Human decisions
AI can suggest wording and a next action, but a person reviews communications and decides whether to act or escalate.
CreditPilot is being built as a credit-control system of action for UK and European teams. This centre explains the operational safeguards in the current beta.
This information describes current product controls. It is not a certification or a substitute for legal advice.
Human
approval before sending
Visible
AI-assisted outputs
Scoped
workspace access
Recorded
collection decisions
Safeguards in the product
CreditPilot supports collection decisions with structured information, transparent assistance and an evidence trail.
AI can suggest wording and a next action, but a person reviews communications and decides whether to act or escalate.
AI-generated recommendations and reply analysis are labelled, explainable and treated as support—not fact or legal advice.
Signed-in users can export workspace data and record access, correction, restriction, objection or erasure requests.
Approvals, exports, rights requests and collection activity are recorded in the workspace audit trail.
Responsibility by context
The exact legal role depends on why information is processed and who determines that purpose.
Your organisation usually decides why and how customer, invoice and collection data is used. It remains responsible for its lawful basis, privacy information and collection activity.
CreditPilot processes workspace data to provide the service. It separately determines how account, security, billing and service-administration information is used.
Current data map
Each data category supports a defined workflow and has a corresponding operational control.
Data category
Purpose
Authentication, workspace and support
Control
Access-controlled, with export and request tools
Data category
Purpose
Prioritisation and collection workflow
Control
Company-scoped; your ledger stays authoritative
Data category
Purpose
Prepare and record communications
Control
Draft, review and approval before sending
Data category
Purpose
Track commitments and ownership
Control
Recorded in the timeline and audit history
Data category
Purpose
Suggested wording and next actions
Control
Labelled assistance; human decision required
Operational guidance
Product controls support responsible use, but organisations must apply them within their own legal and operational context.
Customers remain responsible for identifying and documenting an appropriate lawful basis, supplying privacy information and respecting objections. Consent is not assumed to be the only available basis.
The workspace supports access, correction, restriction, objection, portability and erasure workflows. Requests should be verified, recorded and answered without undue delay.
Keep personal data only as long as needed for collection, contractual duties, legal requirements or claims. Retention exceptions may apply.
Provider terms, processing locations and lawful transfer safeguards must be reviewed before expanding European availability.
Users must apply the privacy and electronic-marketing rules relevant to their recipient and message. An approval record does not make a communication lawful by itself.
Authenticated company-scoped access, private exports, audit records and browser protections support security. Controls require continuing review as the beta grows.
Use the controls
Workspace users can download their data or record a privacy request in Settings. People in a customer’s records should normally contact that customer organisation first.