Artificial Intelligence (AI) Usage Policy

At Disruptive Thinking Ltd, we use technology to help us work smarter, improve efficiency, and deliver better outcomes for our clients. Artificial Intelligence (AI) is one of the tools we use to support our team, enhance our creativity, and help us deliver better results.

However, we believe technology works best when combined with human expertise, curiosity, creativity, and judgement. The value we bring to our clients comes from understanding their challenges, asking the right questions, developing strategic thinking, and creating work that delivers meaningful impact.

AI is used to support our team, not replace the relationships, experience, and personal approach that our clients value.

This policy explains how we use AI, the principles that guide our approach, and the steps we take to ensure information is handled responsibly and securely. It sits alongside the data protection and AI provisions in our client Terms and Conditions, and is supported by an internal AI Use Policy which governs how our team may use these tools day to day. A copy of that internal policy is available to clients on request.


Last reviewed: September 2026

Next review due: September 2027

1. How we use AI

AI tools are used across different areas of our business to improve efficiency, support creativity, and enhance the services we provide.

While AI can help us work faster and explore new possibilities, we place enormous value on the experience, creativity, critical thinking, and expertise that only people can bring. The insight gained from years of working with clients, understanding their audiences, and applying strategic judgement cannot be replaced by technology.

AI is a tool that supports our team. It does not replace the relationships, ideas, problem-solving, and human perspective that sit at the heart of the work we deliver.

All work produced by Disruptive Thinking remains the responsibility of our team. AI-generated outputs are reviewed, refined, and checked by experienced team members before they are used externally or shared with clients.

1.1 AI meeting assistants and transcription tools

We use AI-powered meeting tools, such as Fireflies.ai and Google Gemini, to help capture conversations, record key decisions, and improve the accuracy of meeting notes.

These tools help us spend less time manually documenting discussions and more time focusing on delivering value for our clients.

We tell participants before a meeting is recorded or transcribed, and anyone who would prefer not to be recorded can ask us to turn the tool off.

Any recordings, transcripts, or notes are stored securely and used only for legitimate business purposes connected to the meeting or agreed project activities. Where useful, we may provide copies of recordings, transcripts, or notes to our clients.

We keep meeting content only for as long as it is useful to the work it relates to. When a client engagement ends we remove the recordings, transcripts and summaries relating to it, within the timescales set out in our Terms and Conditions. A client can ask us to delete a particular recording at any time.

1.2 Generative AI tools and large language models

We use generative AI tools, including platforms such as ChatGPT, Claude, and Gemini, to support areas including:

• Research and information gathering

• Content development and refinement

• Brainstorming and idea generation

• Improving internal processes

• Supporting analysis and problem-solving

• Increasing efficiency across everyday tasks

AI outputs are always reviewed by a member of the Disruptive Thinking team before they are used.

We apply our own knowledge, experience, and judgement to ensure all work is accurate, appropriate, aligned with client objectives, and meets our quality standards.

AI supports our thinking and creativity, it does not replace them. The strongest ideas come from combining technology with human insight, experience, and understanding of our clients' goals, audiences, and challenges.

We also recognise that AI-generated material may closely resemble existing work and may not attract copyright protection in the same way that human-authored work does. Where originality or ownership matters to a deliverable, we tell our clients and we make sure a person authors it.

1.3 Using AI for data analysis and CRM insights

We also use AI tools to support data analysis, data interrogation, and insight generation. This may include analysing information from client systems, such as CRM platforms, to help identify trends, uncover opportunities, improve processes, and support better decision-making.

AI can help us process and analyse information at scale, identify patterns, and highlight areas for further investigation. However, insights are always reviewed and interpreted by our team using our knowledge of the client's wider business context, objectives, and challenges.

The value comes from combining AI-powered analysis with human expertise and turning data into meaningful recommendations and practical actions.

We are clear about the difference between the tools anyone can sign up to and the tools we are permitted to use on client information:

• We never enter client personal data, confidential or commercially sensitive information, passwords, access tokens or restricted business information into free or consumer-tier AI tools, or into any tool that has not been approved through our internal AI Use Policy.

• Where client information does need to be processed using AI, we use only approved, business-tier tools operating under a written data processing agreement, accessed through approved methods, with appropriate privacy and security controls in place.

• We keep a register of every AI tool and sub-processor that may process client personal data. It records the provider, the purpose, where the data is processed, and the safeguards that apply. Clients can ask for their copy at any time.

• We do not knowingly enter special category data (such as health, ethnicity or religious belief) or criminal offence data into any AI tool unless a client has instructed us to in writing and we have agreed safeguards first.

1.4 Connecting AI tools and automations to client systems

Some AI tools can now connect directly to the systems our clients use - most commonly a CRM such as HubSpot - through integrations, connected apps, or the Model Context Protocol (MCP). We also build automations on platforms such as Make.com, which move and transform data between a client's systems and can include AI steps of their own. Both let software read live records and, where a client has authorised it, carry out actions inside that system.

Used well, this removes a great deal of manual work: auditing data quality across thousands of records, spotting duplicates, drafting properties and workflows, keeping systems in step with one another, and producing analysis that would otherwise take days. It also means software is working with real customer data, so we treat it with more care than any other use of AI.

Whenever we connect an AI tool or build an automation that touches a client system:

• We only connect systems the client has authorised in writing, and we record each connection, what it can see, and who holds the credential.

• We use named, individually attributable access - never a shared or generic login - so every action can be traced back to a person.

• We request the minimum permissions the work requires. Where a connection only needs to read, we do not ask for the ability to write, and we do not widen permissions without asking first.

• For one-off work - a bulk update, a data cleanse, a migration - a person reviews and approves the change before it is applied. We do not let an AI tool make an irreversible change to a client's system on its own.

• Automations are different by design. Once an automation is live it runs without someone watching each execution, so the review happens before it goes live rather than each time it fires. Any automation that sends a communication, changes records in bulk, deletes or merges data, or alters a live workflow is built, tested against sample data and signed off by a person before it is switched on, and monitored afterwards. We tell our clients what each automation does and when it will act.

• We keep as little client data inside an automation platform as we can. Where a platform stores the contents of every run by default, we turn that off, and we clear out stored records when a piece of work ends.

• We keep a log of the actions taken in a client's system, and of automation run history, so far as the platform supports it, and we make it available on request.

• Clients can suspend, restrict or withdraw any connection at any time, and we disconnect within five working days of a project ending.

• Wherever we can, we build inside the client's own accounts rather than ours. It means the data, the settings, the audit trail and the ongoing control stay with them - and nothing breaks if they ever choose to work with someone else.

We never use an AI tool to make a decision about an individual on an automated basis alone where that decision would have a legal effect on them, or would significantly affect them in a similar way, unless a client has instructed us to in writing and appropriate safeguards are in place.

1.5 AI features within other platforms

Many of the tools we use across marketing, CRM, automation, project management, analytics, design, and communication now include AI-powered functionality.

We may use these features where they provide genuine value, improve efficiency, or enhance the quality of our work.

Before using any AI-enabled feature, we consider:

• What information is being processed

• How that information is stored and used

• Whether appropriate security measures are in place

• Whether the output requires human review

Some platforms also have their own account-level settings which decide whether the platform provider may use a customer's data to improve that provider's AI models. HubSpot is one example, and its setting is switched on by default. That setting belongs to the account owner, not to us. We will always show a client where it is and explain what it does, but the decision, and the change itself, is theirs to make.

2. Data protection and security

Protecting client information and maintaining trust is fundamental to the way we work.

When we handle personal data on behalf of a client, we act as a data processor and the client is the data controller. Our client Terms and Conditions include the terms required by Article 28 of the UK GDPR, and they list the sub-processors - including AI providers - that a client authorises when they engage us. We give notice before we add or change any sub-processor that will handle client personal data, and clients have the right to object.

Our approach includes:

• Restricting access to information to authorised team members, under named accounts protected by multi-factor authentication

• Requesting the least access needed to do the work, and reviewing it regularly

• Using only approved AI tools engaged on business terms that prohibit our clients' data being used to train the provider's models

• Setting retention as tightly as each tool allows, and deleting client information ourselves where a provider does not cap it

• Making sure an appropriate safeguard is in place wherever data is processed outside the UK

• Avoiding the use of sensitive information in unsuitable tools

• Following applicable data protection legislation, including the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025

If a personal data breach affects client information, we notify the client without undue delay and in any event within 24 hours of becoming aware of it, so they have time to meet their own obligations.

We regularly review the tools we use to ensure they continue to meet our expectations around privacy, security, and responsible use. Providers change their terms, and a change that weakens the protection of client data is treated as a change of sub-processor.

3. Responsible and ethical use of AI

AI technology is evolving quickly, but it is not perfect. AI-generated outputs can sometimes contain errors, inaccuracies, outdated information, or unintended bias. We therefore apply human oversight to all AI-assisted work.

Our team is responsible for ensuring that:

• Information is reviewed for accuracy

• Content reflects our clients' requirements and values

• Recommendations are based on appropriate expertise and judgement

• AI-generated outputs are checked before being shared externally

• Anything that changes a client's live system is approved by a person first

We remain accountable for every piece of work we deliver. AI may assist with research, ideas, analysis, or production, but responsibility for accuracy, quality, and strategic relevance always remains with our team.

We do not use AI as a replacement for human decision-making, accountability, or professional expertise. We are also honest about its limits: where accuracy is critical, or where a client operates in a regulated sector, final sign-off always sits with the client.

4. Transparency with clients

We believe transparency builds trust.

Where AI plays a meaningful role in delivering our services, we are open to discussing how it has been used and the safeguards we have in place. If a client asks which deliverables were produced with material help from an AI tool, and which tool was used, we will tell them.

Our priority is always delivering work that meets our clients' needs, aligns with their expectations, and provides genuine value.

5. Your choices

Our clients decide how AI is used in their work. At any time, and without needing to give a reason, a client can:

• Ask us not to use AI tools at all, or not to use a particular tool, on their account

• Exclude specific data, records, objects or systems from AI access

• Withdraw or restrict any connection between an AI tool and their systems

• Object to a new sub-processor we have given notice of

• Ask for our register of AI tools and sub-processors, or for a log of actions taken in their systems

We will action a request to stop using an AI tool within ten working days. Where doing so materially changes the time, cost or feasibility of a piece of work, we will say so honestly and agree a revised approach before proceeding - we will not quietly absorb it or quietly drop the standard.

6. Reviewing and improving our approach

AI technology continues to develop rapidly, and our approach will evolve alongside it.

We regularly review:

• The AI tools we use

• Our internal processes

• Security and privacy considerations

• Industry guidance and best practice, including guidance issued by the Information Commissioner's Office

This policy is reviewed at least annually, and sooner if a provider materially changes its terms or if the law changes.

Our aim is to use AI thoughtfully and responsibly, helping our team work more effectively while maintaining the creativity, expertise, strategic thinking, and personal approach that define Disruptive Thinking.


If you have any questions about our approach to AI, please contact: HQ@hellodisruptive.com