Privacy Policy

(GDPR/UK DPA 2018 Compliant)

Data Collection

We process:

  • Personal data (name, email, contact details)
  • Financial data (invoices, receipts, bank feeds via Open Banking)
  • Device data (IP, browser type for security)

Legal Basis

  • Contractual necessity (service delivery)
  • Legitimate interest (fraud prevention)
  • Consent (for marketing communications)

Data Sharing

  • Subprocessors: AWS (UK data centers), Stripe (payments)
  • Legal compliance: HMRC requests (only when mandated)

User Rights

  • Subprocessors: AWS (UK data centers), Stripe (payments)
  • Legal compliance: HMRC requests (only when mandated)