Data Protection & Processing
How we protect your client conversations at every stage
Last updated: April 2026
When a financial adviser records a client meeting through TakeNote, every element of that interaction — the audio recording, the transcription, the compliance summary, and all associated metadata — is handled under UK GDPR and the Data Protection Act 2018. This is not a premium add-on. Encryption, access control, isolation between firms, and our commitment never to train AI models on client data apply to every plan, for every customer. We believe that when clients share their financial circumstances, health information, family details, and retirement plans in a recorded meeting, that data deserves the highest standard of protection at every stage of its lifecycle. This page explains the safeguards we apply and the documentation available to evidence them.
How your data is handled
TakeNote runs on enterprise managed cloud infrastructure, with each stage of the pipeline covered by the safeguards set out below.
Audio Processing
Meeting recordings are transmitted over TLS 1.3 and encrypted at rest on receipt. Access to raw audio is restricted to the processes that transcribe it and to authorised users within your firm.
Transcription
Speech-to-text processing is carried out by a contracted sub-processor bound by written data protection terms. Transcribed text is stored encrypted at rest and is never used to train or improve third-party models.
AI Summarisation
FCA-structured suitability summaries, risk profile documentation, and compliance analysis are generated by contracted AI providers under zero-retention terms, so prompts and outputs are not retained or used for training.
Data Storage
All stored data, including meeting recordings, transcriptions, summaries, metadata, audit logs, and user account information, is encrypted with AES-256 and logically isolated so no firm can access another firm's records.
Backups
Automated backups run continuously with a 1-hour recovery point objective and are encrypted to the same standard as live data.
Every sub-processor involved in this pipeline is bound by written data protection terms. A current list, including the processing location of each, is available on request.
Why data protection matters for regulated firms
For most businesses, documenting data protection arrangements is good practice. For FCA-regulated financial advisory firms, it is a governance obligation.
Regulatory Expectations
The FCA expects regulated firms to maintain appropriate oversight over their data processing arrangements, including a clear understanding of how client data is protected and who processes it. Under Consumer Duty, firms must demonstrate that they are acting in the best interests of their clients — and that extends to the protection of their personal data.
UK GDPR Compliance
TakeNote acts as your data processor under UK GDPR and the Data Protection Act 2018. Our Data Processing Agreement sets out the purposes of processing, the security measures applied, our sub-processors, and the safeguards relied upon for any transfer — giving your firm the written record it needs as controller.
Client Confidence
Advisory clients are increasingly aware of how their data is handled. Being able to tell a client that their recorded conversations are encrypted, access-controlled, and never used to train AI models is a straightforward, credible assurance that strengthens the trust relationship.
Audit Simplicity
Our documentation pack is written for due diligence. A DPA, DPIA summary, sub-processor list with processing locations, and security whitepaper mean you can evidence your arrangements to the FCA, the ICO, or any other supervisory authority without having to reverse-engineer them.
How this compares to generic AI meeting tools
Most AI meeting and transcription tools are built for general business use, with data protection terms written for a broad market. For an FCA-regulated firm recording conversations that contain sensitive client financial data, the gaps in those terms create governance work that a purpose-built platform can remove.
Common issues with generic tools include:
Uncertain Data Flows
With many generic tools, audio may be processed by one service, stored by another, and backed up by a third, with no clear record of which. TakeNote maintains a documented processing pipeline and a current sub-processor list so you can always establish who handles client data and where.
Undocumented Transfers
Where a transfer of personal data outside the UK is involved, UK GDPR requires an appropriate safeguard such as an International Data Transfer Agreement or the UK Addendum. Our DPA records the safeguards we rely on rather than leaving your firm to assume them.
Sub-processor Chains
Generic tools may use many sub-processors for different parts of the pipeline, added or changed without notice. We keep our sub-processor list short, publish it on request, and commit contractually to notifying you of changes so you can object.
Model Training Concerns
Some AI providers process user data to train and improve their models. TakeNote does not use client data for model training under any circumstances, and we contract with our AI providers on zero-retention terms so they cannot either.
Infrastructure details
| Hosting | Enterprise managed cloud infrastructure. Primary customer data and application hosting located in the United Kingdom |
| Sub-processor Locations | Certain approved sub-processors perform transcription, AI processing and electronic signature services within the European Union |
| Encryption at Rest | AES-256 |
| Encryption in Transit | TLS 1.3 |
| Key Management | Managed by infrastructure providers under their own key management controls |
| Network Security | All traffic served over TLS; database access restricted to authenticated application requests |
| DDoS Protection | Managed DDoS protection at the edge |
| Tenant Isolation | Logical isolation of every advisory firm's data |
| Backups | Encrypted automated backups with point-in-time recovery, 1-hour RPO |
| Sub-processors | Documented list with processing locations, available on request |
Frequently asked questions
Client data is protected using AES-256 encryption at rest and TLS 1.3 in transit, held on enterprise managed cloud infrastructure, and logically isolated per firm. Primary customer data and application hosting are located in the United Kingdom, with certain approved sub-processors performing transcription, AI processing and electronic signature services within the European Union. Access is governed by role-based and team-scoped controls, with Microsoft Entra ID SSO available so your firm can enforce MFA and Conditional Access through its own identity provider. Administrative events are recorded in a tamper-resistant append-only audit log.
Questions about data protection?
If you have specific questions about our data protection arrangements, need documentation for your firm's due diligence process, or would like a copy of our sub-processor list, we're happy to help.
