Auditax Privacy Policy
Controller: AUDITAX SERVICES LIMITED Company number: 15756288 (England and Wales) Registered office: 30 Welbeck Street, London, W1G 8ER, United Kingdom Service: the website auditax.pro and the Auditax tax preparation platform (the "Service")
Version: 1.0 Effective date: 3 August 2026 Last reviewed: 3 August 2026
1. Purpose and scope of this Policy
This Policy explains how AUDITAX SERVICES LIMITED ("Auditax", "we", "us", "our") collects, uses, discloses, transfers, retains and protects personal data when you:
- visit auditax.pro or any subdomain operated by us;
- create an Auditax account and use a United Kingdom or Swiss workspace;
- upload documents, answer questions and build a tax dossier;
- authorise a connection between your Auditax account and a tax authority or third party (including HM Revenue & Customs);
- instruct us, or an authorised tax professional working with us, to prepare, review, sign off or submit a tax return or a periodic update;
- contact us by email, web form, telephone or any support channel;
- receive commercial or service communications from us.
This Policy covers both the "self-preparation" use of the software and the assisted use in which an authorised tax professional (in the United Kingdom, an authorised agent; in Switzerland, an authorised fiduciary, starting with the Canton of Ticino) reviews and signs off your return where the law requires it.
This Policy does not cover third party websites, tax authority portals, banking portals or professional firms that operate under their own privacy notices. Where a separate professional firm acts as an independent controller of your data, we identify that in Section 9 and that firm's own privacy notice will also apply.
2. Applicable data protection law
We process personal data in accordance with:
- the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, as the primary framework for our activities as a UK established company;
- the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP") and the Ordinance on Data Protection ("DPO"), in respect of individuals in Switzerland whose data we process in connection with a Swiss workspace;
- Regulation (EU) 2016/679 ("EU GDPR"), where we offer the Service to individuals located in the European Economic Area or monitor their behaviour in that context;
- the Privacy and Electronic Communications Regulations 2003 ("PECR") and equivalent Swiss and EU rules, in respect of cookies, similar technologies and electronic marketing;
- our professional and statutory obligations under United Kingdom tax, accounting, anti money laundering and record keeping legislation, and their Swiss equivalents.
Where the requirements of these frameworks differ, we apply the standard that gives you the higher level of protection in respect of the specific processing activity.
3. Controller, representatives and contact points
3.1 Controller
AUDITAX SERVICES LIMITED is the controller for the processing described in this Policy, except where this Policy states that we act as processor or that a third party acts as an independent controller.
3.2 Data protection contact
Data protection contact: The Data Protection Lead Email: privacy@auditax.pro Postal address: Data Protection, AUDITAX SERVICES LIMITED, 30 Welbeck Street, London, W1G 8ER, United Kingdom
We aim to acknowledge privacy enquiries within five working days.
3.3 Data Protection Officer
We are not required to appoint a Data Protection Officer under Article 37 UK GDPR. Accountability for data protection sits with the director responsible for compliance, supported by the data protection contact named above.
3.4 Representatives
- Swiss representative (FADP art. 14): not required on the basis of our current volume and nature of processing, reassessed at each review of this Policy.
- EU representative (Article 27 EU GDPR): not currently required, as we do not target the offering of the Service to individuals in the European Economic Area.
3.5 Registration
We are registered with the Information Commissioner's Office ("ICO") under registration reference ZB919507.
4. Categories of personal data we process
The Service is document driven. The volume and sensitivity of the data we hold depends on the tax situation you ask us to handle. We process the following categories.
4.1 Account and identity data
Full name, preferred name, date of birth, marital or civil partnership status where relevant to the return, residential address and address history, country and canton of tax residence, nationality, email address, telephone number, account credentials in hashed form, multi factor authentication identifiers, interface language (EN, IT, FR, DE), workspace selection (United Kingdom, Switzerland) and account status.
4.2 Tax identifiers and authority credentials
National Insurance number, Unique Taxpayer Reference, HMRC Government Gateway identifiers where you disclose or connect them, agent authorisation references, Swiss AHV/AVS number where required by the cantonal return, cantonal and municipal taxpayer reference numbers, tax year and period identifiers.
4.3 Financial and tax data
Employment and PAYE data, including P60, P45 and P11D content, payroll references and employer details; self employment and sole trade income and expenditure, invoices, receipts, mileage and asset records; bank and building society interest; dividends and investment income; pension income and contributions; property income; capital transactions where in scope; Swiss federal, cantonal and municipal income and wealth items, including securities and account statements, real estate values, debts and deductions; foreign income and assets where declarable; bank account details used for refunds or fee payment; balances, transaction level data and statement lines contained in documents you upload or in feeds you authorise.
4.4 Documents and evidence
All files you upload or forward, including scans, photographs, PDFs, spreadsheets and email attachments; machine extracted text and structured fields derived from those files; the audit trail linking each figure in the dossier to its underlying source document, page and field; your answers to platform questions; annotations, review comments and queries raised by you, by us or by the authorised tax professional; version history of the dossier and of every submitted or draft return.
4.5 Data about third parties
Documents you provide may contain personal data relating to other individuals, for example a spouse or civil partner, dependants, business partners, employees, tenants, clients, counterparties or a deceased person's estate. You provide that data to us on the basis set out in Section 14.
4.6 Special category and criminal offence data
We do not seek special category data. It may nevertheless reach us because tax relevant documents contain it, for example medical expenses or disability related allowances (health data), church tax deductions in Switzerland (data revealing religious belief), trade union subscriptions, or donations that reveal political or philosophical convictions. Under the FADP, financial data and data on social assistance measures may also be treated as sensitive. Criminal offence data may arise where a penalty, investigation or voluntary disclosure is relevant to your tax position. We process such data only to the extent strictly necessary to prepare, verify or defend the return, on the bases set out in Section 6.5, and we ask you not to send us sensitive material that is not required for the return.
4.7 Communications data
Emails, support tickets, web form submissions, chat transcripts, call records and call notes where used, and the metadata of those exchanges.
4.8 Technical, usage and security data
IP address, approximate location derived from IP, device and browser type, operating system, device and session identifiers, referring URL, pages and features used, timestamps, language and locale settings, log data, error and diagnostic data, authentication events, consent records, and audit logs of access to your dossier by our staff or by an authorised tax professional.
4.9 Billing data
Subscription or engagement plan, invoices, amounts, payment status, payment method token or reference held by our payment provider, VAT status and billing address. We do not store full payment card numbers.
4.10 Compliance and onboarding data
Identity verification results, document authenticity checks, sanctions, politically exposed person and adverse media screening results, source of funds or source of wealth information where required, risk rating, and records created to satisfy anti money laundering and professional obligations.
5. Sources of personal data
- Directly from you: registration, workspace setup, questionnaire answers, uploads, emails and calls.
- From your devices: cookies and similar technologies, subject to Section 12.
- From tax authorities and connected systems that you authorise: for example HMRC APIs under Making Tax Digital, where you complete the authorisation yourself and we act on the resulting permission; and any accounting, payroll, banking or open banking connection you choose to enable.
- From your representatives: an accountant, fiduciary, employer, family member or adviser acting on your instruction.
- From authorised tax professionals: review comments, sign off records and correspondence generated when a UK authorised agent or a Ticino authorised fiduciary reviews your return.
- From service providers: identity verification, screening, payment, hosting, email and analytics providers.
- From public and commercial sources: company registers, sanctions and PEP lists, land and cadastral registers, and official rates and tables used in calculation.
6. Purposes and legal bases
6.1 Providing the Service
Creating and administering your account and workspaces, ingesting and reading your documents, extracting and structuring data, applying deterministic calculation and verification rules, building the traceable dossier, presenting figures and their sources for your approval, generating drafts, and transmitting a return or a periodic update to the competent authority on your instruction.
Legal basis: performance of a contract (Article 6(1)(b) UK GDPR). Under the FADP, this processing is necessary in relation to the conclusion or performance of a contract with you.
6.2 Assisted review and professional sign off
Making the dossier available to an authorised tax professional for review, query, correction and sign off where the law requires it, and recording that process.
Legal basis: performance of a contract, and compliance with a legal obligation to which we or the professional are subject (Article 6(1)(b) and 6(1)(c)).
6.3 Support, communication and service messages
Answering queries, raising and resolving questions on figures, sending deadline reminders, filing confirmations, security notices and material changes to the Service.
Legal basis: performance of a contract and our legitimate interests in administering the relationship (Article 6(1)(b) and 6(1)(f)).
6.4 Billing, credit control and accounting
Invoicing, collecting fees, managing arrears and maintaining accounting records.
Legal basis: performance of a contract, legal obligation and legitimate interests in recovering sums due.
6.5 Special category and criminal offence data
Processing sensitive material contained in tax relevant documents so that reliefs, deductions and disclosures can be prepared correctly, and so that the dossier remains a complete evidential record.
Legal basis: your explicit consent (Article 9(2)(a) UK GDPR), or where applicable the establishment, exercise or defence of legal claims (Article 9(2)(f)). Criminal offence data is processed under a Schedule 1 Data Protection Act 2018 condition, in particular for the purposes of legal claims and compliance with regulatory requirements. Under the FADP we rely on your express consent for the processing of sensitive personal data, or on an overriding interest where the law permits.
You may withdraw consent to the processing of sensitive material at any time, but if the material is necessary to support a figure in a return, we may be unable to prepare or maintain that part of the dossier and may have to suspend or terminate the engagement.
6.6 Anti money laundering, know your client and sanctions compliance
Identity verification, screening, risk assessment, record keeping, and where legally required the reporting of suspicious activity.
Legal basis: legal obligation and substantial public interest under Schedule 1 Data Protection Act 2018. Where a report is made, we are prohibited by law from informing you of it and your right of access may be lawfully restricted in respect of that material.
6.7 Security, fraud prevention and integrity of the Service
Authentication, access control, logging, monitoring for unauthorised access, abuse prevention, backup, disaster recovery and incident investigation.
Legal basis: legitimate interests in protecting our clients, our systems and the integrity of tax filings, and legal obligation in respect of the security of processing.
6.8 Service improvement, testing and quality assurance
Diagnosing defects, improving extraction accuracy, testing calculation rules, and reviewing sample dossiers for quality. Wherever technically possible we use anonymised, pseudonymised or synthetic data for these purposes.
Legal basis: legitimate interests. Where we cannot achieve the purpose without identifiable client data, we apply strict internal access controls and, where required, seek your consent.
6.9 Artificial intelligence and automated processing components
The Service uses software to read documents, classify them, extract fields and apply deterministic rules. See Section 11 for how we govern this, including the prohibition on using your data to train third party general purpose models without a lawful basis and appropriate contractual controls.
Legal basis: performance of a contract, and legitimate interests in respect of accuracy testing.
6.10 Marketing
Sending information about the Service, new jurisdictions, features and tax deadlines.
Legal basis: consent, or legitimate interests under the soft opt in for existing clients in respect of similar services. Every marketing message contains an unsubscribe mechanism. Withdrawal of marketing consent does not affect service and compliance communications.
6.11 Legal claims, disputes, audits and regulatory requests
Responding to tax authority enquiries, professional indemnity matters, complaints, litigation, insurance and audit.
Legal basis: legal obligation and legitimate interests in establishing, exercising or defending legal claims.
6.12 Corporate transactions
Due diligence and transfer in connection with a reorganisation, financing, merger or sale of all or part of the business, using redaction and confidentiality controls proportionate to the stage of the transaction.
Legal basis: legitimate interests.
7. Legitimate interests assessment
Where we rely on legitimate interests, we have assessed the purpose, the necessity of the processing, and the balance against your rights and expectations, and we have recorded that assessment. In summary, we consider that a client engaging a tax preparation service reasonably expects us to secure the platform, verify identity, log access to the dossier, pursue unpaid fees, improve the accuracy of extraction and calculation, and preserve records needed to defend a filing. You may request a summary of the relevant assessment and you may object under Section 13.6.
8. Automated decision making and profiling
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, with the following qualifications:
- Calculation and verification: figures are computed and checked by deterministic rules. The result is a proposal. Nothing is filed until you have approved it and, where the law requires, an authorised tax professional has reviewed and signed it off.
- Document reading: classification and field extraction are automated and may be imperfect. Every extracted figure is presented with a link to its source so that you can verify it.
- Compliance screening: identity, sanctions and risk screening may generate automated flags. A human reviews any flag before we refuse, suspend or terminate an engagement.
- Fraud and abuse controls: automated rules may temporarily restrict access to an account pending human review.
You may ask for human intervention, express your point of view and contest an outcome by contacting the data protection contact in Section 3.2.
9. Recipients and disclosures
We disclose personal data only as set out below, and always on the minimum necessary basis.
9.1 Tax authorities and public bodies
HM Revenue & Customs, and in Switzerland the competent federal, cantonal and municipal tax authorities, where you instruct a filing, a periodic update, a correction, a claim or a disclosure, or where we are legally required to respond to a lawful request. Other public bodies, courts, regulators, law enforcement and financial intelligence units where legally compelled.
9.2 Authorised tax professionals
UK authorised agents and Swiss authorised fiduciaries, including Ticino fiduciaries, who review, sign off or file your return. Depending on the arrangement, such a professional may act as our processor or as an independent controller subject to its own professional secrecy and privacy notice. We will tell you which applies in your engagement documentation and identify the firm involved.
9.3 Service providers acting as processors
Categories used to operate the Service:
| Category | Function |
|---|---|
| Cloud hosting and storage | Hosting of the application, databases, documents and backups |
| Document processing and text recognition | Reading and extracting data from uploaded files |
| AI and model inference providers | Classification and extraction components, under contractual no training and confidentiality terms |
| Identity verification and AML screening | Onboarding checks, sanctions, PEP and adverse media screening |
| Payment and invoicing providers | Fee collection and billing records |
| Email, notification and support tooling | Transactional email, ticketing and communications |
| Analytics and error monitoring | Diagnostics, performance and stability |
| Security, logging and backup tooling | Monitoring, audit logging and recovery |
| Professional advisers | Legal, accounting, audit and insurance support |
Each processor is bound by a written contract meeting Article 28 UK GDPR requirements, is subject to confidentiality and security obligations, and may not engage a sub processor without authorisation. A current list of processors and their locations is available on request from the data protection contact in Section 3.2.
9.4 Connected systems you authorise
Where you authorise a connection, for example to HMRC or to a bank or accounting system, data flows according to the permission you grant. You may revoke that authorisation at any time in the relevant provider's interface or in your Auditax account, without affecting the lawfulness of processing already carried out.
9.5 Other disclosures
Persons you expressly authorise, such as a spouse, adviser or employer; acquirers and their advisers in a corporate transaction under Section 6.12; insurers and legal advisers in relation to a claim; and any disclosure required by law.
We do not sell personal data and we do not disclose it to third parties for their own advertising purposes.
10. International transfers
Our primary hosting region for customer data storage is Switzerland (Zurich). Application infrastructure is provided by global cloud providers and requests may be served from other regions, including the United States. Some providers process data outside the primary region.
For transfers out of the United Kingdom we rely on:
- UK adequacy regulations, including the adequacy decision covering Switzerland; or
- the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
- the UK Extension to the EU-US Data Privacy Framework where the recipient is certified; or
- a derogation under Article 49 UK GDPR, in particular where necessary for the establishment, exercise or defence of legal claims or for the performance of a contract at your request.
For transfers of data relating to individuals in Switzerland we rely on the Swiss list of states with adequate protection, the Swiss approved Standard Contractual Clauses with the Swiss addendum, the Swiss-US Data Privacy Framework where applicable, or an exception under the FADP.
Transfer measures are supplemented, where appropriate, by encryption in transit and at rest, access restriction, pseudonymisation and contractual commitments on government access requests. You may request a copy of the relevant safeguards, redacted where necessary for commercial confidentiality.
11. Governance of software, AI components and training data
- Extraction and classification components are used to read your documents and populate the dossier. Calculation and verification are performed by deterministic rules, not by generative models.
- We do not use your dossier content, documents or tax data to train third party general purpose models. Where an AI provider is used for inference, our contract prohibits the use of your data for training or model improvement and requires deletion after processing or within a short defined retention window.
- Internal accuracy testing uses anonymised, pseudonymised or synthetic data wherever technically possible. Where identifiable data must be used, access is restricted to named personnel, logged, and limited to the minimum necessary.
- Every figure that reaches the dossier is traceable to its source document, which allows both you and us to detect and correct extraction errors.
- Human oversight is applied to any output that affects a filing, and to any compliance flag that could lead to refusal, suspension or termination.
12. Cookies and similar technologies
We use:
- Strictly necessary cookies: authentication, session integrity, security, load balancing, language and workspace selection, and consent state. These do not require consent.
- Functional cookies: interface preferences and remembered settings.
- Analytics cookies: aggregated measurement of usage and performance.
- Marketing cookies: we do not use marketing or advertising cookies.
Non essential cookies are set only with your consent, obtained through our cookie banner. You may change or withdraw your choices at any time through the cookie settings link on the site, and you may control cookies in your browser. Blocking strictly necessary cookies will prevent the Service from functioning. Full details, including cookie names, providers, purposes and durations, are available on request from the data protection contact in Section 3.2; a separate Cookie Notice will be published if additional cookie categories are introduced.
13. Your rights
Subject to the conditions and exemptions in applicable law, you have the right to:
- Be informed about our processing, through this Policy.
- Access your personal data and receive a copy, together with the prescribed information.
- Rectification of inaccurate data and completion of incomplete data. Note that a submitted tax return cannot be altered retrospectively in our records; corrections are made by filing an amendment or a correction with the authority, and both versions are retained.
- Erasure where the data is no longer necessary, consent is withdrawn and no other basis applies, or the processing is unlawful. Erasure does not apply where we must retain records under tax, accounting, anti money laundering or professional obligations, or to defend legal claims.
- Restriction of processing in the circumstances set out in Article 18 UK GDPR.
- Object to processing based on legitimate interests, and to object at any time and without justification to processing for direct marketing.
- Data portability for data you provided, processed by automated means on the basis of consent or contract, in a structured, commonly used and machine readable format.
- Withdraw consent at any time where consent is the basis, without affecting the lawfulness of prior processing.
- Not be subject to solely automated decisions with legal or similarly significant effect, as described in Section 8.
- Information on the origin of data and, under the FADP, to request that we hand over or transfer your data.
- Complain to a supervisory authority, as set out in Section 18.
13.1 How to exercise your rights
Send your request to the data protection contact in Section 3.2. We may ask for information to verify your identity and, where a request is unclear, to specify the data or processing concerned. We respond within one month of receipt of a valid request, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month. In Switzerland we respond within 30 days or inform you of the reason for any delay. Requests are handled free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, explaining why.
13.2 Limits
Access may be restricted where disclosure would reveal a suspicious activity report, prejudice the prevention or detection of crime, breach legal professional privilege, disclose personal data of another individual without a lawful basis, or infringe a third party's trade secret. We will tell you where a restriction has been applied, unless the law prevents us from doing so.
14. Personal data of third parties that you provide
If you provide personal data relating to another individual, you confirm that you are entitled to do so and that you have informed that individual of this Policy, or that another lawful basis applies. In that context we act as controller for the purpose of preparing your dossier and return. You must not upload material relating to third parties that is not necessary for the tax matter you have engaged us to handle. Where an individual named in your documents exercises rights against us, we may need to contact you before responding.
15. Retention
We retain personal data for as long as necessary for the purposes described, and thereafter for the periods required by law or needed to defend legal claims.
| Data | Retention |
|---|---|
| Tax dossiers, source documents, calculations and audit trail | At least 6 years from the end of the tax year to which they relate, in line with HMRC record keeping expectations, and up to 10 years where the Swiss statutory book keeping and limitation periods apply |
| Filed returns, submission receipts and authority correspondence | Same period as the underlying dossier, and longer where an enquiry, appeal or dispute is open |
| Anti money laundering, identity verification and screening records | 5 years from the end of the business relationship or the completion of the occasional transaction, extendable where legally required |
| Accounting and invoicing records | 6 years in the United Kingdom, 10 years where Swiss book keeping rules apply |
| Account and profile data | For the duration of the account, then deleted or anonymised within 12 months of closure, subject to the retention above |
| Support and communications records | 3 years from the last contact, longer where relevant to a dispute or a filing |
| Security, access and audit logs | 24 months, longer where an incident is under investigation |
| Marketing preferences and suppression lists | Until withdrawal, and suppression records kept indefinitely to honour your objection |
| Cookie consent records | 12 months |
| Backups | Overwritten on a rolling cycle of 35 days after deletion from live systems |
At the end of the applicable period, data is securely deleted or irreversibly anonymised. Anonymised and aggregated statistics may be retained without time limit, as they are no longer personal data.
16. Security
We implement technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) and at rest for documents, databases and backups;
- multi factor authentication for client accounts and for administrative access;
- role based access control, least privilege, and separation between the United Kingdom and Swiss workspaces so that each country's data sits in its own isolated workspace;
- logging of every access to a dossier, whether by you, by our staff or by an authorised tax professional, so that access is auditable;
- secure development practices, code review, dependency management, vulnerability scanning and periodic penetration testing;
- hardened, segregated environments, with production data excluded from development and testing wherever technically possible;
- staff confidentiality undertakings, data protection and security training, background checks where proportionate, and disciplinary consequences for misuse;
- vendor due diligence and written data processing agreements;
- backup, business continuity and disaster recovery, with restoration testing;
- a documented incident response process.
No system is perfectly secure. You must keep your credentials confidential, enable multi factor authentication, use a secure device and email account, and notify us immediately at security@auditax.pro if you suspect unauthorised access.
17. Personal data breaches
We maintain an internal breach register. Where a breach is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours of becoming aware of it, and we notify the Federal Data Protection and Information Commissioner in Switzerland as soon as possible where the FADP applies. Where the risk is high, we notify affected individuals without undue delay, describing the nature of the breach, the likely consequences, the measures taken and the steps you can take to protect yourself.
18. Complaints and supervisory authorities
Please raise any concern with us first, using the contact details in Section 3.2. We will investigate and respond substantively.
You also have the right to complain to:
- United Kingdom: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113; ico.org.uk.
- Switzerland: Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern; edoeb.admin.ch.
- European Economic Area: the supervisory authority of your habitual residence, place of work or place of the alleged infringement.
Exercising a right or making a complaint does not affect any other legal remedy available to you.
19. Children
The Service is intended for adults and is not directed at children. Where a return concerns a minor, we process the minor's data on the instruction of the parent, guardian or legal representative, who is responsible for the accuracy and the lawfulness of that instruction. We do not knowingly create accounts for individuals under 18.
20. Professional confidentiality
In addition to data protection law, the information you provide is subject to professional confidentiality obligations owed by us and by any authorised tax professional involved in your engagement. Confidentiality is not a defence to a legally mandated disclosure, in particular a suspicious activity report or a lawful authority request.
21. Changes to this Policy
We review this Policy at least annually and whenever we materially change the Service, our processors or our transfer mechanisms. The current version, its effective date and a summary of material changes are published at https://auditax.pro/privacy-policy. Where a change materially affects your rights or the nature of the processing, we notify you by email or in the application before it takes effect. Where a change requires consent, we will seek it.
22. Interpretation
Terms such as personal data, processing, controller, processor, special category data and personal data breach have the meaning given in the UK GDPR, and the corresponding meaning under the FADP where that Act applies. In the event of conflict between this Policy and your engagement terms, this Policy governs matters of personal data protection. This Policy is published in English; where translations are provided for convenience, the English version prevails. If any provision is held invalid, the remainder continues in force. This Policy is governed by the laws of England and Wales, without prejudice to mandatory protections available to you under Swiss or EU law.