Privacy Policy
Riskview Technology — Effective date: # e.g. 16 June 2026
1. Who We Are
The data controller is Riskview Technology, a company registered in England and Wales (company number # e.g. 12345678), with its registered address at # e.g. 1 Example Street, London, EC1A 1BB.
ICO Registration Number: # e.g. Z1234567 (ICO registration number)
Data Protection contact: # Data protection / DPO contact email
2. Personal Data We Collect
We collect and process the following categories of personal data:
| Category | Examples | How collected |
|---|---|---|
| Account data | Full name, email address, hashed password | Provided by you or your administrator at registration |
| Tax identity | National Insurance number (NINO), HMRC MTD ID | Provided by you; retrieved from HMRC after authorisation |
| Business details | Trading name, commencement date, accounting type, HMRC business ID | Provided by you; retrieved from HMRC after authorisation |
| Financial records | Transaction date, description, amount, category, import source | Uploaded by you via CSV or OFX/QFX bank statements, or entered manually |
| Submission records | Quarterly update payloads, final declaration details, HMRC responses | Generated during use of the service |
| HMRC OAuth tokens | Access token, refresh token (both encrypted at rest) | Issued by HMRC after you authorise the application |
| Technical and security data | IP address, user agent, device ID, screen resolution, browser plugins, timezone (collected for HMRC fraud prevention headers) | Collected automatically when you use the service |
| Audit log data | Record of login events, submissions, data imports, administrative actions | Generated automatically by the service |
NINO and OAuth tokens are encrypted at rest using AES-128 (Fernet) before storage and are never stored in plain text.
3. Legal Basis for Processing
| Processing activity | Legal basis (UK GDPR Art. 6) |
|---|---|
| Providing the MTD record-keeping and submission service | Article 6(1)(b) — performance of a contract |
| Maintaining digital records and submitting to HMRC | Article 6(1)(c) — compliance with a legal obligation (MTD for Income Tax) |
| Security monitoring, fraud prevention headers, audit logging | Article 6(1)(f) — legitimate interests (security and regulatory compliance) |
| Submitting HMRC fraud prevention headers | Article 6(1)(c) — legal obligation (HMRC API terms require these headers) |
4. How We Use Your Data
We use your personal data solely to:
- authenticate you and manage your account;
- store and categorise your financial transactions;
- calculate income and expense summaries for quarterly reporting;
- submit quarterly updates and a final declaration to HMRC on your behalf;
- retrieve your tax obligations, calculations, and HMRC Assist messages;
- comply with HMRC’s fraud prevention header requirements;
- maintain an audit trail of actions taken within your account for security purposes;
- respond to your support enquiries.
We do not use your data for marketing, profiling, or automated decision-making, and we do not sell your data to any third party.
5. Who We Share Your Data With
Your data is shared only with HMRC, via their Making Tax Digital APIs, to the extent necessary to submit your returns and retrieve your obligations and calculations. This sharing is required by law (MTD for Income Tax).
We do not share your data with any other third party, including analytics providers, advertising networks, or data brokers.
In the event that Riskview Technology is acquired or merges with another organisation, your data may be transferred to that organisation. We will notify you before this occurs.
6. International Transfers
Your data is processed and stored within the United Kingdom. HMRC’s API infrastructure is operated within the UK. We do not transfer your personal data outside the UK.
7. How Long We Keep Your Data
| Data type | Retention period |
|---|---|
| Financial transactions and submission records | Minimum 6 years after the 31 January submission deadline for the relevant tax year, in line with HMRC record-keeping requirements |
| HMRC OAuth tokens | Until revoked by you via Government Gateway or until your account is deleted |
| Audit log entries | 6 years (append-only; not deleted or modified) |
| Account data (name, email) | Until account deletion is requested and fulfilled |
| Technical/fraud prevention data | 6 years (HMRC may request this data for compliance investigations) |
8. Security Measures
We implement the following technical and organisational security measures:
- Encryption in transit: All communications use TLS (HTTPS).
- Encryption at rest: NINO and OAuth tokens are encrypted using AES-128 (Fernet). The database is encrypted at rest.
- Password hashing: Passwords are hashed using bcrypt with a minimum cost factor of 12. Plain-text passwords are never stored.
- Account lockout: Accounts are locked after 5 consecutive failed login attempts to protect against brute-force attacks.
- Access controls: All data access is restricted to the authenticated owner. Row-level ownership checks are enforced on every database query.
- CSRF protection: All state-changing requests require a valid CSRF token.
- Rate limiting: Sensitive endpoints are rate-limited per IP address and per user.
- Input validation: All user-supplied input is validated and sanitised server-side before processing.
9. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — request correction of inaccurate data;
- Erasure — request deletion of your data (subject to legal retention obligations);
- Portability — receive your data in a machine-readable format;
- Restriction — request that we restrict processing of your data in certain circumstances;
- Objection — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at # Data protection / DPO contact email. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint .
10. Requesting Data Export or Account Deletion
You may export your data at any time via Settings → Export My Data in the application. The export includes your transactions, submissions, obligations, and profile details in machine-readable CSV and JSON formats.
You may delete your account at any time via Settings → Profile → Delete Account. This immediately removes your personal details and HMRC tokens. Financial records are retained for a minimum of 6 years as required by HMRC.
For any further data rights request, contact # Data protection / DPO contact email. We will respond within one calendar month.
11. Security Breach Notification
In the event of a personal data breach, we will:
- notify the ICO within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms;
- notify HMRC within 72 hours in accordance with the HMRC Developer Hub Terms of Use;
- notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
12. Cookies
This application uses a single session cookie to maintain your authenticated session. This cookie is:
- strictly necessary for the service to function;
- marked
HttpOnly(not accessible to JavaScript); - marked
Securein production (sent only over HTTPS); - set with
SameSite=Laxto mitigate CSRF risks; - automatically expired after 8 hours of inactivity.
We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email or by a prominent notice within the application. The “effective date” at the top of this page indicates when the policy was last revised.
14. Contact Us
For any data protection enquiry or to exercise your rights, please contact:
Email: # Data protection / DPO contact email
Address: # e.g. 1 Example Street, London, EC1A 1BB
To report a security vulnerability, email # Security vulnerability disclosure email or see our security.txt.
© Riskview Technology. Last updated: # e.g. 16 June 2026. See also our Terms of Service.