Skip to content

Trust and compliance

Where your data goes, stated plainly.

Selling data sovereignty from a site that cannot say where its own data is processed would be a claim rather than a practice. So this page exists, and it is the one a compliance officer should read first.

Data processing

What the audit collects
A domain, and whatever that domain publishes publicly. The audit reads public web pages and puts questions to commercial AI engines. It does not require access to your systems, your analytics, or any customer data.
Where it is processed
Orchestration, storage and every saved audit run on our own server, not on a third-party analytics or processing platform. The AI engines themselves are operated by their providers under their own terms, which is inherent to measuring what those engines say: you cannot find out what ChatGPT answers without asking ChatGPT. [TBC: state the hosting region once confirmed. UK and EU are separate jurisdictions and a compliance reader will notice which one is claimed.]
Which third parties the audit uses
Four, all US-based, and named rather than implied. Firecrawl fetches public pages. OpenRouter routes model calls. Google's Generative Language API is queried directly for AI Overviews. The answers come from OpenAI, Google, Anthropic and Perplexity models. Nothing else is involved, and no analytics, advertising or tracking service touches any of it.
What actually leaves the UK
A domain name, text those pages already publish to the open web, and questions we wrote. No personal data, no customer records, no credentials, and nothing that is not already public. That matters legally: a transfer of published business information is a different question from a transfer of personal data, and the audit deliberately never needs the second.
If that is still not acceptable

Then this is exactly the constraint the self-hosted work exists to remove, and it is a reasonable position rather than an awkward one. An audit has to query the public engines to measure them. An assistant over your own documents does not, and can run entirely inside your estate. If a US transfer of even public data is off the table, say so early and the architecture is built to that from the start.

What is retained

Completed audits are stored against the domain and the date, so a repeat request can be served without re-running and re-billing. You can ask for a domain's stored audits to be deleted.

Client data in delivery work

Fixing and content engagements involve access to your systems under a written agreement, with scope, retention and deletion terms set before work starts.

Self-hosted AI engagements

Compliance-grade AI installations run on infrastructure you control, in a jurisdiction you choose. That is the point of them: your data does not leave your estate, and no third-party model provider sees it.

Sub-processors

A current list of sub-processors used in delivery is available on request, along with a data processing agreement. Both are sent before any engagement involving access to your systems, not after.

Request either at privacy@finlayson.co.uk.

The company

Finlayson is a trading name of Web Pebble Ltd, registered in England and Wales, company number 07926157. Registered office: 26 Hertingfordbury Road, Hertford, SG14 1JX.

Registered as a data controller for our own business records, and acting as a data processor on client engagements under the terms of the relevant agreement.

ICO registrationZC233949

See where you stand.

The same check the accountancy firm got, on your domain. About a minute. Costs nothing.