Home / AI & Data Protection Statement
Our commitment

AI & Data Protection Statement

How we protect your information when artificial intelligence is part of the process — and how we keep it protected against breach at every stage. Plain answers, no small print.

Our position in one paragraph

Stor-a-File uses next-generation AI to read and structure documents because it is materially more accurate than the legacy tools it replaces. We deploy it the same way we have handled sensitive records since 1977: your data is minimised before processing, encrypted throughout, never used to train AI models, retained only as long as instructed, and every engagement is governed by UK GDPR with documented evidence — not promises.

1. What the AI sees — and what it never sees

Where required, personal identifiers (names, NHS numbers, addresses, dates of birth) are detected and replaced with pseudonymous tokens inside our ISO 27001-accredited UK facilities before any content reaches an AI engine. The mapping between tokens and identities is held in an encrypted vault that never leaves our environment. The AI reads content; it does not receive identity.

2. No training on your data — contractually

Our AI providers operate under written data-processing agreements as sub-processors. Those agreements prohibit the use of your content to train AI models and impose strict retention controls, including zero-retention processing where your governance requires it. We review provider security documentation annually and retain the right to audit.

3. Protection against breach

Defence in depth, physical and digital:

Encryption in transit (TLS) and at rest for all digital material. Isolated, uniquely-referenced batch processing — no interactive AI surfaces, no ad-hoc uploads. Access on least-privilege terms, restricted to named, DBS-checked staff, with logging and periodic access reviews. Physical records held in monitored, fire-protected, access-controlled facilities operated under ISO 27001. Chain of custody from collection to destruction, with a certificate for every destruction job.

4. If something goes wrong

Any suspected security event halts the affected batch immediately. Our information-governance lead is notified the same day, affected clients are informed in line with their data-processing agreement, and ICO notification is assessed against the 72-hour statutory duty. Where an AI provider is involved, deletion is requested and evidenced in writing. We rehearse this process — we do not improvise it.

5. Governance, evidenced

A data-protection impact assessment for every AI engagement. Documented lawful basis flowing from the controller. Records of processing. International-transfer safeguards (IDTA / SCCs with UK Addendum) where inference occurs outside the UK. Support for subject-access requests over processed data. Human review of anything the AI is uncertain about — and humans, never AI, make retention and destruction decisions.

6. Questions

Your information-governance team is welcome to test all of this. Call us on 0800 281857 or request our AI processing documentation — including our sample DPIA and secure processing workflow.

This statement summarises our operational controls and is reviewed regularly. It does not replace the contractual terms of individual engagements. Last reviewed: July 2026.