No training on client data
Your customers’, clients’ and patients’ data is never used to train or improve AI models — a contractual commitment in every agreement.
Your regulator expects you to run due diligence on every AI vendor — so we built AION to make that easy. Data protection, human oversight and auditability are engineered into every deployment, and documented in the terms we sign.
AION operates as a data processor under UK GDPR, acting only on your documented instructions. These commitments are standard in every engagement, not negotiated extras.
Your customers’, clients’ and patients’ data is never used to train or improve AI models — a contractual commitment in every agreement.
Every engagement includes a written data processing agreement with the full UK GDPR Article 28 terms — ready for your compliance review before you sign.
A complete list of sub-processors — including AI model providers — is available to every client, with advance notice of any change and a right to object.
Documented safeguards for any processing outside the UK, with deployment tiers up to fully UK-resident and on-premise where your mandate requires it.
Defined incident response with prompt client notification — so you can meet your own 72-hour ICO clock with time to spare.
Assistance with subject access requests, deletion and data-protection complaints — plus return or deletion of all data at contract end.
The controls regulators look for are built into how every AION system runs — the same governed operating layer across all four agents and every Infrastructure build.
Every input, AI output, human edit, approval and delivery is logged and exportable — evidence that stands up to an ombudsman, inspector or court.
Every action runs through permissions and a risk threshold. Low-risk actions execute within defined scope; anything sensitive is held for a named human operator.
Permissions per role, controlled workflow scopes, and retention configured to your sector’s rules — not one-size-fits-all defaults.
Every vertical deployment is scoped around the rules that govern you — because your regulatory accountability can’t be outsourced, and we never pretend otherwise.
Confidentiality-first architecture, no client-money involvement, and AI that handles intake and admin — never legal advice.
Communications designed around tenancy legislation, fee rules and redress requirements — with audit trails on every interaction.
Booking, reminders, registration and recalls only. Anything with clinical signal escalates instantly to your team — with defensible logs.
Admin and workflow automation with confidence-threshold escalation and a complete audit trail for the compliance file.
Marketing and engagement workflows built around consent, screening and suppression — compliant outreach machinery, not spam tooling.
Data flows, model behaviour, oversight design and retention documented per deployment — the inputs your DPIA needs, prepared for you.
Request our vendor due-diligence pack — data processing terms, sub-processor list, security overview and oversight design — and put it in front of your compliance team.
UK GDPR data processor • Human-in-the-loop by design • ISO 27001 Certified