Trust and compliance

Data handling

You are asking us to hold information about your organisation and, often, about identifiable people. Here is exactly how that is handled, and what we will not do with it.

01

Commitments

AreaCommitment
Data residencyAll client data stored in the UK or EU. No transfer outside without your written instruction.
RegulatorRegistered with the Information Commissioner’s Office as a data controller.
SeparationRow-level isolation per client. Your matter is not visible from any other client’s workspace.
EncryptionEncrypted in transit and at rest. Sensitive fields encrypted at column level.
AccessNamed accounts with multi-factor authentication. No shared logins.
AuditAppend-only log of every access, change and disclosure. Producible on request.
RetentionA retention period is set on every record at the point of collection and enforced automatically.
DeliveryReports delivered encrypted. No client data sent over unprotected email.
InsuranceProfessional indemnity and public liability cover in force.
02

How we use AI, and what it never sees

Our platform uses AI agents for collection, corroboration checking, drafting and adversarial review. This matters for your data, so we are specific about it.

We use commercial API services under enterprise terms, which means your data is not used to train anyone’s models and is not retained by the provider beyond the request. We do not paste client material into consumer AI tools — not into ChatGPT, not into any free chatbot — because those terms do not offer the same protection.

No AI system decides anything about you or your counterparties. Agents propose; an accredited human assessor decides, and signs. Nothing is issued without that signature.

03

Lawful basis and proportionality

Before any collection begins on an instruction, we record the lawful basis for processing, the categories of data in scope, a proportionality assessment, and a retention period. This is done at the point of instruction, not reconstructed afterwards.

If a subject exercises their rights — a subject access request, an objection, an erasure request — we can answer it, because the provenance chain and audit log make it answerable. That protects you as much as it protects them.

What we will not do

No pretexting or impersonation. No obtaining personal data by deception. No accessing accounts, devices or systems. No purchasing data from sources that cannot demonstrate lawful provenance. No surveillance, tracking or intrusion into private life. No work on a subject where we hold a conflict.

If your requirement cannot be met lawfully, we will tell you so and decline. An unlawfully obtained finding exposes you to more risk than not having it.

04

Independence

CM Intel is a private company. It holds no access to police, government, military or classified systems, and does not seek any. It is not acting for, endorsed by, or connected to any public authority.

Our principal’s professional background is in counter-terrorism intelligence assessment, and that experience is why the methodology is what it is. It confers no data access, and any material derived from that employment is strictly excluded from this business. Every instruction is screened for conflict before it is accepted, and declined where one exists.

Documentation available on request

Privacy notice, record of processing activities, data protection impact assessment, retention schedule, breach procedure, insurance certificate, and a standard data processing agreement. Procurement teams tend to ask for these; we have them ready rather than assembling them under pressure.