Auditax

Auditax Privacy Policy

Controller: AUDITAX SERVICES LIMITED Company number: 15756288 (England and Wales) Registered office: 30 Welbeck Street, London, W1G 8ER, United Kingdom Service: the website auditax.pro and the Auditax tax preparation platform (the "Service")

Version: 1.0 Effective date: 3 August 2026 Last reviewed: 3 August 2026


1. Purpose and scope of this Policy

This Policy explains how AUDITAX SERVICES LIMITED ("Auditax", "we", "us", "our") collects, uses, discloses, transfers, retains and protects personal data when you:

This Policy covers both the "self-preparation" use of the software and the assisted use in which an authorised tax professional (in the United Kingdom, an authorised agent; in Switzerland, an authorised fiduciary, starting with the Canton of Ticino) reviews and signs off your return where the law requires it.

This Policy does not cover third party websites, tax authority portals, banking portals or professional firms that operate under their own privacy notices. Where a separate professional firm acts as an independent controller of your data, we identify that in Section 9 and that firm's own privacy notice will also apply.

2. Applicable data protection law

We process personal data in accordance with:

Where the requirements of these frameworks differ, we apply the standard that gives you the higher level of protection in respect of the specific processing activity.

3. Controller, representatives and contact points

3.1 Controller

AUDITAX SERVICES LIMITED is the controller for the processing described in this Policy, except where this Policy states that we act as processor or that a third party acts as an independent controller.

3.2 Data protection contact

Data protection contact: The Data Protection Lead Email: privacy@auditax.pro Postal address: Data Protection, AUDITAX SERVICES LIMITED, 30 Welbeck Street, London, W1G 8ER, United Kingdom

We aim to acknowledge privacy enquiries within five working days.

3.3 Data Protection Officer

We are not required to appoint a Data Protection Officer under Article 37 UK GDPR. Accountability for data protection sits with the director responsible for compliance, supported by the data protection contact named above.

3.4 Representatives

3.5 Registration

We are registered with the Information Commissioner's Office ("ICO") under registration reference ZB919507.

4. Categories of personal data we process

The Service is document driven. The volume and sensitivity of the data we hold depends on the tax situation you ask us to handle. We process the following categories.

4.1 Account and identity data

Full name, preferred name, date of birth, marital or civil partnership status where relevant to the return, residential address and address history, country and canton of tax residence, nationality, email address, telephone number, account credentials in hashed form, multi factor authentication identifiers, interface language (EN, IT, FR, DE), workspace selection (United Kingdom, Switzerland) and account status.

4.2 Tax identifiers and authority credentials

National Insurance number, Unique Taxpayer Reference, HMRC Government Gateway identifiers where you disclose or connect them, agent authorisation references, Swiss AHV/AVS number where required by the cantonal return, cantonal and municipal taxpayer reference numbers, tax year and period identifiers.

4.3 Financial and tax data

Employment and PAYE data, including P60, P45 and P11D content, payroll references and employer details; self employment and sole trade income and expenditure, invoices, receipts, mileage and asset records; bank and building society interest; dividends and investment income; pension income and contributions; property income; capital transactions where in scope; Swiss federal, cantonal and municipal income and wealth items, including securities and account statements, real estate values, debts and deductions; foreign income and assets where declarable; bank account details used for refunds or fee payment; balances, transaction level data and statement lines contained in documents you upload or in feeds you authorise.

4.4 Documents and evidence

All files you upload or forward, including scans, photographs, PDFs, spreadsheets and email attachments; machine extracted text and structured fields derived from those files; the audit trail linking each figure in the dossier to its underlying source document, page and field; your answers to platform questions; annotations, review comments and queries raised by you, by us or by the authorised tax professional; version history of the dossier and of every submitted or draft return.

4.5 Data about third parties

Documents you provide may contain personal data relating to other individuals, for example a spouse or civil partner, dependants, business partners, employees, tenants, clients, counterparties or a deceased person's estate. You provide that data to us on the basis set out in Section 14.

4.6 Special category and criminal offence data

We do not seek special category data. It may nevertheless reach us because tax relevant documents contain it, for example medical expenses or disability related allowances (health data), church tax deductions in Switzerland (data revealing religious belief), trade union subscriptions, or donations that reveal political or philosophical convictions. Under the FADP, financial data and data on social assistance measures may also be treated as sensitive. Criminal offence data may arise where a penalty, investigation or voluntary disclosure is relevant to your tax position. We process such data only to the extent strictly necessary to prepare, verify or defend the return, on the bases set out in Section 6.5, and we ask you not to send us sensitive material that is not required for the return.

4.7 Communications data

Emails, support tickets, web form submissions, chat transcripts, call records and call notes where used, and the metadata of those exchanges.

4.8 Technical, usage and security data

IP address, approximate location derived from IP, device and browser type, operating system, device and session identifiers, referring URL, pages and features used, timestamps, language and locale settings, log data, error and diagnostic data, authentication events, consent records, and audit logs of access to your dossier by our staff or by an authorised tax professional.

4.9 Billing data

Subscription or engagement plan, invoices, amounts, payment status, payment method token or reference held by our payment provider, VAT status and billing address. We do not store full payment card numbers.

4.10 Compliance and onboarding data

Identity verification results, document authenticity checks, sanctions, politically exposed person and adverse media screening results, source of funds or source of wealth information where required, risk rating, and records created to satisfy anti money laundering and professional obligations.

5. Sources of personal data

6. Purposes and legal bases

6.1 Providing the Service

Creating and administering your account and workspaces, ingesting and reading your documents, extracting and structuring data, applying deterministic calculation and verification rules, building the traceable dossier, presenting figures and their sources for your approval, generating drafts, and transmitting a return or a periodic update to the competent authority on your instruction.

Legal basis: performance of a contract (Article 6(1)(b) UK GDPR). Under the FADP, this processing is necessary in relation to the conclusion or performance of a contract with you.

6.2 Assisted review and professional sign off

Making the dossier available to an authorised tax professional for review, query, correction and sign off where the law requires it, and recording that process.

Legal basis: performance of a contract, and compliance with a legal obligation to which we or the professional are subject (Article 6(1)(b) and 6(1)(c)).

6.3 Support, communication and service messages

Answering queries, raising and resolving questions on figures, sending deadline reminders, filing confirmations, security notices and material changes to the Service.

Legal basis: performance of a contract and our legitimate interests in administering the relationship (Article 6(1)(b) and 6(1)(f)).

6.4 Billing, credit control and accounting

Invoicing, collecting fees, managing arrears and maintaining accounting records.

Legal basis: performance of a contract, legal obligation and legitimate interests in recovering sums due.

6.5 Special category and criminal offence data

Processing sensitive material contained in tax relevant documents so that reliefs, deductions and disclosures can be prepared correctly, and so that the dossier remains a complete evidential record.

Legal basis: your explicit consent (Article 9(2)(a) UK GDPR), or where applicable the establishment, exercise or defence of legal claims (Article 9(2)(f)). Criminal offence data is processed under a Schedule 1 Data Protection Act 2018 condition, in particular for the purposes of legal claims and compliance with regulatory requirements. Under the FADP we rely on your express consent for the processing of sensitive personal data, or on an overriding interest where the law permits.

You may withdraw consent to the processing of sensitive material at any time, but if the material is necessary to support a figure in a return, we may be unable to prepare or maintain that part of the dossier and may have to suspend or terminate the engagement.

6.6 Anti money laundering, know your client and sanctions compliance

Identity verification, screening, risk assessment, record keeping, and where legally required the reporting of suspicious activity.

Legal basis: legal obligation and substantial public interest under Schedule 1 Data Protection Act 2018. Where a report is made, we are prohibited by law from informing you of it and your right of access may be lawfully restricted in respect of that material.

6.7 Security, fraud prevention and integrity of the Service

Authentication, access control, logging, monitoring for unauthorised access, abuse prevention, backup, disaster recovery and incident investigation.

Legal basis: legitimate interests in protecting our clients, our systems and the integrity of tax filings, and legal obligation in respect of the security of processing.

6.8 Service improvement, testing and quality assurance

Diagnosing defects, improving extraction accuracy, testing calculation rules, and reviewing sample dossiers for quality. Wherever technically possible we use anonymised, pseudonymised or synthetic data for these purposes.

Legal basis: legitimate interests. Where we cannot achieve the purpose without identifiable client data, we apply strict internal access controls and, where required, seek your consent.

6.9 Artificial intelligence and automated processing components

The Service uses software to read documents, classify them, extract fields and apply deterministic rules. See Section 11 for how we govern this, including the prohibition on using your data to train third party general purpose models without a lawful basis and appropriate contractual controls.

Legal basis: performance of a contract, and legitimate interests in respect of accuracy testing.

6.10 Marketing

Sending information about the Service, new jurisdictions, features and tax deadlines.

Legal basis: consent, or legitimate interests under the soft opt in for existing clients in respect of similar services. Every marketing message contains an unsubscribe mechanism. Withdrawal of marketing consent does not affect service and compliance communications.

6.11 Legal claims, disputes, audits and regulatory requests

Responding to tax authority enquiries, professional indemnity matters, complaints, litigation, insurance and audit.

Legal basis: legal obligation and legitimate interests in establishing, exercising or defending legal claims.

6.12 Corporate transactions

Due diligence and transfer in connection with a reorganisation, financing, merger or sale of all or part of the business, using redaction and confidentiality controls proportionate to the stage of the transaction.

Legal basis: legitimate interests.

7. Legitimate interests assessment

Where we rely on legitimate interests, we have assessed the purpose, the necessity of the processing, and the balance against your rights and expectations, and we have recorded that assessment. In summary, we consider that a client engaging a tax preparation service reasonably expects us to secure the platform, verify identity, log access to the dossier, pursue unpaid fees, improve the accuracy of extraction and calculation, and preserve records needed to defend a filing. You may request a summary of the relevant assessment and you may object under Section 13.6.

8. Automated decision making and profiling

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, with the following qualifications:

You may ask for human intervention, express your point of view and contest an outcome by contacting the data protection contact in Section 3.2.

9. Recipients and disclosures

We disclose personal data only as set out below, and always on the minimum necessary basis.

9.1 Tax authorities and public bodies

HM Revenue & Customs, and in Switzerland the competent federal, cantonal and municipal tax authorities, where you instruct a filing, a periodic update, a correction, a claim or a disclosure, or where we are legally required to respond to a lawful request. Other public bodies, courts, regulators, law enforcement and financial intelligence units where legally compelled.

9.2 Authorised tax professionals

UK authorised agents and Swiss authorised fiduciaries, including Ticino fiduciaries, who review, sign off or file your return. Depending on the arrangement, such a professional may act as our processor or as an independent controller subject to its own professional secrecy and privacy notice. We will tell you which applies in your engagement documentation and identify the firm involved.

9.3 Service providers acting as processors

Categories used to operate the Service:

Category Function
Cloud hosting and storage Hosting of the application, databases, documents and backups
Document processing and text recognition Reading and extracting data from uploaded files
AI and model inference providers Classification and extraction components, under contractual no training and confidentiality terms
Identity verification and AML screening Onboarding checks, sanctions, PEP and adverse media screening
Payment and invoicing providers Fee collection and billing records
Email, notification and support tooling Transactional email, ticketing and communications
Analytics and error monitoring Diagnostics, performance and stability
Security, logging and backup tooling Monitoring, audit logging and recovery
Professional advisers Legal, accounting, audit and insurance support

Each processor is bound by a written contract meeting Article 28 UK GDPR requirements, is subject to confidentiality and security obligations, and may not engage a sub processor without authorisation. A current list of processors and their locations is available on request from the data protection contact in Section 3.2.

9.4 Connected systems you authorise

Where you authorise a connection, for example to HMRC or to a bank or accounting system, data flows according to the permission you grant. You may revoke that authorisation at any time in the relevant provider's interface or in your Auditax account, without affecting the lawfulness of processing already carried out.

9.5 Other disclosures

Persons you expressly authorise, such as a spouse, adviser or employer; acquirers and their advisers in a corporate transaction under Section 6.12; insurers and legal advisers in relation to a claim; and any disclosure required by law.

We do not sell personal data and we do not disclose it to third parties for their own advertising purposes.

10. International transfers

Our primary hosting region for customer data storage is Switzerland (Zurich). Application infrastructure is provided by global cloud providers and requests may be served from other regions, including the United States. Some providers process data outside the primary region.

For transfers out of the United Kingdom we rely on:

For transfers of data relating to individuals in Switzerland we rely on the Swiss list of states with adequate protection, the Swiss approved Standard Contractual Clauses with the Swiss addendum, the Swiss-US Data Privacy Framework where applicable, or an exception under the FADP.

Transfer measures are supplemented, where appropriate, by encryption in transit and at rest, access restriction, pseudonymisation and contractual commitments on government access requests. You may request a copy of the relevant safeguards, redacted where necessary for commercial confidentiality.

11. Governance of software, AI components and training data

12. Cookies and similar technologies

We use:

Non essential cookies are set only with your consent, obtained through our cookie banner. You may change or withdraw your choices at any time through the cookie settings link on the site, and you may control cookies in your browser. Blocking strictly necessary cookies will prevent the Service from functioning. Full details, including cookie names, providers, purposes and durations, are available on request from the data protection contact in Section 3.2; a separate Cookie Notice will be published if additional cookie categories are introduced.

13. Your rights

Subject to the conditions and exemptions in applicable law, you have the right to:

  1. Be informed about our processing, through this Policy.
  2. Access your personal data and receive a copy, together with the prescribed information.
  3. Rectification of inaccurate data and completion of incomplete data. Note that a submitted tax return cannot be altered retrospectively in our records; corrections are made by filing an amendment or a correction with the authority, and both versions are retained.
  4. Erasure where the data is no longer necessary, consent is withdrawn and no other basis applies, or the processing is unlawful. Erasure does not apply where we must retain records under tax, accounting, anti money laundering or professional obligations, or to defend legal claims.
  5. Restriction of processing in the circumstances set out in Article 18 UK GDPR.
  6. Object to processing based on legitimate interests, and to object at any time and without justification to processing for direct marketing.
  7. Data portability for data you provided, processed by automated means on the basis of consent or contract, in a structured, commonly used and machine readable format.
  8. Withdraw consent at any time where consent is the basis, without affecting the lawfulness of prior processing.
  9. Not be subject to solely automated decisions with legal or similarly significant effect, as described in Section 8.
  10. Information on the origin of data and, under the FADP, to request that we hand over or transfer your data.
  11. Complain to a supervisory authority, as set out in Section 18.

13.1 How to exercise your rights

Send your request to the data protection contact in Section 3.2. We may ask for information to verify your identity and, where a request is unclear, to specify the data or processing concerned. We respond within one month of receipt of a valid request, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month. In Switzerland we respond within 30 days or inform you of the reason for any delay. Requests are handled free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, explaining why.

13.2 Limits

Access may be restricted where disclosure would reveal a suspicious activity report, prejudice the prevention or detection of crime, breach legal professional privilege, disclose personal data of another individual without a lawful basis, or infringe a third party's trade secret. We will tell you where a restriction has been applied, unless the law prevents us from doing so.

14. Personal data of third parties that you provide

If you provide personal data relating to another individual, you confirm that you are entitled to do so and that you have informed that individual of this Policy, or that another lawful basis applies. In that context we act as controller for the purpose of preparing your dossier and return. You must not upload material relating to third parties that is not necessary for the tax matter you have engaged us to handle. Where an individual named in your documents exercises rights against us, we may need to contact you before responding.

15. Retention

We retain personal data for as long as necessary for the purposes described, and thereafter for the periods required by law or needed to defend legal claims.

Data Retention
Tax dossiers, source documents, calculations and audit trail At least 6 years from the end of the tax year to which they relate, in line with HMRC record keeping expectations, and up to 10 years where the Swiss statutory book keeping and limitation periods apply
Filed returns, submission receipts and authority correspondence Same period as the underlying dossier, and longer where an enquiry, appeal or dispute is open
Anti money laundering, identity verification and screening records 5 years from the end of the business relationship or the completion of the occasional transaction, extendable where legally required
Accounting and invoicing records 6 years in the United Kingdom, 10 years where Swiss book keeping rules apply
Account and profile data For the duration of the account, then deleted or anonymised within 12 months of closure, subject to the retention above
Support and communications records 3 years from the last contact, longer where relevant to a dispute or a filing
Security, access and audit logs 24 months, longer where an incident is under investigation
Marketing preferences and suppression lists Until withdrawal, and suppression records kept indefinitely to honour your objection
Cookie consent records 12 months
Backups Overwritten on a rolling cycle of 35 days after deletion from live systems

At the end of the applicable period, data is securely deleted or irreversibly anonymised. Anonymised and aggregated statistics may be retained without time limit, as they are no longer personal data.

16. Security

We implement technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. You must keep your credentials confidential, enable multi factor authentication, use a secure device and email account, and notify us immediately at security@auditax.pro if you suspect unauthorised access.

17. Personal data breaches

We maintain an internal breach register. Where a breach is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours of becoming aware of it, and we notify the Federal Data Protection and Information Commissioner in Switzerland as soon as possible where the FADP applies. Where the risk is high, we notify affected individuals without undue delay, describing the nature of the breach, the likely consequences, the measures taken and the steps you can take to protect yourself.

18. Complaints and supervisory authorities

Please raise any concern with us first, using the contact details in Section 3.2. We will investigate and respond substantively.

You also have the right to complain to:

Exercising a right or making a complaint does not affect any other legal remedy available to you.

19. Children

The Service is intended for adults and is not directed at children. Where a return concerns a minor, we process the minor's data on the instruction of the parent, guardian or legal representative, who is responsible for the accuracy and the lawfulness of that instruction. We do not knowingly create accounts for individuals under 18.

20. Professional confidentiality

In addition to data protection law, the information you provide is subject to professional confidentiality obligations owed by us and by any authorised tax professional involved in your engagement. Confidentiality is not a defence to a legally mandated disclosure, in particular a suspicious activity report or a lawful authority request.

21. Changes to this Policy

We review this Policy at least annually and whenever we materially change the Service, our processors or our transfer mechanisms. The current version, its effective date and a summary of material changes are published at https://auditax.pro/privacy-policy. Where a change materially affects your rights or the nature of the processing, we notify you by email or in the application before it takes effect. Where a change requires consent, we will seek it.

22. Interpretation

Terms such as personal data, processing, controller, processor, special category data and personal data breach have the meaning given in the UK GDPR, and the corresponding meaning under the FADP where that Act applies. In the event of conflict between this Policy and your engagement terms, this Policy governs matters of personal data protection. This Policy is published in English; where translations are provided for convenience, the English version prevails. If any provision is held invalid, the remainder continues in force. This Policy is governed by the laws of England and Wales, without prejudice to mandatory protections available to you under Swiss or EU law.