Data flow mapping
Where personal data enters, is embedded, cached, logged and retained across the full AI chain.
Governance & Trust
Privacy decided at design time costs a fraction of privacy retrofitted.
The problem we solve
AI systems copy data into places privacy programmes never mapped: prompts, embeddings, caches, logs and evaluation sets. We map those flows, apply minimisation and retention at each hop, and enforce residency in the architecture itself.
Where personal data enters, is embedded, cached, logged and retained across the full AI chain.
PII detection and redaction at ingestion and at the prompt boundary, with reversible tokenisation where needed.
Regional processing, model selection by region and contractual controls on sub-processors.
Retention rules applied to indexes, embeddings and logs, including verifiable deletion on request.
DPIAs, legitimate interest assessments and records of processing written for AI-specific processing.
How the engagement runs
Discovery of AI data flows, sub-processors and current retention behaviour.
Controls, residency architecture and assessment drafting with privacy counsel.
Technical controls delivered and evidenced, with ownership handover.
Common questions
Related practices
Model registry, risk classification, documentation and audit trails mapped to the EU AI Act, ISO 42001 and internal policy.
ViewPrompt-injection defence, data exfiltration testing, agent abuse scenarios and adversarial evaluation before attackers get there.
ViewThird-party review of models, vendors and controls — an objective read for boards and risk committees.
ViewA 45-minute briefing with the people who would run the work — scope, timeline and a straight answer on whether it is the right next step.