Recommendation is not authority
An AI output may support a decision; it does not acquire the authority to make or execute that decision by producing a recommendation.
Back to SerialLabsTRUST, DATA & GOVERNANCE ยท REVIEWED 18 AUGUST 2026
This page records the verified contact-form boundary and the governance commitments used when AI-supported recommendations can influence organisational action, without blanket compliance claims.
An AI output may support a decision; it does not acquire the authority to make or execute that decision by producing a recommendation.
The relevant evidence, assumptions, unknowns and decision conditions are kept with the decision record.
Operational execution receives a defined intention, scope and owner rather than an open-ended instruction.
Review conditions identify which outcomes or new evidence require the organisation to reconsider the decision.
It distinguishes the current contact-form implementation from project-specific commitments. It is not a certification or a universal regulatory conclusion about every future client system.
The opportunity form asks for a name, work email and process; the application also creates pseudonymous anti-abuse hashes, transaction and delivery identifiers, timestamps and delivery state.
The inspected SerialLabs application code does not call an AI model in the contact-form request path; this code review does not establish how infrastructure or email providers process service data.
The form flow is limited to responding to the request and assessing a possible Opportunity Sprint; it does not add the contact to a marketing list.
Each submission receives an expiry no later than 12 calendar months; rate-limit events expire within 24 hours; and a protected daily maintenance workflow removes expired records and retries pending notifications.
A provider policy proves only what that provider states; SerialLabs publishes configuration-specific claims only after the configuration and owner approval exist.
Before using client data, the written scope records the purpose, data boundary and roles, authorised systems and access, retention, and exit or deletion arrangements. These terms are project-specific and separate from the contact-form Privacy Notice.
Connectors, credentials, environments and team permissions are limited to the access approved for the system. Access changes and client responsibilities are recorded for the engagement.
AI outputs support rather than replace accountable business decisions. Human review and escalation are defined for each system; SerialLabs does not make a universal accuracy or full-automation claim.
Models and providers, and the need for a data processing agreement, transfer safeguards or an EU AI Act role, risk and transparency assessment, are decided and documented for each system before relevant data flows.
Our default position is that client data, processes and pre-existing materials remain the client's, and client-specific deliverables and bespoke development paid for by the client belong to the client, subject to signed engagement terms and third-party rights.
SerialLabs retains its pre-existing methods, tools and generic reusable components. When these are embedded in a client deliverable, the client receives the rights needed to use, operate and maintain that deliverable.
SerialLabs does not reuse client confidential information or client-specific logic in an owned product. Any productisation or shared commercial model involving client-specific work requires a separate written agreement.
The Privacy Notice identifies the controller, purposes, legal bases, recipients, transfers, retention and rights for this specific form boundary.
Privacy Notice