This Data Processing Agreement ("DPA") forms part of the agreement for the provision of the AllDone service ("Principal Agreement") between:
It's All Done Ltd, trading as AllDone, a company registered in England & Wales with company number 17245188 and registered address Suite 530, 105 London Street, Reading RG1 4QD (the "Processor"); and
The Client Firm identified in the Principal Agreement (the "Controller").
1. Definitions
Terms defined in the UK GDPR (the retained EU Regulation 2016/679 as amended by the Data Protection Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019) have the same meaning in this DPA, including "personal data", "processing", "data subject", "personal data breach", "controller" and "processor". "Data Protection Laws" means the UK GDPR, the Data Protection Act 2018 and, where applicable to the processing, the EU GDPR.
2. Roles and scope
2.1 The Controller is the controller of the Client Data (as described in Annex 1) and the Processor is the processor of that data. For the avoidance of doubt, the Controller's own clients' personal data uploaded to the service is Client Data, and the Controller warrants that it has a lawful basis, and where required has given the necessary notices, for that data to be processed under this DPA.
2.2 It's All Done Ltd acts as an independent controller only in respect of its own business records (account administration, billing, support correspondence), which are governed by its privacy policy and not this DPA.
3. Processing on instructions
3.1 The Processor shall process Client Data only on the documented instructions of the Controller, including as set out in the Principal Agreement, this DPA and the configuration choices the Controller makes in the service, unless required to do otherwise by law, in which case the Processor shall inform the Controller of that legal requirement before processing unless the law prohibits it.
3.2 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
The Processor shall ensure that all persons authorised to process Client Data are bound by contractual or statutory obligations of confidentiality, and that access is limited to those who need it to provide the service.
5. Security
5.1 The Processor shall implement and maintain appropriate technical and organisational measures to protect Client Data, including as a minimum the measures set out in Annex 2.
5.2 The Processor shall not materially reduce the overall level of protection described in Annex 2 during the term.
6. Sub-processors
6.1 The Controller grants general written authorisation for the engagement of the sub-processors listed in Annex 3.
6.2 The Processor shall give the Controller at least 30 days' written notice of any intended addition or replacement of a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected service without penalty.
6.3 The Processor shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each sub-processor.
7. AI model providers
7.1 Without limiting clause 6, the Processor warrants that: (a) prompts sent to any AI model provider are subject to the pseudonymisation, personal-data screening and image-redaction measures described in Annex 2; (b) its agreements with AI model providers provide that submitted content is not used to train models, and is retained for no longer than 30 days, except where retention is required by law or by the provider's automated trust-and-safety systems, which may retain flagged content for up to two years. The Processor further confirms that, as at the date of this DPA, zero data retention is enabled on its Anthropic organisation, under which prompts and responses are not stored once the API response is returned; the Processor shall update Annex 3 in accordance with clause 6.2 if that arrangement ceases to apply; and (c) any change of AI model provider is a sub-processor change subject to clause 6.2.
8. Data subject rights
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in responding to requests to exercise data subject rights. The Processor shall not respond directly to a data subject except on the Controller's documented instruction, and shall forward any request it receives to the Controller without undue delay.
9. Personal data breach
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Client Data, providing sufficient information to allow the Controller to meet its own obligations, and shall cooperate with the Controller and take reasonable steps to mitigate the effects of the breach.
10. Assistance
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with the Information Commissioner's Office, taking into account the nature of the processing and the information available to the Processor.
11. Deletion and return
11.1 During the term, the Controller may export Client Data using the service's export functions.
11.2 On termination or expiry, the Processor shall, at the Controller's choice, return or delete all Client Data within thirty (30) days, and delete remaining copies from backups within a further thirty (30) days in accordance with the backup cycle described in Annex 2, unless retention is required by law. The Processor shall confirm deletion in writing on request. The Processor may retain: (a) its own business records under clause 2.2; and (b) its pseudonymised platform audit trail (records of processing decisions and system activity, containing no client financial content) for up to six (6) years from termination, to evidence its processing and for the establishment, exercise or defence of legal claims. The Controller, as the entity regulated under the Money Laundering Regulations 2017, is responsible for exporting and retaining its own statutory records (client due diligence, engagement records) using the clause 11.1 export functions before deletion; the Processor holds no Client Data back for the Controller’s statutory purposes.
12. Audit
The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, including certifications held and summaries of third-party assessments, and shall allow for and contribute to audits conducted by the Controller or its appointed auditor, no more than once in any 12-month period except following a personal data breach, on reasonable notice, during business hours, and subject to confidentiality undertakings.
13. International transfers
13.1 Client Data is hosted and processed within the European Union as described in Annex 3. The Controller acknowledges that transfers between the UK and the EU are, at the date of this DPA, covered by the applicable adequacy arrangements.
13.2 Where any processing by a sub-processor involves a transfer of Client Data to a country without UK adequacy regulations, the Processor shall ensure a valid transfer mechanism is in place before the transfer occurs. Processing by the AI model provider (Anthropic) takes place in the United States: pseudonymised prompts are sent to Anthropic's API, under Anthropic's Data Processing Addendum as incorporated into its Commercial Terms. The transfer mechanism relied on is that provided in Anthropic’s Data Processing Addendum.
14. Liability and precedence
Liability under this DPA is subject to the limitations and exclusions in the Principal Agreement, including the aggregate cap by reference to Fees paid in the 12 months preceding the claim; data protection liability does not carry a separate cap. In the event of conflict between this DPA and the Principal Agreement concerning the processing of personal data, this DPA prevails.
Annex 1: Details of processing
Subject matter and purpose: provision of the AllDone service: the preparation of statutory accounts files, tax computations and associated working papers and documents on the Controller's instructions.
Duration: the term of the Principal Agreement plus the deletion period in clause 11.
Nature: hosting, storage, computation, document generation, pseudonymised AI-assisted analysis, backup.
Categories of data subjects: the Controller's partners and staff; the Controller's clients and their directors, shareholders, employees, customers and suppliers to the extent they appear in accounting records and supporting documents.
Categories of personal data: names and contact details; financial and transactional data (including directors' loan accounts, payroll summaries, supplier and customer balances); identifiers appearing in accounting records. Special category data: not required by the service, and the Controller must not upload it or enter it into free-text fields. The personal-data screening described in Annex 2 blocks names and structured identifiers; it does not detect special category content, so the Controller's obligation not to submit it is relied upon. The Controller shall ensure that no special category data is submitted to the service; the Processor has no obligation to detect special category content and no liability for special category data submitted in breach of this paragraph.
Annex 2: Technical and organisational measures
Hosting on AWS infrastructure in the European Union (Ireland, eu-west-1); backups are held in the same EU region and are not replicated outside the EU. Encryption of data in transit (TLS) and at rest, including customer-managed keys for client file storage. Multi-factor authentication: every authenticated request to the service must present multi-factor-authenticated credentials. Least-privilege, role-based access with structural isolation between client firms enforced at the database layer (row-level security). Pseudonymisation of AI processing: client names and identifiers are replaced with reference codes, and every text prompt to an AI model passes an automated personal-data screen before transmission; scanned document images are redacted before transmission with a fail-closed check; identity is restored only within the application when documents are produced. Append-only audit trail of decisions, enforced at database-privilege level, including recommendation, choice, reason, actor and timestamp. Activity logging of state-changing actions and of document downloads and exports. Malware scanning of all uploads. Backup and recovery procedures: daily backups retained for 30 days, plus 7-day database point-in-time recovery, all held within the EU. Vulnerability management and patching (14-day critical-patch rule per the internal IT & Security Policy). Personnel confidentiality obligations and security training. Certifications: Cyber Essentials, certified August 2026 (certificate held by It's All Done Ltd; includes £25,000 cyber-liability insurance).
Annex 3: Approved sub-processors
| Sub-processor | Role | Location of processing | Safeguards |
| Amazon Web Services EMEA SARL | Cloud hosting, storage and transactional email (SES) | EU (Ireland, eu-west-1; backups held in-region) | UK GDPR Art 28 terms; EU processing |
| Anthropic, PBC | AI model processing of pseudonymised prompts (Messages API only) | United States | No-training and 30-day deletion under Anthropic's Commercial Terms (DPA incorporated); zero data retention enabled on the Processor's organisation (August 2026): prompts and responses are not stored once the API response is returned, except content flagged by Anthropic's automated trust-and-safety systems or retention required by law, which Anthropic may retain for up to two years; transfer mechanism per clause 13.2 |
| Auth0 (Okta, Inc.) | Identity and authentication (staff names, email addresses, roles) | EU tenant | UK GDPR Art 28 terms (Okta's customer DPA, executed August 2026: EU SCCs with UK transfer coverage via its Annex IV; covers Auth0) |
Notes: customer support is handled in-app on the Processor's own infrastructure and no analytics or tracking tools process Client Data, so no rows are required for either. Companies House (UK government) is a data source the service reads from (director and officer names); no Client Data is sent to it. Netlify (marketing-site hosting only), HubSpot (marketing-website contact-form enquiries only), Microsoft 365, Dashlane, GitHub and Bitdefender process no Client Data and are not sub-processors.
This Annex is the authoritative list of sub-processors authorised as at the date of this DPA. Additions and replacements are made under clause 6.2 by notice to the Controller and take effect as updates to the published copy of this Annex, without re-execution of this DPA. A copy is published at itsalldone.co.uk/subprocessors.html; the published page mirrors this Annex and the two must never diverge.