What a data protection lead needs from us
This page is for the person who has to sign off a child's record going through an AI system: a data protection officer, an information governance lead, a registered manager with the form in front of them. It says who processes what, where it runs, what leaves, what the processor terms commit us to, what is in the data protection pack, and which certificates we hold, with dates. Nothing here certifies your compliance. Chrysalis produces the evidence, and your own auditor validates it.
If you find a gap between this page and the contract, the pack or the product, email hello@getmothy.ai and we will correct whichever is wrong.
Who processes what
You are the controller. A fostering service or a children's home provider decides why a child's record exists and what goes in it. We are the processor. Chrysalis AI is a product of Impending Tech Limited, registered in England and Wales, Companies House number 14993014, and registered with the Information Commissioner's Office under ZC239982 since 5 September 2026.
There is one named UK processor, us, under a data processing agreement. The sub-processor list is below, and it is short on purpose.
| Who | What they do | Where | Do they see personal data |
|---|---|---|---|
| The UK data centre operator, named in your contract | Physical hosting only: rack, power, cooling and physical security | United Kingdom | No. The disk is encrypted and they hold no credential for the system. |
That is the list. There is no model provider, no cloud platform, no managed database, no hosted search, no analytics service and no error-reporting service, because the system runs the model and the database itself. Under a conventional cloud design this table carries five or six names, and each one is a transfer to assess and a contract to flow obligations through.
Microsoft is not a sub-processor. Where you switch on the optional connections, the system talks to your own Microsoft 365 tenant: sign-in, a read-only mirror of a site you nominate, and reads of mail your staff can already open. Your relationship with Microsoft is yours. We hold no credential that can write to your SharePoint or send mail from your tenant.
We tell you before adding a sub-processor, with time to object, and the processor terms give you the exit if we cannot resolve an objection.
Where it runs, and what leaves
Both tiers are hosted by us in a UK-owned facility under UK jurisdiction, written into the contract. On the Dedicated tier the hardware is reserved for your organisation alone. On the Pooled tier your database, encrypted store, keys and private network are yours alone, and the AI runs on hardware we own in the UK and share across customers. In neither form is your data store shared with another customer.
The model runs on that hardware. It is an open-weight model held under an irrevocable open licence, with the weights on our hardware, so no vendor can change the terms or switch it off. There is no API key to a model vendor, and nothing about a child is sent anywhere to be summarised. Nothing is trained on your data.
What does leave is named in the data processing agreement: monitoring, backup and update traffic inside the environment we run. No personal data is transferred outside the United Kingdom. Your staff reach the system from any site or from home over an encrypted private link.
The questions a data protection lead asks
- Where does a child's record live?
- In a database and an encrypted store that are yours alone, never shared with another customer, in a UK-owned facility under UK jurisdiction. On the Dedicated tier the hardware itself is yours for the term.
- Does any of it go to an AI model provider?
- No. There is no model provider anywhere in the chain. The model runs on hardware we own in the UK.
- Who can see it inside the system?
- Access to a placement is explicit, and it is enforced in the database by row-level security rather than by a screen that declines to show it. An administrator's read of a child's record is written to the audit log in the same transaction as the read, so it cannot happen unrecorded.
- Who can see it from your side?
- When you ask us to operate or support the system, named staff reach it over an authenticated management path. That is us acting as your processor, and the access is logged. What we may need to see to investigate a fault, and what you would rather we did not, is agreed in the contract rather than in the moment.
- How is it protected in transit and at rest?
- TLS in transit, with secure cookies and HSTS. Full-disk encryption at rest. Authentication on by default, and a service that fails closed rather than answering unauthenticated on a network address. A pinned, controlled supply chain, verified at boot.
- What does the audit log prove?
- That a record has not been altered since it was signed. Every interaction is written to an append-only log where each entry sits on a hash chain, and the database refuses an update or a delete to that log. Change an entry and the chain stops verifying. The export carries the chain, a verification report and the head digest, the fingerprint of the last entry, so whoever receives it can check it offline without asking us.
- And what does it not prove?
- It is tamper-evident, not tamper-proof. It shows that a change happened; it does not make a change impossible. We say so in the contract rather than leave it to be discovered.
- What about erasure?
- In the assistant, erasure of a person is a real operation and we run it on your instruction. In the record itself there is no erasure operation and no automated deletion at any age, because those entries are evidence about a child in care with a retention period set by your statutory duty, and a safeguarding freeze can extend it. A request to erase them is your decision against the statutory exemptions; we assist with retrieval and with any disposal you lawfully direct. Disposal of records whose retention period has genuinely expired is specified and not yet built. Until it is built, the system keeps them.
- What happens when something goes wrong?
- We notify you without undue delay, within the hours agreed in your contract, with the detail Article 33(3) asks for so far as it is known. The breach procedure is in the pack. Backups are encrypted, the restore is tested, and the passphrase is held off the system. Backups are retained on the system itself, so the offsite arrangement is agreed with you before go-live.
- Can we leave?
- Yes, at no cost. Your records export with the audit chain, a verification report and the head digest, so the next system, or an inspector, can check them without trusting either of us.
- Does it predict risk, score children or find patterns across a population?
- No. It helps a practitioner see what is already recorded about one child, and it cites what it read.
- Does a model ever write into a child's record on its own?
- No. What the model writes is a draft. It becomes the record when a person reads it and signs a declaration adopting it as their own, and the signature and the AI mark are written together. The child's own words are copied, never composed. What the system holds about a child, which controls enforce that, and which are not built yet, is on what Mothy holds about a child.
What the processor terms commit us to
The data processing agreement is an Article 28 contract in the ordinary shape. It commits us to:
- process personal data only on your documented instructions, and tell you if an instruction appears to break data protection law;
- put every person who handles the data under a duty of confidence;
- keep the technical and organisational measures in its first schedule, the ones set out above;
- engage no sub-processor without your prior authorisation, notify you of any intended change in time for you to object, and flow the same obligations down;
- assist you with subject access and other data subject requests, on a written procedure;
- assist you with security, breach notification, impact assessments and prior consultation;
- at your choice, return or delete all personal data at the end of the service, except where the law requires it to be kept;
- make available what you need to demonstrate compliance, and allow and contribute to audits and inspections, which includes demonstrating the audit chain verifying against the live database and mapping each security claim to the code and test that enforces it.
No international transfers. The full terms come with the pack and are settled with your legal team before anything is signed. They are a document your lawyers mark up, not a click-through. The Pooled form of the terms is being drafted, and until it is settled every contract is on the Dedicated tier.
The data protection pack
A folder of documents your data protection lead can use rather than write, drafted from the controller's side of the table. It holds:
- a pre-completed data protection impact assessment, with the gaps that are yours to fill marked;
- the data flow: what is processed, where, what is retained, and what leaves;
- the record of processing, one per deployment;
- the retention schedule;
- the processor terms;
- the sub-processor list;
- the subject rights procedure: who runs export and erasure, and on whose authority;
- the breach notification procedure;
- a plain English note on the model: what it drafts, what it never decides, and how the audit log evidences that;
- a note on persistent memory: what it would hold, the three tiers governing facts about a child, and why it is switched off;
- the residential addendum: what a children's home changes.
The pack names the version of the code it was checked against; the last full check was on 8 September 2026. The residential addendum describes a product still being built, and says so on its first page. A DPIA that describes a version we no longer ship is worse than none, so the pack is refreshed when the data flow, the model, the retention behaviour or the sub-processor list changes.
Ask for it at hello@getmothy.ai, and we walk your data protection lead through it. It is part of the founding conversation, before anything is signed.
Certifications and registrations
Stated as facts, with dates.
| Item | Status on 1 October 2026 |
|---|---|
| Information Commissioner's Office registration | Impending Tech Limited, ZC239982, registered 5 September 2026, on the public register. It renews in September 2027. |
| Companies House | Impending Tech Limited, 14993014, registered in England and Wales. |
| Cyber Essentials | Assessment in progress. It was bought on 16 August 2026 and must be completed by February 2027. We will say here when the certificate is issued. |
| Cyber Essentials Plus | Not yet held. The audited tier can only be taken within three months of the Cyber Essentials certificate, and it will be booked in that window. |
| ISO 27001 | Not held, and deferred. The policy set and risk assessment behind it are kept. We will say here if that changes. |
| Central Digital Platform, under the Procurement Act 2023 | Registered as a supplier. |
We hold no certificate that is not named here. We would rather you read that from us than find it.
What we do not claim
- We do not claim to be on your premises. Both tiers are hosted. The claim is control, jurisdiction and evidence, never location.
- We do not claim air-gapped operation. The system never calls the internet or a model provider, and the monitoring, backup and update traffic inside the environment we run is named in the agreement.
- We do not claim to out-secure the hyperscale providers. The claim is control, governance and evidence, not perimeter security.
- The audit log is tamper-evident, not tamper-proof.
- Nobody is Ofsted endorsed, ourselves included. An inspector asks whether your decisions about a tool were sensible, and this page is written to help you answer.
- We do not claim cloud AI is forbidden. Councils run cloud AI tools in social care with published impact assessments. We claim Chrysalis is the option you can defend best.
- We produce the evidence. We do not certify your compliance.
How to check us
- Ask for the audit export from the invented demonstration records and verify it offline. The verification report and the head digest are in the export.
- Ask for the mapping from each claim on this site about the record and the audit log to the code and the test that proves it. We keep that register and supply it on request.
- Ask for the pack, and read the processor terms against this page.
- Read what Mothy holds about a child, which says which controls are running and which are not built, and hold us to it item by item.
Reviewed against the processor terms, the sub-processor list, the pack index and the compliance notes on 1 October 2026.