Privacy Policy

Privacy Policy

Effective from: 20 Aug 2026

This page gives a clear, quick overview of our Privacy Policy, explaining how we take care of your data, including how we use artificial intelligence (AI) when processing it. If you'd like a more in-depth look, you can read the full Privacy Policy document linked below.

Keeping data secure How we use AI Your rights

Security comes first

Every choice we make about your data — where it lives, who can access it, and how it's used — starts from security, not convenience.

Nothing trains on your data

Every AI tool we use is set up so your charity's information isn't kept after processing and is never used to train or improve AI models.

Kept on trusted infrastructure

Your records live on systems we own and operate, or reputable cloud hosting.

Keeping your data secure

We apply the same standard we'd want if it were our own charity's money and records.

Where does our data actually live?

On infrastructure we physically own and control ourselves, plus reputable cloud hosted systems we've chosen for its security credentials.

Who at PDMA can see our charity's records?

Only the staff actually working on your account, or people you authorise us to give access to it (for example, your year-end accountant). Access is role-based, so it's limited to what someone genuinely needs to do their job.

What happens if something goes wrong?

We'd report any data breach that puts your rights at risk to the ICO within the legal timescale, and tell you directly if you're affected.

What software does PDMA actually run on?

A small, fixed set we've vetted ourselves — for bookkeeping, secure file storage, client support, and internal communication. The full list is in our full policy.

The Use of AI in Our Company

AI plays a supporting role in how we work — it never replaces professional judgement or handles your bookkeeping on its own.

How do you use AI?

In a limited, deliberate way — for things like searching, summarising, analysing and quality-checking information faster. This allows us to deliver a higher quality, more efficient, more effective, and cost-efficient service to you.

Who's accountable for what AI produces?

We are, always. Nothing AI touches — a summary, a flagged discrepancy, a draft report — goes to you or into your accounts until a person has checked it. AI never has the final word, and it never acts on your account on its own.

Is our data used to train AI models?

No. Our AI providers process data only on our instructions, under written data processing agreements — and we route only to AI models whose providers do not use customer data to train or improve their models.

How long do AI tools hold on to our information?

They don't keep it. Our AI routing is configured for zero data retention — your information is processed to complete the task in front of it, and isn't logged or stored by our providers afterwards.

Could our data leave the UK when AI is involved?

Our default is to keep data on servers based in the UK or EU. Where a sub-processor does send data outside the UK, we only use one with a recognised transfer safeguard already agreed — such as the UK's International Data Transfer Addendum — before any data moves.

Do you use everyday AI chat apps on our data?

No. Consumer AI tools are prohibited within our company — our staff are not permitted to use personal or consumer AI agents for client work. Anything AI-assisted runs only through our carefully vetted, contracted business-grade tools.

Your rights

How do I find out exactly what you hold about our charity?

Ask us — use the contact link below. If we're processing data on your charity's behalf, your trustees can also request this directly, since your charity remains the data controller.

Where can I read the actual policy?

Right here — the button below takes you straight to it.

Want to read the full policy, or have a question of your own?

Read the full policy Ask us a question