TaxCheckIt

Legal

Privacy Policy

Last updated 19 August 2026. Applies to taxcheckit.co.uk and the TaxCheckIt application.

1. Who we are and what this notice covers

Kael Tripton Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ (ICO registration ZC135439), is the data controller for the personal data described here. Contact: [email protected]. This notice covers personal data we collect when you visit taxcheckit.co.uk, use the free tools, or use the TaxCheckIt application. It does not cover personal data that you, as a TaxCheckIt user, enter about your own customers, suppliers or clients — you are the controller of that data and we process it only on your behalf as your processor under our Terms. If you share other people's data with us, make sure you're permitted to do so.

2. What we collect

3. Why and on what basis

4. Where data is stored and who processes it

Your account and financial data is stored in the United Kingdom. We use carefully selected third-party service providers, acting on our instructions, for: cloud hosting and storage, authentication, transactional email delivery, payment processing, analytics, security and content delivery. HMRC receives only the data you choose to submit, under the permissions you grant. Where a provider processes data outside the UK we rely on UK adequacy regulations or the UK International Data Transfer Agreement / standard contractual clauses. A current list of sub-processors is available on request from [email protected].

5. Sharing

We do not sell personal data. We share it only with processors above, with HMRC on your instruction, with your agent/clients within the Service as you configure, and where required by law. Invoices you send contain the data you put in them and go to the recipients you choose.

6. Retention

Account and financial records: while your account is active, then deleted or anonymised within 90 days of closure — except submission payloads and HMRC receipts, invoices and audit logs, which we keep for 6 years after the relevant tax year to meet UK record-keeping and legal requirements. Lookup tool logs: 90 days. HMRC tokens: deleted on disconnect or expiry. Analytics: 14 months.

7. Security

Encryption in transit (TLS) and at rest; HMRC tokens in an encrypted vault; role-based access; audit logging of connections and submissions; secrets rotated; least-privilege service accounts. No system is perfectly secure; we will notify you and the ICO of qualifying breaches as the law requires.

8. Cookies

Strictly necessary: session/sign-in, a device identifier and browser facts required by HMRC fraud-prevention rules (tci_device, tci_fph), security. Analytics: aggregated usage analytics with IP anonymisation (we ask for consent where required). You can block cookies in your browser; HMRC-connected features need the necessary ones.

9. Your rights

You can access, correct, export, restrict, object to processing of, or ask us to delete your personal data, and withdraw consent, by emailing [email protected]. We respond within one month. You can complain to the Information Commissioner's Office (ico.org.uk). Note that some data (submissions, receipts) must be retained by law even if you ask for deletion.

10. Children

The Service is for adults (18+) and businesses; we do not knowingly collect data from children.

11. Changes

We'll post changes here and, for material changes, email account holders. Continued use after the effective date means you accept the updated policy.