Privacy Notice
Last updated: July 2026
This notice explains how Ola Accountancy processes personal data, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Ola Accountancy Ltd is the data controller for personal data processed through this platform. We are registered in England & Wales (company number [COMPANY NUMBER]), registered office [REGISTERED OFFICE], and registered with the Information Commissioner's Office (registration number [ICO NUMBER]).
Contact: privacy@ola-accountancy.co.uk
What we collect and why
| Data | Purpose | Lawful basis |
|---|---|---|
| Identity and contact details (name, date of birth, address, phone, email) | Client onboarding, identity verification, HMRC filings | Performance of contract |
| Tax identifiers (National Insurance number, Unique Taxpayer Reference) | HMRC agent authorisation and Self Assessment submission | Performance of contract; legal obligation |
| Identity verification documents (passport, driving licence, proof of address) | Anti-money-laundering customer due diligence | Legal obligation (Money Laundering Regulations 2017) |
| Bank account details and statement transactions | Preparation of income and expense figures for the tax return | Performance of contract |
| Payment records | Billing for our accountancy services | Performance of contract; legal obligation (accounting records) |
| System audit logs (access events, changes, IP addresses) and page-view records | Security, accountability and service improvement | Legitimate interests |
We do not use third-party analytics, advertising or tracking technologies.
How we use your data with HMRC
When you authorise us to act as your tax agent, we use the HMRC Making Tax Digital APIs to file your Self Assessment on your behalf. This involves transmitting your tax identifiers, income and expense figures, and the technical headers required by HMRC's fraud prevention specification. You can withdraw your authorisation at any time through your HMRC online account.
Where your data is stored
All personal data is stored in the United Kingdom (AWS London region, eu-west-2). Application servers, databases and backups all reside in UK data centres. Data is encrypted at rest and transmitted only over encrypted connections.
Processors
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Application server and database hosting, encrypted at rest | London, UK (eu-west-2) |
| Vercel Inc. | Front-end hosting and content delivery | London edge |
| Stripe Payments UK Ltd | Card payment processing - card numbers never touch our systems | UK / EU |
| Anthropic PBC | AI-assisted categorisation of bank transactions (data processing agreement in place; data is not used for model training) | US (UK IDTA safeguards) |
| Cloudflare Inc. | TLS termination, DDoS protection and content delivery | London edge (UK IDTA safeguards) |
| HM Revenue & Customs | Agent authorisation and tax return submission | UK (statutory) |
International transfers
Your data is hosted in the United Kingdom. Where any processor is based outside the UK or may access data from outside the UK for support, we ensure an adequate safeguard is in place - either UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep your data
| Data | Retention | Reason |
|---|---|---|
| Tax records (returns, income, expenses, supporting documents) | 6 years after the end of the relevant tax year | HMRC record-keeping requirements |
| Identity verification documents | 5 years after the business relationship ends | Money Laundering Regulations 2017 |
| Security and audit logs | Up to 6 years | Accountability, fraud detection and dispute resolution |
| Page-view navigation logs | 90 days | Service improvement (then automatically deleted) |
| Login sessions | 8 hours | Automatically expired |
Your rights
Under the UK GDPR, you have the right to:
- Access - request a full export of your data (we provide a machine-readable JSON export).
- Rectification - ask us to correct inaccurate data, either through the portal or by contacting us.
- Erasure - ask us to delete your data. Where the law requires us to keep tax records (6 years), we anonymise your record and delete it fully once the retention period ends.
- Restriction - ask us to limit how we process your data while a concern is resolved.
- Portability - receive your data in a structured, machine-readable format.
- Objection - object to processing based on legitimate interests.
- Withdraw consent - where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email privacy@ola-accountancy.co.uk. We will respond within one month. You also have the right to complain to the Information Commissioner's Office.
Cookies
We use only strictly necessary cookies: a login session cookie and, during HMRC authorisation, short-lived cookies that secure the OAuth process. We do not use analytics, advertising or tracking cookies. Full details are set out in our Cookie Policy.
Security
We implement the following technical and organisational measures to protect your data, in line with ICO encryption guidance and NCSC cloud security principles.
Encryption
- At rest - uploaded documents are encrypted with AES-256-GCM, each with a unique data encryption key. HMRC access tokens are encrypted with AES-256-GCM before storage. Passwords are hashed with bcrypt (cost factor 12) and never stored in plaintext. The database volume uses AWS-managed encryption at rest.
- In transit - all connections use TLS 1.2 or higher. Browser-to-server traffic is encrypted via Cloudflare. Server-to-database connections require SSL certificates. HMRC API calls use TLS.
Data separation
- Each client's data is logically separated by unique identifiers and enforced through application-level access controls. Clients can only access their own data - there is no ability to search for or view other clients' records.
- Staff access is scoped by branch assignment. Accountants can only view clients within their assigned branches.
- API endpoints enforce ownership checks on every request.
Access control
- Three roles control access: admin (firm-wide management), accountant (client preparation, branch-scoped), and client (own data only via portal).
- Staff accounts are created by invitation only. Client accounts require invitation or self-registration with email verification.
- Every data access and change is recorded in an append-only audit log with user identity, IP address and timestamp.
Authentication
- Passwords must be at least 8 characters and are hashed before storage.
- Sessions expire automatically after 8 hours.
- Accounts lock for 15 minutes after 5 failed login attempts.
- Password resets use single-use, time-limited tokens and invalidate all existing sessions.
Changes to this notice
We may update this notice from time to time. Material changes will be communicated through the platform or by email. The "Last updated" date above will change accordingly.
Contact
Questions about how we handle your data? Contact us at privacy@ola-accountancy.co.uk.