Skip to main content
Data Protection

Data Protection & Processing

How we protect your client conversations at every stage

Last updated: April 2026

When a financial adviser records a client meeting through TakeNote, every element of that interaction — the audio recording, the transcription, the compliance summary, and all associated metadata — is handled under UK GDPR and the Data Protection Act 2018. This is not a premium add-on. Encryption, access control, isolation between firms, and our commitment never to train AI models on client data apply to every plan, for every customer. We believe that when clients share their financial circumstances, health information, family details, and retirement plans in a recorded meeting, that data deserves the highest standard of protection at every stage of its lifecycle. This page explains the safeguards we apply and the documentation available to evidence them.

How your data is handled

TakeNote runs on enterprise managed cloud infrastructure, with each stage of the pipeline covered by the safeguards set out below.

Audio Processing

Meeting recordings are transmitted over TLS 1.3 and encrypted at rest on receipt. Access to raw audio is restricted to the processes that transcribe it and to authorised users within your firm.

Transcription

Speech-to-text processing is carried out by a contracted sub-processor bound by written data protection terms. Transcribed text is stored encrypted at rest and is never used to train or improve third-party models.

AI Summarisation

FCA-structured suitability summaries, risk profile documentation, and compliance analysis are generated by contracted AI providers under zero-retention terms, so prompts and outputs are not retained or used for training.

Data Storage

All stored data, including meeting recordings, transcriptions, summaries, metadata, audit logs, and user account information, is encrypted with AES-256 and logically isolated so no firm can access another firm's records.

Backups

Automated backups run continuously with a 1-hour recovery point objective and are encrypted to the same standard as live data.

Every sub-processor involved in this pipeline is bound by written data protection terms. A current list, including the processing location of each, is available on request.

Why data protection matters for regulated firms

For most businesses, documenting data protection arrangements is good practice. For FCA-regulated financial advisory firms, it is a governance obligation.

Regulatory Expectations

The FCA expects regulated firms to maintain appropriate oversight over their data processing arrangements, including a clear understanding of how client data is protected and who processes it. Under Consumer Duty, firms must demonstrate that they are acting in the best interests of their clients — and that extends to the protection of their personal data.

UK GDPR Compliance

TakeNote acts as your data processor under UK GDPR and the Data Protection Act 2018. Our Data Processing Agreement sets out the purposes of processing, the security measures applied, our sub-processors, and the safeguards relied upon for any transfer — giving your firm the written record it needs as controller.

Client Confidence

Advisory clients are increasingly aware of how their data is handled. Being able to tell a client that their recorded conversations are encrypted, access-controlled, and never used to train AI models is a straightforward, credible assurance that strengthens the trust relationship.

Audit Simplicity

Our documentation pack is written for due diligence. A DPA, DPIA summary, sub-processor list with processing locations, and security whitepaper mean you can evidence your arrangements to the FCA, the ICO, or any other supervisory authority without having to reverse-engineer them.

How this compares to generic AI meeting tools

Most AI meeting and transcription tools are built for general business use, with data protection terms written for a broad market. For an FCA-regulated firm recording conversations that contain sensitive client financial data, the gaps in those terms create governance work that a purpose-built platform can remove.

Common issues with generic tools include:

Uncertain Data Flows

With many generic tools, audio may be processed by one service, stored by another, and backed up by a third, with no clear record of which. TakeNote maintains a documented processing pipeline and a current sub-processor list so you can always establish who handles client data and where.

Undocumented Transfers

Where a transfer of personal data outside the UK is involved, UK GDPR requires an appropriate safeguard such as an International Data Transfer Agreement or the UK Addendum. Our DPA records the safeguards we rely on rather than leaving your firm to assume them.

Sub-processor Chains

Generic tools may use many sub-processors for different parts of the pipeline, added or changed without notice. We keep our sub-processor list short, publish it on request, and commit contractually to notifying you of changes so you can object.

Model Training Concerns

Some AI providers process user data to train and improve their models. TakeNote does not use client data for model training under any circumstances, and we contract with our AI providers on zero-retention terms so they cannot either.

Infrastructure details

HostingEnterprise managed cloud infrastructure. Primary customer data and application hosting located in the United Kingdom
Sub-processor LocationsCertain approved sub-processors perform transcription, AI processing and electronic signature services within the European Union
Encryption at RestAES-256
Encryption in TransitTLS 1.3
Key ManagementManaged by infrastructure providers under their own key management controls
Network SecurityAll traffic served over TLS; database access restricted to authenticated application requests
DDoS ProtectionManaged DDoS protection at the edge
Tenant IsolationLogical isolation of every advisory firm's data
BackupsEncrypted automated backups with point-in-time recovery, 1-hour RPO
Sub-processorsDocumented list with processing locations, available on request

Frequently asked questions

Client data is protected using AES-256 encryption at rest and TLS 1.3 in transit, held on enterprise managed cloud infrastructure, and logically isolated per firm. Primary customer data and application hosting are located in the United Kingdom, with certain approved sub-processors performing transcription, AI processing and electronic signature services within the European Union. Access is governed by role-based and team-scoped controls, with Microsoft Entra ID SSO available so your firm can enforce MFA and Conditional Access through its own identity provider. Administrative events are recorded in a tamper-resistant append-only audit log.

Questions about data protection?

If you have specific questions about our data protection arrangements, need documentation for your firm's due diligence process, or would like a copy of our sub-processor list, we're happy to help.

ClientScan Limited

7 Bell Yard, London WC2A 2JR

Registered in England and Wales

Company number: 14828718

ICO registration: ZB622400