Skip to content

Legal

Privacy notice

This notice explains what personal data Compliance Cockpit handles, on whose instructions, where it is kept and what you can ask us to do about it. It is written for two audiences: the accounting practices that license the software, and the people whose details end up in it.

Last updated: 28 July 2026

Who we are, and which of us is responsible

Almost every record in Compliance Cockpit belongs to an accounting practice, not to us. That distinction decides who you ask for what, so it comes first rather than last.

Two roles, and they are not interchangeable

For a practice’s own client records, the practice is the controller and we are the processor. The practice decides which clients, companies, officers and documents go into the system and what happens to them. We process that data only on the practice’s documented instructions, under a written agreement that meets Article 28 of the UK GDPR. We do not decide what the data is used for, we do not use it for our own purposes, and we never pool one practice’s data with another’s.

For the practice’s own account and for people who contact us directly, we are the controller. That covers staff logins, security and audit records about the use of the software, support correspondence, demo requests and billing.

Our details

Compliance Cockpit is a trading name of [registered company name], a company registered in England and Wales, company number [company number], registered office [registered office address].

Registered with the Information Commissioner’s Office under registration number [ICO registration number]. Data protection enquiries: [data protection contact — name, postal address and email]. We will say plainly whether that person is a statutory Data Protection Officer or a nominated contact.

What this notice covers

This website, and the Compliance Cockpitapplication your practice signs in to. It does not cover the practice’s own privacy notice to its clients, which is the practice’s to write, nor the websites of Companies House, HMRC or any other organisation we link to.

If your accountant uses Compliance Cockpit

Your details are in the system because your accountant put them there. They are the controller: they decide what is held and for how long, and their privacy notice — not this one — governs it. Ask them first for a copy of your data, a correction or a deletion.

If you ask us instead, we will not answer for them and we will not quietly ignore you. We pass the request to the practice, tell you we have done so, and help them respond. That is what a processor is required to do, and it is also the only way you get a complete answer — we hold one practice’s view of you, not every practice’s.

What we hold, and why we are allowed to

Set out by category, with the lawful basis named for each. Where we act as processor, the basis shown is the one the practice will normally be relying on as controller — the practice should state it in its own notice.

Practice account data

For each member of staff: name, work email address, role, whether the account has been disabled, and the time of last sign-in. Passwords are stored only as a bcrypt hash — never in a readable form. Where multi-factor authentication is on, the authenticator secret is encrypted with AES-256-GCM and recovery codes are stored as hashes that are marked spent when used. Invitations and password-reset links exist as an expiring, single-use token hash; the link itself is never kept.

Lawful basis: our contract with your practice, and our legitimate interests in operating a secure service (Article 6(1)(b) and 6(1)(f)).

Session and device data

A server-side session record holding a SHA-256 hash of your session token — not the token itself — its absolute expiry of seven days, and the moment multi-factor authentication was completed. If your practice connects to HMRC for VAT, HMRC’s Fraud Prevention Headers require a device context to be sent with each call: a device identifier, browser user agent, screen and window size, time zone, and the public IP address and port we observe on the request. That record is attached to the one session, is deleted with it, and IP addresses are redacted in diagnostic output.

Lawful basis: legitimate interests in authenticating users and preventing unauthorised access; the HMRC device context is a condition HMRC imposes on use of its Making Tax Digital API.

Client and company records

The practice’s working records: client and contact names, email addresses, telephone numbers, correspondence addresses and postcodes; entity type, engagement status and anti-money-laundering status; the companies acted for, their officers, persons with significant control, members and shareholdings; deadlines, tasks, notes, VAT records and generated documents. Where a practice chooses to record them, a date of birth and government identifiers are held — National Insurance numbers and Unique Taxpayer References are sealed with AES-256-GCM at rest, displayed masked, and revealed only by an explicit action from an owner or administrator.

Lawful basis: we act as processor on the practice’s instructions. The practice’s own basis is usually its legal obligations (the Companies Act 2006 and the Money Laundering Regulations 2017) and the performance of its engagement with the client.

Identity verification documents

Passports, driving licences, proof of address and similar evidence, uploaded by the practice or by the person themselves through a secure link. PDF, PNG, JPG or WEBP, up to 5MB. These files are never stored in the database and never in a publicly served directory: they sit on private storage under a path the server generates from record identifiers, never from the uploaded filename, with file permissions restricted to the application. Every read and write passes a guard that refuses any path resolving outside the storage root. File contents are never written to a log or into an audit entry. An upload link is held only as a token hash, expires, and can be revoked.

Lawful basis: processor, on the practice’s instructions — the practice normally relies on its legal obligation to carry out customer due diligence (Article 6(1)(c), Money Laundering Regulations 2017).

Supporting evidence files

Files attached to a VAT return or a filing as evidence. The database holds metadata only — file name, type, size, a SHA-256 checksum for integrity and duplicate detection, and the malware-scan result; the contents live on the same private storage. Scanning is done by a ClamAV service running inside our own infrastructure, so a client’s confidential spreadsheet is never uploaded to a public file-analysis site. Superseded and deleted evidence is retained in a soft-deleted state so the audit trail of what was relied on remains truthful.

Lawful basis: processor, on the practice’s instructions; scanning rests on our legitimate interests in keeping the service and its users safe.

Audit logs and product usage

An audit entry records who did what, to which record, and when, with a structured detail of the change. This is the accountability spine of the product: it is deliberately not erased when the record it describes is edited, because an audit trail that can be rewritten evidences nothing. We also record product-usage events — event type, the screen it happened on, and a company reference — scoped to your practice, to see which parts of the product are used. There is no third-party analytics, no advertising network and no cross-site tracking anywhere in the product or on this website.

Lawful basis: legitimate interests in accountability, security investigation and improving the product; and, for the practice, its own record-keeping obligations (Article 5(2)).

Enquiries and demo requests

If you email us, book a demonstration or ask a question through this website, we keep your name, contact details and what you wrote, so we can reply and keep track of the conversation. We do not add you to a marketing list on the strength of an enquiry.

Lawful basis: legitimate interests in responding to you and in discussing a possible contract.

Special category data

We do not ask for it, and the product has no field for health, biometric, political, religious or similar data. An identity document may incidentally reveal information a practice did not set out to collect — practices should upload only what their due-diligence procedures actually require, and redact the rest before uploading.

Lawful basis: not applicable — no special category data is collected by design.

Where it is stored, and for how long

Location

The application, its PostgreSQL database and the private file storage run on [cloud hosting provider and region — to be confirmed before launch], in the United Kingdom or the European Economic Area. Uploaded files are held on a persistent volume attached to the same deployment, not on a separate object store in another jurisdiction.

We will not move practice data outside the UK or the EEA without telling affected practices first and putting the safeguards described under international transfers in place.

How long we keep it

Client and company records.For as long as the practice’s account is live. The practice decides what to delete and when, in line with its own retention policy — which will usually be shaped by the five-year record-keeping period in the Money Laundering Regulations 2017 and by professional body requirements. On termination we delete or return the practice’s data within [termination return-or-delete period — to be set in the contract].

Sessions. Seven days from sign-in, as an absolute limit. Signing out deletes the session record immediately, and an administrator can revoke every session for a user at once.

Invitations and reset links. Held as an expiring hash and spent on first use.

Audit logs. Retained for the life of the practice account, because their value is that they cannot be tidied away.

Enquiries. Kept while we are in conversation and for a reasonable period afterwards, then deleted.

International transfers

By default there are none: the data stays in the UK or the EEA. Two optional features can change that, and both are off unless a practice deliberately turns them on — the optical character recognition provider for scanned filings, and the AI assistant. Both are described in the next section, together with what leaves the system when they are enabled.

Where a transfer outside the UK does occur, it is made under the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, supported by a transfer risk assessment. A practice that would rather no data left the UK at all should leave those two features switched off; every other part of the product works without them.

If something goes wrong

As processor, we notify the affected practice of a personal data breach without undue delay after becoming aware of it, with the detail the practice needs to make its own assessment and, where required, to notify the ICO within 72 hours. Where we are controller, we notify the ICO and affected individuals ourselves on the same statutory terms.

Sub-processors, and the registers we read from

We keep this list short on purpose. Two of the entries below are optional and disabled unless a practice supplies its own credentials; with no credentials configured, the feature reports itself unavailable and nothing is transmitted.

Sub-processors we may use

  • Cloud hosting and managed database

    Runs the application, the PostgreSQL database and the private file volume. This is the only sub-processor that is always in the path. Provider and region: to be confirmed before launch, and named in the list below.

  • Transactional email delivery — optional

    Used to send a secure document-upload link to a named person. If no email provider is configured, the product does not send email at all: it hands the practitioner a copyable or printable link instead, and never reports a delivery that did not happen.

  • Optical character recognition — optional, off by default

    For scanned Companies House filings that carry no embedded text. A practice may configure Google Document AI or, as an alternative provider, OpenAI. When enabled, the page image is sent to that provider to be transcribed and the text is returned; the transcription is then treated as evidence a person must check, and is labelled as OCR-derived in the interface. Without credentials, the extraction pipeline reports OCR unavailable and no document leaves our infrastructure.

  • AI assistant features — optional, off by default

    Where a practice enables the assistant, text is passed through a redaction step before it leaves the system: National Insurance numbers, email addresses, encrypted values and similar identifiers are removed. We record how many redactions were applied — a count, never the content — alongside the model, token counts and outcome. With no API key configured the assistant reports itself unavailable and nothing is sent anywhere.

  • Malware scanning — not a third party

    Uploaded evidence is scanned by ClamAV running inside our own infrastructure. Files are never sent to a public or consumer scanning service, and nothing beyond a structured scan outcome is retained by the scanner.

Current named list, with each provider’s location and role: [named sub-processor list — to be published before launch]. We give practices advance notice of any addition or replacement, and a practice may object.

Companies House and HMRC are sources, not processors

Compliance Cockpit reads from the Companies House public register — company profile, filing history, officers and persons with significant control. Companies House publishes a partial date of birth (month and year) and a service address rather than a residential one, and that is what the product consumes. Ownership is reconstructed from those public filings and presented with the filing each figure came from.

Where a practice connects its own HMRC agent credentials, VAT obligations, liabilities, payments and penalties are read into the product; the OAuth tokens for that connection are sealed with AES-256-GCM and only ever opened on the server. In the current pilot deployment the HMRC credentials are omitted entirely, so no connection exists and no submission is possible.

Neither body is our sub-processor. They are independent controllers of their own records, and we do not send them personal data except where a practice itself chooses to transmit a VAT return through the product, in which case HMRC also requires the fraud-prevention device context described above.

What we never do with it

We do not sell personal data, share it with advertisers or data brokers, or make it available to another practice. We do not train any model on your practice’s data. Where an optional third-party provider is enabled, the data sent is used to return that one result — practices should read the provider’s own terms before enabling it, which is why the decision is left with the practice and not made for them.

Your rights under UK GDPR

These rights are not absolute and some depend on the lawful basis in play — the right to erasure, for example, does not override a practice’s statutory duty to keep due-diligence records. We will always explain which exemption we are relying on rather than simply declining.

  • Access. A copy of the personal data held about you, and the information in this notice applied to your particular record.
  • Rectification. Correction of anything inaccurate, and completion of anything partial.
  • Erasure. Deletion where there is no longer a lawful reason to keep it. Statutory retention periods and audit-trail integrity may qualify this.
  • Restriction. A pause on processing while an accuracy or objection question is resolved.
  • Portability. Where processing rests on consent or contract and is automated, a machine-readable copy of the data you provided.
  • Objection. To processing based on legitimate interests, including a right to object at any time to direct marketing, which we then stop.
  • Withdrawal of consent. Where we ever rely on consent, you can withdraw it at any time without affecting what was done beforehand.

How to exercise them

If your details are in the product because a practice acts for you or your company, ask that practice — they hold the record and they decide. If you contact us, we will pass the request on, tell you that we have, and assist the practice in answering it.

If you are a member of a practice’s staff, or you have dealt with us directly, write to [data protection contact email and postal address]. We respond within one month, and will tell you if a complex request needs longer — up to a further two months, with reasons. There is no charge unless a request is manifestly unfounded or excessive.

We may need to confirm who you are before releasing personal data. We will ask for the least we can get away with, and we will not use what you send for anything else.

Automated decision-making and profiling

There is none with legal or similarly significant effect, and this is a design decision rather than a policy statement. The ownership engine reconstructs, grades and recommends; a person at the practice reviews and approves. Nothing is written to a statutory register without someone deciding it should, filings are prepared for a practitioner to submit, and generated documents are drafts for a qualified person to check and sign. Because a human being makes every consequential decision, the Article 22 right to object to a solely automated decision does not arise.

Cookies

One cookie, and it is the one that signs you in

The application sets a single strictly necessary cookie, cc_session. It holds an opaque random token — the server stores only a SHA-256 hash of it — and is marked HttpOnly and SameSite=Lax, is served with the Secure flag outside local development, and expires after seven days. Without it you cannot stay signed in, so it needs no consent banner.

There are no analytics, advertising or third-party cookies on this website. Your choice of the light or dark theme here is kept in your browser’s local storage and never sent to us or to anyone else.

The full cookie notice

Security

The measures behind the promises above

Passwords are stored as bcrypt hashes and session tokens only as hashes, so neither is usable if a database copy is ever obtained. Time-based multi-factor authentication is available and a practice can require it of everyone. National Insurance numbers, taxpayer references, authenticator secrets and third-party OAuth tokens are encrypted with AES-256-GCM at rest.

Every database query is scoped to one practice, and an automated cross-tenant attack suite runs on each change to prove that one practice cannot reach another’s records. Where a practice restricts which staff see which clients, that restriction is applied inside the query rather than by hiding rows on screen. Uploaded files are type-checked, size-limited, stored outside the web root behind a path-traversal guard, and scanned for malware.

How we handle your data

Complaints, contact and changes

If you are unhappy with how we have handled your data

Tell us first — [data protection contact email] — and we will investigate and reply. You do not have to come to us first, and you have the right to complain to the UK supervisory authority at any point.

The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. Make a complaint to the ICO. Complaining to the ICO does not affect any other legal remedy available to you.

Contact

Data protection enquiries and rights requests: [data protection contact email], [postal address for written requests]. General enquiries go through our contact page.

Changes to this notice

We update this notice when what we do changes — a new sub-processor, a new category of data, a different retention period. The date at the top always reflects the current version. Where a change materially affects how a practice’s data is handled, we tell affected practices directly rather than relying on them to notice a new date.

Last updated: 28 July 2026.