# Privacy Policy — Broadhurst Finance Agent

**Last updated: 18 June 2026**

This Privacy Policy explains how Broadhurst Digital Limited ("we", "us", "our")
handles information in connection with the Broadhurst Finance Agent (the
"Application"), an internal tool that connects to QuickBooks Online to assist
with bookkeeping, financial reporting and reconciliation.

Broadhurst Digital Limited is a company registered in England and Wales
(company number [COMPANY NUMBER]), with its registered office at
[REGISTERED OFFICE ADDRESS]. For any privacy questions, contact
martin@broadhurst.digital.

## 1. Scope
The Application is used internally by Broadhurst Digital Limited to access and
analyse our own accounting data held in QuickBooks Online, provided by Intuit
Inc. It is not offered to, or used by, members of the public.

## 2. Information we access
When connected to a QuickBooks Online company, the Application may access
accounting information through Intuit's API, including: financial reports
(e.g. profit and loss, balance sheet, aged receivables/payables), invoices,
bills, payments, transactions, customers, suppliers, products and services,
and related company information. The Application also stores the OAuth 2.0
access and refresh tokens issued by Intuit to maintain the connection.

## 3. How we use information
We use this information solely to produce financial reports, perform
reconciliation, review outstanding receivables and payables, and otherwise
support the internal finance and bookkeeping functions of Broadhurst Digital
Limited.

## 4. Storage and security
- OAuth tokens are stored locally on a single, access-controlled company
  workstation, within the operating system user profile. They are not stored
  on, or transmitted to, any public-facing server operated by us.
- Accounting data is retrieved on demand from Intuit and processed locally. We
  do not maintain a separate cloud database of your QuickBooks data.
- Access to the workstation and the Application is restricted to authorised
  personnel of Broadhurst Digital Limited.

## 5. AI processing and third parties
To provide analysis and reconciliation, the Application uses an AI assistant
(Claude, provided by Anthropic). Relevant accounting data may be transmitted to
Anthropic's API to generate responses. Anthropic processes this data as a
service provider and, under its commercial terms, does not use it to train its
models. Other than this processing, we do not sell, rent, publish or share your
QuickBooks data with any third party, except where required by law.

## 6. Legal basis (UK GDPR)
Where personal data (for example, customer or supplier contact details
contained in accounting records) is processed, we rely on our legitimate
interests in managing the company's finances and on compliance with our legal
and accounting obligations.

## 7. Data retention
OAuth tokens are retained for as long as the connection is active and are
deleted when access is revoked or the Application is removed. You can disconnect
the Application at any time from within QuickBooks (Apps → Connected apps) or by
revoking access in the Intuit developer settings.

## 8. Your rights
Individuals whose personal data we hold have rights under UK data protection
law, including rights of access, rectification and erasure. Requests can be made
to martin@broadhurst.digital.

## 9. Changes
We may update this Policy from time to time. The "Last updated" date above
reflects the latest version.

## 10. Contact
Broadhurst Digital Limited — martin@broadhurst.digital