Privacy and data
Clear information about how your data is used.
This page explains what the current AI Apprenticeships service collects, where information goes and what happens when you ask for human follow-up.
Last updated 24 September 2026
01 / Information
Information we handle
We handle information that you choose to provide through the site. Depending on the feature, this can include:
- your name, email address, organisation, job title and visitor or audience type;
- messages, enquiry details and the kind of advice or follow-up you request;
- Ask Marls questions, replies and the context needed to classify and continue a conversation;
- Capability Check answers and results when you explicitly submit them for independent review;
- member Strategy Builder inputs, generated briefs and saved strategy records; and
- your email address and subscription status when you join the weekly briefing.
Server handlers also process basic request information where needed to validate submissions, reject spam and limit immediate duplicate Ask Marls requests.
02 / Ask Marls
What happens in an Ask Marls conversation
Before the current Marls experience starts, it asks for a first name, work email and organisation. A last name, job title and visitor type can also be supplied. These details are sent through a server-side handler and stored in the Supabase Marls CRM.
- 01
AI response. Recent conversation messages are sent to the OpenAI Responses API with context such as name, organisation, role and visitor type. The current model prompt does not add the visitor's email address.
- 02
CRM record. The recent messages used for a response are stored in Supabase with a summary and service-generated fields such as intent, industry, organisation size, recommended route, lead score and whether the Marls response surfaced adviser support.
- 03
Human follow-up. If you request an adviser discussion, the request email includes your contact details, what you want help with and a lightweight conversation summary, topics and suggested next steps. The full transcript is not included in that email.
Ask Marls is an AI guide, not a private messaging channel. Avoid entering sensitive personal, confidential or special-category information that is not needed for your question.
03 / Capability Check
Assessment answers are submitted only when you ask for review
The Current AI Capability Check calculates its scores and narrative results in the page while you complete it. Completing or viewing the result does not itself send your answers to the server.
If you complete the independent-review form, the contact and organisation details, selected answers, calculated results, priorities and surfaced programme routes are sent to the assessment review handler. The submission is delivered to the adviser through Resend and stored in Supabase.
04 / Browser and account
Browser storage and sign-in
Ask Marls keeps the visitor details and related record identifiers in browser session storage so it can recognise the visitor during the browser session. Its conversation messages are held in the page while chatting, and the recent context used for each response is separately saved to the Supabase CRM as described above.
The Capability Check uses in-page state for answers and does not put those answers into local or session storage. Reloading or leaving the page can therefore clear an assessment that has not been submitted.
Member sign-in uses Supabase authentication and the cookies needed to maintain a signed-in session. The Strategy Builder also keeps saved strategy drafts in browser local storage and can associate saved strategies with the signed-in member in Supabase.
05 / Services
Services used to run the site
Supabase
Authentication and storage for Marls CRM records, submissions, subscriptions and member strategy records.
OpenAI
Generation of Ask Marls responses and Strategy Builder briefs or refinements from the content supplied to those features.
Resend
Delivery of requested contact and adviser emails, subscription confirmations and weekly briefing emails.
Vercel
Hosting and execution of the website and its server-side handlers.
06 / Access and email
Who can access records and when email is sent
Marls CRM tables use Supabase row-level security. An authenticated account does not automatically receive access: reading contacts, conversations and opportunities requires that account to be listed as an authorised Marls administrator. Server-side handlers use restricted server credentials to create and update records for the public workflows.
Member Strategy Builder records are associated with the member account and protected by member-specific access policies. Other public contact and review forms submit through their intended server handlers rather than exposing stored records in the browser.
Resend is used when you take an action that requires email delivery—for example submitting a contact or adviser request, requesting a Marls or assessment review, or subscribing to the weekly briefing. Newsletter emails include an unsubscribe route that updates the subscription record in Supabase.
07 / Your choices
Questions, access, correction or deletion
The current service does not apply one published automatic retention period to every kind of record. If you want to ask what information is associated with you, request access, correct inaccurate information or request deletion, contact us using the address below. We may need enough information to locate the relevant record and verify the request.
james@mprconsulting.co.ukYou can also use the contact form for a general privacy question, but email is the clearest route for a request about an existing record.