Legal & Trust

Trust & Data

This page explains our approach to AI, customer information and security. It does not certify production controls or replace a customer agreement.

AI and human authority

Reasoning with limits

The approved principle is to use AI where reasoning materially adds value. Customer evidence and machine inference remain distinguishable. Requirements become authoritative through governed confirmation; AI does not independently authorise contracts, permissions or consequential actions.

Minimum necessary context

Only bounded information needed for the authorised task should be provided to an approved AI service. Secrets and credentials must never be supplied. Customer confidential information is not automatically reusable training or platform material.

Current approval boundary

The owner instruction records OpenAI Standard Retention approval for synthetic-only Dex V6.5 TEST. That is not approval for real customer data or Production. The Heart reflections use deterministic browser logic, not AI. Production model, purpose, provider terms and retention approval remain to be evidenced.

No unsupported guarantees

No zero-retention, UK-only processing or guaranteed accuracy claim is made. Potential uses such as Discovery, evidence interpretation and engineering proposals must match the authorised deployed service and be transparently disclosed.

Security and incident response

Principles, not production certification

Dex authority describes identity verification, role-based project access, scoped permissions, secure sessions, expiring invitations, environment separation, protected secrets, project isolation and versioned audit evidence. This page does not certify these controls as operational in production.

Controlled actions

Consequential external actions require authority and deterministic controls. Idempotent processing and reconciliation address repeated requests and uncertain outcomes. A description of a control is not a penetration test or production acceptance record.

Incident handling

Approved principles require investigation, containment, evidence preservation, impact assessment, communication, escalation, remediation and audit. Processor notifications follow the applicable contract and law. Regulatory notification requires appropriate human/legal assessment; no arbitrary deadline is invented here.

Capability status

IMPLEMENTED locally: six browser-only reflections and inactive integration boundary. TESTED: see the dated local acceptance report. PRODUCTION VALIDATED: not established by this work. PLANNED: Reflex early-warning anomaly detection. No ISO 27001, SOC 2, insurance, perfect-security or guaranteed-availability claim is made.

Data handling and retention

Policy status

The 7 October 2026 owner operating baseline supplies the periods below. They are policy decisions, not independently verified statutory requirements or evidence that every system enforces them. Owner authorisation to publish this page does not verify statutory requirements or operational implementation.

Governed disposition

Retention needs a purpose, data class, trigger evidence, duration and permitted action. Legal holds override ordinary expiry. Closure revokes ordinary access immediately; recovery requires authority. Backup expiry is not immediate deletion, and restoration must reapply disposition controls.

Backup qualification

The proposed normal maximum backup lifecycle is 90 days, with explicitly approved exceptions only. Actual infrastructure enforcement and legal suitability remain unverified.

Owner Retention Schedule V1 — legal review pending
ClassTriggerPeriod / rule
health-check-prospectsubmission or last meaningful engagement12 months.
abandoned-discoverylast meaningful project activity12 months. Independent obligations survive evidence disposition.
active-operationsservice purpose endsPurpose / event governed. Retain only while genuinely required during active service.
customer-documentsproject milestone purpose reviewPurpose / event governed. Preserve justified authority/provenance, not originals indefinitely.
closed-recoveryauthorised closure90 days. Ordinary access ends on closure. Recovery requires authorised process.
contractualcontract termination or completion6 years. Subject to legal requirements and holds.
accountingrelevant company financial year end6 years. Applicable UK statutory/HMRC period controls; longer where legally required.
ordinary-securityevent12 months. Incident-linked evidence follows incident schedule.
security-incidentincident closure6 years.
consequential-auditproject or service closure6 years. Minimise retained evidence.
ai-invocationinvocation12 months. No automatic retention of full customer context.
ai-contentunderlying source policyPurpose / event governed. Follow underlying source class and minimum-necessary principle.
marketing-prospectlast meaningful engagement12 months.
marketing-suppressionobjection no longer requires suppressionPurpose / event governed. Minimum identifier while needed to honour objection.
revoked-authclosure or revocationPurpose / event governed. Access immediately revoked; residual evidence follows security policy.
backupbackup creation90 days. Normal maximum; justified approved exceptions only. Restoration reapplies disposition requirements.
company-recordsstatutory trigger requires review10 years, True minimum. At least ten years owner baseline; applicable statutory requirement controls.
legal-holdformal hold releasePurpose / event governed. Return to underlying policy after release.

Customer material and InfiniteCTRL technology

Customers retain rights in their confidential and proprietary business material subject to the applicable contract. InfiniteCTRL retains generic platform technology, software, methods, reusable components and independently developed know-how. Commissioning a solution does not automatically transfer the platform. Customer confidential material and customer-specific IP must not automatically become reusable assets.

Service-specific documents

Service agreements and processor terms depend on the relevant customer service. They are separate from website access terms. Service agreements, data-processing terms, and Production AI or provider approvals remain separate dependencies for customer services.