Bringing AI into a business means the person helping you gets close to how it runs. Your client list, your inbox, your numbers, your processes. That's a lot of trust to hand over, and you should know what we do with it before you do.
We don't train AI models on your data
When we use AI tools on your project, we use business and enterprise tiers where the provider's terms state that customer data is not used to train their models. We don't feed your data into consumer chatbots, and we don't use it to build anything for another client.
What we do carry between clients is what we learned. The pattern, the approach, the thing that worked. Not your data.
We take the least data that will do the job
Before we copy anything, we ask whether we need it. A system that flags refinance opportunities needs loan data. It doesn't need your clients' full names and addresses to be designed and tested.
Where we can build and test against de-identified data, we do. Names, contact details and identifiers get stripped or replaced before the data comes anywhere near a development environment, and the mapping back to real people stays with you.
Where your data actually lives
Wherever possible, in your own accounts. When we build you a system, it runs on infrastructure you own and pay for, under your logins. That's deliberate. It means you can see it, audit it, and carry on without us.
Where we need a working copy on our side during a build, it sits in access-controlled storage, limited to the people working on your project.
Who on our side can see it
We're a small team. Only the people actually working on your project get access, and only to the parts they need. If we bring in a specialist contractor for a piece of work, they're under the same confidentiality obligations we are, and we'll tell you if they'll be touching your data.
What happens when we finish
The system is yours. You keep the accounts, the code and the data.
On our side, we delete our working copies of your data within 30 days of the engagement ending, or sooner if you ask. We keep the project documentation and our own business records, because we need those for tax and for supporting you later. If you want written confirmation that your data has been deleted, ask and we'll send it.
If something goes wrong
If your data is exposed through something on our side, we'll tell you as soon as we know. Not after we've worked out how to phrase it. You'll get what happened, what was affected, and what we're doing about it, so you can meet your own notification obligations.
What we won't do
- Use your data to train models, ours or anyone else's
- Share it with another client, or use your business as an unnamed example without asking
- Put your data into a tool we haven't checked the terms on
- Name you as a client publicly without your say-so
The tools we commonly use
Which tools a project uses depends on what we're building. We'll tell you which ones your project touches before we start, and you get the final say on any of them. Ask us for the current list for your engagement at any time.
Your obligations, briefly
If you're giving us data about your customers, you need the right to do that under your own privacy policy and any agreements you have with them. We'll flag it if something looks like it needs checking, but it's your call to make.
Putting it in the contract
Everything on this page is how we work. If you want it as a binding commitment rather than a published position, say so and we'll put it in your engagement agreement or sign your own data processing terms. We're not precious about it.
Questions
If there's something here you want tightened before you engage us, email hello@brightwaters.ai. Good questions about data handling are a sign you're thinking about this properly.