Privacy Policy

← Back to Privacy & Security overview

Privacy Policy — Full Legal Text

Effective from: 12 Feb 2025 · Last updated: 2 Sep 2026

Introduction

PD Marfleet Accounting Limited ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, process, dispose of, and protect information that relates to an identified or identifiable individual across our Website and Service (Personal Information). If an individual cannot be identified (for example, when Personal Information is aggregated and anonymised), then this Privacy Policy does not apply.

We take privacy seriously. When handling Personal Information, we comply with Applicable Privacy Laws, including (as applicable) the UK Data Protection Act 2018 (DPA), the United Kingdom General Data Protection Regulation (UK GDPR), and the General Data Protection Regulation (EU) 2016/679 (EU GDPR).

Who We Are

This website and our services are operated by PD Marfleet Accounting Limited, a limited company registered in England and Wales. PD Marfleet Accounting Limited is the data controller for the personal data described in this policy, and is registered with the Information Commissioner's Office (ICO), registration number ZB570779. If you have any questions about this Privacy Policy, you can contact us at:

Email: https://pdmarfleet.co.uk/contact

Data protection contact: Peter Marfleet, Director — via our contact page: https://pdmarfleet.co.uk/contact

Personal Information We Collect and How We Collect It

How We Use Your Personal Information

We will only process Personal Information where we have a lawful basis to do so. We process your Personal Information to:

If applicable, we may also process your Personal Information for marketing purposes with your prior consent, which you can withdraw at any time.

Disclosing Personal Information

We do not sell or rent your personal data. However, we may disclose your Personal Information to:

Third-Party Processors

We use the following third-party service providers to deliver our services. Each processes data only on our instructions, under contractual terms consistent with UK GDPR:

How we use artificial intelligence (AI)

We use AI tools to help us work efficiently — for example, drafting reports and correspondence, summarising documents, and preparing routine bookkeeping outputs. We want to be transparent about what that means for your data.

Your data is not retained by our AI providers. We use business-grade AI services with data processing agreements in place; our staff are prohibited from using consumer AI tools for client work. Our accounts and routing are configured for zero data retention, which means:

A human always reviews the work. Where AI is used, its output is never published without review by a member of our team. We do not make solely automated decisions about you or your accounts.

Which providers we use. AI processing of client information is routed through Requesty (https://www.requesty.ai/).

Data minimisation. We limit what our AI tooling can access, so that it processes only the information relevant to the task it is performing.

If you are a donor, beneficiary, trustee, or staff member of a charity we work with: the charity remains the data controller for your personal data. We process it only on the charity's behalf, under our agreement with them. If you have questions or wish to exercise your data protection rights over that data, please contact your charity in the first instance — we will support them fully in responding.

International Data Transfers

Some of our third-party processors may store or process data outside the UK. Where this occurs, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent legal mechanisms.

Data Retention

We retain Personal Information only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting obligations. When no longer required, we securely delete or anonymise it.

How We Keep Your Data Secure

We protect Personal Information with appropriate technical and organisational measures. Access is limited to the members of our team who need it for their work, all our accounts have two-factor authentication or passkey sign-in enabled, our systems are protected by encryption, and our staff are bound by confidentiality obligations. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the ICO without undue delay.

Your Rights Under UK GDPR

Making a request: To exercise any of these rights, contact our data protection contact via https://pdmarfleet.co.uk/contact. We will respond within one month, free of charge. If your request is complex we may extend this by up to two further months, and we will tell you within the first month if so. We may ask you to verify your identity before we disclose or act on personal data.

Cookies and Tracking

We use cookies and tracking technologies to improve our Website and Services. You can manage your cookie preferences through your browser settings.

Complaints

If you are unhappy with how we have handled your personal data or a request, please contact us first and we will do our best to put it right. You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint, or by phone on 0303 123 1113.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Effective from" date.