Privacy Policy
Privacy Policy
Effective from: 20 Aug 2026
This page gives a clear, quick overview of our Privacy Policy, explaining how we take care of your data, including how we use artificial intelligence (AI) when processing it. If you'd like a more in-depth look, you can read the full Privacy Policy document linked below.
Keeping data secure How we use AI Your rights
Every choice we make about your data — where it lives, who can access it, and how it's used — starts from security, not convenience.
Every AI tool we use is set up so your charity's information isn't kept after processing and is never used to train or improve AI models.
Your records live on systems we own and operate, or reputable cloud hosting.
We apply the same standard we'd want if it were our own charity's money and records.
On infrastructure we physically own and control ourselves, plus reputable cloud hosted systems we've chosen for its security credentials.
Only the staff actually working on your account, or people you authorise us to give access to it (for example, your year-end accountant). Access is role-based, so it's limited to what someone genuinely needs to do their job.
We'd report any data breach that puts your rights at risk to the ICO within the legal timescale, and tell you directly if you're affected.
A small, fixed set we've vetted ourselves — for bookkeeping, secure file storage, client support, and internal communication. The full list is in our full policy.
AI plays a supporting role in how we work — it never replaces professional judgement or handles your bookkeeping on its own.
In a limited, deliberate way — for things like searching, summarising, analysing and quality-checking information faster. This allows us to deliver a higher quality, more efficient, more effective, and cost-efficient service to you.
We are, always. Nothing AI touches — a summary, a flagged discrepancy, a draft report — goes to you or into your accounts until a person has checked it. AI never has the final word, and it never acts on your account on its own.
No. Our AI providers process data only on our instructions, under written data processing agreements — and we route only to AI models whose providers do not use customer data to train or improve their models.
They don't keep it. Our AI routing is configured for zero data retention — your information is processed to complete the task in front of it, and isn't logged or stored by our providers afterwards.
Our default is to keep data on servers based in the UK or EU. Where a sub-processor does send data outside the UK, we only use one with a recognised transfer safeguard already agreed — such as the UK's International Data Transfer Addendum — before any data moves.
No. Consumer AI tools are prohibited within our company — our staff are not permitted to use personal or consumer AI agents for client work. Anything AI-assisted runs only through our carefully vetted, contracted business-grade tools.
Ask us — use the contact link below. If we're processing data on your charity's behalf, your trustees can also request this directly, since your charity remains the data controller.
Right here — the button below takes you straight to it.