Privacy notice
Layer one — the short version
This is the whole thing on one screen. Everything below it is the same information in full.
Who we are. Pocket Docket Ltd, a company registered in Northern Ireland, number NI742827, registered office 137 York Road, Belfast, BT15 3GZ. We build Pocket Docket — live dashboards made from your own Xero accounting data, with an AI assistant called Kipp that explains the figures and drafts invoices and chasing emails for you to approve and send. It costs £24 a month. We sell it directly to you. There is no accountancy practice standing between you and us.
What we collect about you. Your name, business name, email address and phone number when you start a trial or make an enquiry. Your billing details, which go to Stripe and not to us. The accounting data we read from your Xero organisation, on your instruction. A record of which device your dashboard link is bound to. Security and abuse logs, in which identifying values like IP addresses and email addresses are stored as salted hashes rather than as the real thing. Anything you write to us.
What we do with it. We show you your own numbers, we let Kipp explain them, and we bill you. That is the list.
What we never do. We do not sell your data. We do not put you on a mailing list you did not ask for. We do not use your accounting data, or anyone else's, to train an AI model. We do not pool ledger data across customers to build benchmarks or improve models — there is no lawful basis for it and we have decided not to build it.
Your accounting data goes to an AI company in the United States. When you ask Kipp a question, the question and the relevant figures — which can include the names of your own customers and suppliers — are sent to Anthropic, who run the model. They are contractually barred from training on it. We think you should know this before you connect Xero, not after.
Your own customers' and suppliers' details. For the personal data sitting inside your ledger, you are the controller and we are your processor. We act on your instructions. We do not contact those people, sell their details, or use them for anything outside your own account.
Stopping us. You can disconnect Pocket Docket from inside your own Xero account at any time, without asking us first. That stops any further accounting data reaching us immediately.
Your rights. Access, correction, deletion, restriction, portability, objection. No form, no portal — ask us in whatever way suits you and we will treat it as a request. We answer within one calendar month.
If you are unhappy. Tell us first at privacy@pocketdocket.co.uk or through the complaint form at app.pocketdocket.co.uk/legal/complaint. We will acknowledge within 30 days. You can also complain to the Information Commissioner's Office at any point — you do not have to come to us first.
Layer two — the full notice
1. Who we are and how to reach us
Pocket Docket Ltd is the controller of the personal data described in this notice, except where section 12 says we are a processor.
| Company | Pocket Docket Ltd |
| Registered in | Northern Ireland |
| Company number | NI742827 |
| Registered office | 137 York Road, Belfast, BT15 3GZ |
| ICO registration | ZC223982 |
| Privacy contact | privacy@pocketdocket.co.uk |
| Security contact | security@pocketdocket.co.uk |
| Complaints | app.pocketdocket.co.uk/legal/complaint |
We have not appointed a Data Protection Officer. We are not required to have one — we do not monitor people on a large scale as a core activity, and we do not process special category data on a large scale.
2. Who this notice is for
Three different kinds of people end up in this notice, and they are not in the same position.
If you are a Pocket Docket customer, or you work for one, or you have asked us about a trial — this notice describes what we do with your information and we are responsible for it. Sections 3 to 11 are yours.
If you are a customer of a business that uses Pocket Docket, and your name is in their invoices — that business is responsible for your information, not us. We handle it on their instructions. Section 12 explains the position and section 17 is written for you.
If you are just reading the website — section 3 and section 14 are the relevant parts. We do not track you across the internet.
3. What we collect, why, and on what legal basis
This is the core table. Everything after it is detail.
| What we do | What that involves | Lawful basis | How long we keep it | Who sees it |
|---|---|---|---|---|
| Create your account, sign you in, provide the subscription | Name, business name, email, phone, account and authentication records | Article 6(1)(b) — performance of a contract, where you are the person we contract with (sole traders and unincorporated businesses). Article 6(1)(f) — legitimate interests, where the subscriber is a limited company and you are a director or employee using the service; the interest is administering our contract with your employer | For the subscription, then 12 months | Us; Supabase; Vercel |
| Show you dashboards, analysis and Kipp's commentary on your own figures | Reading your Xero data, computing figures, generating explanations | Article 6(1)(b) — this is the service you are paying for | See section 10 | Us; Supabase; Vercel; Anthropic |
| Handle personal data about your own customers and suppliers that sits in your ledger | Names, contact details, invoice and payment history of the people you trade with | We are your processor. We have no independent lawful basis and we do not need one — your own basis as controller covers this processing, and our Data Processing Terms govern it | Deleted with your data — see section 10 | Us; Supabase; Vercel; Anthropic |
| Send your question and the computed figures to the AI provider | The question, the relevant figures, and the relevant ledger context | Article 6(1)(b) as controller, for your own business data. Processor, on your instructions, for ledger data about third parties | Section 7 | Anthropic (United States) |
| Store your conversations with Kipp so it can follow a conversation | The questions you ask the assistant, the answers it gives you, and when you asked. We store them so Kipp can follow a conversation — without them it cannot understand "and how does that compare with last quarter", because every question would start from nothing. They are never used to train or improve any machine-learning model, by us or by any provider we use | Article 6(1)(b) — this is part of the service you are paying for | 90 days, or until you clear them yourself with "Start a fresh chat" in the assistant | Us; Supabase; Anthropic |
| Keep the service secure — abuse prevention, rate limiting, device binding, hashed IPs | Salted hashes of IP addresses and email addresses, coarse device labels, access outcomes | Article 6(1)(f) — legitimate interests in network and information security | 90 days for request and rate-limit logs; 12 months for access logs | Us; Supabase |
| Take payment | Name, email, billing address, card details, subscription and payment history — handled by Stripe | Article 6(1)(b) — to take the payment you owe | With Stripe per their retention; our copy 6 years | Stripe |
| Keep tax and accounting records | Invoices, payment records, VAT records | Article 6(1)(c) — legal obligation under the Companies Act and VAT record-keeping rules | 6 years from the end of the financial year | Us; our accountant; HMRC on request |
| Answer support requests and handle complaints | Your correspondence and our notes | Article 6(1)(b) for service matters. Article 6(1)(c) for the complaints duty in section 164A of the Data Protection Act 2018. Article 6(1)(f) where we need the record to defend a claim | 24 months; complaint records 6 years | Us; Resend |
| Send you service email — sync failures, billing, security, changes to this notice | Your email address and the message | Article 6(1)(b). These are service messages, not marketing, so the direct marketing rules in PECR do not apply. We keep them strictly non-promotional | Send logs 12 months | Resend |
| Improve the product from usage telemetry | Which features are opened, how often, error rates, response times, AI cost and token counts | Article 6(1)(f) — legitimate interests in knowing whether the product works. This never reaches into the content of your ledger | 24 months | Us; Supabase |
Two things about legitimate interests
Where we rely on Article 6(1)(f), we have weighed our interest against your rights and written the assessment down. You can ask us for a summary and we will send it. You can object — see section 13.
The Data (Use and Access) Act 2025 now names processing necessary for the purposes of ensuring the security of network and information systems as a statutory example of a legitimate interest. That settles the first half of the test for our security processing — we no longer have to argue that the purpose is legitimate. It does not settle the rest. The necessity test and the balancing test still apply, and we still keep a written legitimate interests assessment for it.
One thing we are not relying on
The same Act created a new category of recognised legitimate interests under Article 6(1)(ea). We do not rely on it for anything. The list it points to is narrow — disclosures to public authorities, safeguarding, crime detection, national security, emergencies — and none of it describes what we do. We say this because the new basis is easy to over-claim, and if we ever did rely on it we would have to say so here.
And one commitment
We do not use ledger data across customers for anything. No benchmarking product, no "how does your business compare" feature built from other people's books, no model tuning. There is no lawful basis available to us for it. We are not asking you to trust that we would not — we are telling you it would be unlawful and that we have not built it.
4. Where the information comes from, in detail
Trial and enquiry details
When you ask to start a trial we collect your name, your business name, your email address, your phone number if you give it, whether you already connect other apps to Xero, and anything you type in the free-text box. We use it to set up your trial and to talk to you about it. We do not add you to a mailing list and there is no follow-up sequence if you say no.
If you do not go ahead, we keep the enquiry for 24 months so that we know who we have already spoken to, then delete it.
Referral enquiries
If an accountant or another business refers you to us, we will have your name, your business name and your contact details, and we will know who referred you. We use that to contact you about Pocket Docket and, if you become a customer, to record the referral. We tell you who referred you the first time we make contact. If you do not want to hear from us, say so once and that is the end of it.
The contact address you give us for the dashboard
Your dashboard link is sent to the email address you give us. We keep that address so we can reissue the link if you lose it, and so that we know which addresses are allowed to request a link for your business. When an address is removed it stops working immediately.
Accounting data from Xero
When you connect your Xero organisation, we read your accounting records — invoices, bills, contacts, bank transactions, account balances and the reports built from them. We store the access tokens that let us do it, encrypted. We take a snapshot on a schedule so your dashboard is fast and so we can show you movement over time.
We read. We do not write anything back to Xero, and we do not file anything with HMRC.
Some of that data is personal data about other people — your customers, your suppliers, the individuals at those businesses. Section 12 explains who is responsible for it.
You can disconnect Pocket Docket from inside your own Xero account at any time, without asking us first. That stops any further accounting data reaching us immediately. It does not delete what we already hold — for that, ask us, and see section 10.
Bank data
We have built the plumbing for a direct bank connection through Plaid, an open banking provider. It is not switched on. No customer bank data is being collected through it, and none will be until the regulatory and consent work behind it is finished.
We are telling you about a route that is not live because we would rather you heard it here than found the code. If and when we do enable it, we would collect your account name and number, the balance, and the transaction list for the accounts you specifically chose to connect — on your explicit consent, given at the time, through the bank's own screens, and revocable from your bank as well as from us. We will update this notice and tell existing customers before it is switched on.
Device binding
Your dashboard link locks to the first device that opens it. To do that we store a random identifier we generate ourselves (not a fingerprint of your device), a coarse description such as "iPhone · Safari" so you and we can tell devices apart, and the times it was bound and last seen.
If you need to move to a new device, ask us and we will reset it. If a link is opened on a second device we refuse it, and the refusal page says nothing about your business or your figures.
Security and abuse logs
We log requests to the public parts of the service so we can spot abuse and rate-limit it. In those logs we store salted hashes of IP addresses and email addresses rather than the raw values. That lets us count, correlate and block without keeping a table of real addresses whose only purpose is abuse detection.
Access to dashboards is logged with the outcome — bound, allowed, refused. Those logs are what we would look at if you told us something was wrong.
Support and complaints
If you write to us we keep the correspondence and our notes. Complaint records are kept longer than ordinary support email because we are required to keep a record of complaints and what we did about them.
Usage telemetry
We record that a dashboard was opened, that a question was asked, how long the answer took, how much it cost us, and whether anything errored. We do not log the text of your questions by default, and we never log the content of your ledger into the event store.
5. Payment — Stripe
Payments are taken by Stripe Payments UK Ltd and its group companies.
What Stripe receives: your name, your email address, your card details, your billing address, and your subscription and payment history.
What we receive: the last four digits of the card, the card brand, the expiry, whether the payment succeeded, and the subscription status. We never see or store your full card number. Checkout happens on a page hosted by Stripe, so the card number goes from your browser to Stripe and never passes through our systems.
Stripe's role. Stripe is our processor for taking your payment. Stripe is also an independent controller in its own right for parts of what it does — fraud detection, meeting its own regulatory and anti-money-laundering obligations, and complying with card scheme rules. For that part, Stripe decides what happens to your data and Stripe's own privacy policy applies. We cannot tell Stripe to stop doing it and neither can you.
6. Sub-processors — the companies that touch your data
| Who | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosting and delivery of the application | United States company; our deployment region is London |
| Supabase Inc. | The database where your data is stored | United States company; our database region is London |
| Anthropic PBC | Runs the AI model behind Kipp | United States |
| Stripe | Payments | United States and United Kingdom |
| Resend | Transactional email | United States company; sends from EU/Ireland infrastructure |
| Xero | The accounting system you connect. Xero is not our sub-processor — Xero is your provider, under your own agreement with them | Per your Xero terms |
We keep a current list, and we will tell you before we add a new one. If you object to a new sub-processor you can tell us and, if we cannot resolve it, you can cancel.
7. Kipp — the AI assistant
Kipp is software, not a person. We say so at the start of every session.
How it actually works
Our own code does the arithmetic. Every figure Kipp talks about — the cash position, the aged debt, the margin, the movement since last month — is computed by our software from your Xero data, and checked against known-correct test cases before the model ever sees it. The model is handed finished numbers. It does not do the sums. This matters: language models are unreliable at arithmetic and reliable at explanation, so we only ask them to explain.
What is sent to the AI provider
When you ask a question, we send to Anthropic PBC in the United States: your question, the computed figures relevant to it, and the relevant part of your ledger context.
That ledger context can include personal data about your own customers and suppliers — names, invoice amounts, how late they are paying. If you ask Kipp to draft a chasing email to a named customer, that customer's name and payment history go to Anthropic as part of the prompt.
We are stating this plainly because it is the disclosure most likely to be left out of a notice like this, and it is the one your own clients would care about most. It is also inherent in how the product works — there is no version of Kipp that answers questions about your ledger without the ledger reaching the model.
We store your conversations with Kipp, and you can clear them
The questions you ask Kipp, the answers it gives you, and when you asked are saved to your account. They are stored so that Kipp can follow a conversation: without them it cannot understand "and how does that compare with last quarter", because every question would start from nothing.
They are kept for 90 days and then deleted automatically. Unlike the periods in section 10 that are applied by review, this one is enforced by a sweep that deletes against the same number.
You can clear them yourself at any time with "Start a fresh chat" in the assistant. That deletes the stored turns rather than merely clearing the screen, and if it cannot, it tells you so instead of pretending it worked.
People at Pocket Docket can read them, and we would rather say so than let you assume otherwise. We are a small company; the people who build the service also run it. Your conversations with Kipp appear in our own internal console, which we use to keep the service working, to look into problems you report, and to see how Kipp is being used so we can improve it. We do not share them with anyone outside the company, we do not use them to train any model, and nobody reads them for curiosity. Two things limit what we can see, and both are real rather than promises: anything you clear with "Start a fresh chat" is deleted outright, so it disappears from our console too, and everything else is deleted automatically after 90 days.
The last few exchanges are replayed to Anthropic with your next question, so the model can follow what you are talking about. They are never used to train or improve any machine-learning model, by us or by any provider we use.
Training
Anthropic does not train models on the content we send. That is not a promise we are making on their behalf out of optimism — it is a term of our commercial agreement with them, and their published policy for business API customers says the same. Content is retained for a limited period for trust and safety purposes and then deleted.
Anthropic's role
Anthropic is our sub-processor. Where the data is yours, they process it on our instructions under our contract with them. Where the data is your customers' and suppliers', they are a sub-processor further down the chain from you.
Transfers
The transfer to Anthropic is a transfer to the United States. Section 8 explains the mechanism.
Drafts, not actions
Kipp produces drafts. An invoice Kipp writes is a draft until you approve it. A chasing email Kipp writes is a draft until you read it and press send. Nothing Kipp produces leaves your business, touches money, or reaches one of your customers without a human looking at it first. That is a hard gate in the product, not a setting you can turn off.
Accuracy
AI output can be wrong. It can be incomplete, out of date, or confidently mistaken. Check it before you act on it, and take advice from your accountant on anything that matters. Kipp is a way of understanding your numbers faster — it is not advice and it is not a substitute for your accountant.
Automated decision-making
Article 22 UK GDPR — now Articles 22A to 22D following the Data (Use and Access) Act 2025, in force since 5 February 2026 — is not engaged by anything Kipp does. Here is the reasoning, so you can check it rather than take it on trust.
- Commentary is not a decision. Kipp describes what the figures show. Describing a position is not deciding anything about a person, and Articles 22A to 22D bite on decisions that produce legal effects or similarly significant effects on an individual.
- There is meaningful human involvement. Every output that could affect anyone is a draft that a person reads and approves. The human is not rubber-stamping a machine's conclusion — they can change it, ignore it, or do the opposite. That is the involvement the law is looking for.
- We do not score or rank your customers. Kipp does not produce a credit score, a risk rating, or a ranked list of who to pursue. It does not assign anyone a category that follows them around.
This is a transparency statement and it is also our analysis on the record. If we ever build something that changes the answer, this section changes first.
8. Sending data outside the United Kingdom
Some of the companies above are in the United States. Where personal data goes there, we rely on:
- the UK Extension to the EU–US Data Privacy Framework, where the provider is certified under it; or
- the UK Addendum to the EU Standard Contractual Clauses, where they are not — supported by a documented transfer risk assessment for each provider.
The transfer to Anthropic is unavoidable if you want Kipp to work. The transfers to Vercel and Supabase relate to companies incorporated in the United States operating infrastructure we have configured in London. Resend sends from EU and Irish infrastructure but is a United States entity, so we treat it as a transfer.
You can have a copy of the safeguards. Email privacy@pocketdocket.co.uk and we will send you the relevant clauses and our transfer risk assessment, with commercial terms redacted.
9. Security
We use encryption in transit and at rest, encrypted storage of your Xero tokens, access controls, device binding on dashboard links, rate limiting, and logging of every access attempt.
Dashboard access is by a signed link bound to your device rather than a username and password. Treat the link as a credential and do not forward it. If a link is opened on a device it is not bound to, we refuse it and tell you nothing about the business behind it.
No system is completely secure. If there is a breach that is likely to result in a high risk to your rights, we will tell you without undue delay, and we will tell the ICO within 72 hours where the law requires it.
10. How long we keep things
These periods are policy, applied by scheduled review — not yet by an automated job. We are building one, and we would rather tell you that than let you assume it is already running. What is automatic today is deletion on request and the removal of your Xero tokens when you disconnect or cancel, both of which happen immediately.
| What | How long |
|---|---|
| Trial and enquiry records where you did not go ahead | 24 months |
| Account records | For the subscription, then 12 months |
| Accounting data and dashboard snapshots | 90 days after your subscription ends — so you can come back, or change your mind — and immediately if you ask us to delete them |
| Xero access tokens | Deleted the moment you disconnect or cancel |
| Billing and tax records | 6 years from the end of the financial year, because we are required to keep them |
| Support correspondence | 24 months |
| Complaint records | 6 years |
| Dashboard access logs | 12 months |
| Public request and rate-limit logs (hashed) | 90 days |
| Device bindings | For the subscription, then deleted with the account |
| Your conversations with Kipp | 90 days, or until you clear them yourself with "Start a fresh chat" in the assistant. This one is enforced automatically — a sweep deletes against the same 90 days |
| Usage telemetry | 24 months |
Ask and we delete. If you want your accounting data gone before the 90 days is up, tell us and we will do it, and confirm when it is done. The only things that survive a deletion request are the billing records we are legally required to keep and, where relevant, a minimal record that a deletion request was made and honoured.
11. Your rights
You have the right to:
- be told what we do with your data — this notice;
- get a copy of the data we hold about you;
- have it corrected if it is wrong;
- have it deleted in the circumstances the law allows;
- restrict what we do with it while something is being sorted out;
- portability — get the data you gave us in a machine-readable form, or have it sent somewhere else;
- object to processing we do on the basis of legitimate interests, including profiling;
- withdraw consent, where we asked for consent in the first place. Withdrawing it does not undo what we did before.
There is no form. There is no portal you have to use, no specific address you have to write to, and no particular words you have to say. Ask any part of the business, in any way you like, and we will treat it as a request.
How long we take. One calendar month. We can extend that by up to two further months if the request is complex or if you have made several, and if we do we will tell you within the first month and explain why.
When the month starts. From the latest of: the day we receive your request, the day we are satisfied we know who you are, and the day you pay any fee we are entitled to charge. In practice we do not charge a fee. If we genuinely need more information to work out what you are asking for — which data, which period — the clock pauses while we wait for your answer. These points reflect the Data (Use and Access) Act 2025 changes to how the response period is calculated.
What we search. Reasonable and proportionate searches. We will tell you what we searched if you ask.
Identity. We will ask you to confirm who you are, because handing your data to someone else would be worse than a delay. We will ask for the least we can get away with.
12. Personal data inside your own accounting records
Your ledger contains personal data about other people — your customers, your suppliers, and the individuals who work at them.
The position is settled: you are the controller of that data, and Pocket Docket is your processor. You decided to keep records about those people. You decided to use accounting software. You decide what goes in and what comes out. We read it because you told us to, and we do what you have instructed and nothing else. Our Data Processing Terms govern this and form part of your agreement with us.
In practice that means:
- we do not contact the people in your ledger. Ever. Not to market to them, not to survey them, not to tell them their invoice is overdue. If a chasing email goes out, it goes out from you, after you have read and approved it;
- we do not sell their data or share it for advertising;
- we do not use it for anything outside your own account — not to build benchmarks, not to train models, not to develop features for other customers;
- we delete it when your data is deleted;
- if one of them makes a request to us, we pass it to you and help you answer it. You decide the outcome, because you are the controller.
13. Cookies
We use a small number of cookies that are strictly necessary to make the service work — principally the cookie that binds your dashboard link to your device, which is the thing standing between a forwarded link and someone else reading your books. Strictly necessary cookies do not require consent, which is why you are not being asked to click a banner.
We do not use advertising cookies, we do not run third-party trackers, and there are no third-party assets on our pages.
14. Children
Pocket Docket is a product for businesses. It is not directed at children, and we do not knowingly collect data about them.
15. Complaining to us
If you are unhappy with how we have handled your personal data, tell us. You can email privacy@pocketdocket.co.uk, or use the complaint form at app.pocketdocket.co.uk/legal/complaint.
We will:
- acknowledge your complaint within 30 days;
- investigate it without undue delay;
- keep you informed about what is happening;
- tell you the outcome and what we have done; and
- keep a record of the complaint and how it was resolved.
This is not a courtesy. Since 19 June 2026, section 164A of the Data Protection Act 2018 — inserted by the Data (Use and Access) Act 2025 — requires us to make it easy for you to complain to us, to provide an electronic means of doing so, to acknowledge within 30 days, and to respond without undue delay.
You can also complain to the Information Commissioner's Office, at any time, and you do not have to come to us first:
- ico.org.uk/make-a-complaint
- 0303 123 1113
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Complaining to us does not affect that right, and we will never suggest otherwise.
You can also take a claim to court. Nothing here stops you.
16. Changes to this notice
We will update this notice when what we do changes. Where the change matters to you — a new sub-processor, a new category of data, a new purpose — we will tell you by email before it takes effect, not afterwards. Every version is dated, and previous versions stay available.
17. Information for our customers' customers
You may have arrived here because you saw the name Pocket Docket somewhere and wanted to know what it is.
Pocket Docket is accounting software. A business you deal with — probably one you buy from or sell to — uses it to read and understand its own accounting records. Your details are in those records because that business keeps records of the people it trades with, in the same way it always did when the records were on paper.
That business is responsible for your information, not us. They decided to keep records about you, they decided which software to use, and they are the ones who have to tell you how your data is used and answer your requests. In data protection language, they are the controller and we are their processor.
What we do with it while it is in our systems:
- it is stored in a database hosted in London;
- it may be sent to our AI provider in the United States when that business asks a question that touches your records, so an answer can be produced. That provider is contractually barred from training its models on it;
- it is not used to train any AI model;
- we never contact you. If that business sends you an invoice or a payment reminder that our software helped draft, it came from them, they wrote or approved it, and they are the sender;
- it is not sold, not shared for advertising, and not used to build any profile of you;
- it is deleted when that business's data is deleted.
If you want something done about it — a copy of your data, a correction, deletion — the request needs to go to the business whose records they are, because they are the ones who can decide. If you are not sure who that is, or you would rather start with us, email privacy@pocketdocket.co.uk. We will pass your request on and help them answer it, and we will tell you we have done it.
You can complain to us about our own handling of your data using section 15, and to the ICO at any time.
Version 1.0 · in force from 21 August 2026
© 2026 Pocket Docket Ltd · Registered in Northern Ireland, company number NI742827 · Registered office: 137 York Road, Belfast, BT15 3GZ · ICO registration ZC223982