Keystone Logo
Features Integrations AI Copilot Book a Call
Sign In Book a Demo
Legal

Privacy Policy

Effective date: 26 February 2026  |  Version 1.0

Privacy Policy

Effective date: 26 February 2026  |  Version 1.0

Keystone AI Business Support Ltd ("we", "us", "our") is the data controller for personal data processed through the Keystone AI platform ("Platform"). We are registered in England & Wales.

In brief: We only access the data you authorise, we don't sell it to anyone, and you can disconnect or delete at any time. This policy explains the detail.

1. What This Policy Covers

This policy explains how we collect, use, store, share, and protect personal data when you use the Platform, including when you connect third-party services such as Intuit QuickBooks Online ("QBO"). It applies to all users of the Platform, including business owners, their employees, and end-customers whose data may be processed through the Platform.

2. Data We Collect

2.1 Data you provide directly

CategoryExamplesPurpose
Account informationName, email, phone, business name, addressAccount creation, billing, support
Platform contentNotes, SOPs, job records, communications you createDelivering Platform functionality
Support correspondenceEmails, chat messages to our support teamResolving issues, improving service

2.2 Data from connected services

When you authorise a connection to a third-party service, we access data within the scopes you approve. For QuickBooks Online, this typically includes:

QBO Data CategoryExamplesWhy We Access It
Company informationBusiness name, address, fiscal year settingsSyncing your business context into the Platform
Customer recordsCustomer names, contact details, billing addressesUnified customer view, invoicing, job matching
Financial documentsInvoices, estimates, payments, credit notesCross-platform reporting, reconciliation, KPI dashboards
Product/service itemsService names, rates, descriptionsJob-type mapping, pricing automation
Account/transaction dataChart of accounts, journal entries (if authorised)Financial reporting, margin analysis
Important — QBO data: We access only the data categories you authorise via the OAuth consent screen. We do not access data beyond the approved scopes. We never store your QBO login credentials.

2.3 Data collected automatically

CategoryExamplesPurpose
Usage analyticsPages visited, features used, session durationImproving the Platform, identifying issues
Device/browser infoIP address, browser type, operating systemSecurity, compatibility
CookiesSession cookies, preference cookiesAuthentication, personalisation

3. Legal Basis for Processing (UK GDPR)

Processing ActivityLegal Basis
Providing the Platform and connected integrationsContract — necessary to perform our agreement with you
Connecting to QBO and other third-party servicesConsent — you explicitly authorise each connection via OAuth
Usage analytics and service improvementLegitimate interest — improving our product and detecting issues
Billing and financial recordsLegal obligation — UK tax and accounting requirements
Security monitoringLegitimate interest — protecting you and us from threats

4. How We Use Your Data

We use your data to:

  1. Provide, maintain, and improve the Platform and its features.
  2. Sync, display, and generate reports from your connected services (including QBO).
  3. Generate AI-powered insights, suggestions, and outputs based on your data.
  4. Send service-related communications (e.g. alerts, updates, support responses).
  5. Ensure security, prevent fraud, and comply with legal obligations.

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties for their own marketing purposes.

5. AI Processing

The Platform uses artificial intelligence to analyse your data and generate outputs such as reports, recommendations, and operational insights. This processing is carried out to deliver the core features of the Platform (legal basis: contract performance). AI outputs are decision-support tools; they do not constitute professional advice.

Where AI processing involves automated decision-making with significant effects, you have the right to request human review. Contact us at the address in Section 13.

6. Who We Share Data With

RecipientWhySafeguards
Cloud infrastructure providers (e.g. hosting, databases)Running the PlatformData processing agreements, encryption at rest and in transit
Intuit / QBOTwo-way sync you authorisedOAuth 2.0, Intuit's own security programme
AI model providersGenerating AI outputsData processing agreements, no model training on your data
Payment processorsSubscription billingPCI DSS compliant

We may also disclose data where required by law, regulation, or valid legal process.

7. International Transfers

Some of our sub-processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements (IDTAs), Standard Contractual Clauses (SCCs), or reliance on an adequacy decision. Details of specific transfers are available on request.

8. Data Retention

Data TypeRetention Period
Account dataDuration of your subscription + 30 days
QBO synced dataCached during active connection; deleted within 30 days of disconnection
Billing records6 years (UK legal requirement)
Usage analytics24 months (anonymised thereafter)
Support correspondence24 months from resolution

When you disconnect a Connected Service (e.g. QBO), we delete or anonymise the associated data within 30 days unless retention is required by law.

9. Data Security

We implement appropriate technical and organisational measures, including:

  1. Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
  2. Access controls with least-privilege principles and role-based permissions.
  3. Regular security reviews and vulnerability assessments.
  4. Audit logging of data access and administrative actions.
  5. Incident response procedures with breach notification within 72 hours to the ICO where required.

10. Your Rights (UK GDPR)

You have the right to:

  1. Access — request a copy of the personal data we hold about you.
  2. Rectification — ask us to correct inaccurate data.
  3. Erasure — ask us to delete your data (subject to legal retention requirements).
  4. Restriction — ask us to limit how we process your data.
  5. Portability — receive your data in a structured, machine-readable format.
  6. Object — object to processing based on legitimate interest.
  7. Withdraw consent — where processing is based on consent (e.g. Connected Services), you can withdraw at any time by disconnecting the service or contacting us.

To exercise any right, email info@keystoneai.tech. We will respond within one calendar month.

11. Disconnecting QuickBooks Online

You can disconnect QBO from the Platform at any time by:

  1. Going to Settings → Connected Services in the Platform and clicking "Disconnect" next to QuickBooks Online; or
  2. Revoking access via Intuit's App Management page.

Upon disconnection, our OAuth tokens are revoked immediately and cached QBO data is deleted within 30 days. You may also request immediate deletion by contacting us.

12. Cookies

We use essential cookies for authentication and session management. We use analytics cookies to understand how the Platform is used. You can manage cookie preferences through your browser settings. A detailed cookie notice is available within the Platform.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before they take effect. The "effective date" at the top of this page will be updated accordingly.

14. Contact Us

Keystone AI Business Support Ltd
Data Protection queries: info@keystoneai.tech
General enquiries: info@keystoneai.tech
Registered in England & Wales — Company No. 16962475

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Keystone

Keystone is an AI-powered CRM for field service teams, bringing scheduling, invoicing, and operations together in one place.

Product

Features Integrations AI Copilot Book a Call

Company

About Careers Blog Press

Resources

Privacy Policy Eula Documentation Help Center API Reference Community

Keystone AI Business Solutions Ltd

Company Number: 16962475, Registered in England and Wales. Email: Jon@keystoneai.tech Phone: +447912731017 Registered Office Address: 5 Clares Farm Close, Warrington, Cheshire, WA1 4QE

© 2026 Keystone AI Solutions. All rights reserved.