Skip to main content

Quantum Intelligence Hub

AI & Automated Systems Policy

This Policy explains how Quantum Intelligence Hub Ltd (“QIH”, “we”, “us” or “our”) develops, configures, supplies and uses artificial intelligence, machine-assisted tools and automated systems. It applies to QIH-operated websites, platforms and services, including QIH HUB AI Digital Reception, and supplements our Privacy Policy, Data Protection Policy, Acceptable Use Policy and contractual documents.

Company number: 17246860
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Version: 4.0
Last updated: 23 August 2026

Core notice: Users may interact with an AI-assisted system. AI can make mistakes and does not replace qualified professional judgement. Where an AI interaction involves personal data, QIH and the relevant customer must provide appropriate transparency and comply with the laws applicable to their roles and locations.

1. Scope and Legal Framework

This Policy covers conversational AI, automated call handling, chatbots, generative AI, transcription, translation, classification, routing, summarisation, analytics, workflow automation and machine-assisted decision support used within QIH services.

Depending on the location, service and people concerned, relevant laws may include the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, Privacy and Electronic Communications Regulations, EU GDPR, Regulation (EU) 2024/1689 (EU AI Act), consumer protection, equality, communications and sector-specific rules. References to legislation include amendments and successor provisions.

2. Our AI Principles

  • lawful, fair and transparent use;
  • defined purposes and proportionate processing;
  • data minimisation and appropriate retention;
  • security, resilience and access control;
  • meaningful human oversight where appropriate;
  • accuracy checks and correction mechanisms;
  • accessibility, non-discrimination and respect for individual rights;
  • accountability shared according to each party’s role and conduct.

3. Systems Covered

QIH may use AI and automation for:

  • AI Digital Reception by telephone, website chat and supported communication channels;
  • answering common questions and providing service information;
  • appointment booking, rescheduling, reminders and lead capture;
  • message taking, call routing and escalation to human staff;
  • speech-to-text transcription, summaries and translation;
  • customer-support drafting and workflow automation;
  • authorised cybersecurity, risk analysis and open-source intelligence support;
  • education, content, translation, analytics and internal productivity assistance.

4. QIH Digital Reception

The standard QIH Digital Reception deployment is primarily designed to respond to inbound calls and messages, provide configured information, collect contact details, support appointments, route requests and create service records.

It is not intended to replace emergency services, qualified professional advice or a human decision-maker in matters producing legal or similarly significant effects. Customers must configure opening statements, escalation routes, business information and permitted actions accurately.

5. AI Transparency and Disclosure

Where reasonably required, people must be told clearly and at an appropriate time that they are interacting with an AI or automated system. QIH may provide disclosure tools, but each business customer remains responsible for ensuring that its channel-specific notices are accurate, enabled and legally suitable.

AI-generated or manipulated audio, images, video or other synthetic content must be labelled where required by applicable law and must not be used to deceive or impersonate a person without authority.

6. Calls, Recording and Transcription

Calls or conversations may be transcribed, summarised or recorded only where the relevant feature is enabled and a lawful basis and appropriate notice exist. The customer must determine whether recording is necessary, establish the required legal basis, configure notices and respect objection or opt-out rights where applicable.

QIH may process recordings, transcripts, summaries, caller details and related metadata to provide and secure the service, subject to the applicable contract, data processing terms and retention controls.

7. Inbound Service Communications and Outbound Marketing

Responding to an inbound request, managing an existing appointment or sending a non-marketing service notification is distinct from initiating an automated outbound marketing campaign.

The standard QIH Digital Reception service is not designed to autonomously cold-call marketing lists. Any future outbound AI calling or direct-marketing automation must be separately enabled, assessed and configured. The customer initiating the campaign must have all required permissions, consent or other lawful basis, maintain suppression records and comply with applicable telemarketing, e-privacy and consumer rules.

8. Human Oversight, Handover and Contestability

Customers should provide a practical route to a human representative where the request is sensitive, disputed, outside the AI’s configured authority or requires professional judgement. AI systems may transfer, create a callback request or record a message when a human is unavailable.

Where an automated process materially affects a person, QIH and the customer must provide information and safeguards appropriate to their respective roles, including a meaningful opportunity to raise concerns, correct information and obtain human review where required by law.

9. Automated Decisions and Profiling

QIH Digital Reception is intended for assistance, communication and workflow support, not for making final decisions about employment, credit, insurance, healthcare eligibility, immigration, education admission, essential services or other matters with legal or similarly significant effects.

A customer must not deploy QIH systems for solely automated significant decisions unless the use is lawful, expressly assessed, documented and subject to all required safeguards. QIH may require a data protection impact assessment, AI risk assessment or additional contractual controls before supporting such use.

10. Accuracy, Hallucinations and Reliance

AI systems are probabilistic and may misunderstand a caller, invent information, omit context or produce outdated, biased or inaccurate results. Customers must review business knowledge, prices, availability, instructions and escalation rules before deployment and after material changes.

No AI output should be treated as legal, tax, medical, financial, immigration, regulatory or other licensed professional advice. Important information and decisions require independent verification and appropriately qualified human review.

11. Personal Data and Allocation of Roles

For customer-configured Digital Reception services, the customer will normally determine why and how caller or end-user personal data is used and will ordinarily act as controller or business. QIH will ordinarily act as processor or service provider when processing that data on documented instructions. QIH may act as an independent controller for account administration, security, fraud prevention, legal compliance and its own legitimate operational records.

The precise allocation is governed by the applicable contract and Data Processing Agreement. Each party is responsible for the obligations arising from its own role, instructions, systems, personnel and legal violations.

12. AI Training and Customer Content

QIH does not intentionally use customer conversations or customer content to train QIH’s own general-purpose AI models unless the customer has expressly agreed to a clearly described arrangement. Service data may be processed to provide, secure, troubleshoot and improve the contracted service in accordance with the applicable agreement and privacy information.

Third-party AI providers may process data as subprocessors. QIH seeks contractual and technical settings that restrict provider training or unrelated use where available. Current providers, locations and safeguards should be reviewed through the applicable subprocessor information and Data Processing Agreement.

13. Special Category Data, Children and Vulnerable People

Customers must not configure the system to collect unnecessary health, biometric, political, religious, criminal-offence, sexual-orientation or other sensitive information. Where such processing is necessary, an appropriate Article 6 basis, Article 9 condition and any additional safeguards must be established.

Services directed at children or vulnerable people require age-appropriate transparency, enhanced safeguards, suitable human oversight and parental or guardian involvement where required. QIH may refuse or restrict deployments that present disproportionate risk.

14. Prohibited AI Uses

  • fraud, phishing, malware, credential theft or unauthorised access;
  • unlawful surveillance, stalking or covert monitoring;
  • deceptive impersonation, unauthorised voice cloning or harmful deepfakes;
  • unlawful discrimination, social scoring or exploitation of vulnerability;
  • prohibited biometric categorisation, emotion inference or facial recognition;
  • fabrication of evidence, identity records or professional credentials;
  • automated harassment, spam or unlawful marketing campaigns;
  • any use prohibited by applicable AI, data protection, equality, communications or criminal law.

15. Cybersecurity, OSINT and Safety

AI may assist with authorised risk analysis, security documentation, log classification, public-source research and defensive workflows. It must not be used to conduct unauthorised testing, exploitation, interception or surveillance. AI findings can contain false positives and false negatives and must be validated by competent personnel.

QIH may apply access controls, rate limits, filtering, logging, vulnerability management and protections against prompt injection, data exfiltration and malicious inputs. No system can guarantee absolute security.

16. Customer Responsibilities

Customers using QIH AI systems must:

  • provide accurate business information and lawful instructions;
  • identify their lawful bases and deliver required privacy and AI notices;
  • configure recording, retention, marketing and escalation settings lawfully;
  • avoid uploading unnecessary confidential or sensitive information;
  • maintain suitable human supervision and staff training;
  • review outputs and promptly correct known inaccuracies;
  • notify QIH of suspected misuse, security incidents or harmful outputs;
  • comply with laws applicable to their industry, customers and deployment locations.

17. Third-Party Providers and International Processing

QIH may use model providers, telecommunications services, cloud hosting, transcription, translation, analytics, messaging, payment and automation providers. Their availability, models, security controls and terms may change.

Where personal data is transferred internationally, QIH will use an applicable transfer mechanism and supplementary safeguards where required. Customers remain responsible for assessing providers they connect independently to the QIH service.

18. Intellectual Property and AI Outputs

Customers must have rights to any prompts, recordings, documents, images, voices or other materials supplied to an AI system. AI outputs may not be unique and may require human authorship or modification before intellectual-property protection is available.

No party may use QIH systems to copy protected works unlawfully, remove provenance information, impersonate rights holders or create misleading claims of ownership.

19. Monitoring, Incidents and Suspension

QIH may monitor service health, security events, usage volumes and system performance. Where lawful and proportionate, QIH may investigate suspected misuse, isolate affected functions, suspend access or preserve records needed for security, compliance or legal claims.

Material AI or personal-data incidents will be assessed and notified to the customer, regulator or affected individuals where required by law and according to each party’s role. Customers must cooperate with reasonable investigations and mitigation measures.

20. Responsibility and Liability

Each party is responsible for its own acts, omissions, systems, personnel, instructions and violations of applicable law. A customer is responsible for the business purposes, content, campaign lists, notices and deployment settings it controls. QIH is responsible for its own platform obligations, documented instructions and failures attributable to QIH.

Liability for paid services is governed by the applicable Master Service Agreement or other written contract. Nothing in this Policy excludes or limits liability that cannot lawfully be excluded, including liability arising from fraud or other mandatory legal rights.

21. Changes to AI Systems and this Policy

AI technologies and legal requirements change rapidly. QIH may update models, providers, controls, features and this Policy. Material changes affecting customer rights or processing will be communicated where required. The current version becomes effective when published unless a later date is stated.