Legal
Privacy Policy
Last updated 6 September 2026.
Who this policy covers
Pdcircleai is practice-management software used by UK accounting firms to run their client work: bookkeeping, statutory accounts, corporation tax and VAT filings, and client communication. This policy explains what data we collect and how we handle it, whether you are a member of staff at a subscribing practice or a client of that practice using the client portal.
Each practice is the data controller for its own client and financial records. Pdcircleai (referred to as “we” below) acts as data processor, storing and handling that data only as instructed by the practice.
Data we collect
- Account data — name, email address, and role, for anyone with a staff or client-portal login.
- Client and financial records — the accounting data a practice enters or imports on behalf of its clients: transactions, bank statement lines, statutory accounts figures, tax computations and filing history.
- Uploaded documents — files a practice or its clients upload (receipts, statements, correspondence).
- Communication metadata — records of emails and messages sent through the platform (e.g. client requests, filing confirmations), and, where a practice enables it, WhatsApp messages sent to link and operate the WhatsApp control channel described below.
- Usage and audit data — a record of who did what and when, kept for audit-trail and security purposes.
The WhatsApp control channel
A practice can optionally link a member of staff’s WhatsApp number to Pdcircleai. Once linked, that number can be used to ask read-only questions (such as a client’s filing status or corporation tax estimate) or categorise a transaction. We store the phone number and link status, and process the text of messages sent to the linked WhatsApp number in order to interpret the request and reply. We do not send unsolicited or marketing messages over WhatsApp, and only the staff member who completed the linking process can use the channel.
Messages are transmitted through Meta’s WhatsApp Business Platform, which processes message content to deliver it to us — see Meta’s own WhatsApp privacy documentation for how it handles that transmission.
How we use data
- To provide the service the practice has subscribed to: running client records, preparing filings, and tracking work.
- To send transactional communications the practice initiates: client requests, portal invitations, filing confirmations.
- To classify bank transactions using AI, where enabled — transaction descriptions are sent to our AI classification provider to suggest a category, which a member of staff always reviews before it is applied.
- To maintain an audit trail of actions taken in the system, for the practice’s own compliance record-keeping.
- To keep the service secure and operating correctly.
Who else processes this data
We rely on a small number of specialist providers to run the service, each processing data only for that purpose:
- Supabase — hosts our database, authentication and file storage.
- Amazon Web Services (SES) — delivers transactional emails on our behalf.
- Meta (WhatsApp Business Platform) — delivers WhatsApp messages for practices that enable that channel.
- An AI classification provider (OpenRouter or OpenAI, depending on configuration) — suggests bank transaction categories from transaction descriptions.
- HMRC and Companies House — receive filings the practice explicitly submits through the platform, as required by law.
We do not sell personal data, and we do not share it with anyone else for their own marketing purposes.
Data retention
We retain client and financial records for as long as the practice’s subscription is active, and afterwards only for as long as needed to meet the practice’s own legal and regulatory retention obligations (UK accounting and tax records are typically kept for several years). A practice can request deletion of a client’s data once it is no longer required to be kept for those purposes.
Security
Access to client and financial data is restricted by role-based permissions, so staff only see what their role requires. Data in transit is encrypted, and every significant action is written to an audit trail. Uploaded documents are scanned for malware before being made available.
Your rights
If you are a UK or EU resident, you have rights under UK GDPR / the GDPR to access, correct, or request deletion of your personal data, and to object to certain processing. Because each practice controls its own client data, requests about a specific client’s records should go to that practice directly; requests about your staff account, or anything you cannot resolve with your practice, can be sent to the contact below.
Contact
Questions about this policy can be sent to privacy@pdcircleai.com.