Data Processing Agreement — outline
One-page summary of how Taxcc processes client data on your behalf under UK GDPR Article 28. Template for legal review.
Processor: Taxcc (trading name — confirm registered entity with your adviser) · Request signed DPA: info@taxcc.app
At a glance. You (the accountancy practice) are the controller for client personal data you enter. Taxcc (trading name — confirm registered entity with your adviser) is the processor and will only process that data to deliver Taxcc, on your instructions. This page summarises a full DPA — not a binding contract until signed.
1. Parties & roles
- Controller: The customer (accountancy practice) subscribing to Taxcc.
- Processor: Taxcc (trading name — confirm registered entity with your adviser), provider of the Taxcc platform.
- Scope: Personal data the Controller uploads or generates in Taxcc about the Controller’s clients, staff, and portal users.
2. Subject matter & duration
Processing is limited to providing the Service (hosting, backup, support, integrations you enable) for the subscription term and any agreed wind-down period after termination.
3. Nature & purpose
- Storage and organisation of client records, documents, deadlines, and communications you initiate.
- Companies House lookups you request; engagement and portal workflows you trigger.
- Optional AI Copilot when enabled — prompts and context you submit.
- Billing and account administration for the Controller’s own staff users.
4. Categories of data & subjects
- Data subjects: Controller’s clients, directors, portal users, and Controller’s employees using the Service.
- Typical data: names, contact details, company numbers, tax references, document contents, audit and access logs tied to your tenant.
- Special category data: only if the Controller chooses to upload it — the Controller is responsible for lawful basis and minimisation.
5. Controller obligations
- Lawful basis and transparency with data subjects (privacy notices, engagement letters).
- Accurate instructions to the Processor; no unlawful or excessive processing.
- Staff access control within your tenant (roles and permissions).
- Prompt notification if a data subject request or regulator enquiry requires Processor assistance.
6. Processor obligations
- Process only on documented instructions (Terms, this DPA, and in-product actions).
- Confidentiality commitments for personnel with access.
- Appropriate technical and organisational measures (encryption in transit, tenant isolation, access controls, audit logging — see Security).
- Assist with data subject rights and DPIAs where feasible.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
- Delete or return Controller data at end of contract except where law requires retention.
7. Subprocessors
The Processor may use subprocessors listed in the Privacy notice (e.g. hosting, Stripe, Companies House, optional AI). The Processor will impose equivalent data protection terms and notify material changes (this page and privacy notice updated; email for enterprise accounts where agreed).
| Provider | Role | Location | Typical data |
|---|---|---|---|
| Railway Corp. | Application hosting | USA / EU (region-dependent) | Account, practice and client data at rest in Postgres |
| Stripe, Inc. | Subscription billing | USA / EU | Billing contact, payment metadata (card data stays with Stripe) |
| Companies House | Public register lookups | United Kingdom | Company numbers and search queries you run |
| OpenAI (optional) | AI Copilot when configured | USA | Prompt text and practice context you send to Copilot |
| Cloudflare (optional) | Turnstile bot protection / CDN if enabled | Global | IP address and browser signals for fraud prevention |
8. International transfers
Where subprocessors process outside the UK, appropriate safeguards (e.g. UK IDTA / UK Addendum to SCCs) will be used as required. Details available on request.
9. Security & audit
Security measures are described at /security. On reasonable notice, the Processor may provide summaries of audits or certifications if available; onsite audits only by mutual agreement subject to confidentiality.
10. Liability & law
Liability caps and governing law follow the signed Terms of service unless the executed DPA states otherwise. UK GDPR and the Data Protection Act 2018 apply to Controller personal data processed under this outline.
11. Executing a binding DPA
Email info@taxcc.app with your practice legal name, registered address, and signatory. We will send a PDF for signature (or your paper if mutually agreed). Until signed, this outline describes our intended processor commitments but does not replace an executed agreement.
Related: Privacy notice · Terms · Cookies