Skip to Responsible AI Policy
Legal information

Responsible AI Policy

This Policy explains how DataConsultant approaches the responsible selection, development, configuration, testing, deployment and use of artificial intelligence in our website activities, internal operations and data consulting services.

1. Introduction

This Responsible AI Policy (the “Policy”) describes how DataConsultant (“DataConsultant”, “we”, “us” or “our”) approaches artificial intelligence, machine learning, generative AI, predictive analytics, automated workflows and related technologies.

AI can support analysis, automation, reporting, research and business decision-making. It can also produce inaccurate, incomplete, biased, outdated, misleading or unsuitable results. We therefore seek to use AI with appropriate human oversight, risk assessment, transparency, data controls and professional judgement.

Important: This Policy does not guarantee that an AI system, output or process will be accurate, unbiased, secure, uninterrupted, lawful in every jurisdiction or suitable for every purpose.

2. Purpose of This Policy

This Policy is intended to:

  • promote lawful, fair and responsible AI use;
  • reduce foreseeable risks to individuals, organisations and data;
  • support appropriate human review and accountability;
  • protect confidential, personal and proprietary information;
  • explain the limitations of AI-generated and AI-assisted outputs;
  • encourage transparent communication about material AI involvement;
  • establish restrictions on harmful or inappropriate AI uses; and
  • provide a process for raising AI-related concerns.

3. Scope and Application

This Policy applies to AI-related activities connected with:

  • the DataConsultant website, online forms and digital properties;
  • client projects, consulting engagements and managed services;
  • data analytics, business intelligence and data strategy services;
  • machine learning, predictive modelling and automation support;
  • generative AI, AI-assisted content and coding tools;
  • automated reporting, classification and recommendation systems;
  • internal productivity, research and administrative processes;
  • client portals, dashboards and collaborative environments;
  • third-party AI platforms, APIs, cloud tools and integrations; and
  • proof-of-concept, pilot, testing, training and advisory services.

It applies to our employees, consultants, contractors, managed-team members and authorised service providers. Relevant requirements may also apply to clients, prospective clients, website users, vendors and partners.

4. Website Activities and Client-Service Activities

4.1 Website activities

AI or automated systems may support website functions such as:

  • responding to routine enquiries;
  • directing visitors to relevant information;
  • analysing website performance;
  • identifying technical issues or suspicious activity;
  • filtering spam; and
  • supporting internal review of submitted information.

Automated website features may misunderstand a request and should not be treated as personalised professional advice.

4.2 Consulting and professional services

AI may be used in a client engagement only where appropriate for the agreed scope of work. Relevant factors may include:

  • the service agreement and statement of work;
  • the client’s documented instructions;
  • the type and sensitivity of the data;
  • the intended use and impact of the output;
  • applicable legal and contractual restrictions;
  • the capabilities and limitations of the technology;
  • the need for human review; and
  • the availability of suitable security controls.

5. Important Definitions

Artificial intelligence or AI means technology that processes information to generate predictions, classifications, recommendations, content, decisions or other outputs.

AI system means an application, model, tool, workflow or service that uses AI.

Automated processing means processing performed wholly or partly through software with limited or no direct human involvement at a particular stage.

Generative AI means AI that can create or transform text, images, audio, video, code, data or other content.

Client data means data, documents, files, credentials, instructions or other material supplied by or for a client.

High-impact use means an AI use that may materially affect employment, finances, healthcare, legal rights, education, housing, safety or similarly significant interests.

Human oversight means meaningful review or intervention by a person with sufficient authority and competence to assess or change an AI-supported process.

6. Our Responsible AI Principles

6.1 Lawful and authorised use

AI systems should be used only for lawful, properly authorised and documented purposes.

6.2 Human responsibility

AI does not replace human accountability. Relevant people remain responsible for objectives, review, approval, deployment and risk management.

6.3 Proportionate risk management

The level of assessment, testing, documentation and oversight should reflect the nature and potential impact of the AI use.

6.4 Transparency

Where appropriate, we seek to explain material AI involvement, important limitations, the role of human review and relevant assumptions.

6.5 Data responsibility

Data used with AI should be relevant, appropriately sourced, sufficiently accurate for the intended purpose and handled according to applicable instructions.

6.6 Fairness

Where relevant, we may consider whether an AI system could create unjustified differences in outcomes. We do not guarantee complete freedom from bias.

6.7 Reliability and fitness for purpose

An AI system should be evaluated in the context in which it will be used. Performance in one environment does not establish suitability for another.

6.8 Security and resilience

Reasonable security and access controls should be considered, but no AI system, network or integration can be guaranteed completely secure or continuously available.

7. Governance and Responsibilities

Responsibility for an AI project may be shared between DataConsultant, the client and third-party providers.

Depending on the engagement, our responsibilities may include:

  • advising on appropriate AI use cases;
  • documenting objectives, assumptions and limitations;
  • supporting data preparation and tool configuration;
  • conducting agreed testing;
  • identifying material risks known to us;
  • supporting human-review processes; and
  • reporting identified incidents or material performance concerns.

Unless expressly agreed otherwise, clients remain responsible for:

  • deciding whether to adopt or deploy an AI system;
  • confirming that the intended use is lawful;
  • providing authorised and suitable data;
  • identifying sector-specific obligations;
  • obtaining required notices, permissions or consents;
  • reviewing outputs before relying on them;
  • approving consequential decisions;
  • providing qualified human oversight; and
  • monitoring the system after deployment.

8. Risk Assessment

Before materially using or deploying an AI system, relevant parties should consider:

  • the purpose and intended users;
  • the persons or organisations affected;
  • data sensitivity and quality;
  • the consequences of an error;
  • the level of automation and human review;
  • explainability and documentation;
  • bias, discrimination and accessibility risks;
  • information-security and privacy risks;
  • intellectual-property concerns;
  • third-party terms and cross-border processing;
  • misuse scenarios; and
  • the ability to stop, correct or reverse the process.

9. Human Oversight

Where appropriate, reviewers should:

  • understand the intended purpose of the AI system;
  • know that AI is being used;
  • receive enough information to evaluate the output;
  • be able to question, reject or modify the output;
  • consider information outside the AI system;
  • identify obvious errors or inconsistencies;
  • escalate concerns; and
  • stop or limit use where material risks arise.

AI-generated recommendations should not automatically be treated as verified facts or final professional conclusions.

10. High-Impact and Sensitive Uses

Additional care may be required where AI is connected with:

  • employment, recruitment or worker monitoring;
  • credit, lending, insurance or financial eligibility;
  • healthcare or medical decisions;
  • legal rights or legal services;
  • education admissions or assessment;
  • housing or access to essential services;
  • biometric identification;
  • fraud or risk scoring;
  • surveillance or location tracking;
  • safety-critical systems; or
  • vulnerable individuals.

We may require additional review, safeguards, documentation, specialist advice or contractual terms, and may decline work where risks cannot be reasonably managed.

11. Client Data and Confidential Information

Client data used in an AI project will be handled according to:

  • the applicable service agreement;
  • the agreed project scope;
  • documented client instructions;
  • confidentiality obligations;
  • applicable data-processing terms; and
  • relevant legal obligations.

Clients should not provide personal, confidential, regulated or proprietary data unless they are authorised to do so and appropriate arrangements have been agreed.

Passwords, private keys, payment authentication information and unnecessary personal data should not be placed in AI prompts, general support tickets or unapproved collaboration tools.

12. Use of Data for AI Development or Improvement

We will not intentionally use identifiable client confidential information to train a general-purpose AI model for unrelated purposes unless that use has been clearly authorised through an applicable agreement or instruction.

Where project data is used to develop, configure, test or improve a client-specific model or workflow, permitted purposes, retention, ownership and access rights should be addressed in the relevant agreement.

13. Data Quality and Suitability

AI performance may be affected by:

  • missing or inaccurate records;
  • inconsistent definitions;
  • outdated values;
  • sampling problems;
  • duplicates or incorrect labels;
  • unrepresentative data;
  • historical bias;
  • incomplete context; and
  • data collected for a different purpose.

We may identify data-quality concerns, but we do not guarantee that every error, bias, inconsistency or omission will be detected.

14. Accuracy and Output Limitations

AI-generated and AI-assisted outputs may:

  • contain factual errors;
  • misinterpret instructions;
  • omit relevant information;
  • produce invented information or references;
  • rely on outdated knowledge;
  • provide inconsistent results;
  • reflect bias;
  • produce insecure or unsuitable code;
  • raise intellectual-property concerns; or
  • appear confident even when incorrect.

Important outputs should be independently reviewed before use in business, legal, financial, technical, employment, healthcare, security or compliance decisions.

15. Testing, Validation and Monitoring

Where included in the agreed scope, testing may address:

  • relevance, accuracy and consistency;
  • robustness and error rates;
  • data leakage and inappropriate content;
  • performance across selected user groups;
  • security weaknesses;
  • reliability under expected conditions; and
  • alignment with stated business objectives.

Testing reduces risk but cannot establish that a system will perform correctly in every future situation. Clients should maintain appropriate post-deployment monitoring.

16. Explainability and Documentation

Where appropriate, project documentation may address:

  • the intended purpose;
  • material input data and assumptions;
  • known limitations;
  • the role of human review;
  • testing performed;
  • dependencies and authorised users;
  • prohibited uses;
  • monitoring arrangements; and
  • change-management responsibilities.

The level of explanation available depends on the technology, model, provider and project scope. Not every output can be fully explained at an individual decision level.

17. Fairness, Bias and Non-Discrimination

Where fairness risks are relevant, possible measures may include:

  • reviewing whether data is reasonably representative;
  • examining variables that may act as indirect proxies;
  • comparing selected performance measures across relevant groups;
  • documenting known data gaps;
  • involving subject-matter reviewers;
  • limiting unsupported conclusions; and
  • providing a process for raising concerns.

Fairness is context-dependent. Clients should obtain legal, ethical or specialist advice where AI may affect protected rights or vulnerable individuals.

18. Privacy and Personal Information

AI processing involving personal information may also be governed by our Privacy Policy, client agreements and any applicable data-processing agreement.

Relevant considerations may include:

  • necessity and purpose limitation;
  • the source of the information;
  • required notices, permissions or consents;
  • data minimisation;
  • access controls;
  • retention and deletion;
  • international processing;
  • automated decision-making;
  • individual rights; and
  • the use of service providers.

19. Intellectual Property and AI-Generated Content

Depending on the tool and circumstances:

  • an output may resemble existing material;
  • a provider may retain certain rights;
  • similar output may be generated for another user;
  • legal protection may be uncertain;
  • training data may include third-party material; and
  • licence obligations may apply.

Clients should not assume that AI output is unique, legally protectable or free from third-party rights. Ownership and permitted use should be addressed in the applicable agreement.

20. Third-Party AI Tools and Service Providers

We may use or recommend third-party AI tools, cloud platforms, APIs, software libraries, data providers and technology services.

Third parties may:

  • operate in different countries;
  • apply their own terms and privacy practices;
  • change models, features or pricing;
  • set usage restrictions;
  • process or retain prompts and outputs;
  • experience outages; or
  • discontinue services.

Use of a third-party tool does not mean that we endorse every feature, output or practice of that provider.

21. Generative AI Use

Generative AI may assist with drafting, summarisation, coding, research organisation, classification, data transformation, translation assistance and preliminary analysis.

Appropriate review should consider:

  • factual accuracy and source reliability;
  • confidentiality and personal information;
  • intellectual-property rights;
  • misleading content and bias;
  • security weaknesses;
  • fabricated references; and
  • whether disclosure of AI involvement is appropriate.

22. AI-Assisted Code and Technical Outputs

AI-assisted code, queries, formulas, configurations and technical instructions may contain defects or security weaknesses.

Before production use, appropriate review may include code review, testing, dependency checking, access-control review, credential scanning, licensing review, vulnerability assessment and controlled deployment.

23. Prohibited and Restricted AI Uses

You must not use our website, systems, services, personnel or deliverables to develop, deploy or support AI intended to:

  • facilitate unlawful activity;
  • deceive, defraud or impersonate another person;
  • create fraudulent records, evidence, credentials or reviews;
  • produce non-consensual intimate content;
  • exploit or endanger children;
  • conduct unlawful surveillance, stalking, harassment or doxxing;
  • spread malware or compromise systems;
  • bypass security or access controls;
  • unlawfully discriminate;
  • make prohibited high-impact decisions without required safeguards;
  • manipulate vulnerable persons;
  • create materially misleading deepfakes;
  • infringe intellectual-property or confidentiality rights;
  • unlawfully process personal or biometric information;
  • extract confidential data, system prompts or model parameters without authorisation;
  • cause unlawful physical harm; or
  • evade applicable restrictions or provider rules.

Restriction: This list is illustrative. We may decline or stop other activities that create material legal, security, safety, privacy, rights or reputational risks.

24. Client Responsibilities

Clients should:

  • provide accurate and complete project information;
  • identify sensitive or regulated use cases;
  • confirm that supplied data has been lawfully obtained;
  • define the intended users and purpose;
  • appoint authorised decision-makers;
  • review outputs and deliverables;
  • obtain required legal, compliance and professional advice;
  • maintain security over accounts and credentials;
  • monitor deployed systems; and
  • avoid using systems outside the agreed scope.

25. Personnel and Contractor Responsibilities

Persons working for or on behalf of DataConsultant should:

  • use approved AI tools where required;
  • follow client instructions and project restrictions;
  • avoid entering confidential information into unauthorised systems;
  • review AI-assisted work before delivery;
  • disclose material AI use where required;
  • report suspected errors, bias, leakage or misuse;
  • maintain appropriate documentation; and
  • follow confidentiality, security and data-handling requirements.

26. Security and Misuse Risks

AI systems may introduce risks such as unauthorised disclosure, prompt injection, insecure integrations, model manipulation, malicious inputs, exposed credentials, excessive permissions and harmful automated actions.

Reasonable measures may be used to reduce these risks, but complete security cannot be guaranteed. Responsibilities may be divided between DataConsultant, the client and technology providers.

27. Incident Reporting and Response

An AI-related incident may include:

  • unauthorised disclosure of information;
  • serious or repeated inaccurate outputs;
  • unexpected discriminatory outcomes;
  • harmful automated actions;
  • security compromise;
  • intellectual-property concerns;
  • use outside the agreed scope; or
  • unauthorised model or configuration changes.

Possible responses include restricting access, pausing processing, preserving records, investigating causes, correcting configurations, reviewing affected outputs, changing controls or replacing a tool.

28. Reporting Concerns

AI-related concerns may be reported to support@dataconsultant.in.

Where relevant, include:

  • your name and organisation;
  • the project, service or system involved;
  • a factual description of the concern;
  • when the issue occurred;
  • the persons or processes affected;
  • supporting examples; and
  • any immediate safety or security concern.

Do not send passwords, private keys, authentication codes or unrelated sensitive information.

29. Investigation and Corrective Action

Subject to applicable agreements and obligations, we may:

  • review relevant project records and system logs;
  • request information from authorised users;
  • consult technical or professional advisers;
  • restrict access or pause work;
  • remove or isolate affected data;
  • require corrective measures;
  • change or discontinue a tool; or
  • notify an affected client or provider.

30. Suspension, Restriction or Termination

We may restrict, suspend or terminate access to AI-related services where reasonably necessary to address unlawful activity, serious misuse, unauthorised data processing, security threats, contractual breaches, rights infringement, provider restrictions or risks that cannot be reasonably controlled.

Payment, refunds, data return, transition support and continuing obligations will be governed by the applicable agreement and relevant policies.

31. International and Cross-Border Activities

We may work with clients, personnel, technology providers and systems in more than one country. AI, cloud and data-processing activities may involve international access, hosting, support or transfer.

Clients should identify localisation, sector, transfer or regulatory restrictions before work begins and obtain independent legal advice where cross-border requirements are material.

32. Training and Awareness

Where appropriate to their roles, personnel involved in AI work should understand the system’s intended use, data restrictions, confidentiality requirements, output limitations, human-review duties, escalation procedures, security risks and prohibited uses.

33. Exceptions

An exception may be considered where there is a legitimate purpose, the activity is lawful, risks are understood, suitable controls are established and relevant approvals are obtained.

An exception does not remove contractual, confidentiality, privacy, security or legal obligations. We may refuse an exception where risk is considered unacceptable.

34. No Professional or Legal Advice

AI-generated outputs and general website information should not automatically be treated as legal, financial, medical, regulatory, tax or other licensed professional advice.

Where professional judgement is required, you should consult a suitably qualified adviser.

35. Relationship with Contracts and Other Policies

This Policy should be read with any applicable:

  • service agreement, proposal or statement of work;
  • confidentiality agreement;
  • data-processing agreement;
  • Privacy Policy;
  • Information Security Policy;
  • Acceptable Use Policy;
  • intellectual-property terms;
  • third-party provider terms; and
  • project-specific instructions.

Where a signed agreement contains more specific terms, that agreement will generally take precedence for the subject matter it covers.

36. Policy Limitations

This Policy does not address every AI technology, project, jurisdiction or risk. Nothing in it should be interpreted as a promise of:

  • perfect accuracy or complete fairness;
  • uninterrupted availability;
  • complete security;
  • guaranteed legal compliance;
  • guaranteed business outcomes;
  • error-free automation; or
  • suitability for every use.

37. Changes to This Policy

We may update this Policy periodically to reflect changes in our services, AI technology, business practices, identified risks, provider practices, contracts or applicable obligations.

The latest version will be published at https://dataconsultant.in/legal/responsible-ai-policy/ with an updated “Last Updated” date.

38. Frequently Asked Questions

1. Does DataConsultant use AI in every project?

No. AI use depends on the project scope, client requirements, data sensitivity and intended outcome. Some projects may use conventional analytics or manual professional review.

2. Will clients be told when AI is used?

Where AI use is material to the service, output, risk or client decision, we seek to communicate its role appropriately. Specific disclosure may also be addressed in the project agreement.

3. Can AI outputs be used without human review?

Important outputs should receive suitable human review. AI can produce incomplete, biased or incorrect information, and the review level should reflect the potential consequences of an error.

4. Can clients provide confidential data for an AI project?

Confidential data should be provided only where necessary, authorised and covered by suitable contractual and technical arrangements. Sensitive information should not be entered into unapproved tools.

5. Is client data used to train public AI models?

We do not intentionally use identifiable client confidential information to train general-purpose AI models for unrelated purposes unless that use has been clearly authorised.

6. Who owns AI-generated project deliverables?

Ownership depends on the applicable agreement, the provider’s terms, the nature of the output and relevant intellectual-property considerations.

7. Does DataConsultant guarantee that AI outputs are unbiased?

No. Reasonable measures may be used to assess identified risks, but complete freedom from bias cannot be guaranteed.

8. Can DataConsultant support AI used for important decisions?

Potentially, but such projects may require additional safeguards, documentation, specialist advice and human oversight. We may decline work where risks cannot be reasonably managed.

9. What happens if a third-party AI provider changes its service?

Third-party providers may change features, models, prices, terms or availability. We may assess alternatives where included in scope, but cannot control a provider’s decisions.

10. Do signed client contracts take precedence?

A signed agreement, statement of work, confidentiality agreement or data-processing agreement may contain more specific terms and will generally take precedence for the subject matter it covers.

11. How can an AI-related concern be reported?

Send a factual description to support@dataconsultant.in, including the relevant project, dates, examples and potential impact. Do not send passwords or unnecessary sensitive data.

12. How will users know when this Policy changes?

The latest version will be published on our website with a revised “Last Updated” date. Material changes may also be communicated directly where appropriate.

39. Contact Information

Questions, concerns and reports relating to this Policy may be sent to:

Business name: DataConsultant

Legal business name: Rudrriv Solutions Pvt. Ltd

Website: https://dataconsultant.in

General contact: support@dataconsultant.in

Privacy contact: support@dataconsultant.in

Business address: India

Country or jurisdiction: India