Uploaded PDFs (P60, PSS, chargeable-event certificates) are parsed, then permanently deleted from UK-region object storage 24 hours later. An hourly cron enforces the cutoff; nothing carries over between paraplanner sessions.
ParaplanAI · privacy policy
Privacy policy.
What we collect, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. Written for UK advisers and the clients you serve.
Last updated · 20 July 2026
1 · Who we are
ParaplanAI (the “Service”) is operated as a sole trader in the United Kingdom under the trading name ParaplanAIby a working UK paraplanner at a regulated UK firm. The operator’s identity is available to professional bodies and prospective firms on request via info@paraplanai.co.uk; contracts and data-protection agreements are entered into under the trading name ParaplanAI. We are the data controller for the personal data we collect from you when you create an account. We are a data processor for personal data your firm, as controller, uploads about its end clients.
Contact: info@paraplanai.co.uk.
2 · What we collect
2.1 · Account data (controller)
When you sign up:
- Email address (used for sign-in and notifications).
- Firm name + the role you hold (owner / adviser / paraplanner).
- Optional: firm branding (a logo and brand colour, stored inline against your firm record).
- Billing data — handled by our payments processor, see §4. We never see your card details.
- Authentication events (sign-ins, OAuth callbacks) — retained for security forensics then purged.
2.2 · Client data (processor)
When your firm runs a calculation for an end client, the firm uploads or types in figures about that client. ParaplanAI does not requirethe client’s name, NI number, address, or any other directly-identifying field to function. We strongly recommend you use only an anonymised client reference (e.g. JS-2026-04-12).
Where your firm chooses to upload identifying information into free-text fields or via document upload, that information is encrypted at rest and in transit. The calculation engine and audit trail operate on the anonymised reference only — they never see PII. Where a client’s name is set on the record, the rendered PDF annex displays it.
2.3 · Uploaded documents
P60s, pension scheme statements, chargeable-event certificates, and other source documents you upload for figure-extraction are stored in UK/EU-region encrypted object storage. To lift the structured figures off each document we use a large language model through a managed AI service hosted in the EU. The document is processed in-region; it is not transmitted outside the UK / EU.
What the AI provider does with the document. The model runs as a managed, stateless service. Your document and the figures returned from it are not stored by the model provider after the request completes, and are never used to train any model. The same applies to Pan, our read-only query assistant — it runs on the same EU-hosted service and computes nothing itself. Processing is covered by a Data Processing Agreement with the provider.
Retention on our side: 24 hours. An hourly automated job permanently deletes uploaded source PDFs from our UK/EU-region object storage 24 hours after upload. The structured figures extracted from them (and the calculation that consumed those figures) are retained for audit per §6. The output PDF (the compliance annex you download) is held for 30 days by default and can be re-fetched without re-running the calc.
See /data-minimisation for the full picture — what we hold, what we deliberately don't hold (NINO, address, employer, scheme references), and how the three retention buckets fit together.
3 · Legal basis
Our lawful bases under UK GDPR Article 6:
- Performance of contract (Art 6(1)(b)) for providing the calculator, audit trail, and PDF outputs you have subscribed to.
- Consent (Art 6(1)(a)) for persistent, account-linked browser product analytics and anonymous browser session replay on eligible queryless public pages in production. You can refuse or withdraw this choice at any time without affecting the Service. Browser session replay is disabled on authenticated and client workspace pages.
- Legitimate interests (Art 6(1)(f)) for operational security logs, abuse prevention, error diagnostics, service reliability, and limited cookieless public-page and calculator counters. Those memory-only counters do not use an account, firm or persistent browser identifier and stop if you reject analytics. Our legitimate interests assessment is on file; available on request.
- Your firm's instructions as controller(Art 28) for keeping calculation records for the retention period your firm chooses (six years by default). Your firm holds its own FCA SYSC 9 record-keeping obligation; we retain on its behalf and delete when it tells us to or the period lapses.
- Legal obligation (Art 6(1)(c)) for our own records — e.g. a six-year record of paid invoices for HMRC.
4 · Who else sees your data (sub-processors)
We use sub-processors under written Data Processing Agreements (UK GDPR Article 28). Categories of recipients:
- Hosting and infrastructure — the application, database, and file storage used for the client-data path are hosted on UK / EU infrastructure.
- AI document-extraction — source PDFs are sent to an EU-hosted AI provider for figure-extraction only (see §2.3). The provider does not retain documents after the request or train on customer data.
- Payments — subscription billing handled by a PCI-compliant payments processor. It receives billing data only — never your client data — and we never see your card details.
- Transactional email — sign-in links and member invitations, via an EU-resident email provider. It receives the address, subject, and service-message content needed to deliver the email, but no client records or source documents.
- Browser analytics — before a choice, only allowlisted public-surface counters with memory-only state; on our public marketing and calculator pages only, those counters also include page-leave, page-speed, frustrated-click and unhandled browser-error signals, which carry a redacted page path and no identifier and are never collected on sign-in or signed-in pages; after consent, pseudonymous product events and anonymous, blanket-masked browser replay on allowlisted queryless public pages in production. Hosted in the EU; browser session replay is disabled on authenticated and client workspace pages, all rendered text and input values are masked, dynamic financial views are blocked, query strings and sensitive route identifiers are removed, and request headers, bodies, console output and canvas content are not recorded.
- Operational telemetry — unlinkable server-side reliability, usage, and cost counters. Each event has a fresh random identifier and carries no browser, account, or firm identifier.
- Application error monitoring — browser, edge, and server diagnostic events, EU-hosted. Financial figures and client references are stripped before transmission; session replay is disabled.
We host on UK / EU infrastructure throughout. The full named list of the sub-processors we currently engage — with the purpose and data location of each — is available in the disclosure below. This named register supports our UK GDPR Article 28(2) sub-processor obligations and is the register referenced by our Data Processing Agreement. The ParaplanAI–to–your-firm DPA is at /legal/dpa.
View current sub-processor registerLast updated 20 July 2026
| Sub-processor | Purpose | Data processed | Location / region | Last updated |
|---|---|---|---|---|
| Supabase (Supabase Inc.) | Managed database, authentication and encrypted file storage | Account data; encrypted client records; uploaded source documents (24-hour retention) | UK / EU — London (AWS eu-west-2) | 23 Jun 2026 |
| Vercel (Vercel Inc.) | Application hosting and content delivery | Application traffic and request metadata; no client data stored at rest | EU region (Frankfurt) for compute; global edge for static assets | 23 Jun 2026 |
| Amazon Web Services (AWS) — Lambda | Compliance-annex PDF rendering (self-hosted WeasyPrint service) | Annex HTML built from the calc-run record, including the client name where set — the calculation engine and audit trail never see it | EU — Frankfurt (AWS eu-central-1) | 23 Jun 2026 |
| Anthropic (Anthropic PBC) — AI model | Document figure-extraction and the Pan query assistant (LLM) | Uploaded source documents and the figures lifted from them; not retained after the request, never used for training | EU — accessed in-region via AWS Bedrock (eu-west-2 / eu-central-1); document content does not leave the UK / EU | 23 Jun 2026 |
| Amazon Web Services (AWS) — Bedrock | EU-region transport for the Anthropic model | Uploaded source documents and extracted figures; not retained after the request, never used for training | EU — London / Frankfurt (AWS eu-west-2 / eu-central-1) | 23 Jun 2026 |
| Stripe (Stripe Payments Europe Ltd.) | Subscription billing and payment processing | Billing contact and subscription details; card data handled by Stripe directly — never your client data | EU (Ireland), with onward transfers under Stripe’s own approved safeguards | 23 Jun 2026 |
| Brevo (Sendinblue SAS) | Transactional email (sign-in links, invitations, receipts, service notices) | Recipient email address and message content only | EU — primary data storage in France, Germany and Belgium; onward processors governed by Brevo’s DPA | 12 Jul 2026 |
| PostHog (PostHog, Inc.) | Cookieless public-surface counters, optional product analytics and masked anonymous public-page replay | Before a choice, allowlisted public-surface events use memory-only state and exclude account, firm and persistent browser identifiers. Consented events may include pseudonymous account and firm identifiers, subscription tier, redacted page paths and product interactions. Browser session replay is disabled on authenticated and client workspace pages. Consented replay is limited to anonymous, queryless public pages on the production host; it masks all rendered text and inputs, blocks dynamic financial views and excludes query strings, sensitive route identifiers, request headers, bodies, console output and canvas content. Server operational counters use a fresh random identifier per event. Financial inputs and client references are stripped before send | EU (eu.i.posthog.com) | 20 Jul 2026 |
| Sentry (Functional Software, Inc.) | Application error and performance monitoring (browser, edge and server) | Error and diagnostic events with PII removed at source — financial figures, client references, emails, NINOs, addresses are scrubbed before transmission | EU region | 13 Jul 2026 |
AI-transport residency note. Document extraction and Pan use a single Anthropic model, accessed in-region through AWS Bedrock in the UK / EU — document content does not leave the UK / EU. The document and the figures returned from it are processed statelessly: not retained after the request and never used to train any model.
We give at least 30 days’ notice of any new or replaced sub-processor via your dashboard before it begins processing, so you can object. This list is maintained for our UK GDPR Article 28(2) obligations.
5 · International transfers
We do not transfer client personal data outside the UK / EU. Everything in the client-data path — the database, file storage, AI figure-extraction, PDF rendering, analytics, and error monitoring — is hosted and processed within the UK and EU.
The only data that touches a non-UK/EU service is billing: our payments processor operates internationally under its own approved transfer safeguards, and it receives subscription and billing details only — never the client data your firm uploads.
6 · Retention
- Uploaded source documents— 24 hours from upload, then permanently deleted by an hourly automated job. Tightened from the previous 30-day window: the structured figures extracted from each document are the canonical artefact, the raw bytes don't need to linger.
- Parsed extractions(the structured figures lifted from each document) — part of the client record, which is yours to delete on demand. Otherwise kept for the period your firm sets (see “Calculation records”).
- Output PDFs (the compliance annex you download) — kept alongside the calculation they belong to, and deleted with it (or whenever you delete the record). Any PDF can be re-rendered from the calculation record while it exists.
- Calculation records (inputs, intermediate steps, configured tax-year rules, output) — you can delete these on demand. Finalised (filed) calculations you keep are retained for the window your firm configures — six years by default — then deleted automatically. Drafts you never finalise are removed after 90 days.
- Account email + firm record— for the lifetime of the subscription. On closure we return or delete your firm's client data on its instruction (UK GDPR Art 28); account/billing identifiers are then anonymised.
- Billing records — held by our payments provider under its retention policy; we retain a six-year record of paid invoices for HMRC (our own legal obligation).
- Sign-in logs — 90 days, then purged.
Clients, policies and calculations are yours to delete — one click, whenever you want. You hold your own FCA record; we never force a period on you. Finalised calculations you keep are auto-retained for the window your firm sets (six years by default), then deleted. Drafts you never finalise are removed after 90 days.
The compliance annex you download stays available so it can be re-fetched without re-running the calc. It is kept alongside its calculation under your firm’s retention policy, and goes the moment you delete the record — export it first if you need a copy.
The full data-minimisation story — what we hold, what we don't.
7 · Your rights
Under UK GDPR you have the right to:
- Ask what data we hold about you (Article 15 — subject access).
- Have inaccurate data corrected (Article 16).
- Have your data erased (Article 17 — “right to be forgotten”); you can delete your client records yourself at any time (see below).
- Have processing restricted (Article 18).
- Take your data elsewhere in a machine-readable format (Article 20 — portability).
- Object to processing based on legitimate interests (Article 21).
- Withdraw consent at any time, where we are relying on it (Article 7).
Self-serve deletion. Any firm member can delete a client, policy, calculation or draft on demand — it is hard-deleted, along with any stored documents and PDFs. Firm owners can delete the whole firm and its client PII from Settings → Firm → Danger zone. We don't hold your records beyond what you choose: finalised calculations are kept only for the window your firm configures (six years by default), and you can export anything you want to keep before deleting.
Self-serve data export. Subject access (Art. 15) and portability (Art. 20) are available at Settings → Account → Export my data. The ZIP arrives by email within a few minutes (signed download link valid for 7 days). For corrections, restriction, or anything else, email info@paraplanai.co.uk and we will respond within 30 days. We will not charge for the first request in any 12-month period.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk/concerns · 0303 123 1113.
8 · Security
All personal data is encrypted in transit (TLS 1.3) and at rest. Client PII is encrypted at the application layer (AES-256-GCM) before storage, so the database alone is not sufficient to decrypt it, and the calculation engine never sees it. Database row-level security policies enforce firm-level isolation on every read and write — your firm cannot read another firm’s rows. Sign-in is passwordless (magic-link + Google / Microsoft OAuth); we store no passwords.
For account data where we act as controller, we assess every personal-data breach and notify the ICO within 72 hours where Article 33 requires it; where the risk is high, we notify affected individuals without undue delay under Article 34. For client data where we act as processor, we notify the affected firm without undue delay and provide the information it needs to make those controller-side decisions.
The full control set — encryption, tenant isolation, data residency, auditability and continuity — is documented on our security page.
10 · Children
ParaplanAI is a professional tool for UK financial advisers and accountants. It is not designed for or marketed to people under 18.
11 · Changes to this policy
We may update this policy. Material changes will be flagged on your dashboard for at least 14 days before they take effect, and we will email account owners. The “Last updated” date at the top of this page is the canonical version date.
See also: Terms of service · Data Processing Agreement · Security · Data minimisation · Back to ParaplanAI.
