Governance

Data Ethics and Responsible AI Statement

Symolem Limited · Effective July 2026 · Under continuous review

Section 1

Scope of this statement

This statement applies to Symolem Limited, the independent advisory practice, and covers how we handle data and use AI tools in delivering advisory work. It does not cover Symolem-ID Ltd, a separate company developing an AI-native Digital Product Passport verification platform, currently in development. As an AI-native product, Symolem-ID will operate under its own data governance and responsible AI framework, published when the platform launches and designed to meet the obligations that apply to AI systems placed on the market, which go beyond those of an advisory practice using AI as a tool. The two companies are deliberately structured as separate entities with distinct responsibilities.

Section 2

Why this statement exists

Symolem Limited advises businesses on transparency, traceability, and evidence. It would be inconsistent to demand that standard of our clients and not apply it to ourselves. This statement sets out how we handle data and how we use artificial intelligence in our work, so that clients, partners, and regulators can see the principles we operate under and hold us to them.

Section 3

Our principles

Four principles govern our use of data and AI.

  • Purpose limitation: we collect and process only the data needed to deliver the work we have been engaged to do, and we do not repurpose client data beyond that engagement without consent.
  • Human accountability: AI supports our work; it does not replace our judgement. Every deliverable that carries the Symolem name has been reviewed, verified, and stands behind a named human, and responsibility for our advice always rests with us, never with a tool.
  • Transparency: we are open about where AI is used in our processes, and clients may ask at any time how a piece of work was produced.
  • Proportionality: the safeguards we apply scale with the sensitivity of the data and the consequences of the output. Work touching regulatory compliance, personal data, or published claims receives the highest level of human scrutiny.

Section 4

How we use AI

Our intellectual property is human work. The frameworks, datasets, and methodologies at the core of our practice, including our impact framework and our client analysis, were developed by us, grounded in expertise built before modern AI tools existed. Our work on digital product passports began in 2018, starting with white papers written years before the term entered regulation, culminating in the 2019 launch of Blu-Label, one of the world's first digital fashion labels. Because these frameworks and datasets are now extremely extensive, we use AI to check them for errors and inconsistencies; the content itself is human-generated.

Where we do use AI is at the edges of the practice, mainly for speed: building and maintaining this website, marketing content, and search and generative engine optimisation. Much of this site, including its design and code, was created with AI assistance, and everything published on it has been reviewed and approved by us.

We do not currently use AI in client work. If that changes, we will say so — here, and to the clients concerned.

We do not use AI agents in our business.

Section 5

What we do not do

We do not use client data to train AI models. We do not enter confidential client information into AI tools that lack contractual data protection commitments appropriate to that information. We do not use AI to make automated decisions with legal or similarly significant effects on individuals. And we do not use AI to generate sustainability claims, impact figures, or compliance conclusions without verification against underlying evidence — the practice we exist to help the market move beyond.

Section 6

Data protection

We process personal data in accordance with UK GDPR and the Data Protection Act 2018, and with EU GDPR where our work involves EU-based clients or data subjects. We apply data minimisation by default, retain data only as long as the engagement and our legal obligations require, and use appropriate technical and organisational security measures. Client commercial data is treated as confidential regardless of whether it contains personal data. Requests concerning personal data we hold can be directed to the contact below.

Section 7

Regulatory alignment

We monitor the development of AI regulation, including the EU AI Act and emerging UK guidance, and align our practices with their direction of travel ahead of formal obligation where practicable. Our exposure as an advisory user of AI tools differs from that of an AI system provider, and we hold ourselves to the standard appropriate to our role. As advisers working within the EU regulatory perimeter on product data and transparency, we hold ourselves to the standard of evidence and accountability that regime expects.

Section 8

Governance and review

This statement is owned by the founder and is under continuous review. Our use of data and AI is not a settled position but an evolving practice: as our tools change, as regulation develops, and as the nature of our work shifts, this statement is revisited and updated to match. A formal review takes place monthly, because AI is constantly evolving, with interim updates whenever a material change occurs. The effective date above reflects the most recent revision. Questions about this statement or our practices can be sent to lavinia@symolem.com, or via our contact page.