Legal
Privacy notice
This notice explains what personal data Compliance Cockpit handles, on whose instructions, where it is kept and what you can ask us to do about it. It is written for two audiences: the accounting practices that license the software, and the people whose details end up in it.
Last updated: 28 July 2026
Who we are, and which of us is responsible
Almost every record in Compliance Cockpit belongs to an accounting practice, not to us. That distinction decides who you ask for what, so it comes first rather than last.
Two roles, and they are not interchangeable
For a practice’s own client records, the practice is the controller and we are the processor. The practice decides which clients, companies, officers and documents go into the system and what happens to them. We process that data only on the practice’s documented instructions, under a written agreement that meets Article 28 of the UK GDPR. We do not decide what the data is used for, we do not use it for our own purposes, and we never pool one practice’s data with another’s.
For the practice’s own account and for people who contact us directly, we are the controller. That covers staff logins, security and audit records about the use of the software, support correspondence, demo requests and billing.
Our details
Compliance Cockpit is a trading name of [registered company name], a company registered in England and Wales, company number [company number], registered office [registered office address].
Registered with the Information Commissioner’s Office under registration number [ICO registration number]. Data protection enquiries: [data protection contact — name, postal address and email]. We will say plainly whether that person is a statutory Data Protection Officer or a nominated contact.
What this notice covers
This website, and the Compliance Cockpitapplication your practice signs in to. It does not cover the practice’s own privacy notice to its clients, which is the practice’s to write, nor the websites of Companies House, HMRC or any other organisation we link to.
If your accountant uses Compliance Cockpit
Your details are in the system because your accountant put them there. They are the controller: they decide what is held and for how long, and their privacy notice — not this one — governs it. Ask them first for a copy of your data, a correction or a deletion.
If you ask us instead, we will not answer for them and we will not quietly ignore you. We pass the request to the practice, tell you we have done so, and help them respond. That is what a processor is required to do, and it is also the only way you get a complete answer — we hold one practice’s view of you, not every practice’s.
What we hold, and why we are allowed to
Set out by category, with the lawful basis named for each. Where we act as processor, the basis shown is the one the practice will normally be relying on as controller — the practice should state it in its own notice.
Practice account data
For each member of staff: name, work email address, role, whether the account has been disabled, and the time of last sign-in. Passwords are stored only as a bcrypt hash — never in a readable form. Where multi-factor authentication is on, the authenticator secret is encrypted with AES-256-GCM and recovery codes are stored as hashes that are marked spent when used. Invitations and password-reset links exist as an expiring, single-use token hash; the link itself is never kept.
Lawful basis: our contract with your practice, and our legitimate interests in operating a secure service (Article 6(1)(b) and 6(1)(f)).
Session and device data
A server-side session record holding a SHA-256 hash of your session token — not the token itself — its absolute expiry of seven days, and the moment multi-factor authentication was completed. If your practice connects to HMRC for VAT, HMRC’s Fraud Prevention Headers require a device context to be sent with each call: a device identifier, browser user agent, screen and window size, time zone, and the public IP address and port we observe on the request. That record is attached to the one session, is deleted with it, and IP addresses are redacted in diagnostic output.
Lawful basis: legitimate interests in authenticating users and preventing unauthorised access; the HMRC device context is a condition HMRC imposes on use of its Making Tax Digital API.
Client and company records
The practice’s working records: client and contact names, email addresses, telephone numbers, correspondence addresses and postcodes; entity type, engagement status and anti-money-laundering status; the companies acted for, their officers, persons with significant control, members and shareholdings; deadlines, tasks, notes, VAT records and generated documents. Where a practice chooses to record them, a date of birth and government identifiers are held — National Insurance numbers and Unique Taxpayer References are sealed with AES-256-GCM at rest, displayed masked, and revealed only by an explicit action from an owner or administrator.
Lawful basis: we act as processor on the practice’s instructions. The practice’s own basis is usually its legal obligations (the Companies Act 2006 and the Money Laundering Regulations 2017) and the performance of its engagement with the client.
Identity verification documents
Passports, driving licences, proof of address and similar evidence, uploaded by the practice or by the person themselves through a secure link. PDF, PNG, JPG or WEBP, up to 5MB. These files are never stored in the database and never in a publicly served directory: they sit on private storage under a path the server generates from record identifiers, never from the uploaded filename, with file permissions restricted to the application. Every read and write passes a guard that refuses any path resolving outside the storage root. File contents are never written to a log or into an audit entry. An upload link is held only as a token hash, expires, and can be revoked.
Lawful basis: processor, on the practice’s instructions — the practice normally relies on its legal obligation to carry out customer due diligence (Article 6(1)(c), Money Laundering Regulations 2017).
Supporting evidence files
Files attached to a VAT return or a filing as evidence. The database holds metadata only — file name, type, size, a SHA-256 checksum for integrity and duplicate detection, and the malware-scan result; the contents live on the same private storage. Scanning is done by a ClamAV service running inside our own infrastructure, so a client’s confidential spreadsheet is never uploaded to a public file-analysis site. Superseded and deleted evidence is retained in a soft-deleted state so the audit trail of what was relied on remains truthful.
Lawful basis: processor, on the practice’s instructions; scanning rests on our legitimate interests in keeping the service and its users safe.
Audit logs and product usage
An audit entry records who did what, to which record, and when, with a structured detail of the change. This is the accountability spine of the product: it is deliberately not erased when the record it describes is edited, because an audit trail that can be rewritten evidences nothing. We also record product-usage events — event type, the screen it happened on, and a company reference — scoped to your practice, to see which parts of the product are used. There is no third-party analytics, no advertising network and no cross-site tracking anywhere in the product or on this website.
Lawful basis: legitimate interests in accountability, security investigation and improving the product; and, for the practice, its own record-keeping obligations (Article 5(2)).
Enquiries and demo requests
If you email us, book a demonstration or ask a question through this website, we keep your name, contact details and what you wrote, so we can reply and keep track of the conversation. We do not add you to a marketing list on the strength of an enquiry.
Lawful basis: legitimate interests in responding to you and in discussing a possible contract.
Special category data
We do not ask for it, and the product has no field for health, biometric, political, religious or similar data. An identity document may incidentally reveal information a practice did not set out to collect — practices should upload only what their due-diligence procedures actually require, and redact the rest before uploading.
Lawful basis: not applicable — no special category data is collected by design.
Where it is stored, and for how long
Location
The application, its PostgreSQL database and the private file storage run on [cloud hosting provider and region — to be confirmed before launch], in the United Kingdom or the European Economic Area. Uploaded files are held on a persistent volume attached to the same deployment, not on a separate object store in another jurisdiction.
We will not move practice data outside the UK or the EEA without telling affected practices first and putting the safeguards described under international transfers in place.
How long we keep it
Client and company records.For as long as the practice’s account is live. The practice decides what to delete and when, in line with its own retention policy — which will usually be shaped by the five-year record-keeping period in the Money Laundering Regulations 2017 and by professional body requirements. On termination we delete or return the practice’s data within [termination return-or-delete period — to be set in the contract].
Sessions. Seven days from sign-in, as an absolute limit. Signing out deletes the session record immediately, and an administrator can revoke every session for a user at once.
Invitations and reset links. Held as an expiring hash and spent on first use.
Audit logs. Retained for the life of the practice account, because their value is that they cannot be tidied away.
Enquiries. Kept while we are in conversation and for a reasonable period afterwards, then deleted.
International transfers
By default there are none: the data stays in the UK or the EEA. Two optional features can change that, and both are off unless a practice deliberately turns them on — the optical character recognition provider for scanned filings, and the AI assistant. Both are described in the next section, together with what leaves the system when they are enabled.
Where a transfer outside the UK does occur, it is made under the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, supported by a transfer risk assessment. A practice that would rather no data left the UK at all should leave those two features switched off; every other part of the product works without them.
If something goes wrong
As processor, we notify the affected practice of a personal data breach without undue delay after becoming aware of it, with the detail the practice needs to make its own assessment and, where required, to notify the ICO within 72 hours. Where we are controller, we notify the ICO and affected individuals ourselves on the same statutory terms.
Sub-processors, and the registers we read from
We keep this list short on purpose. Two of the entries below are optional and disabled unless a practice supplies its own credentials; with no credentials configured, the feature reports itself unavailable and nothing is transmitted.
Sub-processors we may use
Cloud hosting and managed database
Runs the application, the PostgreSQL database and the private file volume. This is the only sub-processor that is always in the path. Provider and region: to be confirmed before launch, and named in the list below.
Transactional email delivery — optional
Used to send a secure document-upload link to a named person. If no email provider is configured, the product does not send email at all: it hands the practitioner a copyable or printable link instead, and never reports a delivery that did not happen.
Optical character recognition — optional, off by default
For scanned Companies House filings that carry no embedded text. A practice may configure Google Document AI or, as an alternative provider, OpenAI. When enabled, the page image is sent to that provider to be transcribed and the text is returned; the transcription is then treated as evidence a person must check, and is labelled as OCR-derived in the interface. Without credentials, the extraction pipeline reports OCR unavailable and no document leaves our infrastructure.
AI assistant features — optional, off by default
Where a practice enables the assistant, text is passed through a redaction step before it leaves the system: National Insurance numbers, email addresses, encrypted values and similar identifiers are removed. We record how many redactions were applied — a count, never the content — alongside the model, token counts and outcome. With no API key configured the assistant reports itself unavailable and nothing is sent anywhere.
Malware scanning — not a third party
Uploaded evidence is scanned by ClamAV running inside our own infrastructure. Files are never sent to a public or consumer scanning service, and nothing beyond a structured scan outcome is retained by the scanner.
Current named list, with each provider’s location and role: [named sub-processor list — to be published before launch]. We give practices advance notice of any addition or replacement, and a practice may object.
Companies House and HMRC are sources, not processors
Compliance Cockpit reads from the Companies House public register — company profile, filing history, officers and persons with significant control. Companies House publishes a partial date of birth (month and year) and a service address rather than a residential one, and that is what the product consumes. Ownership is reconstructed from those public filings and presented with the filing each figure came from.
Where a practice connects its own HMRC agent credentials, VAT obligations, liabilities, payments and penalties are read into the product; the OAuth tokens for that connection are sealed with AES-256-GCM and only ever opened on the server. In the current pilot deployment the HMRC credentials are omitted entirely, so no connection exists and no submission is possible.
Neither body is our sub-processor. They are independent controllers of their own records, and we do not send them personal data except where a practice itself chooses to transmit a VAT return through the product, in which case HMRC also requires the fraud-prevention device context described above.
What we never do with it
We do not sell personal data, share it with advertisers or data brokers, or make it available to another practice. We do not train any model on your practice’s data. Where an optional third-party provider is enabled, the data sent is used to return that one result — practices should read the provider’s own terms before enabling it, which is why the decision is left with the practice and not made for them.
Your rights under UK GDPR
These rights are not absolute and some depend on the lawful basis in play — the right to erasure, for example, does not override a practice’s statutory duty to keep due-diligence records. We will always explain which exemption we are relying on rather than simply declining.
- Access. A copy of the personal data held about you, and the information in this notice applied to your particular record.
- Rectification. Correction of anything inaccurate, and completion of anything partial.
- Erasure. Deletion where there is no longer a lawful reason to keep it. Statutory retention periods and audit-trail integrity may qualify this.
- Restriction. A pause on processing while an accuracy or objection question is resolved.
- Portability. Where processing rests on consent or contract and is automated, a machine-readable copy of the data you provided.
- Objection. To processing based on legitimate interests, including a right to object at any time to direct marketing, which we then stop.
- Withdrawal of consent. Where we ever rely on consent, you can withdraw it at any time without affecting what was done beforehand.
How to exercise them
If your details are in the product because a practice acts for you or your company, ask that practice — they hold the record and they decide. If you contact us, we will pass the request on, tell you that we have, and assist the practice in answering it.
If you are a member of a practice’s staff, or you have dealt with us directly, write to [data protection contact email and postal address]. We respond within one month, and will tell you if a complex request needs longer — up to a further two months, with reasons. There is no charge unless a request is manifestly unfounded or excessive.
We may need to confirm who you are before releasing personal data. We will ask for the least we can get away with, and we will not use what you send for anything else.
Automated decision-making and profiling
There is none with legal or similarly significant effect, and this is a design decision rather than a policy statement. The ownership engine reconstructs, grades and recommends; a person at the practice reviews and approves. Nothing is written to a statutory register without someone deciding it should, filings are prepared for a practitioner to submit, and generated documents are drafts for a qualified person to check and sign. Because a human being makes every consequential decision, the Article 22 right to object to a solely automated decision does not arise.
Complaints, contact and changes
If you are unhappy with how we have handled your data
Tell us first — [data protection contact email] — and we will investigate and reply. You do not have to come to us first, and you have the right to complain to the UK supervisory authority at any point.
The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. Make a complaint to the ICO. Complaining to the ICO does not affect any other legal remedy available to you.
Contact
Data protection enquiries and rights requests: [data protection contact email], [postal address for written requests]. General enquiries go through our contact page.
Changes to this notice
We update this notice when what we do changes — a new sub-processor, a new category of data, a different retention period. The date at the top always reflects the current version. Where a change materially affects how a practice’s data is handled, we tell affected practices directly rather than relying on them to notice a new date.
Last updated: 28 July 2026.