top of page

ATHENA — INTERNAL USE POLICY

Almond Valley Accounting Limited

Document owner:
Bobby Gallacher, Director
Version: 1.0
Effective date: 6 April 2026
Review date: 6 April 2027
Classification: Internal —  Confidential



1. PURPOSE

This policy governs the use of Athena, an AI-powered practice management ecosystem developed and operated exclusively by Almond Valley Accounting Limited ("AVA", "the firm"). Athena is a private, internal tool. It is not a commercial product and is not made available to third parties.

The purpose of this policy is to set out the terms under which Athena may be accessed and used by authorised personnel, and to define the firm's obligations with respect to the data it processes.



2. SCOPE

This policy applies to:

 

  • All directors, employees, contractors, and consultants of Almond Valley Accounting Limited who access or use Athena in any capacity.

  • All data processed by Athena, including data sourced from third-party platforms integrated into the ecosystem (including QuickBooks Online, BrightManager, HMRC APIs, Google Workspace, and Make).

  • All automation scenarios, skills, workflows, and outputs generated by or within Athena.




3. WHAT ATHENA DOES

Athena is an AI-driven workflow orchestration system that enables AVA's team to manage client accounting work more efficiently. Its capabilities include:
 

  • Reading and analysing accounting data from client QuickBooks Online company files to which AVA holds authorised accountant access.

  • Generating structured review workbooks, reports, and outputs for internal use in VAT reviews, year-end reviews, and management account preparation.

  • Automating routine client communications, task management, and document generation under team supervision.

  • Orchestrating multi-step workflows via Make (formerly Integromat), with human checkpoints and approval routing at defined stages.


Athena does not make autonomous decisions on behalf of clients. All outputs are reviewed and approved by a qualified member of the AVA team before any action is taken.



4. DATA ACCESSED AND PROCESSED

4.1 Client Accounting Data

Athena accesses client QuickBooks Online data solely for the purpose of providing accountancy services to those clients. Access is established through the Intuit OAuth 2.0 authorisation framework. AVA holds accountant-level access to each client's QBO company file, granted by the client or established as part of the client engagement.

Data accessed includes, but is not limited to: trial balances, profit and loss reports, balance sheets, general ledger transactions, aged receivables, aged payables, and customer information.

4.2 Client Reference Data

Athena maintains an internal client registry containing reference information sourced from AVA's own practice management systems. This includes: client name, internal reference codes, company registration numbers, UTR numbers, VAT numbers, VAT scheme and period information, services provided, and assigned team members.

4.3 Data Flows

- Inbound: Client accounting data is pulled from QBO on demand, via authorised API calls, and is not retained beyond the active session unless explicitly saved to an output workbook.
- Outbound: Processed outputs (review workbooks, reports) are saved to AVA's Athena Shared Drive within Google Workspace, accessible only to authorised AVA personnel.
- Storage: Client reference data and OAuth tokens are stored in Make's encrypted data store infrastructure. OAuth tokens are refreshed automatically and subject to revocation at any time.



5. DATA PROTECTION AND SECURITY

Almond Valley Accounting Limited is the data controller for all personal data processed by Athena. Athena's operation is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

5.1 Lawful Basis

The lawful basis for processing client data through Athena is the performance of a contract (Article 6(1)(b) UK GDPR) — specifically, the provision of accountancy services under the terms agreed with each client — and legitimate interests (Article 6(1)(f)) in operating an efficient and secure internal practice management system.

5.2 Security Measures
 

  • All data in transit between Athena components is encrypted using TLS 1.2 or higher.

  • OAuth 2.0 client credentials (Client ID and Client Secret) are stored within Make's encrypted connection store and are never transmitted in plain text or stored in unsecured locations.

  • OAuth access tokens have a maximum lifespan of 60 minutes and are refreshed automatically. Refresh tokens are subject to a 100-day expiry and are revoked upon disconnection.

  • Access to the Athena Shared Drive and Make workspace is restricted to authorised AVA personnel via Google Workspace and Make role-based access controls.

  • Athena does not store sensitive financial data beyond what is required to produce and save an output. Raw API responses are not permanently retained.


5.3 Data Retention

Output workbooks and reports generated by Athena are retained in Google Drive in accordance with AVA's standard data retention policy. Client reference data held in the Make data store is reviewed annually and updated or removed as required.



6. THIRD-PARTY PLATFORM INTEGRATIONS

Athena integrates with the following third-party platforms. Each integration is subject to the respective platform's terms of service and data processing agreements:

QuickBooks Online (Intuit)
Purpose: Retrieval of client accounting reports and data
Data direction: Inbound

Make (Integromat)
Purpose: Workflow automation, data store, scenario orchestration
Data direction: Bidirectional

Google Workspace / Drive
Purpose: Output storage, document management
Data direction: Outbound

BrightManager
Purpose: Client practice management data
Data direction: Inbound (planned)

HMRC APIs
Purpose: VAT and tax submission data
Data direction: Bidirectional (planned)



7. AUTHORISED USE

Athena may only be used by personnel expressly authorised by the Director. Authorised use is strictly limited to:

- The performance of accountancy services on behalf of Almond Valley Accounting Limited for its clients.
- Internal practice management, workflow automation, and reporting activities.
- Testing and development of Athena capabilities within a controlled environment.

The following are expressly prohibited:
- Use of Athena to access data belonging to companies or individuals with whom AVA does not hold a current client engagement.
- Sharing Athena outputs, credentials, or access with third parties outside AVA without explicit director authorisation.
- Using Athena or its integrations to process data for any purpose unrelated to the provision of accountancy services.
- Attempting to circumvent Athena's human checkpoint and approval routing mechanisms.



8. SECURITY INCIDENTS

Any suspected or actual security incident involving Athena — including unauthorised access, data loss, or credential compromise — must be reported immediately to the Director (Bobby Gallacher) and the firm's Data Protection Officer.

AVA will assess all incidents in accordance with its data breach response procedure. Where a breach is likely to result in a risk to individuals' rights and freedoms, AVA will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR.

AVA has not experienced any security breach requiring notification to customers or regulatory authorities to date.



9. POLICY REVIEW AND UPDATES

This policy will be reviewed annually, or following any material change to Athena's architecture, integrations, or data processing activities. Updates will be version-controlled and communicated to all authorised users.Requests for changes to Athena's data processing activities or integrations must be submitted through the Athena Ideas pipeline and approved by the Director before implementation.



10. CONTACT

Questions regarding this policy or Athena's data processing activities should be directed to:

Director: Bobby Gallacher
Firm: Almond Valley Accounting Limited
Website: almondvalleyaccounting.co.uk
Email: info@almondvalleyaccounting.co.uk



This document is an internal policy of Almond Valley Accounting Limited.Version 1.0 | Effective 6 April 2026

© 2018 by Almond Valley Accounting

bottom of page