Frequently asked questions

Plain-English answers to what buyers ask us most — ownership, your data, security and how a build runs. We're an honest, early-stage business: where something is on the roadmap we say so. Our products are structured to match the relevant standards — a head start, not a guarantee — and we're not a legal or compliance authority.

Getting started

Who owns the dashboard and the data?+

You do. It's built for you and it's yours to keep. If you ever want to take it fully in-house, there's a self-hosted licensed-file option so nothing is tied to us.

How long does a build take?+

It starts with a free discovery call to map your data and the decisions it needs to support. From there a typical build runs a few weeks to handover, depending on how many sites and sources are involved.

What if my data is messy or inconsistent?+

That's the norm, not the exception. Cleaning, reconciliation, duplicate sites, credits against debits and legacy exclusions are all part of the build — handled once in a repeatable import routine.

Can I update the data myself instead of paying for management?+

Yes — that's the self-manage hosting tier. You load the data on your own schedule, and you can hand it back to us to manage whenever it suits.

Do I need separate AML software?+

Not for the record-keeping side. FinanceIQ keeps your Money Laundering Regulations 2017 client due-diligence register — risk rating, ID/KYC status, beneficial owners and review dates — built in alongside the deadlines, so it's one system rather than a standalone AML subscription on top. It's the record-keeping framework, not a PEP/sanctions data provider, and it doesn't submit SARs — those stay with you.

Your data, security & privacy

Where is my data stored?+

By default, on your own device — our dashboards run in your browser's local storage, with no backend and nothing sent to us. An optional hosted team mode (rolling out across the suite) keeps data in a UK database (London region), so it stays in the UK. We'll confirm whether it's available for your product and deal.

Who can see my data?+

In the default local mode, only you — it never leaves your device. Where the optional hosted team mode is enabled, access is limited to the people you invite, with role-based permissions designed to be enforced by the database, not just the app.

Can you — the vendor — read my data?+

In local mode, no — it's on your device and we have no access to it. In the optional hosted team mode, the design keeps your data in your own tenancy rather than a shared pool, and we never use it for analytics, training or marketing. There are no third-party trackers in the dashboards by default.

Is it UK GDPR compliant?+

Our products are structured to support UK GDPR — local-first by default (so often no personal data reaches us at all), and the optional hosted team mode is designed around UK data residency, role-based access, an audit trail and "you own your data". For any hosted data we act as your processor, with you as the controller, and we'll sign a Data Processing Agreement. We're honest that "GDPR compliant" is something you achieve as the controller — we give you a strong head start, not a guarantee.

Is my data encrypted?+

Yes — in local mode your data sits in your browser on your device and is as secure as that device (e.g. if you use disk encryption). Where the optional hosted team mode is used, data is encrypted in transit over HTTPS/TLS and at rest via the platform's database encryption.

Is there an audit trail?+

The optional hosted team mode is designed with an append-only audit log — entries can be added and read but not edited or deleted, so the trail is tamper-evident. We'll confirm availability for your specific product.

Do you use any third-party trackers or analytics?+

Not in the dashboards by default — there are no embedded third-party trackers or analytics. Our website and email use standard providers (e.g. Cloudflare for delivery); we'll share the full sub-processor list on request.

Certifications & assurance

Which security schemes and standards have you signed up to?+

Here's the honest list. Signed up today: we're on the ICO's public data-protection register (registration ZC184332 — verifiable on the ICO website), and we work to UK GDPR, acting as your processor with a Data Processing Agreement for any hosted data. In practice we run controls aligned to Cyber Essentials: multi-factor authentication on every admin and supplier account, encryption in transit (HTTPS/TLS) and at rest for hosted data, and UK (London) data residency. Not yet held: Cyber Essentials certification and the NHS DSPT — both are next on the roadmap, in that order. If it's not named here, we don't hold it.

Do you have Cyber Essentials or the NHS DSPT?+

Not yet — and we won't claim otherwise. We're an early-stage business with a clear, honest roadmap, and the first step is done: we're registered with the ICO (registration ZC184332). Cyber Essentials certification is next, then the NHS DSPT for NHS and social-care buyers. We're happy to talk you through exactly where we are.

What about NHS or patient-identifiable data?+

Because our apps are local-first by default, they often don't need to send any personal or patient data to us at all. Where the optional hosted team mode is used, it's designed to keep data in a UK tenancy with role-based access and an audit log. We don't position our tools as clinical systems, and for NHS use the relevant assurance route is the DSPT, which is on our roadmap. We'll support your DPIA with the information you need.

Can we run it on our own infrastructure?+

In effect, yes for the data: in default mode everything runs locally in your browser with no server. The optional hosted team mode follows an "own your data" model designed to keep hosted data in your own project rather than a vendor-controlled pool. We'll confirm the exact provisioning options available for your deal.

Pricing & contracts

Is there a minimum term?+

Self-serve plans are monthly-rolling — cancel anytime. Bespoke and managed builds run to a fixed minimum term (see pricing), with the first year payable in advance; within that you can still switch between managing the data yourself and having us manage it.

What does it cost?+

A one-off implementation fee sized to your business, then month-to-month hosting (self-manage or fully managed). Your exact tier depends on the number of sites and whether you or we keep the data current — you get a firm fixed quote on a free scoping call before you commit. See the pricing page for the bands.

Where is it hosted, and is it secure?+

UK-hosted, and built to the reporting and data-protection standards you already work to — Making Tax Digital and HMRC record-keeping for finance and invoicing, and UK GDPR throughout. See the full standards breakdown.

Still got a question?

Happy to provide a completed security questionnaire, a DPA, or information to support your DPIA. Email martyn@intelligentdashboards.co.uk and we'll come straight back.

Got a question we haven't covered?

Book a free scoping call — we'll answer it and confirm implementation and hosting once we've seen your data.

You own your dataUK-hostedUK GDPR compliant