Client files
Your data, in plain words
This page covers the files you send us for a diagnostic or a sprint. Our privacy notice covers this website and business contact details.
What we ask for
- Read-only exports of the process: ledger exports, trial balances, purchase or rebate files, till and settlement totals. Business figures, not people.
- Access to where the output has to land, in your own account, at the lowest permission level that works.
Where your files go
| Where | What happens there |
|---|---|
| Our machine in the UK | Your files are stored and worked on here while the diagnostic or sprint runs. It is a single computer operated by Sam Usher, not a shared platform. |
| The AI model provider (Anthropic) | Sienna runs on Anthropic's Claude models, so the parts of your files Sienna reads are sent to Anthropic to be processed. Anthropic may process them outside the UK, including in the United States. |
| Email (Microsoft 365) | Files you email to us pass through our Microsoft 365 mailbox. |
| Your own account | What we build runs in your account, under your control. We do not host it. |
Nobody else receives your files. We do not sell them, share them or publish anything about you. We will not name you as a client or write a case study without your written permission.
How long we keep them
- Diagnostic: deleted within 7 days after the 5 working days you have to tell us the report is missing something.
- Sprint: deleted within 7 days after the 14-day fix window closes.
- If a sprint follows a diagnostic, the diagnostic files are kept for the sprint and follow the sprint rule.
- Sooner on request. Ask at any time and we delete them.
Deletion covers the working folder on our machine and the emails that carried the files. We confirm each deletion to you in writing.
The folder your files are kept in is excluded from our version history, so no copy of them is kept there. Before we take on a first client we confirm that the folder is also excluded from every backup we run.
What we do not accept
- Personal data. No employee, customer, patient or pupil records. Processes that need personal data are declined before any money is taken. Because none is in scope, we do not act as your data processor and no data processing agreement is needed.
- Payment-card data of any kind.
- Write access to production accounting or banking systems, and anything that could initiate a payment. We will not accept it even if offered.
If personal data reaches us by accident
If an export turns out to contain personal data, we stop, tell you the same working day, delete that copy and confirm the deletion. We do not work from it. If the process cannot be automated without personal data, you choose: we re-scope it so it does not touch that data, or we cancel and refund the deposit in full.
Questions
Email sam@dtventures.co.uk. The contractual version of this page is clauses 9 and 11 of the engagement letter you sign before any payment.