Where your data lives
Your data stays inside the tools you already pay for. Every AI
workflow we build reads from and writes to your existing stack —
your CRM, your inbox, your accounting software, your project
tool — using your accounts and your permissions. We don't
centralise client data into a system we own. There is no
"Practical Workflows database" of your records to leak.
Some workflows call out to an external language model (most often
from Anthropic or OpenAI). When that happens we use the
enterprise / API endpoints that don't train on your prompts, and
we tell you in writing which model the workflow uses and what
data it sees. If you'd rather a workflow only use a model with
a UK or EU data-residency commitment, that's a constraint we
design around.
UK GDPR posture
We're a UK consultancy and work to UK GDPR / Data Protection
Act 2018 defaults. For every workflow that touches personal data
we document the lawful basis, the categories of data processed,
the retention window, and any onward processors involved. We'll
sign a Data Processing Agreement on request before any
implementation work starts.
We don't train AI models on your data. We don't share or sell
your data. We don't use your data to build features for other
clients. If a workflow we're scoping would require us to step
outside any of these defaults, we'll flag it before we quote.
API permissions
Least privilege, always. For each tool a workflow needs to touch,
we ask for the narrowest permission scope that will let it do
its job — never broader read or write than the workflow
actually needs. If a workflow only needs to read invoice
statuses, we don't ask for permission to delete invoices.
Every permission we'll ask for is listed in writing in the build
brief, before the implementation engagement starts. Nothing is
connected without explicit, named approval. You can revoke any
permission at any time without breaking the rest of the setup —
the workflow that depends on it stops cleanly and we get a
notification to fix or retire it.
Who can see what
The senior consultant on your engagement, and nobody else. We
don't have account managers, junior delivery staff, or an
offshore build team. The person on the discovery call is the
same person on the implementation, the same person on the
hand-off, and the same person on any future calls.
During implementation, the consultant has the access they need
to build and test the workflow inside your tools. After
hand-off, that access is either reduced to monitoring scope
(for clients on a Care Plan) or removed entirely. You choose.
When teams change
Every workflow we ship comes with a short hand-off doc that
covers what it does, what tools it touches, how to switch it
off, and how to swap the credentials it uses. The workflow
doesn't depend on the person who set it up — your team can
hand it over to a new joiner without us, and we can pick it up
again later if you ask.
On our side, the consultant who builds your workflow is the
same person on call for any future change. We've kept the
consultancy small for this reason: there's no "the person who
built it left the company" problem here.
Audit logs
Every AI workflow we build keeps a log of what it did, when, and
with what input. For workflows running inside your tools, the
log lives where you can already see it — the activity feed in
your CRM, the message log in your inbox, the run history in
your automation platform. For workflows that touch multiple
systems, we add a central run log inside an account you own.
If a regulator, auditor, or partner asks for evidence of what a
workflow did to a specific record, the answer is always: read
the log. We won't build workflows that don't leave one.
What we won't do
- We won't centralise your client list anywhere new.
- We won't train AI models on your data.
-
We won't connect a tool or grant a permission you haven't
explicitly approved in writing.
-
We won't build workflows that don't leave a log — every
action is auditable.
-
We won't ship anything we'd be uncomfortable showing a
regulator on your behalf.
-
We won't quote on a process that's the wrong fit for AI.
We'll say so on the call, even if it costs us the engagement.