You are trusted with the most sensitive information your clients have. Any system you bring into the firm inherits that trust, so this page sets out exactly how AllDone handles client data: what the AI sees, what it never sees, where everything lives, and what gets recorded. Plain answers, because you will be asked plain questions.
Most of AllDone is not AI at all. The mapping, the reconciliations, the computations, the schedules: automation and calculation, applying explicit rules the same way every time. The AI is invoked only where judgement is involved: suggesting wording, shortlisting options at a decision gate, helping when something is missing.
When the AI is involved, it works from a reference code, not your client's name. Client names and identifiers stay inside the application; every prompt sent to a model passes a personal-data check before it goes; and the real name is only restored when your documents are produced.
C-4821C-4821 · DLA optionsClient data is stored on AWS infrastructure in the EU (Ireland), encrypted in transit and at rest.
Access is least-privilege, with full isolation between firms: your data is yours, structurally, not just contractually.
Sign-in requires multi-factor authentication, for every user, every time.
In detail: encryption at rest and in transit with TLS enforced everywhere; multi-factor authentication for every user account; row-level isolation between firms enforced in the database itself; uploads scanned for malware on the way in, with account-level threat detection; application and infrastructure audit trails retained and reviewable; and a dedicated, isolated cloud environment with its own keys and access controls, shared with nothing else.
Cyber Essentials certifiedEvery decision gate records the engine's recommendation, your partner's choice, the reason and the timestamp, to an permanent audit trail that carries into the review pack. Access to the platform is logged.
If a regulator, an insurer or a difficult client ever asks how a figure was arrived at and who decided what, the answer is on the record, not in somebody's memory.
The AI in AllDone runs on Claude, from Anthropic. Their commercial API terms mean prompts are never used to train Anthropic's models and are deleted within 30 days. We hold better than that standard: Anthropic granted zero data retention on our organisation, so prompts and responses are not stored at all once the answer comes back. The exception is Anthropic's own, and we would rather you heard it from us: content flagged by their automated safety systems, or held because the law requires it, can be kept for up to two years. Combined with the reference-code design and the personal-data check, the practical position is simple: no model provider holds your client list, and no prompt identifies a client.
Nothing about your professional obligations moves. You remain the data controller for your clients' information; AllDone processes it on your instructions as your processor, under our Data Processing Agreement, with a published list of sub-processors.
No. Our provider's commercial terms exclude training on your data, prompts are not stored once the answer comes back, and no prompt identifies a client in the first place.
No. Isolation between firms is structural, enforced in the database itself, not just promised in a contract.
Your accountant, every time. And it is on the record.
The full detail lives in the Data Processing Agreement, the sub-processor list and the privacy policy. For anything else, ask us the hard question.