AI Use Policy
This policy sets out how In4ra IT Business Support governs the adoption, oversight, and responsible use of artificial intelligence tools across our services and operations.
Last updated: 28 July 2026 · Version 1.0
Looking for a summary of which AI tools we currently use?
View our AI Transparency Register1. Introduction
In4ra IT Business Support ("In4ra", "we", "us", "our") is committed to the responsible, ethical, and transparent use of artificial intelligence (AI) tools. This policy sets out the principles, governance arrangements, and controls that apply whenever AI tools are used within our business operations or in the delivery of services to clients.
This policy applies to all In4ra staff, contractors, and any third parties acting on our behalf. It should be read alongside our Privacy Policy, Information Security Policy, and Data Protection Policy.
This policy is reviewed at least annually, or sooner when significant new AI tools are adopted or when relevant regulatory guidance is updated.
2. Scope
This policy covers:
Internal use — AI tools used by In4ra staff to support business operations, including drafting documents, analysing data, generating code, and automating workflows.
Client-facing use — AI tools or AI-assisted features deployed as part of services delivered to clients, including threat detection, automated monitoring, and support tooling.
Website and digital channels — AI-powered features on in4ra.co.uk, including the In4ra AI chatbot and any future AI-assisted functionality.
This policy does not cover AI tools embedded within third-party software that In4ra procures and uses in the ordinary course of business, unless In4ra has the ability to configure or influence how those tools operate.
3. Governing Principles
All AI use at In4ra is governed by the following principles:
Transparency — We are open about where and how AI tools are used. We do not deploy AI in ways that are hidden or deceptive to clients, staff, or other stakeholders.
Human oversight — AI-assisted outputs are always reviewed by a qualified In4ra team member before being acted upon. No automated AI decision directly affects a client without human review.
Data minimisation — We do not input personal data, confidential client information, or sensitive business data into third-party AI tools unless covered by an appropriate data processing agreement and a documented lawful basis under UK GDPR.
Fairness and non-discrimination — We actively monitor AI-assisted processes for bias. We do not use AI in recruitment, performance management, or client-facing decisions without appropriate safeguards.
Security — AI tools are subject to the same security vetting as any other third-party software. Access is restricted to authorised staff on a least-privilege basis.
Accountability — A named individual within In4ra is responsible for maintaining this policy and for overseeing compliance with it.
4. Approved Uses of AI
The following uses of AI are approved under this policy, subject to the controls described in Section 6:
Documentation and drafting — AI writing assistants may be used to draft internal documents, proposals, reports, and knowledge-base articles. All outputs must be reviewed and edited by a human before use or distribution.
Code assistance — AI coding tools may be used to assist with software development, scripting, and configuration tasks. All AI-generated code must be reviewed, tested, and approved by a qualified engineer before deployment.
Cyber threat detection — AI-powered threat detection and anomaly-detection tools may be used within managed security services. Alerts must be triaged by a qualified technician before any remediation action is taken.
Support ticket management — AI-assisted categorisation and prioritisation of support tickets may be used to improve response times, subject to human review of categorisation decisions.
Website chatbot — The In4ra AI chatbot on in4ra.co.uk uses keyword-matching logic built in-house. It does not use a third-party large language model. Conversations are not stored beyond the session.
Research and analysis — AI tools may be used to assist with market research, competitive analysis, and summarisation of publicly available information, provided no confidential data is inputted.
5. Prohibited Uses of AI
The following uses of AI are prohibited without explicit written approval from In4ra management:
Processing personal or confidential client data — Inputting client personal data, financial data, or confidential business information into any third-party AI tool not covered by an appropriate data processing agreement.
Automated decision-making with legal or significant effect — Using AI to make or substantially influence decisions that have a legal or similarly significant effect on individuals (e.g. employment decisions, credit assessments, access to services) without human review and appropriate safeguards.
Impersonation or deception — Using AI to generate content that impersonates a real person, creates false impressions, or is intended to deceive.
Unapproved AI tools — Using AI tools that have not been reviewed and approved under this policy. Staff must seek approval before adopting new AI tools for business use.
Bypassing security controls — Using AI tools to circumvent In4ra's information security policies, access controls, or monitoring systems.
6. Controls and Safeguards
The following controls apply to all approved AI use:
Tool approval — Any AI tool proposed for use must be assessed against In4ra's information security and data protection requirements before adoption. A record of approved tools is maintained by the policy owner.
Data handling — Staff must not input personal data, client confidential information, or sensitive business data into AI tools unless the tool is covered by a signed data processing agreement and the use has been approved.
Output review — All AI-generated outputs (text, code, analysis, recommendations) must be reviewed by a qualified human before being used, shared, or acted upon. The reviewing individual takes responsibility for the accuracy and appropriateness of the output.
Disclosure — Where AI tools have been used to produce content delivered to a client, this should be disclosed to the client on request.
Access control — Access to AI tools used for business purposes is restricted to authorised staff. Shared or generic credentials must not be used.
Incident reporting — Any suspected misuse of AI tools, data breach arising from AI use, or AI-generated output that causes harm must be reported immediately to the policy owner and handled under In4ra's incident response procedure.
7. Data Protection and UK GDPR
The use of AI tools at In4ra must comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Lawful basis — Any processing of personal data using AI tools must have a documented lawful basis. In most cases this will be legitimate interests or performance of a contract.
Data processing agreements — Where a third-party AI tool processes personal data on our behalf, a data processing agreement must be in place before use begins.
Data minimisation — Only the minimum personal data necessary for the specific purpose should be used. Where possible, data should be anonymised or pseudonymised before being processed by AI tools.
Retention — Personal data processed by AI tools is subject to In4ra's standard data retention schedules. AI tools must not retain personal data beyond the period necessary for the stated purpose.
Subject rights — Individuals have the right to request information about how their data has been used, including in AI-assisted processes. Such requests should be directed to [email protected].
For further information on how In4ra handles personal data, please refer to our Privacy Policy.
8. Governance and Accountability
Policy owner — This policy is owned and maintained by In4ra management. The policy owner is responsible for ensuring the policy remains current, that staff are aware of their obligations, and that compliance is monitored.
Review cycle — This policy is reviewed at least annually. It will also be reviewed following any significant change in AI tool usage, a relevant data protection incident, or material updates to applicable law or regulatory guidance.
Training — Staff who use AI tools as part of their role are expected to familiarise themselves with this policy. Guidance on approved tools and safe use practices is available from the policy owner.
Compliance monitoring — The policy owner may conduct periodic reviews of AI tool usage to assess compliance with this policy. Non-compliance may result in disciplinary action.
9. Questions and Concerns
If you have any questions about this policy, wish to report a concern about AI use at In4ra, or would like to request information about how AI tools have been used in connection with your data, please contact us:
Email: [email protected] Address: In4ra IT Business Support, 86-90 Paul Street, London, EC2A 4NE
You can also view our AI Transparency Register, which provides a public summary of the AI tools currently in use at In4ra and their operational status.
Questions about this policy?
Contact us at [email protected] or visit our contact page.
