AI and automation

How your data is handled in our AI workflows

NorthFirn's client-facing guide to AI data handling: what we send, what we never do, how sensitivity tiers work, who owns the keys, and how data is retained and deleted.

The least data, for the shortest time

Our starting point is to avoid holding your production data at all. When a workflow genuinely needs data, we use the smallest useful amount, send only the fields the task needs to an approved business service, and keep it only as long as the work requires.

Your accounts, your keys, your control

You own the keys

We use client-owned AI accounts and API keys wherever practical, so billing, limits, logs, and revocation stay with you.

You approve the use

Before your data reaches any AI service, the project record names the service, the data involved, the retention position, and your approval.

Data is deleted on a schedule

Temporary exports and samples are deleted within 30 days of the test or your acceptance. Nothing is kept in case it is useful later.

Some things we never do

We do not upload your data to consumer AI tools, train models on it without express approval, or reuse it for another client.