GDPR Compliance
TakeNote's commitment to UK GDPR and data protection compliance
Our Commitment to Data Protection
ClientScan Limited, trading as TakeNote.ai ("TakeNote", "we", "us"), is committed to protecting the personal data of our clients, their customers, and all individuals whose data is processed through our platform. Our platform is designed to support compliance with UK GDPR and the Data Protection Act 2018. A comprehensive Data Processing Agreement is available.
As a platform that processes recorded client meetings for FCA-regulated financial advisory firms, we recognise that we handle particularly sensitive personal data. Our approach to data protection reflects this responsibility — privacy and security are embedded into the design of our platform, not added as an afterthought.
Our Role Under the UK GDPR
When an advisory firm uses TakeNote to record, transcribe, and summarise client meetings, the firm acts as the Data Controller — it determines why and how personal data is processed. TakeNote acts as a Data Processor — we process personal data on behalf of the firm, strictly in accordance with their documented instructions.
We do not determine the purposes of processing. We do not use client data for our own commercial purposes. We process data solely to deliver the services our clients have engaged us to provide.
A formal Data Processing Agreement (DPA) is available to all clients and is executed prior to the commencement of any data processing. The DPA sets out the scope, nature, and purpose of processing, the categories of personal data involved, and the technical and organisational measures we implement to protect that data.
Lawful Basis for Processing
TakeNote processes personal data on behalf of our clients under the following lawful bases:
Processing is necessary for the performance of the contract between TakeNote and the advisory firm for the provision of meeting transcription, summarisation, and compliance documentation services.
Where applicable, processing may be carried out in pursuit of the legitimate interests of the advisory firm in maintaining accurate client records, evidencing regulatory compliance, and fulfilling obligations under FCA rules and MiFID II.
Where the advisory firm relies on consent as the lawful basis for recording client meetings, TakeNote supports this by providing transparency mechanisms and consent management features within the platform.
The advisory firm, as Data Controller, is responsible for determining and communicating the appropriate lawful basis to its clients and meeting participants. TakeNote provides guidance and documentation to support this.
What Personal Data We Process
In the course of providing our services, TakeNote may process the following categories of personal data on behalf of the advisory firm:
Names, roles, and voice recordings of individuals participating in recorded meetings, including financial advisers, clients, and any third parties present such as a spouse, accountant, or solicitor.
The full text of transcribed conversations, which may include financial circumstances, investment objectives, health information relevant to capacity or vulnerability assessments, employment details, family circumstances, and attitudes to risk.
Dates, times, durations, meeting platform used, and attendee information.
Structured suitability summaries including risk profiles, capacity for loss assessments, vulnerable customer indicators, advice given, action items, and next review dates.
Names, email addresses, and role information of authorised users within the advisory firm, together with access logs and usage data necessary for security and audit purposes.
We do not process personal data beyond what is necessary to deliver the contracted services.
Special Category Data
Recorded client meetings may incidentally contain special category data as defined under Article 9 of the UK GDPR — for example, where a client discloses health information relevant to a capacity for loss assessment or vulnerability indicator.
TakeNote does not actively seek to collect special category data. Where such data is present within meeting recordings or transcriptions, it is processed in accordance with Article 9(2)(a) (explicit consent, where the advisory firm has obtained this from the client) or Article 9(2)(f) (establishment, exercise, or defence of legal claims).
The advisory firm, as Data Controller, is responsible for ensuring that an appropriate lawful basis exists for the processing of any special category data.
How We Protect Your Data
All personal data processed by TakeNote is held on enterprise managed cloud infrastructure, encrypted with AES-256 at rest and TLS 1.3 in transit, and logically isolated so that no advisory firm can access another firm's records.
Client meeting recordings, transcriptions, summaries, and metadata are processed only to deliver the contracted services and on the instructions of the advisory firm as controller. We maintain a documented list of every sub-processor involved, including the processing location of each, which is available on request.
These measures, and our commitment never to use client data to train AI models, are contractually guaranteed in our Data Processing Agreement.
Data Retention
TakeNote retains client data in accordance with the retention period specified by the advisory firm. The default retention period is five years from the date of each meeting, in accordance with MiFID II record-keeping requirements (Article 16(7) of MiFID II as retained in UK law).
All retained records are stored with immutable timestamps and a complete audit trail, ensuring their integrity for regulatory purposes throughout the retention period.
Upon expiry of the retention period, or upon the advisory firm's written request (subject to applicable regulatory retention obligations), personal data is securely deleted using industry-standard methods that render the data irrecoverable. Written confirmation of deletion is provided within 30 days.
Data Subject Rights
Individuals whose personal data is processed through the TakeNote platform have the following rights under the UK GDPR:
The right to obtain confirmation of whether personal data is being processed and, if so, to access that data together with supplementary information about the processing.
The right to have inaccurate personal data corrected without undue delay.
The right to have personal data deleted in certain circumstances, subject to applicable regulatory retention requirements. Where MiFID II retention obligations apply, erasure may be deferred until the expiry of the mandatory retention period.
The right to restrict the processing of personal data in certain circumstances.
The right to receive personal data in a structured, commonly used, machine-readable format.
The right to object to the processing of personal data in certain circumstances.
As a Data Processor, TakeNote does not respond directly to data subject requests. All requests should be directed to the advisory firm in the first instance. TakeNote will provide the advisory firm with all necessary technical assistance to fulfil data subject requests promptly and within the timeframes required by the UK GDPR.
Security Measures
TakeNote implements comprehensive technical and organisational measures to protect personal data, including:
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Encryption keys are managed by our infrastructure providers under their own key management controls.
Role-based access controls ensure that advisers can only access their own meeting records, while compliance officers have appropriate firm-wide visibility. Firms using Microsoft Entra ID single sign-on inherit their own tenant's MFA and conditional access policies.
All access to personal data is recorded with immutable audit logs capturing user identity, action performed, timestamp, and IP address.
All TakeNote personnel with access to client data are subject to background checks, binding confidentiality obligations, and mandatory data protection training.
TakeNote is Cyber Essentials certified. ISO 27001 certification is in progress.
Full details of our security measures are set out in Schedule 2 of our Data Processing Agreement, available on request.
Data Protection Impact Assessment
TakeNote has conducted a Data Protection Impact Assessment (DPIA) in respect of the processing activities carried out through our platform, in accordance with Article 35 of the UK GDPR. The DPIA addresses the nature, scope, context, and purposes of the processing, the risks to the rights and freedoms of data subjects, and the measures implemented to mitigate those risks.
A summary of the DPIA is available to clients and prospective clients on request to support their own data protection compliance obligations.
Sub-processors
TakeNote engages a limited number of sub-processors to deliver its services. All sub-processors are contractually bound by data protection obligations no less onerous than those set out in our Data Processing Agreement.
Our current sub-processors are disclosed in Schedule 3 of the Data Processing Agreement. Clients are notified at least 30 days in advance of any proposed changes to sub-processors, with the right to object on reasonable grounds.
No sub-processor processes client data outside the United Kingdom.
No Training on Client Data
TakeNote does not use client data — including meeting recordings, transcriptions, summaries, or any associated personal data — to train, fine-tune, or improve artificial intelligence or machine learning models.
This commitment is contractually guaranteed in our Data Processing Agreement.
Client data is processed solely for the purpose of delivering the contracted services to the advisory firm. It is never aggregated, anonymised for secondary use, or shared with any third party for model development purposes.
International Data Transfers
Where the processing of personal data involves a transfer outside the United Kingdom, TakeNote implements appropriate safeguards in accordance with Chapter V of the UK GDPR, including the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses as applicable, supported by a transfer risk assessment where required.
Our Data Processing Agreement identifies each sub-processor engaged and the transfer mechanism relied upon. We will give advance notice of any intended addition or replacement of a sub-processor so that the advisory firm may object on reasonable data protection grounds.
Breach Notification
In the event of a personal data breach affecting client data, TakeNote will notify the advisory firm without undue delay and in any event within 24 hours of becoming aware of the breach. The notification will include a description of the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
TakeNote maintains a documented incident response procedure and conducts regular breach response exercises to ensure readiness.
Contact
For questions about our data protection practices, to request a copy of our Data Processing Agreement or DPIA summary, or to raise any data protection concern, please contact:
Related Documents
The following documents are available on request:
- Data Processing Agreement (DPA)
- Data Protection Impact Assessment (DPIA) summary
- Sub-processor list
- Security whitepaper
To request any of these documents, please contact dpo@takenote.ai or speak to your TakeNote account manager.
