Privacy Policy
Last updated: December 2024
1. Introduction
TaxStats Ltd ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our TaxStats Source platform.
We are registered in England and Wales and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
Personal Information
- Name and contact details (email address, phone number)
- Account credentials
- National Insurance number (for HMRC submissions)
- Unique Taxpayer Reference (UTR)
- Business information
Financial Information
- Income and expense records
- Bank transaction data (when connected)
- Receipts and invoices you upload
- Tax calculation data
Technical Information
- IP address and device information
- Browser type and version
- Usage data and analytics
- Cookies and similar technologies
3. How We Use Your Information
We use your information to:
- Provide and maintain our tax filing services
- Process your quarterly and annual tax submissions to HMRC
- Automatically categorise your receipts and expenses using AI
- Calculate your tax obligations accurately
- Connect with HMRC on your behalf via their APIs
- Send you important updates about deadlines and submissions
- Improve our services and develop new features
- Comply with legal obligations
4. Legal Basis for Processing
We process your personal data based on:
- Contract: To provide the services you've signed up for
- Legal obligation: To comply with tax and accounting regulations
- Legitimate interests: To improve our services and prevent fraud
- Consent: For marketing communications (which you can withdraw anytime)
5. Data Sharing
We may share your information with:
- HMRC: For tax submissions as authorised by you
- Service providers: Cloud hosting, payment processing, and AI services
- Professional advisers: Lawyers, accountants, and auditors
- Regulatory authorities: When required by law
We do not sell your personal data to third parties.
6. Data Security
We implement robust security measures including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication
- Regular security audits and penetration testing
- SOC 2 Type II compliant infrastructure
- Employee security training and access controls
7. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations. Tax records are typically retained for 7 years in accordance with HMRC requirements.
You can request deletion of your account and data at any time, subject to our legal retention obligations.
8. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data
- Portability: Receive your data in a portable format
- Restriction: Limit how we use your data
- Objection: Object to certain processing activities
- Withdraw consent: Where processing is based on consent
To exercise these rights, contact us at privacy@taxstatsai.com
9. International Transfers
Your data is primarily stored and processed within the UK and European Economic Area. Where we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK ICO.
10. Contact Us
For privacy-related enquiries:
- Email: privacy@taxstatsai.com
- Data Protection Officer: dpo@taxstatsai.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.