Part A
Privacy notice
1. Who we are
[LEGAL COMPANY NAME], trading as The Applied Workflow Lab (“we”, “us” or “our”), is responsible for the personal information described in this notice. Registered office: [ADDRESS]. Company number: [NUMBER].
Privacy contact: [NAME / ROLE], [EMAIL], [POSTAL ADDRESS].
2. What this notice covers
This notice explains how we use personal information relating to website visitors, prospects, clients, programme sponsors, participants, facilitators and business contacts. A client may remain responsible for separate notices concerning its employees and internal data.
3. Information we may collect
- Business identity and contact details.
- Enquiry, discovery and relationship records.
- Contract, billing and payment information.
- Participant, attendance, feedback and agreed workflow-responsibility information.
- Client-provided examples, process descriptions and project materials where necessary to deliver agreed work.
- Technical website or communication data where collected through hosting or security systems.
- Supplier, facilitator and contractor due-diligence and payment information.
4. Why we use information
We may use information to respond to enquiries, prepare proposals, deliver contracted services, manage participants and sessions, issue invoices, protect confidential information and systems, improve delivery, maintain professional relationships and communicate relevant B2B services.
Depending on the activity, the lawful basis may include contract, steps requested before entering a contract, legitimate interests, legal obligation or consent.
AI tools and client information
We do not intentionally enter client confidential information or personal data into an external AI tool unless the use, tool, purpose and safeguards have been agreed with the client.
- Clients and participants should provide only the minimum information needed for the engagement.
- Personal or sensitive information should be removed or anonymised wherever possible.
- The approved tool and data boundary should be recorded in the engagement documents.
- AI-assisted drafts and outputs remain subject to human review.
Sharing and international transfers
We may share information with authorised facilitators and contractors; providers of email, hosting, scheduling, document storage, video meetings, electronic signature, accounting, payment and security services; professional advisers; regulators or authorities where legally required; or a genuine business successor subject to appropriate confidentiality.
Where a restricted international transfer occurs, we will use an applicable adequacy decision, approved contractual safeguard or another lawful mechanism.
Retention
- Unsuccessful enquiry and prospect records: normally up to 24 months after the last meaningful contact.
- Contracts, invoices and core transaction records: normally six years after the relevant financial or contractual period.
- Participant and delivery administration records: normally 12 months after the engagement.
- Temporary client working examples: normally deleted or returned within 90 days after final delivery unless continuing support or another written instruction applies.
- Marketing suppression records: kept as necessary to respect an objection or unsubscribe request.
These periods must be confirmed against the final operating systems, legal obligations, insurance requirements and client instructions.
Your rights
Depending on the circumstances, you may have rights to request access, correction, deletion, restriction, objection, data portability and information about automated decision-making. You may withdraw consent where consent is the lawful basis.
To exercise a right, contact [PRIVACY EMAIL]. You may complain to the Information Commissioner’s Office or another competent supervisory authority.
Effective date: [DATE].
Part B
Confidentiality and responsible AI commitment
What we will do
- Agree the team, tools, information boundaries and intended workflow before implementation.
- Limit access to authorised people who are subject to confidentiality obligations.
- Use the minimum client information reasonably required.
- Avoid entering personal or confidential client information into third-party AI tools unless expressly approved and appropriately safeguarded.
- Identify where human review, management approval or specialist advice is required.
- Keep client-specific materials separate from generic templates and delivery methodology.
- Notify the client promptly if a significant confidentiality or personal-data incident affects the engagement.
What we ask clients and participants to do
- Use only approved AI tools and accounts.
- Do not paste passwords, credentials, unnecessary personal data, regulated data or trade secrets into AI tools.
- Anonymise sensitive examples where possible.
- Check material outputs for accuracy, completeness, suitability and bias.
- Retain human ownership of decisions and external communications.
- Obtain specialist advice where the use case requires it.
Methodology and client materials
The client retains ownership of its data, examples and confidential business information. The Applied Workflow Lab retains ownership of its generic methodology, templates, facilitation materials, workflow structures and know-how. Client-specific deliverables are licensed for the client’s internal business use in accordance with the Client Services Agreement.