Your message has been sent.
We’ll process your request and contact you back as soon as possible.
The form has been successfully submitted.
Please find further information in your mailbox.
Select language
This AI policy defines how Innowise governs data and AI use across client engagements. It sets requirements for data handling, AI development, third-party AI tools, security controls, human oversight, and accountability. The policy provides a consistent basis for protecting client data and addressing applicable legal and contractual requirements.
The AI company policy applies throughout the AI lifecycle to Innowise employees, contractors, and other authorized parties involved in AI-related work. It covers data accessed, processed, stored, transferred, or otherwise used in connection with AI systems, subject to any stricter project-specific requirements.
For the purposes of this policy, the client acts as the data controller and AI deployer, while Innowise acts as the data processor and AI system provider. Where applicable law or a project agreement assigns additional or different responsibilities, those requirements take precedence.
These principles apply to every AI engagement Innowise delivers. They define the baseline for responsible data use and the controls our teams follow throughout the AI lifecycle.
Innowise limits data collection and processing to what the approved AI use case requires. Any data used in an engagement must have a defined purpose, with access and retention limited to that purpose. Data that is no longer required should not remain in active use.
AI systems must be documented according to their purpose and risk. Relevant stakeholders must be able to understand the system’s use of data and the basis of its outputs. Known limitations that may affect how those outputs are interpreted must also be documented.
Human review is required where AI output may materially affect people or business operations. The level of oversight must reflect the risk and regulatory context of the use case. AI output does not replace human approval where such approval is required.
AI systems must be assessed for unfair or discriminatory outcomes relevant to their intended use. Identified risks must be documented and addressed before deployment, with controls matched to their likely impact.
Responsibility for AI governance decisions must be assigned across the lifecycle. Records must identify who approved material decisions and what controls were applied. Significant changes to the system or its data must also be reviewable.
The AI policy covers the main categories of data Innowise may handle during AI engagements. Protection measures depend on data sensitivity and its role in the project.
Personal and sensitive data includes names, contact details, financial records, health information, and other information that may identify an individual. Innowise restricts access to authorized project roles and uses approved environments for handling such data.
Client records, pricing information, operational data, and internal processes fall under proprietary business data. We treat them as confidential, restrict access to authorized project roles, and limit their use to the agreed engagement.
Training and evaluation datasets may be used to train, fine-tune, validate, or benchmark AI models. Innowise documents their source and approved purpose while restricting access according to project requirements.
This category covers synthetic datasets and copies of real data with direct identifiers removed. Where the data can still be linked to an individual, as is commonly the case with pseudonymized rather than fully anonymized records, Innowise applies the same access restrictions as the source data. For datasets used to train or fine-tune models, Innowise also assesses the risk that a model may retain and reproduce fragments of its training data and adds controls where that risk is material to the use case.
Authentication credentials, encryption keys, API tokens, and other system secrets must never be submitted to or processed by AI tools. This restriction applies across all engagements, regardless of data tier or project context.
Data security applies at every stage of an AI engagement. Before client data enters an AI workflow, Innowise defines the rules for its collection and use. The same requirements remain in force during development and production.
Before client data is introduced into an AI workflow, the team determines what information the system actually needs and where it comes from. Any restrictions on its use are documented at this stage. Innowise keeps collection within the agreed project scope, and data without a defined project purpose must not enter the workflow.
Client data is kept in approved project environments with access limited to people whose responsibilities require it. Innowise assigns permissions according to project roles and reviews them when responsibilities change. Project requirements also determine whether access activity needs to be logged or reviewed. Data at rest and in transit is protected using encryption appropriate to the sensitivity of the information and the requirements of the project.
When client data is used to train, fine-tune, validate, or evaluate a model, the team records what data is involved and how it may be used. Access remains limited to the approved project context. Where the technical task allows it, synthetic or anonymized datasets can reduce unnecessary exposure of identifiable information during testing.
Before deployment, Innowise reviews how production data will move through the system and where processing will take place. The team also defines who may access that data. The production setup follows the security requirements agreed for the project, including controls required for sensitive or regulated information.
Client data is kept only for the period defined for the project or required by an applicable obligation. When that period ends, Innowise follows the agreed process for returning or deleting the data. The project team also records any approved exceptions that require data to remain available longer.
Client source code, proprietary datasets, and model weights developed or fine-tuned during an engagement are treated as client-owned assets for the purposes of this policy, subject to the applicable project agreement. They are not reused on other projects, retained beyond the agreed engagement scope, or submitted to third-party AI tools without explicit client approval.
AI governance starts before technical work begins and remains part of development, release, and later updates. Innowise defines how AI can be used within each project and applies controls according to the system’s purpose, risk, and operating context.
Before development begins, the team defines how AI will be used in the solution and what level of oversight the use case requires. Innowise records the intended purpose and relevant risk factors. Responsibility for governance decisions is also assigned before technical work moves forward.
During development, AI components follow the architecture and engineering rules agreed upon for the project. Changes to models, prompts, datasets, or AI logic must remain traceable through the development workflow. Access to AI development environments follows the roles defined for the engagement.
Before an AI model or feature is cleared for release, the team evaluates its behavior against the agreed use case and acceptance criteria. Testing focuses on risks identified for the project. Where relevant, that includes unreliable outputs, discriminatory behavior, or other issues that could affect how the system is used. Where a system accepts external inputs, testing also covers prompt injection, unintended data leakage through model outputs, and other adversarial misuse patterns relevant to the deployment context. Material findings are addressed before release.
AI functionality moves into production after the required project reviews are complete. Innowise checks that the deployed version matches the approved configuration and that required human review points remain in place. Changes that materially affect model behavior or data use go through review before release.
Governance continues after deployment. The project setup defines which aspects of system behavior require monitoring and how issues are escalated. Model updates and other material changes are reviewed against the governance requirements already established for the project.
Any third-party AI platform, foundation model, or automated component must be reviewed and formally approved before it is used in a client project or connected to an operational environment. Innowise evaluates vendors against the intended use, the data involved, and the risks the integration may introduce.
We review what data the provider receives, where it is processed, how long it may be retained, and whether submitted information can be used to train or improve the provider’s models.
Innowise assesses the vendor’s security controls and available compliance documentation against the requirements of the client environment and the type of data involved.
We check the terms governing confidentiality, data access, and permitted use. Any restrictions relevant to the project are recorded before the tool is approved.
The team reviews how the tool will connect to the client architecture and what systems or data it will be able to access. Formal approval and applicable procurement requirements must be completed before the integration moves into operational use.
Everyone involved in AI work at Innowise is accountable for how they use AI tools and handle project data within their assigned role. Team members must follow applicable data classifications, use approved tools, respect access restrictions, and review AI-generated output before it is used in project work. Project leads are responsible for making sure these requirements are understood and followed within their teams.
Violations of this AI acceptable use policy are reviewed based on their nature and severity. Confirmed breaches may result in disciplinary action under applicable company policies.
The frameworks below give clients and auditors a concrete way to check whether AI controls address the security, privacy, quality, and sector-specific requirements relevant to the project.
Clients have the right to understand how their data and AI systems are governed throughout an engagement. Innowise provides access to relevant project evidence and uses agreed response procedures when security exceptions or material drift are identified.
Clients can request information on data use, model documentation, evaluation results, known limitations, and governance controls applied during the project. Innowise also provides available project records within the agreed scope to support internal or external audits.
Clients can request removal or correction of project data under the terms agreed for the engagement. Requests are documented and handled through the project’s established data management process.
The project agreement or SLA defines notification and response windows for confirmed security exceptions or material drift in data processing or model behavior. Clients receive an initial notice within the agreed timeframe and further updates as the investigation progresses.
Innowise assigns governance ownership and review checkpoints for each AI engagement. Material incidents, significant model changes, and approved exceptions are documented for follow-up and audit review. These records provide a traceable basis for checking whether agreed controls were applied and whether corrective action was completed.
Innowise reserves the right to update this AI corporate policy as governance practices, regulatory requirements, or internal controls evolve. Any changes will be published on this page or elsewhere on the company’s websites.
This version was last updated on 18 August 2026, and historic versions can be obtained by contacting Innowise.
If you have any questions about this AI corporate data governance & safety policy, its application to an AI engagement, or Innowise data governance practices, please contact:
Innowise | privacy@innowise.com
Your message has been sent.
We’ll process your request and contact you back as soon as possible.