Skip to content
← Home

Legal

How we use AI.

Last updated · May 2026

Summary

We use AI to process data for audits, Reports and Managed Services, where required. It is a tool inside our engagements, not a product in its own right, and it operates under fixed rules. Your data is never used to train any AI model, ours or anyone else's. Inference runs under a zero-retention contract, so nothing sent is stored by the model provider. Everything is encrypted in transit and at rest, and no decision that matters is made by AI alone. The detail, with the underlying contractual clauses, is below.

1. Where AI is used

AI assists our work in three places, and only where required. During an audit, it helps process the platform, contract and cost data we analyse to produce your audit report. In Reports, it helps turn the day's operational data into readable commentary. In Managed Services, it assists with contract intake, term extraction and renewal preparation.

In each case, AI is applied only to the data needed for the task at hand, and only to deliver the engagement that data was provided for. We do not use AI to make decisions about pricing, account management or support priority, and we do not run AI over your data for any other purpose.

2. How data processed by AI is protected

Data touched by AI sits inside the same security programme as everything else we hold, described in section 10 of our Privacy Policy at /privacy and Annex 2 of our Data Processing Agreement at /dpa: TLS 1.2 or higher in transit, AES-256 or provider-equivalent at rest, logical tenant isolation, role-based access control with mandatory multi-factor authentication, and UK-based primary hosting.

What gets sent for AI processing is the minimum the task requires, and the inference step itself is governed by Annex 2 of the DPA:

AI inference performed via Sub-processors under zero-retention, no-training contracts. Customer Personal Data sent for inference is processed in-memory only and not stored by the inference provider beyond the request lifetime.

3. What we never do with your data

These commitments are contractual, not aspirational. Clause 14 of our Data Processing Agreement at /dpa binds us to every customer:

Preshift expressly commits, as part of this DPA, that Customer Personal Data:

• will not be sold or shared with any third party except as expressly permitted by this DPA (Sub-processors) or required by law;

• will not be used to train any machine-learning or AI model, whether Preshift's or a third party's;

• will not be used for marketing to the Customer, the data subjects, or any third party;

• will be processed strictly for the purposes of providing the Services it was uploaded or ingested for.

Data submitted for an audit receives the same treatment: it is used only to produce your audit report, is never shared beyond the sub-processors needed to produce it, and is held only briefly. Section 7 of our Privacy Policy at /privacy states:

If you submit contracts to us as part of an audit (without being an ongoing customer), we hold the contracts only for the duration of the audit and delete them within thirty days of delivering the audit document, unless you become a customer and choose to keep them in Managed Services.

The benchmarking dataset described in section 7 of our Privacy Policy is strictly opt-in and anonymised, and audit submissions are never included in it.

4. Who runs the models

AI inference is performed by the sub-processor listed for that purpose at /sub-processors, under a contract that requires zero retention and prohibits training on your data. Data sent for inference is processed in memory for the lifetime of the request and is not stored by the provider.

Any change of inference provider is a sub-processor change: existing customers get at least thirty days' notice by email and the right to object, under clause 7 of the DPA at /dpa.

5. Human oversight

No decision with a legal or similarly significant effect on any person is made by AI alone in any of our work. AI output, whether a line of Reports commentary, an extracted contract term or an audit finding, is material for a person to weigh and verify, not a decision. This is our commitment under Article 22 of the UK GDPR, set out in section 13 of our Privacy Policy at /privacy.

AI models can make mistakes, and our engagements are designed around that fact. Outputs are decision support, reviewed by people, and anything consequential is verified against the source material. We review and test the configurations behind these features before changes ship, and we monitor output quality in production.

6. Regulation

Our AI processing is governed by the UK GDPR framework described in our Privacy Policy at /privacy and our DPA at /dpa, including the Article 22 protections above and the Article 32 security measures in Annex 2 of the DPA.

For customers in the EEA, we monitor our obligations under the EU AI Act. Our use of AI (processing operational and contract data to support human-reviewed analysis) falls outside the Act's high-risk categories, and we will meet applicable transparency obligations as they take effect.

7. Questions

If you want more detail on any of this, including the specific contractual safeguards we hold with our inference provider, email privacy@preshift.co.uk and we will share what we can.

Related documents: our Privacy Policy at /privacy, our Data Processing Agreement at /dpa, and our sub-processor list at /sub-processors.

whenever you're ready

Let's talk about your stack.

Half an hour on Zoom or in person. We'll show up with questions, not a slide deck.