Compliance Document
Data & AI Summary
A one-page overview of how we handle adviser meeting notes, protect client data, and govern AI behaviour, for compliance, procurement, and decision-makers.
Last Updated: February 2026
What This Tool Does
This is a cloud-hosted, AI-assisted letter drafting tool for IFA paraplanning teams. Staff upload or paste an adviser's meeting note, and the system:
- Identifies the correct letter template (from 41 templates)
- Extracts client details, fund information, and switch instructions
- Pre-fills a draft suitability letter for human review
- Routes the letter to Compliance for approval before generation
Think of it as a well-trained assistant that reads the meeting note and fills in the paperwork. But one that always needs a human (and Compliance) to check its work before anything goes out.
How We Handle Your Data
1Browser-Side Document Processing
When a meeting note PDF or Word document is uploaded, it is read and converted to text directly in the user's browser. The original file is never sent to our servers or anywhere else. Only the extracted text proceeds to the next step.
2AI Extraction
The extracted text is sent securely to our AI model, which identifies the correct template and extracts structured fields (fund names, platforms, ATR ratings, adviser details). Meeting note text is processed transiently. It is not stored after extraction.
✓Active: PII Masking Gateway
Before any text reaches the AI model, a browser-side PII masking layer automatically detects and replaces personal identifiers (client names, addresses, NI numbers, postcodes, email addresses, phone numbers, dates of birth, and account references) with neutral placeholders. After AI extraction, original values are reinjected into the results. So the AI never sees actual client identity data.
Key Commitments
Meeting notes are processed in your browser. The original file is never uploaded to our servers.
We do not use your data to train AI models.
Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Data is hosted in the UK/EU (London region) to meet GDPR residency requirements.
AI is a decision-support tool. Every letter requires human review and compliance sign-off.
Security & Access Controls
Authentication
Email and password authentication with two-factor authentication (mock/planned TOTP)
Encryption at Rest
AES-256 encryption on all stored data
Encryption in Transit
TLS 1.2+ (256-bit) for all connections
Data Residency
UK/EU hosted (London region)
Tenant Isolation
Row-level security. Each firm's data is fully partitioned
Meeting Note Retention
Raw text is processed transiently and not stored after AI extraction; only structured fields are retained
Audit Logging
All significant actions are logged with user, timestamp, and metadata
AI Governance
Decision-support only
AI analyses meeting notes and drafts letters, but humans always review and Compliance always approves before any letter is generated. Every AI output is presented as a draft, never as a final document.
Anti-hallucination controls
The AI uses a low temperature setting (0.3) for deterministic, factual output. It draws from a closed set of 41 approved letter templates and cannot invent new formats. Fields with low confidence are flagged for manual verification.
No model training
We do not use your data to train AI models. Our AI provider processes text to generate responses and does not use that text to train or improve its models.
Compliance Workflow
Staff uploads meeting note
File processed in browser, text extracted
AI identifies template & extracts fields
Low-confidence fields flagged for review
Staff reviews & completes draft
Confirms all fields, adds missing info
Compliance reviews & approves
Can approve or request amendments with feedback
Letter generated as .docx
Only after compliance sign-off
This document summarises the platform's data handling and AI governance. It does not constitute legal advice.
Full documentation:
Questions? Contact info@caseflowautomation.co.uk