AI Policy
How we use AI in our work, and what we do with your data
Last updated: July 2026
We build AI systems and we use AI tools internally. Both raise the same fair question from a client: what happens to my data? This is our answer.
1. Principles
- AI is applied where it changes an outcome, not because it is expected of a proposal.
- A person stays accountable for consequential decisions.
- Client data is not used to train models outside that client’s engagement.
- How a system reaches a result is documented and reviewable.
2. Your data in AI systems we build
When we build an AI capability for you:
- Your data is used to serve your system, and for nothing else.
- We do not use it to train shared or general-purpose models.
- Providers and data residency are agreed with you before anything is sent, and we prefer arrangements where your data is excluded from provider training by contract.
- Retention at the provider is configured to the minimum the system needs.
- Inputs and outputs are logged so a decision can be reconstructed later, with the same access controls as the rest of the system.
3. Human oversight
We design for review rather than full autonomy where the stakes justify it. In practice that means confidence thresholds that route uncertain cases to a person, a visible path to challenge or override a result, and monitoring for drift once the system is in production.
Where a decision affects someone’s access to care, credit, employment, or a similar outcome, we treat human review as a requirement rather than an option.
4. AI tools in our own work
Our engineers use AI-assisted development tools. Our rules for them:
- Client code and data go into an AI tool only where the engagement permits it, and never into a consumer-tier service.
- PHI and regulated data are never submitted to a general-purpose AI tool.
- Generated code is reviewed by a person and held to the same standard as anything else we write.
- Where a client asks us not to use these tools on their work, we do not.
5. The assistant on this website
The assistant on this site is automated and gives general answers. It is not a person, and the interface says so.
What you type there reaches us as an ordinary enquiry and is handled under our Privacy Policy. Do not send confidential information, PHI, or credentials through it.
6. Limitations
AI systems are probabilistic. They can be confidently wrong, they degrade as the world moves away from their training data, and they can reflect bias present in that data.
We say this plainly in scoping rather than after go-live, and we design the surrounding system (validation, review, monitoring) on the assumption that the model will sometimes be wrong.
7. Questions
For questions about this policy or how AI is used in your engagement, write to hi@zionn.io.