Legal
Privacy Policy
Last updated: 4 July 2026
1. Who we are
Digital VAT UK ("Digital VAT UK", "we", "us", "our") provides an online bookkeeping and VAT filing service for UK sole traders and small businesses, operated by [SOLE TRADER LEGAL NAME], trading as Digital VAT UK, of [REGISTERED/BUSINESS ADDRESS].
For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), we are the data controllerof the personal data described in this policy. Our data protection registration with the Information Commissioner's Office (ICO) is [ICO REGISTRATION NUMBER — PENDING].
If you have questions about this policy or how we handle your data, contact us at [email protected].
2. Information we collect
We collect the following categories of information:
- Account information: name, email address, password (hashed), and phone number if you enable two-factor authentication, collected via our authentication provider when you sign up or log in.
- Business and tax information: your VAT registration number (VRN), business name, VAT scheme, and the figures that make up your VAT returns (sales, purchases, VAT due and reclaimed), which we prepare on your behalf and submit to HMRC.
- Bank transaction data: when you connect a bank account via Open Banking, we receive transaction descriptions, amounts, dates, counterparty names, and merchant category information from your bank, in order to import and categorise your bookkeeping records.
- Documents you upload or import: CSV statements, invoices, or receipts you choose to import, and any records you type or upload for categorisation.
- AI advisor conversations: questions you ask our AI bookkeeping assistant and the transaction/business data needed to answer them.
- Billing information: your subscription plan and billing history. Card details are collected and stored directly by our payment processor, Stripe — we do not store full card numbers ourselves.
- Technical and device data: IP address, browser type, device identifiers, screen and window size, timezone, and similar diagnostic data. Some of this data is required by HMRC (see section 5) and some is collected for security, fraud prevention, and error monitoring.
- Usage data: pages visited, features used, and general product analytics, collected via our analytics provider.
3. How we use your information
We use your information to:
- Create and manage your account, and authenticate you when you log in;
- Import, store, and categorise your bank transactions and bookkeeping records;
- Calculate your VAT liability and prepare and submit VAT returns to HMRC under Making Tax Digital (MTD), on your instruction;
- Provide AI-assisted transaction categorisation and answer questions through our AI advisor feature;
- Process subscription payments and manage your billing;
- Monitor, secure, and improve the service, including diagnosing errors and preventing fraudulent use;
- Communicate with you about your account, service updates, and (where you have consented) product news; and
- Comply with our own legal and regulatory obligations, including HMRC's fraud prevention requirements for software that connects to its APIs.
4. Our legal basis for processing
- Contract:processing your account, bank, and VAT data is necessary to provide the bookkeeping and filing service you've signed up for.
- Legal obligation: HMRC requires certain device, connection, and identity data to be sent alongside every VAT submission made through its Making Tax Digital APIs, as an anti-fraud measure (see section 5).
- Legitimate interests:for security monitoring, error tracking, and improving the product, in ways that don't override your own privacy rights.
- Consent: for non-essential analytics cookies and marketing communications, which you can withdraw at any time (see sections 8 and 10).
5. Submitting VAT returns to HMRC
When you ask us to submit a VAT return, we send your VAT registration number, the 9-box VAT return figures, and the relevant accounting period to HMRC's Making Tax Digital (MTD) VAT API, using an authorisation you grant directly to us through HMRC's own login page (we never see or store your Government Gateway password).
HMRC requires every MTD-compatible application to send "fraud prevention headers" with each API call. This means each submission is also accompanied by data such as your approximate IP address, device identifier, browser user agent, timezone, screen dimensions, and whether you have multi-factor authentication enabled. This data goes directly to HMRC, is required by law for any software connecting to their systems, and is not something we can turn off on your behalf. You can read more in HMRC's own fraud prevention guidance.
6. Connecting your bank account
We use a regulated Open Banking provider to let you connect your bank account. When you do, you're redirected to your bank's own secure login page — we never see or store your online banking credentials. Once connected, we receive read-only access to your transaction history, which we use solely to populate and categorise your bookkeeping records. You can disconnect your bank at any time from Settings → Connections, which revokes our access.
8. International transfers
Some of our service providers process data outside the UK. Where this happens, we rely on adequacy regulations or standard contractual clauses approved by the ICO to ensure your data continues to receive an equivalent level of protection.
9. How long we keep your data
- Account and bookkeeping data is kept for as long as your account is active.
- VAT submission records are retained for at least 6 years, in line with HMRC's record-keeping requirements for VAT.
- If you close your account, we delete or anonymise your personal data within 90 days, except where we're required to keep VAT-related records for the statutory period above, or need to retain limited data to comply with a legal obligation or resolve disputes.
11. Your rights
Under UK data protection law, you have the right to:
- Ask us for a copy of the personal data we hold about you;
- Ask us to correct inaccurate or incomplete data;
- Ask us to delete your data, subject to our record-keeping obligations above;
- Ask us to restrict or object to certain processing;
- Ask for your data in a portable format; and
- Withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email [email protected]. You also have the right to complain to the Information Commissioner's Office (ICO) if you think we haven't handled your data properly.
12. Security
We use industry-standard measures to protect your data, including encryption of data in transit and at rest, access controls restricting who can view your records, and mandatory two-factor authentication support for your account. No system is completely secure, but we monitor our service for vulnerabilities and respond promptly to any incidents.
13. Children
Our service is intended for business users aged 18 and over. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy from time to time, for example as our service or legal obligations change. We'll update the "last updated" date above, and if the changes are significant, we'll notify you by email or an in-app notice.
15. Contact us
If you have any questions about this policy or how we handle your data, contact us at [email protected].
Looking for our Terms of Service?