Data & AI Practices
Effective: August 27, 2026
What this document covers
These practices describe the default operating standards FarmTable applies when evaluating, teaching, designing, or building with data and AI. The Privacy Policy governs personal information collected through the website. A signed client agreement, statement of work, security schedule, or data-processing agreement may add stricter requirements for a particular engagement.
Start with the problem and the boundary
We define the intended user, business purpose, inputs, outputs, decisions, and unacceptable uses before choosing a model or tool. We prefer the smallest system that can produce a useful, testable result and we say plainly when a checklist, process change, conventional software, or better data is a better answer than AI.
We identify where human judgment must remain, what the system may recommend or draft, what it may never decide, and how a person can refuse, correct, or stop the workflow.
Data minimization and client control
We request only the data reasonably necessary for the agreed work. Wherever practical, work occurs in client-owned accounts and environments with access limited by role, time, and purpose. We do not take copies merely for convenience and we do not reuse one client's confidential data for another client.
Access, storage location, permitted uses, subprocessors, retention, return, and deletion are defined in the governing agreement when client data is involved. Credentials should be provided through an approved secure method, never through a public website form or ordinary email.
Selecting and configuring AI tools
Tool selection considers data-use terms, model-training settings, retention controls, access management, security documentation, deployment location, reliability, cost, and the sensitivity of the proposed use. Consumer accounts are not used for confidential client data.
We use business or enterprise controls when the work requires them and disable provider training or data reuse where the service and engagement require that setting. A provider is not treated as safe merely because it is popular or describes itself as enterprise-ready.
Human review and evidence
A named person remains accountable for every deliverable and consequential action. AI output is treated as a draft, hypothesis, extraction, or recommendation until the required review is complete.
Where accuracy matters, we preserve or link to source material, test representative and difficult examples, make uncertainty visible, and document known limitations. We do not present generated citations, calculations, legal conclusions, or factual claims as verified without checking them.
Automation and agent safeguards
Automated workflows begin with the least authority needed, such as read-only access, draft-only output, test data, or a limited set of records. Additional authority is earned through testing and explicit approval, not assumed from a successful demonstration.
Safeguards may include approval checkpoints, allowlists, spending or volume limits, logging, monitoring, exception queues, reversible actions, timeouts, and a practical stop mechanism. We do not deploy an autonomous system without an identified owner, operating boundary, and response plan.
Sensitive and high-impact uses
Uses involving health, employment, education, housing, lending, insurance, legal rights, public benefits, biometric identification, children, precise location, or similarly significant decisions require heightened review and may be declined. FarmTable does not use AI to make final decisions in these areas on behalf of a client.
We do not build deceptive impersonation, unlawful surveillance, discriminatory profiling, hidden manipulation, credential theft, or systems designed to evade legal or platform safeguards.
Security and incident handling
We use reasonable safeguards appropriate to the engagement, which may include least-privilege access, multifactor authentication, encryption in transit, separation of environments, dependency and secret management, backups, logging, and removal of access at handoff.
Suspected unauthorized access, disclosure, model misuse, or material failure is investigated promptly. We preserve relevant evidence, contain access where practical, notify the appropriate client contact, and follow contractual and legal notification duties.
Ownership, documentation, and handoff
The governing agreement defines ownership and licenses. Our default delivery goal is a system the client can understand and operate: source or configuration as agreed, architecture and data-flow notes, setup instructions, limitations, review points, monitoring guidance, and an exit or rollback path.
At handoff we remove FarmTable access that is no longer needed and return or delete working material according to the agreement. Ongoing access requires an active support scope.
Training and public examples
Classes and public demonstrations use fabricated, licensed, public, or deliberately deidentified material. Participants are told not to expose confidential, regulated, or client data. Examples are labeled as examples and are not presented as client results without written permission.
Questions or concerns
Questions about these practices, a proposed use, or a concern about FarmTable's handling of data or AI may be sent to info@farmtable.ai.
Questions or requests related to this policy may be sent to info@farmtable.ai. FarmTable AI Lab, LLC is a Texas limited liability company.
