Privacy notice
How Taxcc handles personal data for practice users and marketing visitors. Template for UK GDPR — have your solicitor review before relying on it in contracts.
Last updated: 2026-08-27 · Controller: Taxcc (trading name — confirm registered entity with your adviser)
1. Who we are
Taxcc (trading name — confirm registered entity with your adviser) operates Taxcc (the “Service”) at taxcc.app. For account holders we act as a data controller for your staff account and billing data. For client records you enter, you are usually the controller and Taxcc acts as your data processor — see section 8.
Privacy contact: info@taxcc.app
2. Personal data we collect
- Account data: name, work email, password hash, role, practice name, tenant identifier.
- Billing: subscription status, Stripe customer id (payments handled by Stripe).
- Practice & client data you upload: client names, company numbers, contacts, documents, deadlines, portal users — under your instructions.
- Technical: IP address, request logs, audit events, security signals (rate limits, Turnstile if enabled).
- Marketing: mailing list sign-ups from the contact form (name, email, practice name) with consent.
3. Lawful bases (UK GDPR)
- Contract — providing the Service, authentication, support.
- Legitimate interests — security, fraud prevention, product improvement, minimal server logs (balanced against your rights).
- Legal obligation — where required for tax, accounting or court orders.
- Consent — optional analytics/marketing cookies and mailing list where we ask explicitly. You can withdraw consent anytime.
4. How we use data
We use data to run tenant-isolated workspaces, sync Companies House where you request it, send engagement and portal communications you trigger, process subscriptions, maintain audit trails, and protect the platform. We do not sell personal data.
5. Retention
- Active account data: for the life of your subscription plus a reasonable export window.
- Audit logs: retained for security and compliance (configure exact periods in your DPA).
- Marketing contacts: until you unsubscribe or ask us to delete.
- Backups: rolling backups on hosting provider schedules — deletion propagates per provider SLAs.
6. Sharing and subprocessors
We use vetted providers who process data on our instructions. Current list:
| Provider | Role | Location | Typical data |
|---|---|---|---|
| Railway Corp. | Application hosting | USA / EU (region-dependent) | Account, practice and client data at rest in Postgres |
| Stripe, Inc. | Subscription billing | USA / EU | Billing contact, payment metadata (card data stays with Stripe) |
| Companies House | Public register lookups | United Kingdom | Company numbers and search queries you run |
| OpenAI (optional) | AI Copilot when configured | USA | Prompt text and practice context you send to Copilot |
| Cloudflare (optional) | Turnstile bot protection / CDN if enabled | Global | IP address and browser signals for fraud prevention |
We may update this list; material changes will be reflected here and in your DPA.
7. International transfers
Some subprocessors may process data outside the UK. Where required we rely on appropriate safeguards (e.g. UK IDTA / SCCs) as implemented in vendor agreements. Ask us for copies relevant to your contract.
8. Practice client data & DPA
When you store client personal data in Taxcc, you determine purposes and means — you are the controller. Taxcc processes that data only to provide the Service, on your documented instructions (terms + acceptable use + DPA).
See our Data Processing Agreement outline for what a signed DPA with Taxcc covers. For a countersigned copy: info@taxcc.app.
9. Your rights
If UK GDPR applies you may have the right to access, rectify, erase, restrict, object, and data portability, and to withdraw consent where processing is consent-based. You may lodge a complaint with the Information Commissioner's Office (ICO).
To exercise rights: info@taxcc.app. We may need to verify your identity.
10. Security
We use encryption in transit (TLS), tenant-scoped access, httpOnly session cookies, CSRF protection on forms, rate limiting, and audit logging. See our Security page for technical detail.
11. Cookies
| Name | Category | Purpose | Duration | Type |
|---|---|---|---|---|
| accounthub_token | essential | Keeps you signed in to your practice workspace. | Up to 12 hours (session JWT) | HTTP cookie |
| taxcc_csrf | essential | Protects login, signup and contact forms from cross-site request forgery. | Up to 4 hours | HTTP cookie |
| taxcc_cookie_consent_v2 | essential | Remembers your cookie choices on the public website. | 12 months (browser local storage) | Local storage |
| _optional_analytics | analytics | Would measure site usage if you opt in. No third-party analytics script is loaded until you accept analytics cookies. | Varies by provider if enabled | HTTP cookie (if enabled) |
| _optional_marketing | marketing | Would support campaign measurement if you opt in. Not used on Taxcc today unless we enable it and you consent. | Varies by provider if enabled | HTTP cookie (if enabled) |
12. Changes
We may update this notice. We will post the new version on this page with an updated date. Significant changes affecting processors may also be emailed to account owners.