Legal
AI usage policy
How we use AI inside the studio, how we protect your data, and the rules we follow when we build AI tools for clients. Plain English. No client personal data ever goes into an AI system.
01
Introduction
This AI Usage Policy explains how Helmflux Ltd ("Helmflux", "we", "us", or "our") uses artificial intelligence tools within our business, how we protect client data when using AI, and how we build and deliver AI solutions for our clients.
Helmflux provides three core services: unlimited graphic design, WordPress website development and hosting, and AI building and training. AI plays a role in our internal operations and is also a service we deliver directly to clients. This policy covers both.
We believe in transparency. We want our clients, prospective clients, and website visitors to understand exactly how we use AI, where the boundaries are, and what protections are in place.
Read alongside. This policy should be read alongside our Privacy Policy, Terms and Conditions, and Cookie Policy.
02
Our position on AI
AI is a tool. It is not a replacement for human skill, judgement, or creativity.
Every creative deliverable produced by Helmflux is human-made. AI may assist with research, ideation, drafting, or process optimisation, but a human professional always reviews, refines, and approves the final output before it reaches the client.
We are committed to using AI responsibly, transparently, and in full compliance with UK data protection law, including the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA).
03
AI tools we use
Helmflux currently uses the following AI tools internally:
Claude by Anthropic
Used to assist with the following internal activities:
- Content drafting and ideation
- Process optimisation and workflow improvement
- Code and development assistance
- Internal research and analysis
- Strategy support
We do not use AI tools from providers whose data practices conflict with our commitment to client confidentiality and data protection. We review our AI tool selection annually and will update this policy if our toolset changes.
04
How we use AI internally
We use AI to support the following internal activities:
Content drafting and ideation
AI assists with generating initial drafts, brainstorming concepts, and exploring creative directions for marketing content, blog posts, and social media. All AI-generated content is reviewed, edited, and approved by a human before use.
Process optimisation
AI helps us improve internal workflows, automate repetitive tasks, and identify efficiencies across our operations.
Code and development assistance
AI assists our developers with writing, reviewing, and debugging code for website builds and AI projects. All code is reviewed and tested by a human developer before deployment.
Research and analysis
AI supports internal research into market trends, competitor analysis, and industry insights.
Strategy support
AI helps us develop and refine content strategies, marketing approaches, and operational planning.
05
Client data and AI: our absolute rule
Non-negotiable. We never input client personal data into any AI system. This rule applies across the entire business.
This means we do not enter client names, email addresses, phone numbers, financial information, login credentials, or any other personally identifiable information into any AI tool.
This rule applies to all team members, contractors, and anyone working on behalf of Helmflux. It is covered in our staff training and reinforced in our internal guidelines.
06
Human review and quality control
Every output that involves AI assistance goes through a mandatory human review process before it reaches the client.
Content and copy
A human writer reviews, edits, and approves all AI-assisted drafts. No AI-generated text is delivered to a client without human review and refinement.
Code and development
A human developer reviews, tests, and validates all AI-assisted code. No AI-generated code is deployed without human testing and approval.
Strategy and research
A human strategist reviews and validates all AI-assisted analysis. No AI-generated insights are presented to a client without human verification.
We check all AI outputs for accuracy, factual correctness, bias, hallucinations, and relevance before delivery. If an output does not meet our standards, it is discarded or reworked by a human.
07
Transparency with clients
We are transparent with our clients about our use of AI.
When AI has been used to assist in the creation of any deliverable, we will always tell the client. We do not pass off AI-assisted work as purely human-created without disclosure.
This does not mean every deliverable involves AI. Many tasks are completed entirely by human professionals without any AI involvement. We use AI where it adds value, and we always disclose when we do.
Clients are welcome to ask us about our AI usage at any time. We will provide a clear and honest answer.
08
AI building and training service
In addition to using AI internally, Helmflux offers AI Building and Training as one of our three core services. This includes:
The following principles apply to all AI work we deliver to clients:
Ownership
When we build AI tools for a client (chatbots, agents, internal tools, workflow automations, or similar), the client owns the finished product, including the source code, prompts, training data and model configuration. AI builds are delivered as fixed-price projects, and ownership transfers to the client upon full payment of the agreed build fee, as set out in the intellectual property terms in our Terms and Conditions. Pre-existing frameworks, libraries, and tools that Helmflux developed independently remain our property. Where these are incorporated into a client's deliverable, the client receives a perpetual, non-exclusive licence to use them as part of the delivered work.
Client data in AI projects
Where an AI project requires the use of the client's own data (for example, training a chatbot on a client's knowledge base), we will agree the scope and handling of that data in writing before the project begins. We will only use client data for the specific purposes agreed in the project brief. We will not use client data for any other purpose, share it with any third party, or retain it beyond the agreed project scope. All client data used in AI projects is handled in accordance with our Privacy Policy and the UK GDPR.
Third-party AI providers
Where an AI project involves the use of third-party AI platforms or APIs, we will inform the client which platforms are being used and ensure that appropriate data processing agreements are in place. We will only use third-party providers whose data practices comply with UK data protection law. We will not use providers that retain, train on, or share client data without the client's explicit written consent.
Testing and validation
All AI tools built for clients are tested for accuracy, reliability, and fitness for purpose before delivery. We conduct quality assurance testing across a range of scenarios to identify and resolve issues before deployment. We do not guarantee specific performance levels, outcomes, or return on investment from AI deliverables. AI tools are provided on an "as delivered" basis, as set out in our Terms and Conditions.
09
Bias, fairness, and accuracy
We recognise that AI tools can produce outputs that are biased, inaccurate, or misleading. We take this seriously.
All AI outputs are reviewed by a human before delivery to check for bias, factual inaccuracies, hallucinations (fabricated information), and cultural or contextual appropriateness.
Where we build AI tools for clients, we test for bias and fairness as part of our quality assurance process. If a client has specific requirements around bias, fairness, or ethical AI use, we will work with them to address those requirements.
We do not use AI to make automated decisions that produce legal or similarly significant effects on individuals without appropriate safeguards, as required by the UK GDPR and the DUAA.
10
Staff training and guidelines
All Helmflux team members receive formal training on our AI usage policy, including what they can and cannot use AI for, how to handle client data, and how to review AI outputs for quality and accuracy.
Our internal AI guidelines cover
These guidelines are reviewed and updated annually, or sooner if our tools, processes, or legal obligations change.
11
Data protection and compliance
Our use of AI complies with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations (PECR).
Where AI processing involves personal data, we ensure there is a valid lawful basis for processing, as set out in our Privacy Policy.
Where we make solely automated decisions that produce significant effects on individuals, we ensure appropriate safeguards are in place, including transparency, the right to contest decisions, and the right to request human review, in accordance with Article 22A of the UK GDPR as amended by the DUAA.
Today. Helmflux does not make any decisions based solely on automated processing without human involvement.
12
Prohibited uses of AI
Helmflux does not use AI for any of the following purposes:
13
Annual review
We review this AI Usage Policy and our internal AI practices annually. The review covers:
If material changes are made to this policy, we will update the effective date and notify clients where appropriate.
14
Contact us
If you have any questions about this AI Usage Policy or how Helmflux uses AI, please contact us:
- Company
- Helmflux Ltd
- Address
- 14 Beyon Drive, Cam, Gloucester GL11 5JW
- info@helmflux.co.uk
- Website
- www.helmflux.co.uk
This document was last updated on 20 April 2026.