Thirty-four answers about how this firm works, what things cost, what AI can and cannot do, and how we handle your data. Written to be useful before you contact us, not to make contacting us the only way to find out.
This page answers thirty-four of the questions we are asked most often about working with Green Arrow Consultancy. It covers who we are, how engagements start, how we price work, what AI can and cannot do, how we handle your data and your access, and what is realistic in AI search visibility. If your question is missing, ask it.
Who you would actually be dealing with, and how to verify it without taking our word for it.
Green Arrow Consultancy is a UK AI agency and digital consultancy. Darren Tyler founded it in 2012 and it was incorporated as a limited company in 2020. The firm builds production AI systems, builds and manages websites, and runs privacy, consent, analytics and accessibility programmes for global consumer brands and mid-market organisations. The order of that history matters: websites first, privacy engineering from the arrival of GDPR, applied AI on top of both. You can see the whole range on the services page.
The registered office is Sophia House, 28 Cathedral Road, Cardiff, CF11 9LJ, Wales. We work across the UK, the USA, the EU, Asia Pacific, the Middle East, South America and South Africa. Roughly half of the client base is in the United States. Multi-country delivery is normal here: campaigns across thirteen European countries, and a site estate that has included Asia Pacific since 2017. Meetings happen in your working hours, not ours.
Small and senior, by design. Darren Tyler is founder and chief executive, Carol Tyler is a director and Paul Knowlson handles business development, supported by specialist contractors for particular disciplines. The business is owned and run by the people who do the work, so there is no account management layer between you and whoever is building the thing. We do not staff an engagement with juniors and invoice them as specialists. More on the team is on the about page.
Green Arrow Consultancy Ltd, company number 12491770, VAT number 344486874, ICO data protection registration ZA822868, registered in Cardiff. All three are checkable on Companies House and the ICO register without asking us. The firm is a member of the International Association of Privacy Professionals, and in 2024 formed a partnership with the UpGuard security platform. We are not a law firm and do not give legal advice; we do the engineering and programme work alongside your counsel.
Consumer products and retail is the deepest vein: Energizer Holdings, Varta, Rayovac, Eveready, Armor All, STP, Jelly Belly, Eagle One, California Scents and others. Beyond that, market research and data with Circana, property with Healey Fox, retail with Neiman Marcus Group, and food and gifting with Scottish Hampers. The AI work has been deployed into consumer goods, industrial and manufacturing, hospitality, healthcare, financial services, education and legal. See the case studies.
How engagements start, how long they run, who owns what at the end.
With a conversation about the symptom, not the solution. Tell us what is going wrong, who it affects and what would count as fixed. If it is obvious and bounded, such as a consent deployment or an accessibility audit, we quote it there. If it is not, the next step is a fixed-price discovery that produces a written scope, a cost and a recommendation. An NDA can be in place before the first call if you need one.
Two to three weeks of looking rather than talking. We inventory the systems, get read access to the content and the codebase, map the data flow, review the analytics and consent setup, and interview the people who do the work today. The output is a written scope with costs, a risk list, and an honest recommendation that sometimes says the thing you asked for is not the thing you need. It stands on its own, so you can take it to another supplier.
Audits run one to three weeks. A consent management deployment on a single site takes days; across an estate it takes weeks. Websites usually run eight to sixteen weeks depending on templates, languages and integrations. A scoped AI system reaches a production pilot in six to twelve weeks. In almost every case the slow part is access to content and systems, not the build, which is why discovery starts with access.
Yes, and a good share of the work arrives that way. Agency assistance has been part of this business since the beginning, and we are used to being the specialist layer for privacy, accessibility, build or applied AI inside somebody else's client relationship. We can be white-labelled or named, we work to your project management, and we do not pitch your client behind your back.
Yes to both, routinely. Where our work involves personal data we act as a processor under a data processing agreement setting out purpose, categories, retention, sub-processors and security measures, and we hold ICO registration ZA822868. We will also complete supplier security questionnaires and vendor onboarding forms. If your legal team prefers your own paper, we work from your templates rather than insisting on ours.
You do. Deliverables transfer to you on final payment, the source lives in a repository you control, and there is no proprietary runtime you have to keep renting from us to run your own system. Third-party licences and open-source components are listed so you know exactly what you have. Where we bring pre-existing tooling, it is licensed to you for the delivered system rather than withheld. This goes in the contract, not a handshake.
Handover is a pack, not an email: documentation, runbooks, architecture notes, credentials transferred into your own vault, third-party licence list, and for AI work a model card, prompt set and the evaluation harness. A working session with the team who will own it is included. Retainers are optional and monthly, covering hosting and maintenance, change requests, monitoring and regression evaluation as vendor models update.
Most questions about cost are really questions about shape. These five cover almost everything we sell.
| Shape | Price model | Typical length | What you walk away with |
|---|---|---|---|
| Discovery | Fixed price | Two to three weeks | Written scope, costed options, risk list and a recommendation you can take elsewhere |
| Audit | Fixed price | One to three weeks | Findings with severity, effort and cost, for privacy, consent, accessibility or AI security |
| Build | Fixed price after discovery | Six to sixteen weeks | A working system, documentation, an accessibility pass and, for AI, an evaluation set you own |
| Retainer | Monthly, rolling | Ongoing | Hosting, patching, change requests, monitoring and regression evaluation with a named contact |
| Training and enablement | Fixed price | One to three days | Your team working on your own system, plus the runbooks they need afterwards |
Lengths are typical rather than promised. The variable that moves them most is how quickly we get access.
We will not publish a price list for work whose scope we have not seen. Here is how the numbers are actually built.
Three ways. Discovery and audits are fixed price and quoted up front. Build work is fixed scope and fixed price, quoted after discovery, because a number produced before anyone has seen the codebase or the content is a guess dressed up as a quote. Ongoing work is a monthly retainer sized to the estate. We avoid open hourly billing on defined scope, because it puts the risk of our own estimating errors on you.
It depends on things we can only see by looking: how many templates, how many languages, how much content has to be migrated or rewritten, which systems it integrates with, and what accessibility conformance level you need. A single-language brochure site and a multi-country estate with a product database differ by an order of magnitude. We quote after a scoping call, and we will tell you where a platform such as WordPress or Shopify saves you money over a bespoke build.
Three components. A fixed-price discovery. A build quoted per system after discovery. Then running costs: model usage, hosting and an evaluation retainer. The cost drivers are almost never the model. They are the state of your content, how complicated the permission model is, and how many systems it has to integrate with. Model prices fall over time; the content and permissions work does not. See AI consulting for how the phases break down.
It scales with the number of websites, jurisdictions and third-party vendors in scope. Deploying a consent management platform on one site is a small piece of work. Doing it across a two hundred site estate with regional legal differences is a programme. Platform licences for Osano or OneTrust are bought by you directly from the vendor, so our fee covers the implementation, the tag governance and the ongoing maintenance, not a resale margin.
Number of sites, languages and jurisdictions. Integrations with systems that have no documentation. Content that has to be rewritten before it can be migrated or retrieved. Complicated permission models. A long approval chain with several stakeholders who each want a say. Fixed external deadlines. What brings a quote down: one decision maker, access granted in the first week, and a willingness to release in phases rather than all at once.
What is realistic, what is oversold, and what we do to keep a system honest. More detail on AI consulting.
Reliably: answer questions from your own documents with citations, triage and route incoming work, draft replies for a human to approve, extract structured data from unstructured documents, search across systems that do not talk to each other, and handle image and document input at volume. Unreliably: anything requiring judgement about people, anything where you have no agreed definition of a correct answer, and anything built on data that is already wrong. AI amplifies the state of your information; it does not improve it.
Any language model can. Engineering decides how often, and whether anyone notices. We ground answers in retrieved passages of your own content rather than model memory, attach a citation to every claim so a human can check it in one click, and explicitly test that the system refuses when retrieval returns nothing relevant. On top of that sits an evaluation set built from your real questions that runs on every change, so quality is a number rather than an impression.
Not on the configurations we deploy. We use enterprise API tiers with training opt-out, keep retrieval corpora inside your tenancy or ours under contract, encrypt in transit and at rest, and document the whole data flow in a record of processing before anything goes live. Access is scoped by role so the system cannot answer from documents the person asking may not read. Privacy engineering is what this firm grew out of, so see privacy consulting and AI security.
We are model-agnostic and choose per workload. Most production systems we run use Anthropic's Claude models for instruction following and long-context behaviour, with cheaper and faster models routed the simpler traffic, and open-weight models deployed on infrastructure you control where data residency or unit cost demands it. Almost nobody needs their own model. Fine-tuning is proposed far more often than it is the right answer, and retrieval usually solves the problem for less money.
Retrieval-augmented generation, or RAG, is the pattern where the system searches your own content for relevant passages, then asks the language model to answer using only those passages. The model supplies language and reasoning; your documents supply the facts. It is cheaper than fine-tuning, updates the instant your content does, and produces citations a person can verify. It is the backbone of most of the systems we put into production, including the ones running as demos under Neuro.
Vendors retire models on their own schedule and give you months, not years. We build so the application layer, the retrieval layer and the evaluation layer sit apart from the model, which makes a swap a configuration change plus a re-run of the evaluation set rather than a rebuild. On a retainer that migration is routine work we do for you. A system that cannot survive a model change is a liability nobody warned you about at the time of sale.
Usually, and the first step is measurement rather than surgery. We build an evaluation set from your real transcripts so improvement can be proved. The recurring findings are the same: no grounding in real content, no permission awareness, poor chunking so retrieval returns the wrong passage, no refusal behaviour, and no logging to learn from. Fixing retrieval and adding citations usually moves quality more than changing the model does. See AI consulting.
The half of the business that predates the AI work, and the reason the AI work is built the way it is.
Privacy has been a core practice here since the run-up to GDPR, and it is now most of what the trust side of the firm does: records of processing, data protection impact assessments, vendor and sub-processor review, subject rights handling, consent architecture and the engineering remediation that follows an audit. We work under UK GDPR and EU GDPR, and across US state privacy laws for the American half of the client base. We are not a law firm, so we work with your counsel rather than replacing them.
We do not take statutory DPO appointments as a matter of course. What we do is act as the engineering and programme arm alongside your DPO, your general counsel or your external legal adviser, producing the artefacts the role depends on: the data map, the record of processing, impact assessments, vendor assessments and the technical remediation plan. Where no DPO exists yet, we can run the programme and leave you with the documentation an appointed officer would need on day one.
A data protection impact assessment is a structured written analysis of how a processing activity affects people, what could go wrong and what you are doing about it. Under UK GDPR it is required when processing is likely to result in high risk, which covers large-scale processing, systematic monitoring and automated decisions with significant effects. Most AI systems that touch personal data need one. We produce it as part of AI governance, before launch rather than after.
Named accounts in your own identity provider, never shared logins. Least privilege, so we get the access the task needs and nothing else. Multi-factor authentication throughout. Secrets live in a password manager, never in email or chat. Access is reviewed during the engagement and revoked at handover, with a written list of who held what. The 2024 partnership with the UpGuard security platform supports the supplier and attack surface side of this.
Start with an inventory: every AI system in use, including the ones bought inside other software without anyone calling it AI. Then classify each by risk tier, since obligations follow the classification. Transparency duties apply to user-facing generative systems, and higher tiers add technical documentation, human oversight, logging and post-market monitoring. ISO/IEC 42001 and the NIST AI Risk Management Framework are the frameworks we map controls to. This is the whole of AI governance and compliance.
Commercial terms, including insurance cover, liability caps and indemnities, are confirmed during contracting and evidenced with certificates on request through your procurement process. We do not publish policy values on a web page, because the number that matters is the one written into your contract. We also complete supplier security questionnaires, vendor risk assessments and onboarding portals as a normal part of getting started with larger clients.
Being described accurately by ChatGPT, Claude, Gemini and Perplexity, and what can honestly be promised about it.
Generative engine optimisation, GEO, is the work of making sure AI answer engines describe your organisation accurately and cite your pages. The engines that matter are ChatGPT, Claude, Gemini, Perplexity and Google's AI overviews. The work is entity clarity, structured data, content shaped so a passage can be lifted and attributed, machine-readable source availability, and corroboration on third-party sources the models already trust. It is covered by AI search optimisation.
They share foundations and diverge at the goal. Classic search optimisation competes for a position in a list of links and is measured in clicks. Generative optimisation competes to be retrieved, quoted and cited inside a synthesised answer, where there may be no click at all. Crawlability, structure, speed and clarity help both. What is specific to GEO is consistent entity description across the web, extractable answers near the top of a page, and being the source other sources agree with.
No, and anyone who guarantees it is selling something. Nobody outside those companies controls what their systems retrieve or how they were trained, outputs vary by user, by session and by model version, and the engines change their behaviour without notice. What is honest to promise is measurable improvement: more frequent inclusion, more accurate description and more citations across a defined set of questions your buyers actually ask, tracked over time.
Define the questions your buyers ask, run them across the engines on a schedule, and record four things for each: are you present, is the description accurate, what sentiment does it carry, and is your site cited. That gives a baseline you can move. Factual corrections often land within weeks as sources are re-crawled. Entity consistency and third-party corroboration take a quarter or more, and anything dependent on training data is slower still.
None of this is mandatory. All of it makes the first conversation shorter and the quote more accurate.
Ask it directly. If it is a good one it usually ends up on this page, and you get the answer either way. No form gate, no drip sequence.