Back

AI Policy

AuditOwl · Last updated 10 August 2026

Version v1.0 · Effective 10 August 2026

This policy explains how AuditOwl uses artificial intelligence: where it is applied, what we hold ourselves to, what we deliberately do not do, and what you should check before acting on anything it produces. AuditOwl is a decision-support tool. Its output is not professional advice — financial, investment, legal or otherwise — and the decision to act on it is always yours.

1. Scope

This policy covers every AI-assisted feature of AuditOwl, in both the subscription platform used by agencies and the one-time audit report bought without an account. It sits alongside our Privacy Policy, Terms of Service and sub-processor list, and does not replace them.

2. Legal basis

We have written this policy against:

  • Regulation (EU) 2024/1689 (the EU AI Act) — in particular the transparency obligations applicable from 2 August 2026. The Act reaches providers established outside the EU where the output of their system is used in the EU, which includes us.
  • the UK GDPR and PECR, and the EU GDPR where we offer services to people in the EU, for everything involving personal data.
  • Our Data Processing Agreement, where an agency uses AuditOwl to process its own clients' data.

We are established in England and Wales, which has no direct equivalent of the AI Act. We apply its standards because we sell into the EU, not because a domestic rule compels us to.

3. Where AI is used

AuditOwl uses Google's Gemini as its language model. We do not operate a closed, curated knowledge base: we send a structured prompt, built from the answers you provide together with our own audit framework, to a general-purpose model. The model has no access to your account, your other clients, or anything you have not submitted for that specific request.

On the platform (agencies)

  • scoring the opportunities identified in an audit,
  • refining the business case (cost and tooling assumptions),
  • generating candidate solutions for a problem you select,
  • drafting the narrative of the client report,
  • scoring leads to help you prioritise follow-up.

Every one of these is started by you, by hand, and every result is editable before it reaches anyone. If no AI key is configured the platform falls back to deterministic algorithms instead, and each result records which of the two produced it.

In the one-time audit report

The report is generated end-to-end by AI — the diagnosis, every proposed solution and the accompanying narrative — once you submit the questionnaire. There is no deterministic fallback in this path: if the model cannot produce a complete report, the report is not delivered rather than being quietly replaced by algorithmic output. You do not trigger anything by hand, which is why this page, and the note printed on the report itself, are how you are told.

4. The standards we hold ourselves to

  • Transparency. Output generated with AI assistance is marked as such on the report itself, both on screen and in the PDF.
  • A human decides. Nothing is sent, published or acted on automatically. On the platform the agency reviews and edits every word before its client sees it.
  • We do not train models on your data. Neither your content nor your clients' content is used to train or fine-tune any model, by us or on our behalf.
  • Data minimisation. Prompts carry the audit content you submit — answers, pain points, financial inputs. They do not carry contact e-mail addresses or contact-person names. Where you can describe a situation without naming a person, please do.
  • Purpose limitation. What you enter is processed to produce your result, not to build a profile of you or of anyone described in it.
  • Dignity and non-discrimination. The system is instructed not to produce content that demeans or discriminates on grounds of sex, religion, origin, disability, sexual orientation, or personal and financial circumstances.
  • Plain language. Output is written to be understood by the person who has to act on it, not to sound impressive.
  • Security. Traffic is encrypted in transit (TLS), and access to the systems holding your content is restricted and logged.
  • Location. Our database sits in the EEA. Our model, payment and e-mail providers are in the United States — they are named on the sub-processor page, and those transfers rely on the UK Extension to the EU-US Data Privacy Framework and/or the UK International Data Transfer Agreement or Addendum. We say this plainly rather than claim that everything stays in one region, because it does not.
  • Oversight. We monitor generation failures and output quality, and adjust prompts and safeguards when a pattern of poor or implausible output appears.

5. What we do not do

AuditOwl does not, and is not designed to:

  • make automated decisions producing legal effects, or similarly significant effects, for any individual;
  • profile individuals, or infer anything about a person's private life;
  • process biometric data, recognise faces, or infer emotions;
  • assign social scores;
  • assess anyone's creditworthiness or eligibility for a service or benefit;
  • screen job applicants or make employment decisions;
  • operate in a safety-critical setting.

6. Risk classification

Under the EU AI Act's risk framework we classify AuditOwl as limited risk. It supports business decisions and produces documents; it falls into none of the high-risk uses listed in Annex III of the Act, and engages no prohibited practice. What limited risk asks of us is transparency — that you know you are reading AI-generated content — which is what section 4 and the note on each report deliver.

Lead scoring, specifically. The platform can score a prospect to help an agency decide who to contact first. We class this as limited risk too, and the distinction matters: the subject is a business being ranked for sales prioritisation, not a person being assessed for credit, employment, insurance, or access to an essential public or private service — the situations Annex III is concerned with. No outcome for any individual follows from the score, and a human decides what to do with it.

7. Accuracy, estimates and what they are not

Language models can be confidently wrong. They can state something plausible that is untrue, and they do not know what they do not know. We reduce this with structured prompts, validation of results in code and deterministic checks, but we cannot eliminate it.

Every figure in a report is an estimate. Savings, revenue uplift, return on investment, cost of inaction and any projection are derived from the answers you gave — your own volumes, rates and costs — combined with our assumptions. They are not a forecast, a guarantee, a valuation or a promise of a result, and we make no representation that they will be achieved.

Before acting on a report, check that the inputs describe your business correctly and that the conclusions hold against what you already know. If you are an agency, that check is your responsibility before the report reaches your client — see section 1 of the Terms.

8. Reporting an AI incident

An AI incident is anything that breaches this policy: output that is harmful, discriminatory or seriously misleading; a suspected exposure of data through an AI feature; or any use of the system you consider unsafe or unfair. If you see one, tell us at supportauditai@gmail.com.

On receiving a report we:

  1. identify — record what happened, which feature was involved and what kind of data;
  2. contain — suspend the affected feature where needed, and preserve the content in question rather than deleting it;
  3. remediate — correct or withdraw the output, and fix the cause;
  4. notify — where personal data is involved, notify the Information Commissioner's Office (ICO) in the United Kingdom and the people affected within the time the law requires, and tell the reporter the outcome.

9. Talking to a person

There is always a way out of the machine. Questions about this policy, about how a particular result was produced, or a request for a human to look at something: write to supportauditai@gmail.com and a person will answer.

10. Changes

We will update this policy as the product and the law develop. The version and effective date at the top change with it, and material changes are announced on this page. This policy is issued by InsuGreen Ltd, whose details are below.

InsuGreen Ltd (trading as AdaptifyAI)

59 Debdale Way, Mansfield Woodhouse, Mansfield NG19 7NR, England

Company number: 14166331 · Registered in England and Wales