Data & security

Exports only after scope, terms and responsibility are clear.

An enquiry needs no client data. A pilot begins only after the supervised practice and Litt Horizon agree the exact exports, transfer method, processing instructions and deletion or return process in writing.

Core ruleNo platform credentials. No bank access. No records by email.

The accounting practice keeps corrections, client contact, professional judgement and final approval.

Engagement requirements

Written into the pilot—not left to assumption.

These requirements must be agreed before an export-review pilot can accept records. If they cannot be met, the work does not begin.

01

Contract and data-processing terms

A service scope, confidentiality terms and UK GDPR processor clauses are agreed before personal or financial data is accessed.

02

Approved exports, not credentials

The entry pilot uses agreed bank and general-ledger exports. It does not require accounting-platform credentials, bank credentials, payment authority or HMRC filing access.

03

Minimum necessary fields

The firm agrees the required CSV fields and removes data that the defined controls do not need before transfer.

04

Controlled data movement

The transfer method, storage location, access list and deletion or return instruction must be specifically authorised in writing.

05

AI use requires written approval

AI-assisted analysis is used only when the accounting practice approves the named provider, purpose, data fields, retention and transfer terms in writing. Otherwise the pilot is limited to deterministic controls. No client record is sent to an unapproved model.

06

Incident and access removal

A suspected data incident is escalated to the firm without undue delay. Pilot access is removed and data is returned or deleted as the contract requires.

Standard access boundaries

What Litt Horizon does not need for a pilot.

Bank payment authorityHMRC filing authorityAccounting-platform credentialsClient records in the enquiry formUnrestricted administrator accessDirect end-client contact

Before access

Questions a firm should ask—and Litt Horizon should answer.

  • Who will access the records?Named people, role and reviewer responsibility.
  • Where will data be processed?Approved systems, devices, locations and any subprocessors.
  • How long will copies exist?A defined retention and deletion/return instruction.
  • What happens after an incident?Named contact, escalation route and notification support.
  • What assurance is available?Truthful evidence of insurance, training, certifications and policies actually held.

Need a security or processor questionnaire?

Send the questionnaire before sharing client information.

Request details