Specimen pack

See what you're getting before you buy

Every document in your pack follows these premium templates. Scroll through a specimen pack prepared for a fictional company.

Document 01

AI Use Statement

3 pages
DRAFT
Document 01

AI Use Statement

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Introduction and Scope

This AI Use Statement describes how Brightfield Digital Ltd (the “Company”) uses artificial intelligence systems within its digital marketing operations. It is published in accordance with our transparency commitments under Article 50 of the EU AI Act and our UK GDPR Article 13–14 obligations.

The Company is a 15-person UK digital marketing agency headquartered in London, serving SME and mid-market clients across the UK and EU. Approximately 15% of our revenue is attributable to EU-established clients, bringing in-scope processing within the territorial reach of the EU AI Act.

2.Purpose of This Document

We publish this statement so that clients, prospective clients, regulators, and our own staff understand which AI systems we operate, what those systems do, and what controls we have placed around them. It is a living document and is reviewed at least annually.

Regulatory Reference
Article 50 of the EU AI Act requires providers and deployers of certain AI systems to inform natural persons that they are interacting with an AI system, unless this is obvious from the circumstances. This statement, combined with our Customer Disclosure Snippets (Document 06), satisfies that obligation for our deployment context.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 01 · AI Use Statement
v1.0 · 7 Jun 2026

3.AI Systems in Use

The following table sets out the AI systems used internally by the Company, their purpose, and the regulatory classification we have applied to each system following our internal risk assessment.

SystemVendorPurposeAI Act Classification
ChatGPT (Team plan)OpenAI, OpenAI Ireland LtdDrafting client copy, internal research, summarisation of meeting notes.Limited risk (Article 50)
Notion AINotion Labs Inc.Knowledge-base summarisation and internal documentation drafting.Limited risk (Article 50)
Grammarly BusinessGrammarly Inc.Grammar and tone checking on outbound client deliverables.Limited risk
Microsoft Copilot for M365Microsoft CorporationEmail drafting and document assistance within Microsoft 365.Limited risk (Article 50)

4.Systems Not in Use

For the avoidance of doubt, the Company does not currently deploy any AI system falling within the “high-risk” categories of Annex III of the EU AI Act. We do not use AI for biometric identification, employment decision-making, access to essential services, or any other Annex III use case.

5.Human Oversight

All AI-generated output that is delivered to clients or used in customer-facing communications is reviewed by a named human employee before release. The Founder retains overall accountability for AI use across the business.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 01 · AI Use Statement
v1.0 · 7 Jun 2026

6.Controls and Safeguards

6.1 Data minimisation

Staff are instructed not to enter client personal data, financial information, or contractually-restricted material into general-purpose AI tools. Where processing of client-confidential information is required, only enterprise tiers with documented zero-retention commitments are used.

6.2 Training and acceptable use

All staff have completed the Company's Internal AI Use Policy training (see Document 05). New starters complete this training within their first week.

6.3 Review schedule

This statement is reviewed annually, and on a triggered basis whenever a new AI system is adopted or an existing system materially changes its function.

Document Control
Document TitleAI Use Statement (Document 01)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 02

Privacy Notice Addendum

3 pages
DRAFT
Document 02

Privacy Notice Addendum

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.About This Addendum

This Privacy Notice Addendum supplements the Company's existing Privacy Notice. It describes the AI-specific personal data processing activities carried out by Brightfield Digital Ltd and the lawful bases relied upon for each.

2.Controller Details

FieldDetail
ControllerBrightfield Digital Ltd
Address4th Floor, 87 Hatton Garden, London EC1N 8JT
ICO RegistrationZA000000 (example)
Contact for data rightsprivacy@brightfielddigital.example

3.Scope

This addendum applies to personal data we process about prospective clients, existing clients, end-user audiences of our clients' campaigns, and our own staff, in connection with our use of artificial intelligence tools.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 02 · Privacy Notice Addendum
v1.0 · 7 Jun 2026

4.AI-Specific Processing Activities

ActivityPersonal DataLawful BasisRetention
Generative copy draftingNames and job titles where included in briefsLegitimate interests (Art. 6(1)(f))Source briefs: 24 months
Meeting summarisationVoice transcripts, attendee namesLegitimate interests; consent where opt-inTranscripts: 90 days
Lead enrichmentBusiness contact detailsLegitimate interests (Art. 6(1)(f))CRM lifecycle (3 years inactive)
Internal knowledge searchEmployee-authored contentLegitimate interests; employment contractDuration of employment
No Solely-Automated Decisions
The Company does not make decisions about individuals based solely on automated processing (including profiling) that produce legal or similarly significant effects on them. All AI output that informs decisions affecting individuals is reviewed by a named human employee before any action is taken.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 02 · Privacy Notice Addendum
v1.0 · 7 Jun 2026

5.Your Rights

You retain all rights set out in the UK GDPR, including the right to access, rectify, erase, and restrict processing of your personal data, and to object to processing carried out on the basis of our legitimate interests.

6.International Transfers

Several AI services we rely on are operated from the United States. We rely on the UK Extension to the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses where required, and we maintain a transfer impact assessment for each onward transfer.

7.Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time. Our internal complaints procedure is set out in Document 08 of this pack.

Document Control
Document TitlePrivacy Notice Addendum (Document 02)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 03

AI Risk Register

3 pages
DRAFT
Document 03

AI Risk Register

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Purpose

This Register records identified risks arising from the Company's use of artificial intelligence systems, the mitigations in place for each, and the residual risk position after those mitigations are applied. It is a living document and is reviewed at least quarterly.

2.Methodology

Each risk is scored on two dimensions — likelihood of occurrence and severity of impact — each on a three-point scale (Low / Medium / High). The combined score determines the inherent risk band shown on the matrix overleaf.

3.Risk Matrix

Severity ↑
Low likelihood
Medium
High likelihood
High
Medium
High
Critical
Medium
Low
Medium
High
Low
Low
Low
Medium
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 03 · AI Risk Register
v1.0 · 7 Jun 2026

4.Risk Register

IDRiskLikelihood / SeverityMitigationResidual
R-01Inadvertent disclosure of client-confidential content via promptsMedium / HighEnterprise-tier accounts only; staff training; quarterly auditLow
R-02Hallucinated factual content reaching a client deliverableHigh / MediumMandatory human review of all AI-assisted client outputLow
R-03Vendor lock-in or unexpected service discontinuationLow / MediumVendor register maintained; viable alternatives identifiedLow
R-04Cross-border data transfer non-compliance (US-hosted tools)Medium / HighDPF reliance plus SCCs; annual transfer impact assessmentMedium
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 03 · AI Risk Register
v1.0 · 7 Jun 2026

5.Review Schedule

This Register is reviewed quarterly by the Founder. Material changes — including the introduction of a new AI system, a vendor change, or a near-miss incident — trigger an interim review.

6.Escalation

Any risk rated “High” or “Critical” on the matrix is escalated immediately to the Founder and reviewed against the Company's continuity plan. Where the residual risk after mitigation remains High, the underlying AI system is either replaced or withdrawn pending further controls.

Cross-references
Mitigations are operationalised through the Internal AI Use Policy (Document 05) and the Vendor AI Register (Document 07). High-impact processing activities are separately assessed through the DPIA-Lite Template (Document 04).
Document Control
Document TitleAI Risk Register (Document 03)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 04

DPIA-Lite Template

3 pages
DRAFT
Document 04

DPIA-Lite Template

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Processing Under Assessment

This DPIA-Lite assesses the Company's use of generative AI tools to draft marketing copy and summarise client meetings. It is focused on the data protection impacts on natural persons whose personal data is incidentally processed during these activities.

2.Necessity and Proportionality

AI-assisted drafting and summarisation deliver material productivity gains. The processing is limited to the minimum personal data required to complete the relevant task and uses enterprise-tier tools with documented zero-retention or short-retention commitments from the vendor.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 04 · DPIA-Lite Template
v1.0 · 7 Jun 2026

3.Risks to Individuals

Risk to IndividualLikelihoodSeverityMitigation
Disclosure of personal data in a prompt to a third-party vendorMediumHighEnterprise plans; staff trained on prohibited inputs
Inaccurate output describing an identified individualMediumMediumMandatory human review prior to any external release
Use of personal data for vendor model trainingLowHighContractually disabled on all enterprise tiers in use
Loss of meaningful human control over decisions affecting individualsLowHighNo solely-automated decisions; documented oversight
ICO Reference
This template follows the structure recommended by the Information Commissioner's Office in its “DPIA template for AI” guidance. Where a higher-risk processing activity is identified, a full DPIA is completed in place of this Lite version.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 04 · DPIA-Lite Template
v1.0 · 7 Jun 2026

4.Conclusion

With the mitigations recorded above, the residual risk to the rights and freedoms of natural persons is assessed as Low. No prior consultation with the ICO is required.

5.Sign-off

Prepared by
Mark WhitfieldFounder · Brightfield Digital Ltd
Date
7 June 2026Next review: 7 June 2027
Document Control
Document TitleDPIA-Lite Template (Document 04)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 05

Internal AI Use Policy

3 pages
DRAFT
Document 05

Internal AI Use Policy

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Purpose

This Policy sets out how staff at Brightfield Digital Ltd are permitted to use artificial intelligence tools in the course of their work. It is binding on all employees, contractors, and freelancers.

2.Scope

This Policy covers all generative AI tools — including ChatGPT, Notion AI, Microsoft Copilot, and any tool subsequently approved by the Founder — and applies wherever those tools touch client data, internal business data, or public-facing deliverables.

3.Roles

The Founder is accountable for AI governance. Each team lead is responsible for ensuring their team complies with this Policy in day-to-day work.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 05 · Internal AI Use Policy
v1.0 · 7 Jun 2026

4.Acceptable Use

Do
  • Use approved enterprise accounts for any work involving client material.
  • Review every AI-generated output before it leaves the Company.
  • Disclose AI assistance in client deliverables where the client has asked us to.
  • Report suspected near-misses or breaches to the Founder within 24 hours.
Don't
  • Paste client personal data, payment details, or confidential briefs into consumer accounts.
  • Use AI to make hiring, performance, or disciplinary decisions about colleagues.
  • Adopt a new AI tool for work purposes without written sign-off from the Founder.
  • Treat AI output as factually verified — every claim must be checked.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 05 · Internal AI Use Policy
v1.0 · 7 Jun 2026

5.Enforcement

Breaches of this Policy will be handled under the Company's normal disciplinary procedure. Significant breaches that result in a data protection incident are also assessed against the Company's personal data breach procedure.

6.Training and Acknowledgement

Every member of staff must acknowledge this Policy at induction, and again whenever it is materially updated. The Founder maintains the record of acknowledgements.

Approved by
Mark WhitfieldFounder · Brightfield Digital Ltd
Effective Date
7 June 2026Review annually
Document Control
Document TitleInternal AI Use Policy (Document 05)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 06

Customer Disclosure Snippets

3 pages
DRAFT
Document 06

Customer Disclosure Snippets

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.How to Use This Document

The snippets in this pack are ready-to-paste disclosures designed to satisfy Article 50 of the EU AI Act and UK GDPR transparency expectations. Each snippet is tagged with the context where it is intended to appear. Replace the bracketed placeholders before use.

When to disclose
Article 50 of the EU AI Act requires that natural persons be informed when they are interacting with an AI system unless this is obvious from the circumstances. The snippets below are calibrated for the Company's use cases and should not be edited without sign-off from the Founder.

2.Snippet Index

TagUse case
WEBSITE FOOTERGeneral disclosure on every public page
SUPPORT HANDOVERWhen a human takes over from an AI assistant
PROPOSAL DISCLOSUREInside a client-facing proposal or SOW
AUTO-RESPONDEREmail auto-replies generated by AI
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 06 · Customer Disclosure Snippets
v1.0 · 7 Jun 2026

3.Snippets — Public-Facing

Website footer · short formWEBSITE FOOTER
Parts of this website and the services we deliver are produced with the assistance of generative AI tools. We review all output before publication. For details, see our AI Use Statement at [link].
In-product banner · chat widgetSUPPORT HANDOVER
You're chatting with an automated assistant powered by AI. A human team member will join the conversation if your enquiry needs one. Read more about how we use AI: [link].
Email auto-reply · out-of-hoursAUTO-RESPONDER
Thanks for your message. This reply was generated by an AI assistant on our team's behalf. A named colleague will be in touch within one working day. — Brightfield Digital
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 06 · Customer Disclosure Snippets
v1.0 · 7 Jun 2026

4.Snippets — Client-Facing Deliverables

Proposal cover-page disclosurePROPOSAL DISCLOSURE
Sections of this proposal have been drafted with the support of generative AI tools used under enterprise terms with no model training on our content. All recommendations have been reviewed by a named Brightfield Digital strategist before sending.
Statement of Work — AI use clausePROPOSAL DISCLOSURE
Brightfield Digital uses AI tools to assist with drafting, research and analysis. We do not enter client confidential information into consumer AI products and do not permit the use of client data for vendor model training. Our full AI Use Statement is available on request.
Document Control
Document TitleCustomer Disclosure Snippets (Document 06)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 07

Vendor AI Register

3 pages
DRAFT
Document 07

Vendor AI Register

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.About This Register

This Register lists every third-party AI tool used by Brightfield Digital Ltd, the data categories that touch each tool, and the lawful basis on which we transfer that data. It supports our UK GDPR Article 30 record of processing activities.

2.Maintenance

The Register is reviewed quarterly by the Founder. New vendors are added at the point of sign-off; decommissioned vendors are retained for two years before removal so that historical processing remains traceable.

Connected documents
Risk treatment for each vendor is recorded in the AI Risk Register (Document 03). Customer-facing disclosure about these tools is covered by the AI Use Statement (Document 01) and Customer Disclosure Snippets (Document 06).
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 07 · Vendor AI Register
v1.0 · 7 Jun 2026

3.Vendor Register

Vendor / ProductData TouchedRegion / Transfer Mechanism
OpenAI — ChatGPT Team
Use: drafting, summarisation, research.
Names, business email addresses (incidental). No special-category data.US-hosted. DPF + SCCs. Training on Company data disabled at tenant level.
Notion Labs — Notion AI
Use: knowledge-base search and drafting.
Employee-authored content; client names within internal notes.US-hosted. SCCs. Enterprise tier; no training on Company workspace.
Microsoft — Copilot for M365
Use: email and document drafting in M365.
All mailbox content available to the named user.UK + EU data residency selected. UK Adequacy regulations apply.
Grammarly Inc. — Business
Use: grammar and tone checking on outbound content.
Document text submitted for analysis.US-hosted. DPF + SCCs. Knowledge-share disabled at tenant level.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 07 · Vendor AI Register
v1.0 · 7 Jun 2026

4.Decommissioning

When a vendor relationship ends, the Founder ensures that any data the vendor retains is deleted in accordance with the contract, and the Register entry is marked “Decommissioned” with the effective date.

5.Onboarding New Vendors

Before a new AI vendor is adopted, the Founder reviews the vendor's data processing terms, transfer mechanisms, and security posture against this Company's standards. Adoption is only authorised in writing.

Document Control
Document TitleVendor AI Register (Document 07)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 08

Complaints Procedure Pack

3 pages
DRAFT
Document 08

Complaints Procedure Pack

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Purpose

This Procedure sets out how Brightfield Digital Ltd receives, acknowledges, investigates and resolves complaints about its processing of personal data, including processing carried out using AI tools. It satisfies the Company's obligation under Section 103 of the UK Data (Use and Access) Act 2025.

DUAA Section 103
From 19 June 2026, organisations that process personal data must operate a documented complaints handling procedure and must acknowledge complaints promptly. The Information Commissioner's Office can investigate non-compliance.

2.How to Complain

Complaints may be made by email to privacy@brightfielddigital.example, by post to the registered address, or in person at any pre-arranged meeting with a member of staff.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 08 · Complaints Procedure Pack
v1.0 · 7 Jun 2026

3.Process

1
Day 0

Acknowledge receipt

We acknowledge every complaint within one working day, confirming the named individual handling the matter.

2
Day 1 – 7

Investigate

The handler reviews the relevant processing records, vendor logs and internal correspondence. Additional information may be requested from the complainant.

3
Day 7 – 30

Substantive response

A written response is issued setting out our findings and any remedial action. If we cannot respond within 30 days, we explain why and provide a revised timeline.

4
Day 30+

Escalation to the ICO

Complainants who remain dissatisfied are told how to escalate to the Information Commissioner's Office.

— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 08 · Complaints Procedure Pack
v1.0 · 7 Jun 2026

4.Records

A record of every complaint received, the action taken and the outcome is retained for a minimum of six years. The Founder reviews the complaints log quarterly for trends and improvement opportunities.

5.Confidentiality and Non-Retaliation

Complaints are handled in confidence so far as is consistent with carrying out an effective investigation. The Company prohibits any form of retaliation against an individual for raising a good-faith complaint.

6.Escalation Contacts

RouteContact
Internal — First contactprivacy@brightfielddigital.example
Internal — EscalationMark Whitfield, Founder
External — RegulatorInformation Commissioner’s Office (ICO) — ico.org.uk
Document Control
Document TitleComplaints Procedure Pack (Document 08)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

Document 09

Procurement Response Memo

3 pages
DRAFT
Document 09

Procurement Response Memo

Prepared for Brightfield Digital Ltd

Version 1.0 · 7 Jun 2026Owner: Mark Whitfield, FounderConfidential
CLIENT LOGO

1.Executive Summary

This Memo summarises Brightfield Digital Ltd's compliance position with respect to UK GDPR, the EU AI Act, and the UK Data (Use and Access) Act 2025. It is intended to accompany procurement responses and supplier questionnaires from enterprise customers.

2.Compliance Snapshot

AreaStatusEvidence
UK GDPR — Records of Processing (Art. 30)✓ In placePrivacy Notice Addendum (Doc 02), Vendor AI Register (Doc 07)
EU AI Act — Article 50 Transparency✓ In placeAI Use Statement (Doc 01), Customer Disclosure Snippets (Doc 06)
EU AI Act — Risk Management✓ In placeAI Risk Register (Doc 03)
DUAA Section 103 — Complaints✓ In placeComplaints Procedure Pack (Doc 08)
High-risk AI systems (Annex III)⚠ Not in scopeNo Annex III systems deployed; reviewed quarterly
Cross-border transfers — Adequacy⚠ Reliance on DPF/SCCsTIA on file; reviewed annually
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 09 · Procurement Response Memo
v1.0 · 7 Jun 2026

3.Documentation Index

The following documents are available on request from any enterprise customer and form the complete ReadyPack compliance documentation set for the Company.

DocTitleOwner
01AI Use StatementMark Whitfield, Founder
02Privacy Notice AddendumMark Whitfield, Founder
03AI Risk RegisterMark Whitfield, Founder
04DPIA-Lite TemplateMark Whitfield, Founder
05Internal AI Use PolicyMark Whitfield, Founder
06Customer Disclosure SnippetsMark Whitfield, Founder
07Vendor AI RegisterMark Whitfield, Founder
08Complaints Procedure PackMark Whitfield, Founder
09Procurement Response MemoMark Whitfield, Founder
Bid use
This Memo is the recommended single attachment when a vendor questionnaire asks for a high-level AI & data governance summary. Individual documents can be released under NDA where the customer requires the underlying detail.
— Page Break —
DRAFT
CLIENT
Brightfield Digital Ltd
Document 09 · Procurement Response Memo
v1.0 · 7 Jun 2026

4.Points of Contact

TopicContact
Data protection enquiriesprivacy@brightfielddigital.example
AI governance enquiriesMark Whitfield, Founder
Security and incident reportingsecurity@brightfielddigital.example
Commercial / procurementsales@brightfielddigital.example

5.Review Cycle

This Memo is refreshed at least annually, and on a triggered basis whenever any of the underlying documents in the documentation index materially change.

Document Control
Document TitleProcurement Response Memo (Document 09)
Prepared ForBrightfield Digital Ltd
Document OwnerMark Whitfield, Founder
Version1.0
Issue Date7 June 2026
Next Review Date7 June 2027 (or upon material change)
Quality AssuranceReadyPack Compliance Assurance — multi-stage automated QA & risk review
ClassificationConfidential — Internal & Customer Use

This document was generated by ReadyPack's compliance documentation platform and verified through ReadyPack's multi-stage compliance assurance process. It does not constitute legal advice.

AI & Data Governance Compliance Documentation Pack

Prepared for Brightfield Digital Ltd

CLIENT LOGO
9 Documents · 35 Pages · Version 1.0
Issued 7 June 2026