NODE · LON-01|LONDON --:--:--
DC-Services — Digital Claims Services Limited
Legal Documentation

DC-Services UK AI and Automated Processing Policy

Where automation supports documentation work, and where a human review is always required.

This policy describes how Digital Claims Services Limited (trading as DC-SERVICES UK) uses automation and AI-assisted tools to support documentation work, and the boundaries human reviewers always apply. It is informational only and is not financial, investment, legal or tax advice.

Last reviewed: February 2026 · 20 sections

ai-automated-processing-policy.pdf · A4 · brandedAll documents
01

Purpose of the policy

  1. 1.1DC-SERVICES UK publishes this policy so clients know where automation is used, what it does and where a human reviewer remains responsible.
  2. 1.2Automation can speed up document handling but cannot replace human judgement on legally significant questions.
  3. 1.3The policy applies to every tool that processes client data, regardless of vendor or hosting location.
  4. 1.4Clients can consult this page to understand which automated steps may be applied to their materials.
02

Definition of automation

  1. 2.1Automation means any computer process that performs a task on data without a human action for each step.
  2. 2.2Examples include text extraction, indexing, classification, deduplication and template population.
  3. 2.3Automation does not include final review or sign-off of deliverables.
  4. 2.4Each automation step is documented and approved before deployment.
03

Definition of AI-assisted processing

  1. 3.1AI-assisted processing means automation that uses machine-learning models to suggest, classify or extract content.
  2. 3.2AI-assisted outputs are treated as suggestions; they are not relied upon without human verification.
  3. 3.3Models used must meet documented data-handling, accuracy and security thresholds.
  4. 3.4Clients are told which AI-assisted steps may be applied to their engagement.
04

Human review principle

  1. 4.1Every deliverable passes a documented two-stage human review before release.
  2. 4.2Human review confirms that automated outputs are correct, complete and faithful to the source materials.
  3. 4.3Reviewers can override or discard automated outputs at any point.
  4. 4.4The reviewer of record is identified in the engagement file.
05

No automated legal or financial decision-making

  1. 5.1Automation is not used to make legal, financial, regulatory or tax decisions about clients or third parties.
  2. 5.2Such decisions remain the responsibility of qualified humans, not software.
  3. 5.3Outputs that look like recommendations are descriptive only, not advice.
  4. 5.4Clients should rely on their own professional advisers for decisions on their financial or legal position.
06

No client-document training without permission

  1. 6.1Client documents are not used to train, fine-tune or evaluate any model without the client's written permission.
  2. 6.2Where training is permitted, the data is anonymised and contractually ringfenced.
  3. 6.3Default vendor settings that would allow training are disabled before deployment.
  4. 6.4Clients can ask, at any time, whether their data has been used in any training process.
07

Document structuring tools

  1. 7.1Automation may organise documents into folders, timelines, indices and templates.
  2. 7.2Structuring tools change presentation, not the underlying content of source materials.
  3. 7.3Where a tool re-orders or groups content, the original source remains accessible.
  4. 7.4Structured outputs are checked against the original source by a reviewer.
08

Data extraction tools where applicable

  1. 8.1Extraction tools may pull dates, amounts, parties and references from documents into a working record.
  2. 8.2Extraction outputs are treated as candidate data, not as final values, until reviewed.
  3. 8.3Confidence thresholds determine when extracted values are surfaced for reviewer attention.
  4. 8.4Extraction logs allow each candidate value to be traced to its source location.
09

Quality control

  1. 9.1Sampled outputs from automated steps are reviewed against original materials at defined intervals.
  2. 9.2Sampling rates are higher for newer tools and for tools handling higher-risk content.
  3. 9.3Findings drive tool adjustments, additional human checks or retirement of the tool.
  4. 9.4Quality-control reports are retained internally for audit.
10

Human verification

  1. 10.1Every automated extraction or classification that materially affects a deliverable is verified by a human reviewer.
  2. 10.2Verification is recorded with the reviewer's identity and the time of the check.
  3. 10.3Where verification fails, the affected output is reworked and the failure analysed.
  4. 10.4Verification cannot be skipped to meet deadlines.
11

Limitations of automation

  1. 11.1Automation may misclassify, miss content, or misinterpret context — particularly with handwritten, low-quality or unusual source materials.
  2. 11.2Limitations are documented per tool and considered in the level of human review applied.
  3. 11.3Where limitations are material, the affected step is performed by a human from the outset.
  4. 11.4Clients are told if a limitation has affected their deliverable.
12

Error handling

  1. 12.1Where an error in an automated step is detected, the affected step is rerun manually and the impact assessed.
  2. 12.2Errors that could affect a delivered output trigger a client notification and remediation plan.
  3. 12.3Errors that recur drive a root-cause review of the tool.
  4. 12.4Error logs are retained internally for review and audit.
13

Client review of outputs

  1. 13.1Clients are invited to review draft deliverables before final release where the engagement allows.
  2. 13.2Client feedback is recorded and reflected in the next version of the deliverable.
  3. 13.3Client review does not transfer professional responsibility for the underlying work to the client.
  4. 13.4Review timelines are agreed in writing as part of the engagement.
14

Automated decision-making position

  1. 14.1DC-SERVICES UK does not make solely automated decisions with legal or similarly significant effect about clients or third parties.
  2. 14.2Article 22 UK GDPR rights against solely automated decisions therefore do not need to be invoked.
  3. 14.3If this position changes, the affected data subjects are told and Article 22 protections are applied.
  4. 14.4Position changes are version-controlled and published with a new 'Last reviewed' date.
15

Profiling position

  1. 15.1DC-SERVICES UK does not perform profiling within the meaning of Article 4(4) UK GDPR for marketing or scoring purposes.
  2. 15.2Internal classification of documents (for example by type or date) is not profiling of natural persons.
  3. 15.3Risk-flagging during onboarding follows the AML / KYC Policy, not generic profiling.
  4. 15.4If profiling is ever introduced, this page is updated and affected data subjects are told.
16

Security of automated tools

  1. 16.1Automated tools and AI models are deployed only after a security review covering data handling, access and logging.
  2. 16.2Tools are restricted to authenticated staff and segregated from other systems.
  3. 16.3Telemetry is reviewed for anomalous behaviour.
  4. 16.4Tools failing security review are not used on client data.
17

Vendor controls

  1. 17.1Where an external vendor supplies an AI or automation tool, the vendor is bound by UK GDPR Article 28-aligned terms.
  2. 17.2Vendor terms cover data location, training restrictions, breach notification and audit rights.
  3. 17.3Vendors that cannot meet our baseline are not engaged.
  4. 17.4Vendor changes affecting AI or automated processing are notified to active clients.
18

Data minimisation

  1. 18.1Only the data needed for an automated step is exposed to the tool that performs it.
  2. 18.2Sensitive fields are redacted or tokenised where the tool does not need them.
  3. 18.3Outputs strip data that is not needed downstream.
  4. 18.4Minimisation is reviewed when a tool is updated.
19

User rights connected to automation

  1. 19.1Data subjects may ask whether automation has been applied to data about them and request a description of the steps used.
  2. 19.2Requests are routed to the Data Protection Officer for response within one calendar month.
  3. 19.3Where automation has materially affected an outcome, the relevant logs can be summarised for the data subject.
  4. 19.4Data subjects retain all other UK GDPR rights independently of automation.
20

Policy review schedule

  1. 20.1This policy is reviewed at least annually and whenever tools, vendors or processing change materially.
  2. 20.2Reviews are owned by the Compliance Office with input from the Data Protection Officer.
  3. 20.3Updates are version-controlled and published with a new 'Last reviewed' date.
  4. 20.4Active clients are notified of changes materially affecting them.
Frequently Asked Questions

Questions about this page

Do you use AI on my documents?
Only AI-assisted tools that meet our security and data-handling thresholds, and always with human review. Your documents are never used to train models without your written permission.
Do you make automated decisions about me?
No. Decisions with legal or similarly significant effect are made by humans. Automation supports the work; it does not replace professional judgement.
Can I see what automation was applied to my materials?
Yes. The Data Protection Officer can describe the automated steps used on your engagement and the human review applied to them.
Will you tell me if a tool gets something wrong?
Yes. If an automation error could affect a deliverable we provided to you, we notify you and explain the remediation.