Skip to content
Longbow

Legal

AI Policy

This AI Policy explains how Longbow Works Limited (“we”, “us”, “our”) uses artificial intelligence in our own work and in what we deliver, and what that means for you. It should be read alongside our Privacy Policy and our Terms of Service.

Scope

This policy applies to:

  • Our use of AI tools in designing, building, and supporting client projects.
  • AI capability that may form part of what we deliver.
  • AI tools we use to run our own business, including drafting, research, and support.
  • Visitors to our websites who interact with any AI-assisted feature.

It does not apply to third-party services you use independently of us, even where we have integrated with them. Those services are governed by their own terms and policies.

Our Principles

Four commitments govern every use of AI described here:

  1. A person remains accountable. AI assists our work; it does not sign it off. Every deliverable is reviewed by a person before it reaches you or your visitors.
  2. Proportionality. We use AI where it removes tedious work, not as a substitute for judgement, craft, or a conversation.
  3. Transparency. We will tell you where AI is materially involved in what we deliver, and we do not present generated output as human-authored where the distinction matters.
  4. Your data stays yours. We do not treat client material as raw supply for model training. See Training on Your Data below.

How We Use AI in Our Work

We may use AI-assisted tools for:

  • Code assistance: generating, reviewing, refactoring, and testing code, always subject to human review before release.
  • Drafting and editing: first drafts of copy, documentation, proposals, and technical writing.
  • Research and summarisation: condensing documentation, standards, and reference material.
  • Design exploration: generating layout or visual options as a starting point for human design work.
  • Support and triage: classifying and summarising incoming requests so they reach the right person faster.

AI output is treated as a draft in every one of these cases. Nothing is shipped, published, or sent on the strength of a model's output alone.

AI in What We Deliver

Where AI capability forms part of what we build, we take a considered approach to how it is designed, deployed, and disclosed to those it affects.

  • We aim to give AI-assisted features sensible safeguards, with a way to fall back to non-AI operation where practical.
  • We aim to be clear, where it matters, about the role AI played in producing something.
  • We take the providers behind any AI capability into account as part of our due diligence before it goes live.

We do not build features that make automated decisions with legal or similarly significant effects on individuals without explicit written agreement, a documented lawful basis, and a route for a person to intervene.

Human Oversight and Accountability

Responsibility for our work does not transfer to a tool. Where AI has contributed to a deliverable, the same named people remain accountable for it as if it had been produced by hand, and our obligations to you under our Terms of Service are unchanged.

Where AI-assisted content is published under your name, editorial responsibility for what you publish rests with you, and your own review step is the control that matters.

Personal Data and AI

We minimise personal data in AI workflows. Specifically:

  • We avoid entering personal data into AI tools where the task does not require it, and we redact or substitute identifiers where it does not change the outcome.
  • We do not enter special category data, credentials, payment details, or client secrets into general-purpose AI tools.
  • Where AI capability we deliver processes personal data, that processing is covered by the same data protection terms as the rest of our engagement.

The legal bases, retention periods, and rights described in our Privacy Policy apply to personal data processed in connection with AI in the same way they apply to everything else we process.

Training on Your Data

We do not license, sell, or contribute client content, client data, or project material to third parties for the purpose of training their models.

When selecting AI tools for work that touches client material, we prefer configurations and plans under which submitted content is not retained for provider model training. Where a tool cannot meet that condition, we do not use it for that material.

Third-Party AI Providers

AI features rely on third-party providers, which act as processors or sub-processors depending on the arrangement. Before we introduce one into your project we consider its data handling and retention terms, its security posture, where processing takes place, its stability and support, and its published limitations.

Providers change their terms. Where a change materially affects how your data is handled, we will tell you and, if necessary, propose an alternative.

Accuracy and Limitations

AI systems can produce output that is fluent and wrong. They can invent citations, misstate facts, reproduce bias present in their training data, and fail in ways that are not obvious on a quick read.

We therefore treat AI output as unverified until a person checks it. We do not rely on AI for legal, financial, medical, or regulatory advice, and nothing generated by an AI feature we build should be relied on as professional advice.

Intellectual Property

Ownership of the work we deliver is governed by our Terms of Service and is not altered by our use of AI tools in producing it.

We take reasonable care that delivered work does not infringe third-party rights, including reviewing AI-assisted output for material reproduction of existing works. The legal position on AI-generated material is still developing in the UK and elsewhere, and we will tell you where that uncertainty is relevant to something we are delivering.

Security

AI tools are covered by the same technical and organisational measures as the rest of our operations: access controls, least-privilege access, credential hygiene, and vendor due diligence. API keys for AI providers are held in managed secret storage and are never committed to source control or embedded in client-side code.

Your Choices and Rights

You may ask us to:

  • Restrict or exclude the use of AI tools on your project.
  • Tell you more about how AI is used in what we deliver to you.
  • Disable AI capability where we have delivered it.
  • Exercise any of the data protection rights set out in our Privacy Policy in relation to AI-assisted processing.

A request to restrict AI use may affect timescales or cost, and we will say so clearly before proceeding rather than afterwards.

Reporting a Concern

If you believe AI use in our work has produced harmful, inaccurate, or unlawful output, or that AI has been used in a way inconsistent with this policy, contact us at hello@longbowworks.co.uk. We will investigate, tell you what we find, and correct what needs correcting.

Changes to This Policy

AI practice and regulation are both moving quickly, and we expect to revise this policy more often than our others. The “Last updated” date reflects the latest revision. Where a change materially affects a live engagement, we will raise it with you directly rather than relying on this page.

Contact

If you have questions about this policy or how we use AI, contact:

Longbow Works Limited
Email: hello@longbowworks.co.uk
Data protection queries: hello@longbowworks.co.uk