Privacy Policy
Privacy Policy
← Back to Privacy & Security overview
Effective from: 12 Feb 2025 · Last updated: 2 Sep 2026
PD Marfleet Accounting Limited ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, process, dispose of, and protect information that relates to an identified or identifiable individual across our Website and Service (Personal Information). If an individual cannot be identified (for example, when Personal Information is aggregated and anonymised), then this Privacy Policy does not apply.
We take privacy seriously. When handling Personal Information, we comply with Applicable Privacy Laws, including (as applicable) the UK Data Protection Act 2018 (DPA), the United Kingdom General Data Protection Regulation (UK GDPR), and the General Data Protection Regulation (EU) 2016/679 (EU GDPR).
This website and our services are operated by PD Marfleet Accounting Limited, a limited company registered in England and Wales. PD Marfleet Accounting Limited is the data controller for the personal data described in this policy, and is registered with the Information Commissioner's Office (ICO), registration number ZB570779. If you have any questions about this Privacy Policy, you can contact us at:
Email: https://pdmarfleet.co.uk/contact
Data protection contact: Peter Marfleet, Director — via our contact page: https://pdmarfleet.co.uk/contact
We will only process Personal Information where we have a lawful basis to do so. We process your Personal Information to:
If applicable, we may also process your Personal Information for marketing purposes with your prior consent, which you can withdraw at any time.
We do not sell or rent your personal data. However, we may disclose your Personal Information to:
We use the following third-party service providers to deliver our services. Each processes data only on our instructions, under contractual terms consistent with UK GDPR:
We use AI tools to help us work efficiently — for example, drafting reports and correspondence, summarising documents, and preparing routine bookkeeping outputs. We want to be transparent about what that means for your data.
Your data is not retained by our AI providers. We use business-grade AI services with data processing agreements in place; our staff are prohibited from using consumer AI tools for client work. Our accounts and routing are configured for zero data retention, which means:
A human always reviews the work. Where AI is used, its output is never published without review by a member of our team. We do not make solely automated decisions about you or your accounts.
Which providers we use. AI processing of client information is routed through Requesty (https://www.requesty.ai/).
Data minimisation. We limit what our AI tooling can access, so that it processes only the information relevant to the task it is performing.
If you are a donor, beneficiary, trustee, or staff member of a charity we work with: the charity remains the data controller for your personal data. We process it only on the charity's behalf, under our agreement with them. If you have questions or wish to exercise your data protection rights over that data, please contact your charity in the first instance — we will support them fully in responding.
Some of our third-party processors may store or process data outside the UK. Where this occurs, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent legal mechanisms.
We retain Personal Information only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting obligations. When no longer required, we securely delete or anonymise it.
We protect Personal Information with appropriate technical and organisational measures. Access is limited to the members of our team who need it for their work, all our accounts have two-factor authentication or passkey sign-in enabled, our systems are protected by encryption, and our staff are bound by confidentiality obligations. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the ICO without undue delay.
Making a request: To exercise any of these rights, contact our data protection contact via https://pdmarfleet.co.uk/contact. We will respond within one month, free of charge. If your request is complex we may extend this by up to two further months, and we will tell you within the first month if so. We may ask you to verify your identity before we disclose or act on personal data.
We use cookies and tracking technologies to improve our Website and Services. You can manage your cookie preferences through your browser settings.
If you are unhappy with how we have handled your personal data or a request, please contact us first and we will do our best to put it right. You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint, or by phone on 0303 123 1113.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Effective from" date.