Eleven services, three families, one accountable team. We build production AI, we build and run the websites it lives on, and we do the privacy, consent and accessibility work that decides whether either of those survives a legal review.
Green Arrow Consultancy runs eleven services in three families: AI and automation, web and digital, and trust and compliance. The same team builds the AI, the website it sits on, the analytics behind it, and the privacy, consent and accessibility work that keeps all three defensible. Start with one. Most clients add the others.
Most firms in this market pick a lane. An AI shop that has never had to make a consent banner block a tracker. A web agency that treats accessibility as a plugin. A privacy consultancy that writes a policy and leaves the engineering to somebody else. Each of those gaps has a cost, and the cost usually lands on the client at the worst possible moment.
We do the three together because the work is genuinely the same work. A retrieval assistant is only correct if it respects the permission model of the systems it reads from, which is a privacy engineering problem before it is a model problem. An AI interface that cannot be operated with a keyboard fails WCAG 2.2 and is unusable for a chunk of your staff, which is an accessibility problem you find in week one or in the audit. Analytics that ignore consent produce numbers you are not allowed to act on.
The order of that history matters. Green Arrow Consultancy started in 2012 building websites, took on more than thirty Energizer sites in 2014, added Asia Pacific in 2017, began privacy work around the arrival of GDPR, and passed two hundred managed websites in 2022. Applied AI came last, on top of a decade of running other people's estates under real compliance pressure. That is why our AI engagements start with data flow, access and evaluation rather than with a model choice.
The practical effect for a buyer is that one contract covers the whole failure surface. When the consent platform update breaks a tag, when an accessibility complaint arrives, when the EU AI Act questionnaire turns up in procurement, and when the assistant starts answering from a document it should not have read, the same team owns all four. Nobody gets to say it is the other supplier's fault.
Five services covering what an AI system needs to be useful, safe and defensible. They are sold separately and they are usually bought in that order.
Strategy, design, build and operation of production AI systems. Retrieval assistants, document AI, enterprise search and customer-facing assistants, grounded in your content and evaluated against your real questions.
When the requirement is not an answer but an action: raise the ticket, draft the reply, reconcile the list. Every action logged, reversible and scoped to what the agent is permitted to touch.
Generative engine optimisation. Getting ChatGPT, Claude, Gemini and Perplexity to describe your organisation accurately, cite your pages and stop repeating a competitor's framing of your market.
Prompt injection, data exfiltration, tool abuse and over-permissioned agents, tested against the OWASP Top 10 for LLM Applications before somebody less friendly finds them first.
The EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework translated into an inventory, a risk classification, human oversight design and controls your team can actually run.
Build it, run it, measure it. This is the oldest part of the business and it funds the engineering discipline the AI work inherits.
Websites and web applications built for speed, accessibility and measurement. WordPress, Shopify or a bespoke stack, chosen for who has to maintain it after we hand it over, with Core Web Vitals treated as a requirement rather than a report.
Hosting, updates, security patching, content changes, uptime and the unglamorous maintenance that keeps an estate alive. We have run portfolios past two hundred sites, across multiple regions and languages.
Google Analytics 4, Google Tag Manager and server-side tagging configured so that measurement survives consent, respects the choices people actually made, and still answers the commercial question you had.
The services that decide whether the rest of your digital estate is defensible. This firm is an IAPP member and holds ICO registration ZA822868.
UK GDPR, EU GDPR and US state law programmes: records of processing, data protection impact assessments, vendor review, subject rights handling and the remediation work that follows the audit.
Osano and OneTrust are the two consent platforms we deploy most often. The job is blocking trackers before consent, not adding a banner to a site that fires everything anyway.
WCAG 2.2 and EN 301 549 audits with axe and manual keyboard and screen reader testing, then the remediation, then the European Accessibility Act paperwork that follows.
The symptom that brought you here usually names the service. This is the mapping we use on a first call.
| If this is true right now | Start here | Why this one first |
|---|---|---|
| Nobody can say where personal data goes | Privacy consulting | A record of processing is the map everything else is planned from, including AI |
| The cookie banner exists but nothing is blocked | Consent management | A banner that does not block trackers is worse than none: it documents the breach |
| An AI answer about your company is wrong | AI search optimisation | Buyers are reading that answer today, and it is cheaper to fix than to outrank |
| A team repeats the same task every week | AI agents | Repeatable, rule-bounded work is where automation pays back fastest and safest |
| You have a pilot nobody uses | AI consulting | The failure is almost never the model. It is access, retrieval, permissions or adoption |
| Procurement sent an EU AI Act questionnaire | AI governance | You need an inventory and a risk classification before you can answer honestly |
| A user complained they cannot use the site | Accessibility | A complaint is a deadline. An audit converts it into a scoped, costed list |
| Reporting stopped making sense after consent | Ethical analytics | Consent mode and server-side tagging recover most of what looked lost |
If two rows are true at once, the privacy or accessibility one usually goes first, because both carry a legal clock.
Four shapes cover almost every engagement. The pricing model follows the shape, not the service.
Two to three weeks. We look at the systems, the content, the data flow and the people who do the work today, then produce a written scope, a cost and a recommendation. Discovery is a deliverable in its own right: if you take it and build elsewhere, it still stands up. Sometimes the recommendation is that you do not need the thing you asked for.
A fixed scope, a fixed price and a named delivery window. Larger programmes run as a sequence of releases rather than one long build, so something useful lands early and the direction can change on evidence. Every build ships with documentation, an accessibility pass and, for AI work, an evaluation set you own.
For estates and for anything with a model in it. Covers hosting and patching, content and change requests, consent platform maintenance, regression evaluation as vendor models update, and a named person who answers the phone. This is how the two hundred site portfolio is run and it is the least glamorous, most valuable thing we sell.
Accessibility, privacy, consent, AI security or a full digital estate review. You get a findings list with severity, effort and cost. You are free to hand it to your own team or another supplier. We would rather be the firm whose audit was worth paying for than the firm whose audit was a sales document.
Both lists are honest. The second one saves everybody a fortnight.
Thirty-four more answers, including cost, contracting and AI specifics, are on the full FAQ.
No. Most engagements start with a single service and a single problem. The families exist because the problems overlap, not because we bundle. A consent implementation stands on its own; so does an accessibility audit or a retrieval assistant. What you get by using one firm across several is that nobody can point at somebody else when the consent banner breaks analytics or the AI assistant fails a keyboard-only test.
Start where the risk or the cost is loudest this quarter. If a regulator, a customer or a procurement questionnaire is the pressure, start with privacy or accessibility. If the pressure is commercial, start with AI search visibility or the website itself. If a team is drowning in repeatable work, start with agents. The table above maps the common symptoms.
Frequently. Agency assistance has been part of this business since the beginning, and a good share of our work arrives through creative and media agencies who need a specialist privacy, accessibility, build or AI layer they do not staff internally. We can be white-labelled or named, we work to your project management and we do not pitch your client behind your back.
Yes, and a large part of the managed portfolio arrived that way. Takeover starts with an audit: hosting, domains, certificates, dependencies, plugins, analytics, consent, accessibility and whatever documentation exists. You get a written findings list with severity and cost before anything is changed, so the decision to remediate or rebuild is made on evidence rather than on our preference.
Yes. We are based in Cardiff and work across the UK, the USA, the EU, Asia Pacific, the Middle East, South America and South Africa. Roughly half the client base is in the United States. Multi-country work is normal here: we have run campaigns across thirteen European countries and managed site estates in Asia Pacific, so jurisdictional differences in privacy and accessibility law are part of the day job.
Discovery and audits are fixed price. Build work is quoted after discovery, because a quote given before anyone has seen the content, the codebase or the data flow is a guess dressed as a number. Ongoing work is a monthly retainer sized to the estate. The FAQ goes into what moves a quote up and what we will not quote on before looking.
Mid-market organisations and the regional or divisional teams of large enterprises. We have worked with Fortune 500 brands including Energizer Holdings and with owner-managed firms such as Healey Fox, and the method does not change much: find the real constraint, fix it, document it, hand it over. Very small organisations are usually better served by a product than by a consultancy, and we will say so.
Yes. Privacy-first training and applied AI enablement are both delivered as standalone engagements, usually alongside a first build so the team learns on their own system rather than on a generic example. Handover documentation, runbooks and an evaluation set come with every build regardless, because a system nobody internal can operate is a dependency, not an asset.
Describe the symptom rather than the solution. We will tell you which of the eleven applies, which of them you can skip, and what a first engagement would cost.