TRUST, DATA & GOVERNANCE ยท REVIEWED 18 AUGUST 2026

Trust starts with a defined boundary.

This page records the verified contact-form boundary and the governance commitments used when AI-supported recommendations can influence organisational action, without blanket compliance claims.

How AI recommendations cross into action

Recommendation is not authority

An AI output may support a decision; it does not acquire the authority to make or execute that decision by producing a recommendation.

Decision context is preserved

The relevant evidence, assumptions, unknowns and decision conditions are kept with the decision record.

Action is explicitly bounded

Operational execution receives a defined intention, scope and owner rather than an open-ended instruction.

Outcomes can reopen decisions

Review conditions identify which outcomes or new evidence require the organisation to reconsider the decision.

It distinguishes the current contact-form implementation from project-specific commitments. It is not a certification or a universal regulatory conclusion about every future client system.

The contact-form boundary

Data created

The opportunity form asks for a name, work email and process; the application also creates pseudonymous anti-abuse hashes, transaction and delivery identifiers, timestamps and delivery state.

No model call in application code

The inspected SerialLabs application code does not call an AI model in the contact-form request path; this code review does not establish how infrastructure or email providers process service data.

Purpose and retention

One stated purpose

The form flow is limited to responding to the request and assessing a possible Opportunity Sprint; it does not add the contact to a marketing list.

A bounded period

Each submission receives an expiry no later than 12 calendar months; rate-limit events expire within 24 hours; and a protected daily maintenance workflow removes expired records and retries pending notifications.

Claims follow evidence

A provider policy proves only what that provider states; SerialLabs publishes configuration-specific claims only after the configuration and owner approval exist.

How client engagements are governed

Define the data boundary

Before using client data, the written scope records the purpose, data boundary and roles, authorised systems and access, retention, and exit or deletion arrangements. These terms are project-specific and separate from the contact-form Privacy Notice.

Use approved access

Connectors, credentials, environments and team permissions are limited to the access approved for the system. Access changes and client responsibilities are recorded for the engagement.

Keep decisions accountable

AI outputs support rather than replace accountable business decisions. Human review and escalation are defined for each system; SerialLabs does not make a universal accuracy or full-automation claim.

Assess each system

Models and providers, and the need for a data processing agreement, transfer safeguards or an EU AI Act role, risk and transparency assessment, are decided and documented for each system before relevant data flows.

How commercial ownership is handled

Client-specific work stays with the client

Our default position is that client data, processes and pre-existing materials remain the client's, and client-specific deliverables and bespoke development paid for by the client belong to the client, subject to signed engagement terms and third-party rights.

Background IP remains reusable

SerialLabs retains its pre-existing methods, tools and generic reusable components. When these are embedded in a client deliverable, the client receives the rights needed to use, operate and maintain that deliverable.

No quiet productisation

SerialLabs does not reuse client confidential information or client-specific logic in an owned product. Any productisation or shared commercial model involving client-specific work requires a separate written agreement.

Read the form notice

The Privacy Notice identifies the controller, purposes, legal bases, recipients, transfers, retention and rights for this specific form boundary.

Privacy Notice