Effective 4 August 2026 · Last updated 11 September 2026
Effective date: 4 August 2026 Last updated: 11 September 2026
AllDone (“we”, “us”, “our”) is an accounts production platform for UK accountancy firms, operated by It’s All Done Ltd, a company registered in England and Wales (company number 17245188), whose registered office is at Suite 530, 105 London Street, Reading, RG1 4QD. We are registered with the Information Commissioner’s Office (ICO) under registration reference ZC212638.
The platform is available at app.itsalldone.co.uk. Our marketing website is at itsalldone.co.uk.
We are committed to protecting personal data and to being transparent about how we process it. This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions, contact us at hello@itsalldone.co.uk, or privacy@itsalldone.co.uk for privacy and data requests.
AllDone is a business-to-business service. Our customers are accountancy firms. Because of this, we process personal data in two distinct capacities:
As a controller. We decide how and why to process: - account data about the firm’s users (partners, seniors, juniors, assistants) who sign in to the platform; - data about visitors to our marketing website and people who contact us; - billing and contractual records about our customer firms.
This policy covers that processing in full.
As a processor. When a firm uploads its clients’ accounting records to the platform (trial balances, ledgers, bank statements, payroll reports, statutory accounts and similar), the firm is the controller of that data and we process it only on the firm’s instructions, under our Data Processing Agreement (the “DPA”). The people whose data appears in those records (the firm’s clients, their directors, employees, customers and suppliers) should direct privacy questions to the accountancy firm that holds their relationship. Section 6 below describes how we handle this data as processor, for transparency.
Account and identity data. When a firm user is invited or signs up: email address, name, role within the firm (partner, senior, junior or assistant), authentication identifiers, and multi-factor-authentication enrolment status. Authentication is operated by our identity provider, Auth0 (see section 8); we never see or store your password.
Firm data. Firm name, professional body and designation, firm address, firm logo, and the settings the firm configures.
Usage and security data. We keep an append-only audit trail of actions taken in the platform (for example: files uploaded, engine runs, decisions recorded, sign-offs). Audit events include the acting user, timestamp, IP address and browser user agent. We also keep standard infrastructure logs.
Support and contact data. If you email us or submit the contact form on our marketing website, we receive the details you provide (name, email, firm, message). The contact form is operated by HubSpot (see section 8).
AI telemetry. When the platform’s AI features run, we record the model used, token counts, cost, latency and a cryptographic hash of the prompt. We do not store the prompt text itself in this telemetry.
We do not collect any special category data about platform users, and we do not use automated decision-making that produces legal or similarly significant effects about you.
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing the platform to your firm | Account, firm, usage data | Performance of a contract |
| Authentication, MFA and session security | Account data | Performance of a contract; legitimate interests (keeping accounts secure) |
| The audit trail (professional accountability, security, fraud prevention) | Usage and security data | Legitimate interests; legal obligation where applicable |
| Service emails (invitations, notifications) | Email address | Performance of a contract |
| Responding to enquiries | Contact data | Legitimate interests |
| Billing and account management | Firm and billing data | Performance of a contract; legal obligation (tax and accounting records) |
| Improving and securing the service | Aggregated usage data, security logs | Legitimate interests |
| Complying with law (including AML and regulatory requests) | As required | Legal obligation |
We do not sell personal data. We do not use personal data for third-party advertising.
This section describes, for transparency, how the platform handles the accounting records firms upload. The controller for this data is the firm; the contractual terms are in the DPA.
AI features are powered by Anthropic’s Claude models via the Anthropic API. Under Anthropic’s commercial terms, API inputs and outputs are not used to train Anthropic’s models, and are deleted by Anthropic within 30 days. Anthropic has additionally granted zero data retention on our organisation, so prompts and responses are not stored once the response is returned, except where retention is required by law or where content is flagged by Anthropic’s automated safety systems, which may be retained for up to two years. Data sent to Anthropic is limited to the scrubbed, placeholder-substituted text described in section 6: prompts carry reference codes and placeholders, never client names. Anthropic processes in the United States under its data processing addendum, which incorporates recognised international transfer safeguards (see section 9).
Sub-processors for data we process on firms’ behalf. The current list, with purposes and locations, is published at itsalldone.co.uk/subprocessors.html and forms part of the DPA. It is currently:
| Sub-processor | What they do | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, database and transactional email. All platform infrastructure runs in the eu-west-1 (Ireland) region. | Ireland (EEA) |
| Auth0 (Okta, Inc.) | Authentication, MFA and session management. EU-hosted tenant. | EEA |
| Anthropic | AI model provider (scrubbed, pseudonymised text only, as described in sections 6 and 7) | USA (with safeguards, see section 9) |
We give firms advance notice of sub-processor changes as set out in the DPA.
Other service providers we use as controller:
| Provider | What they do | Location |
|---|---|---|
| Companies House | Source of public company data (we retrieve data from them; we do not send them personal data) | UK |
| HubSpot | Contact form and, with your consent, website analytics on the marketing website (see our cookie policy) | USA / EEA (with safeguards) |
| Netlify | Hosting of the marketing website (static content only; no client data reaches it) | USA (with safeguards) |
| Google Fonts | Font files loaded by the browser on our sites (Google receives standard request data such as IP address) | USA / EEA |
We may also disclose personal data where required by law, regulation or court order, or to professional advisers under confidentiality obligations.
Platform data (accounts, uploads, working papers, the database) is stored and processed in the AWS Ireland region and does not leave the UK/EEA in the ordinary course. Where a provider processes data outside the UK/EEA (Anthropic, HubSpot, Netlify), we rely on appropriate safeguards: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and, where applicable, the UK Extension to the EU-US Data Privacy Framework. Copies of the relevant safeguards are available on request.
Security measures implemented in the platform include:
It’s All Done Ltd is Cyber Essentials certified (August 2026), the UK government-backed security standard, and operates an internal IT and security policy covering device security, a 14-day critical-patch rule, least-privilege access and incident response.
No system is perfectly secure. If we become aware of a personal data breach affecting your data we will notify affected firms and, where required, the ICO without undue delay and in any event within the timescales required by law.
| Data | Retention |
|---|---|
| Raw uploaded files (pre-processing) | Deleted immediately after processing; one-day automated backstop |
| Processed client files, working papers and outputs | For the life of the engagement and the firm’s account. Firms can delete individual files, jobs and clients at any time; deletion of files and jobs is immediate and irreversible |
| Account data (users, firm) | For the life of the account. On account closure, user accounts are disabled immediately and deleted after any retention period agreed in the DPA |
| Audit trail | 6 years, reflecting professional record-keeping and security needs; audit entries survive deletion of the records they describe |
| Application and network logs | 90 days |
| Infrastructure audit logs (CloudTrail) | 400 days |
| Database backups | 7 days (rolling) |
| File-system backups | 30 days (rolling) |
| AI telemetry (token counts, cost, prompt hash; no prompt text) | 24 months, for cost control and abuse prevention |
| Contact form enquiries | 24 months after last contact |
| Contract and billing records | 6 years after the end of the contract (legal obligation) |
On termination of a firm’s contract, the firm can export its data (including the complete engagement file pack for each completed engagement), and all client data is returned or deleted within 30 days of termination, with remaining copies deleted from backups within a further 30 days, as set out in the Terms of Service and the DPA.
The platform learns firm-level working preferences to improve its suggestions: for example, which account a firm habitually maps a type of cost to, or house wording for disclosure notes. These learned preferences are stored as generic patterns (decision codes, option keys, generic keywords, counts) and are engineered so that client names and identifiers are excluded. Firms can view their learned patterns in the platform and a partner can purge them at any time; purging is the erasure control for the learning loop. We may also use fully anonymised, aggregated data (which is no longer personal data) for product improvement and statistics.
If you are in the UK or EEA you have the right to: access your personal data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. To exercise any right, email privacy@itsalldone.co.uk with “Data request” in the subject line. We will respond within one month (extendable by two further months for complex requests, in which case we will tell you).
If your request concerns data we process on behalf of an accountancy firm (for example, you are a client of a firm that uses AllDone), we will refer the request to that firm, which is the controller, and assist it in responding.
You also have the right to complain to the Information Commissioner’s Office (ico.org.uk, or 0303 123 1113). We would appreciate the chance to address your concerns first.
The platform and website are for business use and are not directed at children. We do not knowingly collect data from anyone under 18.
We may update this policy from time to time. Material changes will be notified to firms by email or in-platform notice. The “Last updated” date at the top shows the current version.
It’s All Done Ltd (trading as AllDone) Company number 17245188 Registered office: Suite 530, 105 London Street, Reading, RG1 4QD ICO registration: ZC212638 General enquiries: hello@itsalldone.co.uk Privacy and data requests: privacy@itsalldone.co.uk