, supplier accounts and any continuing licences or responsibilities.
Questions and updates
This policy is reviewed as services, providers and law change. Questions: hello@relaymere.site.
