Data handling
You are asking us to hold information about your organisation and, often, about identifiable people. Here is exactly how that is handled, and what we will not do with it.
Commitments
| Area | Commitment |
|---|---|
| Data residency | All client data stored in the UK or EU. No transfer outside without your written instruction. |
| Regulator | Registered with the Information Commissioner’s Office as a data controller. |
| Separation | Row-level isolation per client. Your matter is not visible from any other client’s workspace. |
| Encryption | Encrypted in transit and at rest. Sensitive fields encrypted at column level. |
| Access | Named accounts with multi-factor authentication. No shared logins. |
| Audit | Append-only log of every access, change and disclosure. Producible on request. |
| Retention | A retention period is set on every record at the point of collection and enforced automatically. |
| Delivery | Reports delivered encrypted. No client data sent over unprotected email. |
| Insurance | Professional indemnity and public liability cover in force. |
How we use AI, and what it never sees
Our platform uses AI agents for collection, corroboration checking, drafting and adversarial review. This matters for your data, so we are specific about it.
We use commercial API services under enterprise terms, which means your data is not used to train anyone’s models and is not retained by the provider beyond the request. We do not paste client material into consumer AI tools — not into ChatGPT, not into any free chatbot — because those terms do not offer the same protection.
No AI system decides anything about you or your counterparties. Agents propose; an accredited human assessor decides, and signs. Nothing is issued without that signature.
Lawful basis and proportionality
Before any collection begins on an instruction, we record the lawful basis for processing, the categories of data in scope, a proportionality assessment, and a retention period. This is done at the point of instruction, not reconstructed afterwards.
If a subject exercises their rights — a subject access request, an objection, an erasure request — we can answer it, because the provenance chain and audit log make it answerable. That protects you as much as it protects them.
No pretexting or impersonation. No obtaining personal data by deception. No accessing accounts, devices or systems. No purchasing data from sources that cannot demonstrate lawful provenance. No surveillance, tracking or intrusion into private life. No work on a subject where we hold a conflict.
If your requirement cannot be met lawfully, we will tell you so and decline. An unlawfully obtained finding exposes you to more risk than not having it.
Independence
CM Intel is a private company. It holds no access to police, government, military or classified systems, and does not seek any. It is not acting for, endorsed by, or connected to any public authority.
Our principal’s professional background is in counter-terrorism intelligence assessment, and that experience is why the methodology is what it is. It confers no data access, and any material derived from that employment is strictly excluded from this business. Every instruction is screened for conflict before it is accepted, and declined where one exists.
Privacy notice, record of processing activities, data protection impact assessment, retention schedule, breach procedure, insurance certificate, and a standard data processing agreement. Procurement teams tend to ask for these; we have them ready rather than assembling them under pressure.