Legal
Privacy Policy
Last updated 19 August 2026. Applies to taxcheckit.co.uk and the TaxCheckIt application.
1. Who we are and what this notice covers
Kael Tripton Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ (ICO registration ZC135439), is the data controller for the personal data described here. Contact: [email protected]. This notice covers personal data we collect when you visit taxcheckit.co.uk, use the free tools, or use the TaxCheckIt application. It does not cover personal data that you, as a TaxCheckIt user, enter about your own customers, suppliers or clients — you are the controller of that data and we process it only on your behalf as your processor under our Terms. If you share other people's data with us, make sure you're permitted to do so.
2. What we collect
- Account data: email address, organisation name and type, VAT number, addresses you enter.
- Financial records you enter: ledger entries, bank CSV imports, contacts, invoices.
- HMRC data: with your authorisation, data we retrieve from or send to HMRC (obligations, returns, liabilities, payments, business details) and HMRC's receipts. HMRC access tokens are stored encrypted and never shown in the browser.
- Technical data required by HMRC: to comply with HMRC's fraud-prevention rules we collect and send to HMRC with each API call: your public IP address and port where available, device identifier (a random ID in a cookie), screen and window size, browser user-agent, time zone, local network IP addresses where your browser permits, a hashed user reference, and details of our software. This is a legal requirement for MTD software and cannot be opted out of while using HMRC-connected features.
- Lookup tool data: VAT numbers/EORIs you check, the HMRC response, your IP address (for rate limiting) and timestamp.
- Usage data: pages visited and interactions (analytics with IP anonymisation) and server logs.
- Payments: processed by a PCI-DSS compliant payment provider; we store plan, status and a payment-customer reference, never card numbers.
3. Why and on what basis
- Providing the Service and submitting to HMRC on your instruction — performance of a contract.
- Sending HMRC fraud-prevention headers and retaining submission records — legal obligation (HMRC MTD requirements; record-keeping rules).
- Security, fraud prevention, service improvement, analytics — legitimate interests, balanced against your rights.
- Marketing emails — consent, which you can withdraw at any time.
4. Where data is stored and who processes it
Your account and financial data is stored in the United Kingdom. We use carefully selected third-party service providers, acting on our instructions, for: cloud hosting and storage, authentication, transactional email delivery, payment processing, analytics, security and content delivery. HMRC receives only the data you choose to submit, under the permissions you grant. Where a provider processes data outside the UK we rely on UK adequacy regulations or the UK International Data Transfer Agreement / standard contractual clauses. A current list of sub-processors is available on request from [email protected].
5. Sharing
We do not sell personal data. We share it only with processors above, with HMRC on your instruction, with your agent/clients within the Service as you configure, and where required by law. Invoices you send contain the data you put in them and go to the recipients you choose.
6. Retention
Account and financial records: while your account is active, then deleted or anonymised within 90 days of closure — except submission payloads and HMRC receipts, invoices and audit logs, which we keep for 6 years after the relevant tax year to meet UK record-keeping and legal requirements. Lookup tool logs: 90 days. HMRC tokens: deleted on disconnect or expiry. Analytics: 14 months.
7. Security
Encryption in transit (TLS) and at rest; HMRC tokens in an encrypted vault; role-based access; audit logging of connections and submissions; secrets rotated; least-privilege service accounts. No system is perfectly secure; we will notify you and the ICO of qualifying breaches as the law requires.
8. Cookies
Strictly necessary: session/sign-in, a device identifier and browser facts required by HMRC fraud-prevention rules (tci_device, tci_fph), security. Analytics: aggregated usage analytics with IP anonymisation (we ask for consent where required). You can block cookies in your browser; HMRC-connected features need the necessary ones.
9. Your rights
You can access, correct, export, restrict, object to processing of, or ask us to delete your personal data, and withdraw consent, by emailing [email protected]. We respond within one month. You can complain to the Information Commissioner's Office (ico.org.uk). Note that some data (submissions, receipts) must be retained by law even if you ask for deletion.
10. Children
The Service is for adults (18+) and businesses; we do not knowingly collect data from children.
11. Changes
We'll post changes here and, for material changes, email account holders. Continued use after the effective date means you accept the updated policy.