Governance, in the open
Documents & Policies
This is the live governance library for JonnyAI — the agency, the BizOS platform and the wider software line. Twelve governing policies say what must be true; fourteen standard operating procedures say how it’s done. They are published here because customers in regulated sectors deserve to see how the platform holding their data is actually run — not a summary of it.
Version 1.0 · effective 13 July 2026 · reviewed annually and after any material change. The source of truth lives in version control; this page tracks it.
Governing policies
What must be true, always — security, data protection, AI governance, continuity and the rest.
The whole security posture: least privilege, tenant isolation, mandatory controls across every account and asset.
Personal data as controller and processor under UK GDPR — including special category care data, subject rights and breach clocks.
Rules for using company systems, accounts and devices — written so the first collaborator inherits them on day one.
Who can reach what: BizOS product roles enforced down to the database, and operational access to the infrastructure.
How the AI is governed: deterministic engines as source of truth, confirm-steps on every action, data minimisation to models, the HMRC red line.
How code reaches production: the four gates, change classes, standing engineering rules and supply-chain discipline.
Keeping the platform and business running: RPO/RTO, continuity scenarios, and the sole-operator contingency.
Classifying and governing incidents: severity classes, non-negotiable duties, evidence handling and external reporting.
Subprocessors and vendors: the authoritative register, selection and exit rules, fail-open vs fail-closed.
How long data lives and how it dies: the retention schedule, deletion standards and the keep-less rule.
The live risk register: 5x5 scoring, appetite, and escalation rules.
PECR-compliant marketing: consent-first, tokenised unsubscribe, honest outbound and the platform's own campaign guarantees.
Standard operating procedures
How the work is actually done — onboarding, deployment, incidents, support, billing, offboarding.
New BizOS customer or pilot: self-serve and assisted onboarding, DPA discipline, the go-live checklist.
The strict per-module order from migration to gates, with the governance hooks bound in.
Shipping to production: pre-deploy gates, the SSH fast-forward deploy, the smoke test and rollback.
Schema changes: numbered, idempotent, RLS on every table, forward-only.
Outage, security event or data breach: first five minutes, containment moves, comms and close-out.
What is backed up and by whom, the monthly check, surgical and full restores, the annual drill.
Customer support channels, response targets, working inside tenant workspaces, ticket records.
Stripe events, plan changes, dunning, refunds, reconciliation and the founding-price promise.
Where secrets live, the register, rotation cadences and guard rails.
Cancellation or deletion request: exports, the 90-day clock, what survives deletion.
Any JonnyAI agency project: brief to proposal to delivery rhythm to handover and ownership defaults.
New prospect to tailored demo to pilot — the Southernbrook method.
Adding or changing anything JonnyAI can see (signals) or do (actions).
The scheduled automation lines: rules, the weekly check, and runaway containment.
Annexes
Governance for the other trading activities.
Questions about any of these — including data processing agreements for BizOS workspaces — go to hello@jonnyai.co.uk.
See also the customer-facing Privacy Policy and Terms.