Technophobia Logo
AI Use Policy

Last updated: 14 September 2025

This policy sets rules for using artificial intelligence (AI) at Technophobia Ltd. It applies to staff, contractors, and anyone acting for us. It sits with our Privacy Policy, Data Processing Addendum, Acceptable Use Policy, Information Security Policy, and Sub-processor list.

1. Scope and roles
  • AI Lead (Director): owns this policy, approves high-risk uses, and maintains the vendor list.
  • Project Lead: checks client contracts and records approved use cases.
  • Everyone: follow this policy and report issues at once.
2. Types of AI use
TypeExamplesControls
Assistive Draft copy, outlines, meeting notes, code suggestions Human review and edit before release
Analytic Summaries, data classification, log triage Spot checks, source links where possible
Customer-facing Chatbots, forms, email replies Clear signposting; escalation to a human; logging
Automated actions Workflows that trigger changes or transactions Guard rails, approvals, and audit

High-risk uses (legal effects, profiling, safety impact) need the AI Lead’s written approval.

3. Data handling rules
  • No sensitive data in prompts unless a contract and a documented control set allow it. Sensitive data includes special categories, payment data, and credentials.
  • For client personal data, the client is the controller. Our DPA applies. Use a provider on our Sub-processor list with the right data location and terms.
  • Use zero-data retention modes where available. Do not allow vendors to train on our prompts or outputs unless the AI Lead agrees in writing.
  • Mask or minimise inputs. Prefer references (IDs) over raw content.
  • Do not paste secrets. Use a vault and short-lived tokens passed by the platform, not by the model.
4. Intellectual property and content
  • Staff remain responsible for outputs. Edit for accuracy, originality, and tone.
  • Check licences for any code or text you keep. Keep third-party attributions where required.
  • Do not imitate living artists, brands, or individuals in a way that confuses origin or endorsement.
  • Do not submit client content to public tools without permission recorded in the project folder.
5. Accuracy, bias, and safety
  • Models can produce errors. For facts, add sources or verify with trusted references.
  • Use clear prompts that state constraints and required sources.
  • Avoid harmful or discriminatory outputs. Re-prompt or remove content that could cause harm.
  • Flag medical, legal, or financial content for human expert review before use.
6. Security and prompts
  • Assume prompts and outputs may be logged by the tool. Treat them as business records.
  • Defend against prompt injection: set system prompts to ignore external instructions; strip HTML/JS from untrusted inputs before passing to a model.
  • Limit tools with write access. Approve outbound actions explicitly. Log all actions triggered by AI.
  • Follow our Access Control & Password Policy for keys and tokens.
7. Vendors and approvals
  • Use vendors listed at /sub-processors. New vendors need a short review covering terms, data location, retention, and security.
  • Record the model family and version used (e.g., “text-model X, 2025-08”).
  • Prefer UK/EU processing where the client requires it. Document transfer safeguards if data leaves the UK/EU.
8. Logging, retention, and audit
  • Keep key prompts, outputs, and decisions for client work with the ticket or repo.
  • Retention follows our Data Retention Schedule.
  • For customer-facing AI, log confidence notes, fallback use, and any manual overrides.
9. Transparency and disclosure
  • Tell clients where AI meaningfully shapes content or decisions, and how to contact a human.
  • Mark AI-generated marketing copy for internal review. Remove the flag before publishing once checked.
  • For chatbots, show a short notice that an AI assistant is in use and how data is handled (link to the Privacy Policy).
10. Prohibited uses
  • Bypassing access controls, scraping against a site’s terms, or testing security without written permission.
  • Deepfakes, impersonation, or synthetic media of real people without consent and a clear, lawful basis.
  • Automated decisions with legal or similar effects on individuals without human oversight.
  • Generating malware, exploits, or content that promotes harm.
  • Targeting individuals based on protected characteristics.
11. Incidents and reporting
12. Review and training
  • AI basics at induction for all staff who may use these tools.
  • Quick refreshers after major vendor or legal changes.
  • Policy review at least yearly.
13. Contact

Questions about this policy or a new use case?

Technophobia Ltd · Company No. 14898332 · VAT GB 495 7043 58
13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom
+44 1229 774591hello@technophobia.uk

Technophobia

n8n automation for small teams. UK-based. Fast turnarounds. Clear handovers.

Address
South Cumbria Skills Exchange
Millom
LA18 4JS
United Kingdom

Phone +44 01229 774591
Email hello@technophobia.uk

VAT registered • GDPR-aligned • Typical lead time: 1–2 business days