The short version
- We use one AI vendor, Anthropic, and two of their Claude models. Nothing else.
- We use AI for two separate things: drafting our customers’ documents, and ordinary internal work like writing and code.
- Every pack is drafted by one AI model, checked by a second, and then released by a person. No pack reaches a customer without someone at ReadyPack releasing it.
- We use no high-risk AI as the EU AI Act defines it. Nothing touching recruitment, credit, biometrics, policing or access to essential services.
- We are unusual among our own customers: we are both a business that uses AI and one whose product runs on it. Section 3 says so plainly rather than hiding it.
This summary is here to help you find things. The numbered sections below are the statement itself.
Who this covers
This statement is published by MOFE LTD (Company Number 16633320), trading as ReadyPack. It covers every AI system used in running the business and in delivering our product.
It exists to answer three audiences without them having to ask: business customers who want to know how their documents were produced, a procurement or compliance team assessing us as a supplier, and a regulator asking for evidence. It is written to meet the transparency duty in Article 50 of the EU AI Act (Regulation 2024/1689) and the information duties in Articles 13 and 14 of the UK GDPR.
We sell to UK businesses and do not currently have customers in the European Union.
The AI systems we use
One vendor, two models. We have deliberately kept this short, because a long list would mean a larger surface to govern than a business this size can honestly govern.
| System | Vendor | What we use it for | EU AI Act class |
|---|---|---|---|
| Claude Sonnet 4.6 | Anthropic PBC | Drafting the documents in a customer’s pack, and revising them when a customer asks for changes | Limited risk (Art. 50) |
| Claude Haiku 4.5 | Anthropic PBC | Checking a finished draft for completeness, risk and contradictions between documents, and answering customer questions about their own pack | Limited risk (Art. 50) |
| Claude (general use) | Anthropic PBC | Ordinary internal work: writing, research and software development | Limited risk (Art. 50) |
Anthropic is our only AI vendor. We have a data processing agreement with them. They do not train their models on data we send, and on the commercial interface we use, conversation content is not retained by default. Content their trust-and-safety systems flag can be retained by them for up to two years, and we say so rather than leave it out.
We are both a user and a provider
Most businesses that buy this pack are AI users — they use tools someone else built. We are that, but we are also a business whose product runs on AI. Those are different obligations, and it would be misleading to publish a statement that only covered the first.
As a user, our position is the ordinary one described in section 2: a small set of tools, human accountability, no high-risk use.
As a provider, our customers’ questionnaire answers are processed by an AI model in order to produce their documents. That is the product working as sold, not an incidental use, and it deserves more than a line in a statement like this. It is set out in full in section 5 of our Privacy Notice: exactly which fields are swapped for placeholders before drafting, exactly what is sent, what the second model receives, and what Anthropic does with it.
If you are assessing us as a supplier, section 5 of the Privacy Notice and Schedule 1 of our Terms — a full Article 28 data processing agreement — are the two documents you actually want.
Who checks the output
Three steps, and we describe them precisely because a vaguer description would flatter us.
- An AI model drafts each document from the customer’s answers.
- A second AI model checks it — scoring completeness and risk, and looking for contradictions between the documents. This step is automated. It is not a person.
- A person at ReadyPack releases it. No pack reaches a customer until someone here does that, and where the answers flag something higher-risk or uncertain the pack is held for a closer look first.
Olu Adebiyi, Director, holds accountability for AI governance in the business, for keeping this statement current, and for acting on any concern raised about an AI output. The business has fewer than ten people, so that accountability is direct rather than delegated through a hierarchy.
Every time an administrator opens a customer case, it is recorded in our internal log.
What we do NOT use AI for
We deploy no AI system falling within the high-risk categories in Annex III of the EU AI Act, and no prohibited practice under Article 5. Specifically, we do not use AI for:
- biometric identification or categorising people
- recruitment, or any decision about someone’s employment
- deciding access to essential services such as credit, insurance or housing
- educational assessment
- law enforcement, or the administration of justice
- any decision made solely by a machine that produces a legal or similarly significant effect on a person
The pack we produce is a document about a business, not a decision about a person. We re-check this at every review, and immediately if what we use AI for changes.
What we put into AI tools
For internal use, staff are instructed not to put customer personal data, confidential client material or special category data into a general-purpose AI chat. Internal use is for writing, research and code.
For the product, the position is different and is deliberately not summarised here, because a summary would blur it. Seven identity fields are replaced with placeholders before the drafting request leaves our servers; everything else in the questionnaire is sent, including free text; and the second, checking model receives the finished draft with the real details restored. Section 5 of the Privacy Notice sets out each of those in full, field by field.
When this is reviewed
Annually, with the next scheduled review due 5 August 2027. It is also reviewed immediately, without waiting for that date, if any of the following happens:
- we adopt a new AI tool or vendor
- an existing tool materially changes what it does, how it processes data, or its risk classification
- there is a security incident involving an AI tool
- a customer complains about an AI-assisted output
- the law or regulatory guidance changes
Olu Adebiyi is responsible for starting each review and for reissuing this statement.
Contact
Questions about how we use AI, or a request for the internal evidence behind this statement — our AI risk register, DPIA, vendor register and internal AI policy, which we produce on request rather than publish: hello@readypack.co.uk.
ReadyPack is a trading name of MOFE LTD (Company Number 16633320). This statement describes our own AI use. It is not legal advice. Where you need advice on your own circumstances, engage a qualified solicitor.