WorkNest Secure
Artificial Intelligence Notice
Updated: 05/10/2026
Introduction
This notice gives you information on how WorkNest protects your personal data in our use of Artificial Intelligence (AI) tools (software applications that incorporate AI technology).
Personal data may be contained within the documents uploaded to our AI tools. We are a data controller of your personal data when it is processed while using our AI Tools, and Microsoft, Sybill, Bedrock, Open AI and Claude are our data processors.
This notice is supplemental to our privacy notice which you can view here.
This privacy notice was last updated in September 2026.
How this notice is organised
We use AI in four broad ways. The rest of this notice is grouped to make clear which is which:
AI you interact with directly - tools you may speak or type to yourself.
AI our teams use to support your service - tools used internally by our advisers and consultants to help them work efficiently. You do not interact with these tools, and a qualified person reviews the output before it reaches you.
An AI service you purchase directly from us e.g. consultant led AI pen testing
How we use your data to tailor what we offer you - where we analyse information about you to personalise the products and services we recommend.
Important information on technology
Our services leverage Microsoft Azure's cloud platform and its suite of AI tools, to deliver robust and scalable solutions. These tools enable us to provide advanced data processing capabilities, including machine learning, natural language processing, and predictive analytics.
Data processed using Azure's AI tools may be shared with Microsoft, the provider of the platform, to facilitate the provision of services. Microsoft cannot access the data that is processed by our AI Tools. This means that your personal data is secure and can only be accessed by us. We have a signed agreement in place with Microsoft to ensure that your personal data is protected and remains in the United Kingdom. For more information please refer to Microsoft's data privacy page here.
Our services also utilise the OpenAI Assistants API to enhance user interactions through advanced artificial intelligence capabilities. Data processed through the OpenAI Assistants API may be shared with OpenAI, the provider of the API, to facilitate the generation of responses. Data sent to the OpenAI API is not used to train or improve OpenAI models.
Within Worknest Secure the following AI technology is used;
Sybill is used by the sales team to improve your service.
Bedrock is used where customers have purchased specific human led AI testing.
Claude is used for uploading data sets from events into our CRM and for general background admin work.
None of these are used for machine learning, they are segregated and secured.
Users of our AI Tools know to process personal data in accordance with UK data protection legislation, and our data protection policies. All employees receive annual training on data security, data protection and AI.
Client confidential data
We will sometimes process client confidential data when using AI Tools. Users adhere to the highest standards of confidentiality and have internal policies and training to ensure compliance. Only WorkNest and our processors who are authorised to do so, will have access to your client confidential data.
How we use AI tools
AI you interact with directly
Website AI agent (Beta)
We use an AI-powered chat agent on our website to help visitors learn more about our products and services. Conversations with the AI are logged and analysed to improve the accuracy, quality, and usefulness of our responses and to gain insights into visitor needs and interests. If you choose to provide your contact details and request to be contacted, this information will be added to our CRM system (Salesforce) and shared with an appropriate member of our sales team. You will also be added to our marketing communications lists, and you can opt out at any time. All information is handled securely and in accordance with our privacy policy. We rely on legitimate interests as our lawful basis for this processing.
AI our teams use to support your service
You do not interact with the tools in this section. They are used by our advisers and consultants to help them work efficiently, and a qualified expert reviews the output before anything is sent to you.
AI-powered assistance in WorkNest products
Our employment law advisors, HR consultants, and health and safety consultants have access to an AI-powered assistance tool integrated into CaseNest and SafetyNest systems. This tool aids in drafting responses to your enquiries, summarisation of documentation and drafting of documents. Every response is reviewed and edited by an expert in the relevant field before it is sent ensuring accuracy and reliability. This integration helps to speed up our responses, providing you with quick, high quality responses.
The AI assistance tool is powered by the OpenAI Assistants API.
We have chosen the lawful basis of legitimate interests to process your information in this way.
Case summarisation
We use AI technology to generate summaries of cases in our case management system. This enables our advisers to quickly review and respond to queries, especially when cases are reassigned or picked up by new team members. Before any data is processed by the AI, personally identifiable information is anonymised. All data is transmitted securely and monitored to protect your privacy.
The case summarisation tool processes data within WorkNest's secure Azure environment and uses the OpenAI GPT service to generate summaries via a secure API call.
We rely on legitimate interests as our lawful basis for this processing.
Email classification
We use an AI-powered system to classify incoming emails sent to our advisers, helping us prioritise and manage your queries efficiently. Email content and classification data are stored securely and are only accessible to authorised WorkNest staff. This system supports compliance, auditability, and continuous improvement through adviser feedback, and your data is always handled in line with our confidentiality policies and UK data protection law.
The email classification tool is powered by the OpenAI Assistants API.
We rely on legitimate interests as our lawful basis for this processing.
Microsoft Teams transcription and meeting summaries
When you speak with our employment law advisors in a meeting on Microsoft Teams, we may record the conversation. We will ask for your consent before we record the meeting and you are welcome to decline. If you choose to decline, this will not negatively impact your service during the call. If you give consent to record a meeting, we will use an AI tool to create a transcription and meeting summary of the call, so that WorkNest colleagues can review the content of the meeting quickly and easily in future. This helps WorkNest ensure that we have all the information we need to advise you in future.
The transcription and summary service are provided by Microsoft Teams and Microsoft Teams Premium. Microsoft cannot access the data that is processed on behalf of WorkNest.
We have chosen the lawful basis of legitimate interests to process your information in this way.
Telephone calls on our legal advisory phone line
Calls to and from our phone line are recorded as a standard part of our service, and you are made aware of this when you call. Within our legal advisory team, we use an AI tool to automatically transcribe these calls and generate a summary, so that WorkNest colleagues can review what was discussed and have the information they need to advise you in future.
We have chosen the lawful basis of legitimate interests to process your information in this way.
Email and document drafting
We use AI technology to assist our employment law advisors in preparing client emails and related documents. The AI supports advisers by analysing incoming correspondence and relevant case information to suggest draft responses and documents. These suggestions are designed to help advisers work efficiently and maintain consistency across communications. All AI-generated drafts are strictly reviewed, edited, and approved by an advisor before being sent to clients or shared externally. The advisor remains fully responsible for the accuracy, appropriateness, and quality of all final communications. All data is transmitted securely, with appropriate monitoring and safeguards in place to protect your privacy.
The drafting tool is powered by the OpenAI Assistants API.
We rely on legitimate interests as our lawful basis for this processing.
Care 4 Quality Services
We use ClickUp as our internal operational management and client relationship system. ClickUp includes an integrated AI tool, which our teams use to help them prepare and maintain the documents and reports that support your service. Specifically, we use it to:
research and update our master policy templates, so that they reflect current legislation and CQC guidance
apply those template updates to client-specific policies
support our quality assurance processes, including the preparation of mock inspection and other compliance reports
assist in drafting email correspondence with clients
All AI-generated content is reviewed, edited and approved by a suitably qualified member of our team before it is issued to you or relied upon. The reviewing consultant remains fully responsible for the accuracy, appropriateness and quality of the final document.
The AI tool is provided by ClickUp and draws on a range of third-party large language models including from Anthropic and OpenAI. Data processed through the tool is not used to train these models. All data is transmitted securely, with appropriate safeguards and monitoring in place to protect your privacy. A full list of ClickUp LLM/Gen AI Capabilities Subprocessors can be found here. Where data is transferred outside the UK, including to the United States, we rely on the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) together with a transfer risk assessment, and we put in place additional safeguards where necessary.
We rely on legitimate interests as our lawful basis for this processing.
Worknest Cyber testing (Cloud & Pen testing)
Bedrock is used for consultant led AI cloud and pen testing where a customer has specifically chosen this option. The outcome of these tests are then reviewed and translated into a user friendly report by one of our pen testing consultants.
Sales meetings, calls and emails
We use Sybill within our sales teams, which records and transcribes sales and Teams calls, reviews sales emails and calendar invites, updates our sales systems, drafts sales emails prior to being reviewed by a member of our sales team and enables sales training to ensure our customers are offered the best products and services for them. Customers are able to opt out of the use of Sybill for this. Data in Sybill is stored in the US. We rely on legitimate interests as our lawful basis for this processing.
Marketing
Claude (Commercial Tier) is used to upload new business prospect lists from events, de duplicate and update contacts within the CRM. Data within Claude is fully segregated and Anthropic legally guarantees that the inputs and outputs are isolated from training models. We rely on legitimate interests as our lawful basis for this processing.
Using AI to tailor our offering
Product recommendations
WorkNest collect client data for the purposes of delivering our service to you, but we also use it for making product recommendations. In addition to the information provided at the start of our contract, we utilise data regarding your engagement with our services - such as webinar attendance, file downloads, and case information like case types and descriptions - to create product recommendations tailored specifically for you, our client. These recommendations are generated through thorough data analysis, ensuring they are relevant and beneficial. A member of the WorkNest team reviews these recommendations to confirm their suitability.
We use these recommendations in our outbound communications, including emails, telephone calls, and on the myWorkNest platform. Your recommendations are personalised and will not be shared with other clients.
We may share recommendations with other companies in our family, Axiom GRC, so that we can offer a broader range of services to you.
We have chosen the lawful basis of legitimate interests to process client information for product recommendations.
Your data, your choice
You can opt out of your information being processed in any of the ways listed above by contacting Cyber-DPO@worknest.com.
For more information on ways we process your data or for a copy of our internal AI policy, please contact our Data Protection Officer at Cyber-DPO@worknest.com.
Or you can write to:
Cyber Data Protection Officer & Information Security Officer, WorkNest, Woodhouse, Church Lane, Aldford, Chester CH3 6JD
Concerns or complaints
If you have any concerns with how WorkNest processes your data, please contact Cyber-DPO@worknest.com or refer to our Data Protection Complaints Policy.
Definitions
Anonymise: to change data so that it cannot be linked to an individual person.
Cookie: a small file of information – like a username or password – that are stored on your device and identify the user. Cookies are used to work out what to show you, improving your web experience.
Consent: permission, usually only valid when you have been told exactly what you are consenting to. One of the ways that processing data can be justified under data protection law.
Contractual performance: the data processing needed to carry out an agreement with an individual. One of the ways that processing data can be justified under data protection law.
Data Controller: an organisation (or person) that makes decisions about how and why data is processed.
Data minimisation: collecting the smallest amount of personal data that you need.
Data Processor(s): an organisation (or a person) that carries out the instructions of the Data Controller and processes data on behalf of the Data Controller.
Data Protection Officer: a person who is an expert in data protection and looks after the interests of the data subject.
Data subject: the individual whose personal data is being processed.
Encrypted: encryption allows information to be hidden so that it cannot be read without special knowledge (such as a password). This is done with a secret code or cypher. The hidden information is said to be encrypted.
Generative artificial intelligence (also generative AI or GenAI): is artificial intelligence capable of generating text, images, or other media, using generative models. Generative AI models learn the patterns and structure of their input training data and then generate new data that has similar characteristics.
Information Commissioner’s Office (ICO): the UK’s independent body set up to uphold information rights. The ICO has the power to investigate organisations which do not obey Data Protection laws.
Joint Controllers: two or more Data Controllers who together decide how and why data is processed.
Legal/lawful basis/bases: six reasons recognised by UK GDPR for processing personal information.
Legitimate interests: a strong reason (or reasons) for a Data Controller to process data for no other reason than that it is beneficial to the Data Controller if it does not have an adverse effect on the data subject. This is one of the ways that processing data can be justified under GDPR law, although whenever a Data Controller relies on it, they should have a written decision called a Legitimate Interest Assessment.
Personal information: any information about a real, living individual. For example, name, telephone number, address, health conditions, or qualifications. Information about organisations, such as annual turnover, is not personal information. Information about individuals working at organisations – for example, a business email address, or a job title – is personal information.
Privacy notice: a publicly displayed explanation of how organisations process data.
Purpose limitation: one of the principles of GDPR – personal data should only be used for the reasons it was collected.
Public interest: beneficial for the public. One of the ways that processing data can be justified under GDPR law.
Retention schedule: a table of how long organisations should store data.
UK GDPR: UK General Data Protection Regulation. This is a law designed to protect personal data stored on computers, or in an organised paper filing system. This law is the UK version of a law that is applied across many European countries.












