For procurement

The questions you have to ask us anyway.

Written for information governance, procurement, SEND and ICT teams. Everything here is something we can evidence on request. Where we cannot substantiate a claim, it is not on this page.

Roles and responsibilities

Who is the controller, who is the processor, and what that means in practice.

Is DIGI a data controller or a data processor?

On client engagements DIGI is normally a processor, and the client remains the controller. You decide the purpose of the processing and the lawful basis. We process personal data only on your documented instructions, as set out in the contract and the data processing agreement.

DIGI is a controller only for its own business data, such as enquiries sent through this website and the records we keep about our own staff and suppliers.

Will you sign our data processing agreement?

Yes. We expect to sign the controller-to-processor terms required by Article 28 of the UK GDPR, and we are used to reviewing an authority’s own DPA rather than insisting on ours.

Where an authority has a preferred template, send it with the tender or at contract stage and we will mark up anything we cannot accept rather than returning it unread.

Will you support our DPIA?

Yes. A Data Protection Impact Assessment is the controller’s document, but the supplier holds most of the technical detail needed to complete it.

We provide the processing description, the data flows, the categories of data and data subjects, the security measures, the retention position and the details of any sub-processors, in a form you can lift directly into your DPIA. We would rather do this at the start of an engagement than retrofit it before go-live.

Data handling and residency

Where data lives, who can reach it, and what happens at the end.

Where is data hosted and processed?

DIGI engineers in the United Kingdom and hosts in the United Kingdom by default.

Where an authority’s requirements do not permit shared infrastructure, fully sovereign self-hosted deployment is available through our sister company CHMS Cyber Security, so the system runs inside your own estate.

Do you have experience with special-category data?

Yes. We build SEND software used across 70 local authorities, in partnership with Invision360. That involves special-category personal data about children and young people, handled under public-sector expectations for security, retention, access control and audit.

We treat that as the baseline standard for public-sector work rather than a special case.

Who at DIGI can access our data?

Access is limited to the named engineers working on your engagement, on a least-privilege basis, and is removed when someone leaves the project.

Production access is separate from development access. Where an engagement allows it, we prefer to work against anonymised or synthetic data and to keep production access exceptional, time-boxed and logged.

What happens to our data when the contract ends?

On termination we return or delete personal data at your direction, and confirm deletion in writing. The specific retention periods and the deletion route are set in the contract and the DPA rather than decided by us unilaterally.

AI-specific questions

The questions that a standard supplier questionnaire does not yet ask.

Is our data used to train AI models?

No. Client data is not used to train, fine-tune or improve any model, ours or a third party’s.

Where an engagement uses a commercial model provider, we configure the service so that submitted content is excluded from training, and we will state in the contract which provider is used and on what terms.

Does the AI make decisions about individuals?

No. We build systems that assist people, not systems that decide about them. Statutory and casework decisions remain with your officers.

Article 22 of the UK GDPR restricts solely automated decisions with legal or similarly significant effects. Our designs keep a person accountable for the outcome, and we document where that human decision point sits so you can evidence it.

How do you stop the system inventing information?

Answers are grounded in your authoritative systems rather than in the model’s general knowledge. The model retrieves approved information through a controlled interface and presents it; it is not the source of truth.

Where a request is sensitive, unsupported or uncertain, the system escalates to a person instead of guessing. We build that escalation path first, not last.

What controls sit outside the model?

Authentication, authorisation, data minimisation and allowlists are enforced by the platform, not by the model. A model instruction is not a security control.

The model has no direct database access and no unrestricted internal API access. Every interaction is auditable.

Can you audit an AI system we already run?

Yes, provided we did not build it. Our AI Assurance Audit reviews governance, risk, bias, data handling, transparency and human oversight independently.

We do not assure systems we built ourselves. Assurance depends on independence, and a supplier reviewing its own work is not providing any.

Security

How the software is built and what sits behind it.

What security expertise sits behind DIGI?

CHMS Cyber Security is our sister company, and Revelion, an autonomous AI penetration-testing platform, was designed and built in-house.

Security is not a discipline we buy in when a client asks about it, and penetration testing is not something we have to outsource.

How is security handled during the build?

Security, accessibility and infrastructure are part of the build rather than a phase added before go-live. That includes authentication and authorisation design, data minimisation, audit logging and dependency management.

We are happy for an authority to require independent testing before go-live and to see the results.

How do you handle a personal data breach?

As a processor we notify the controller without undue delay after becoming aware of a personal data breach, so that you can meet your own 72-hour reporting obligation to the ICO. We support the investigation and provide the technical detail your report needs.

We also publish a security.txt so that researchers can report a vulnerability to us directly rather than disclosing it publicly.

Accessibility

A legal requirement for public-sector services, not a preference.

Do you meet accessibility requirements?

We engineer to WCAG 2.1 AA, the standard commonly required in UK public-sector procurement, and we treat accessibility defects as defects rather than as feature requests.

This site is built to the same standard, and publishes its own accessibility statement including the measured contrast ratios behind our colour system.

Will you provide an accessibility statement for what you build?

Yes. Public-sector bodies are required to publish an accessibility statement for their services. We provide the technical content for it, including known limitations, and we would rather record a genuine limitation than claim full conformance we cannot evidence.

Commercial and contractual

How we contract, and who you are actually contracting with.

Which legal entity would we contract with?

UK public-sector work is contracted with CHMS Cyber Security Limited, registered in England and Wales under company number 15650214, with a registered office at 85 Great Portland Street, First Floor, London, England, W1W 7LT. DIGI is a trading brand of that company.

Do you own the software you build for us?

Under a Build engagement you commission the software, pay a fixed price for a fixed scope, and hold the intellectual property and the source code from the outset.

Where a client would rather not carry the whole build cost up front we can agree a different commercial structure, but that is an option we offer, never a condition of working with us.

Are you a small supplier, and does that carry risk?

We are a small, senior team. We would rather state that plainly than imply a scale we do not have.

The mitigations we can evidence are: you hold the source code and the intellectual property, we document the architecture as we build, and we design engagements to transfer capability into your team rather than to create dependency on us. Where continuity matters, we will agree escrow or handover terms in the contract.

Need this in your own format?

We are used to completing supplier questionnaires, security schedules and DPIA templates in whatever form a framework or authority requires. Send us the template and we will fill it in properly rather than returning marketing copy.

Or email ask@chmsdigi.com.