Responsible AI Policy
Last updated: 27 September 2026
At Data Brainz AI, our approach to artificial intelligence fits in four words: AI drafts. Experts decide.
We use AI tools to help our people work faster on data architecture, data platform projects, data modelling, software development and training. We do not let AI make decisions on its own. This policy explains how we use AI, what it is never allowed to do, how we protect your data and how you can stay in control. It applies to all work by DataBrainzAI LLP and anyone working on our behalf.
Our principles
- Human approval at every gate. A qualified person reviews and approves anything AI helps to produce before it moves forward.
- Accountability stays with people. Our experts, not tools, are responsible for the work we deliver.
- Data minimisation. AI tools see only the data they need, and by default no real personal data.
- Transparency. We tell clients where AI assists on their project and keep records of it.
- Anyone can say stop. Any team member or client can reject an AI output or pause AI use.
Our practices are designed to help meet India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. They also align with the human-oversight principles of the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework. We do not claim certification against any of these standards.
Five things AI never does on its own
- Deploy to production. Only an authorised person can release a change to a live system.
- Access, move or delete personal or sensitive data. AI tools are not given independent access to this data.
- Make architecture decisions. AI may suggest options; an architect decides and records the reasons.
- Change business rules. Rules that affect how your organisation works are agreed with you and changed by people.
- Approve its own output. Every AI-assisted output is reviewed by a person other than the tool that produced it.
How we handle data when using AI
- By default, AI tools work on metadata (such as table structures and column names), masked data or synthetic data.
- Real personal data is used with AI tools only with the client's written approval, and only for the agreed purpose.
- We use enterprise AI services whose terms state that your data is not used to train their models, or models hosted in the client's own cloud environment.
- We do not paste client secrets, credentials or confidential documents into consumer AI tools.
- We follow the client's own data policies wherever they are stricter than ours.
Human gates in our projects
Each project passes through gates that need a person's approval before work moves on:
- Requirements sign-off. The client confirms that we have understood what is needed.
- Architecture approval. A senior architect reviews and approves the design.
- Model review. Data models, including dimensional and Data Vault models, are checked by an experienced modeller.
- Code review and tests. Code is reviewed by an engineer and must pass automated tests.
- User acceptance. The client tests the result and accepts it.
- Change approval. Changes to live systems follow the client's change process and are approved by an authorised person.
AI can help prepare drafts at any of these stages. It cannot pass a gate.
Transparency and records
We keep a record of where AI assisted with project outputs and who reviewed and approved them. On request, we will tell a client which AI tools were used on their project and for what. Records are kept in line with the client's agreement and our data retention practices.
Opting out of AI assistance
If you would prefer that we do not use AI tools on your project, or on certain parts of it, tell us before or at any point during the engagement. We will record your choice in the project agreement and follow it. Opting out may affect timelines, and if it does we will explain how before you decide.
AI in our trainings
In our trainings, participants may use an AI practice assistant to explore ideas, get hints or check their understanding. The trainer reviews exercises and gives the feedback that counts. We teach participants to question AI outputs, check them against sources and never share personal or confidential data with AI tools.
Guarding against over-trust
AI tools can be confidently wrong. Our reviewers are trained to check AI outputs critically, to verify facts, logic and code rather than assume they are correct, and to reject anything they cannot verify.
Incidents
If an AI-assisted output causes, or could cause, a problem, such as an error reaching a client deliverable or data being handled outside the agreed rules, we will:
- stop or pause the affected AI use
- tell the affected client promptly
- fix the issue and check for similar problems
- record what happened and what we changed to prevent it happening again
Where personal data is involved, we follow the breach process in our Privacy Policy.
Review of this policy
We review this policy at least once a year, and sooner when the law, the tools we use or good practice changes significantly. Updates are published on this page with a new "Last updated" date.
Contact us
If you have a question about how we use AI, or want to opt out of AI assistance, contact us at contact@databrainzai.com or on +91 77805 94658.