1. Purpose and scope
This policy applies to Mabelhr Ltd, trading as Mabel HR, and our use of artificial intelligence, machine learning, generative AI and AI-enabled automation in our Website, internal operations and client delivery. It should be read alongside our Privacy Policy, information-security controls and client agreements.
Client-specific requirements, risk controls and approval processes may be documented separately and will take precedence for that engagement.
2. Our principles
We design and use AI around the following principles:
- Human responsibility: people remain accountable for professional advice, approvals and material decisions.
- Purpose and proportionality: AI should solve a defined problem and be proportionate to the risk and impact.
- Privacy and data minimisation: use only information that is necessary, lawful and appropriate.
- Fairness: consider bias, discrimination, accessibility and unequal impact throughout the AI lifecycle.
- Transparency: explain meaningful AI involvement where it is relevant to a person or client.
- Security and resilience: select, configure and monitor tools with appropriate safeguards.
- Quality and challenge: verify outputs rather than treating them as authoritative.
3. How we may use AI
Subject to appropriate controls, AI may support activities such as research, summarisation, drafting, document checking, workflow automation, knowledge management, reporting, data analysis, meeting preparation, project administration and service design.
AI may also be used to help clients assess readiness, design HR workflows, create governance frameworks, train teams and improve operational processes.
4. Human review and decision-making
AI output is treated as a draft, signal or decision-support input, not a substitute for professional judgement. The level of human review should reflect the potential impact, sensitivity and likelihood of error.
We do not intend to make solely automated decisions through the public Website that produce legal effects or similarly significant effects for individuals. Where client work could involve automated decision-making, roles, lawful basis, explanations, testing, safeguards and rights must be addressed before deployment.
5. Personal and confidential information
Personal, confidential or client information must not be entered into a public or consumer AI tool unless its use has been authorised and the tool, settings, contract and data-handling arrangements have been assessed as suitable.
Where AI processes personal information, we consider purpose limitation, lawful basis, transparency, data minimisation, accuracy, retention, security, individual rights and international transfers. A data-protection impact assessment may be required for processing likely to create high risk.
We do not use information submitted through the Website contact form to train our own AI models. We also do not intentionally permit client confidential information to be used to train a third party’s general model unless this has been expressly authorised and contractually addressed.
6. Accuracy, hallucination and professional review
AI systems can generate inaccurate, incomplete, outdated or fabricated content. Users must check facts, calculations, citations, legal propositions, policy wording and recommendations against reliable sources before use.
Employment, payroll, tax, legal, compliance and high-impact workforce outputs require appropriate qualified review. AI-generated material must not be represented as independently verified when it has not been checked.
7. Fairness and bias
We consider whether training data, prompts, features, proxies, outputs or implementation choices could disadvantage people or groups. Where appropriate, safeguards may include representative testing, impact assessment, outcome monitoring, accessible alternatives and escalation to a human reviewer.
AI should not be used to infer sensitive characteristics or make high-impact employment recommendations without a clear lawful purpose, robust evidence, appropriate expertise and meaningful human oversight.
8. Transparency and explainability
We aim to be open with clients about material use of AI in service delivery. The level of explanation will depend on context and may cover the tool’s purpose, data used, human involvement, limitations, key factors and routes to question or challenge an outcome.
Content should not be presented as wholly human-authored where AI involvement would be material to trust, risk, rights or a contractual commitment.
9. AI suppliers and tools
Before approving an AI tool for sensitive or material use, we consider matters such as security, privacy, data location, retention, model training settings, intellectual property, access controls, auditability, availability, contractual terms and the supplier’s ability to support compliance.
Approved tools and use cases may be reviewed, restricted or withdrawn if risks change.
10. Intellectual property
Users must respect copyright, database rights, trade marks, confidentiality and licence terms when providing inputs or using outputs. AI output may not be unique or protectable and may resemble third-party material, so appropriate checks are required before publication or commercial use.
11. Security and prohibited use
AI must not be used to create malware, facilitate unlawful discrimination, deceive people, bypass security, impersonate others, expose credentials, or process information in a way that breaches law, contract or professional obligations.
Suspected data loss, inappropriate disclosure, harmful output or material AI failure should be reported promptly so use can be stopped, contained, assessed and remediated.
12. Governance and accountability
Responsibility for an AI use case must be clear. Depending on risk, governance may include documented approval, a named owner, risk and impact assessment, testing, access controls, change management, staff training, monitoring, incident handling and periodic review.
For client solutions, responsibilities between Mabel HR, the client, technology suppliers and other partners should be agreed in writing.
13. Questions and concerns
Questions about this policy, or concerns about our use of AI, can be sent to hello@mabelhr.com. Privacy-related requests are handled under our Privacy Policy.
Mabelhr Ltd is registered in England and Wales under company number 08171703. Registered office: 2 Tower House, Tower Centre, Hoddesdon, Hertfordshire, EN11 8UR.
14. Policy review
AI technology, law and regulatory guidance develop quickly. We review this policy periodically and update it where our practices, risks or obligations change.