CreditPilot AI
Europe-ready foundation

Practical privacy, visible AI and human control.

CreditPilot is being built as a credit-control system of action for UK and European teams. This centre explains the operational safeguards in the current beta.

This information describes current product controls. It is not a certification or a substitute for legal advice.

Human

approval before sending

Visible

AI-assisted outputs

Scoped

workspace access

Recorded

collection decisions

Safeguards in the product

Control stays with the people doing the work.

CreditPilot supports collection decisions with structured information, transparent assistance and an evidence trail.

Human decisions

AI can suggest wording and a next action, but a person reviews communications and decides whether to act or escalate.

Operational safeguard

Visible AI assistance

AI-generated recommendations and reply analysis are labelled, explainable and treated as support—not fact or legal advice.

Operational safeguard

Data rights support

Signed-in users can export workspace data and record access, correction, restriction, objection or erasure requests.

Operational safeguard

Traceable collection work

Approvals, exports, rights requests and collection activity are recorded in the workspace audit trail.

Operational safeguard

Responsibility by context

Who is responsible for the data?

The exact legal role depends on why information is processed and who determines that purpose.

Normally the controller

Your organisation

Your organisation usually decides why and how customer, invoice and collection data is used. It remains responsible for its lawful basis, privacy information and collection activity.

Service processor

CreditPilot

CreditPilot processes workspace data to provide the service. It separately determines how account, security, billing and service-administration information is used.

Current data map

What the workspace uses—and why.

Each data category supports a defined workflow and has a corresponding operational control.

Current founding beta

Data category

Account and company

Purpose

Authentication, workspace and support

Control

Access-controlled, with export and request tools

Data category

Customers and invoices

Purpose

Prioritisation and collection workflow

Control

Company-scoped; your ledger stays authoritative

Data category

Reminders and replies

Purpose

Prepare and record communications

Control

Draft, review and approval before sending

Data category

Promises, disputes and actions

Purpose

Track commitments and ownership

Control

Recorded in the timeline and audit history

Data category

AI prompts and outputs

Purpose

Suggested wording and next actions

Control

Labelled assistance; human decision required

Operational guidance

Compliance is an ongoing business process.

Product controls support responsible use, but organisations must apply them within their own legal and operational context.

Lawful use

Customers remain responsible for identifying and documenting an appropriate lawful basis, supplying privacy information and respecting objections. Consent is not assumed to be the only available basis.

Rights handling

The workspace supports access, correction, restriction, objection, portability and erasure workflows. Requests should be verified, recorded and answered without undue delay.

Retention and deletion

Keep personal data only as long as needed for collection, contractual duties, legal requirements or claims. Retention exceptions may apply.

Providers and transfers

Provider terms, processing locations and lawful transfer safeguards must be reviewed before expanding European availability.

Electronic communications

Users must apply the privacy and electronic-marketing rules relevant to their recipient and message. An approval record does not make a communication lawful by itself.

Security and incidents

Authenticated company-scoped access, private exports, audit records and browser protections support security. Controls require continuing review as the beta grows.

Use the controls

Manage your information and privacy requests.

Workspace users can download their data or record a privacy request in Settings. People in a customer’s records should normally contact that customer organisation first.