Skip to main content

Privacy Policy

Riskview Technology — Effective date: # e.g. 16 June 2026

1. Who We Are

The data controller is Riskview Technology, a company registered in England and Wales (company number # e.g. 12345678), with its registered address at # e.g. 1 Example Street, London, EC1A 1BB.

ICO Registration Number: # e.g. Z1234567 (ICO registration number)

Data Protection contact: # Data protection / DPO contact email

2. Personal Data We Collect

We collect and process the following categories of personal data:

Category Examples How collected
Account data Full name, email address, hashed password Provided by you or your administrator at registration
Tax identity National Insurance number (NINO), HMRC MTD ID Provided by you; retrieved from HMRC after authorisation
Business details Trading name, commencement date, accounting type, HMRC business ID Provided by you; retrieved from HMRC after authorisation
Financial records Transaction date, description, amount, category, import source Uploaded by you via CSV or OFX/QFX bank statements, or entered manually
Submission records Quarterly update payloads, final declaration details, HMRC responses Generated during use of the service
HMRC OAuth tokens Access token, refresh token (both encrypted at rest) Issued by HMRC after you authorise the application
Technical and security data IP address, user agent, device ID, screen resolution, browser plugins, timezone (collected for HMRC fraud prevention headers) Collected automatically when you use the service
Audit log data Record of login events, submissions, data imports, administrative actions Generated automatically by the service

NINO and OAuth tokens are encrypted at rest using AES-128 (Fernet) before storage and are never stored in plain text.

3. Legal Basis for Processing

Processing activity Legal basis (UK GDPR Art. 6)
Providing the MTD record-keeping and submission service Article 6(1)(b) — performance of a contract
Maintaining digital records and submitting to HMRC Article 6(1)(c) — compliance with a legal obligation (MTD for Income Tax)
Security monitoring, fraud prevention headers, audit logging Article 6(1)(f) — legitimate interests (security and regulatory compliance)
Submitting HMRC fraud prevention headers Article 6(1)(c) — legal obligation (HMRC API terms require these headers)

4. How We Use Your Data

We use your personal data solely to:

  • authenticate you and manage your account;
  • store and categorise your financial transactions;
  • calculate income and expense summaries for quarterly reporting;
  • submit quarterly updates and a final declaration to HMRC on your behalf;
  • retrieve your tax obligations, calculations, and HMRC Assist messages;
  • comply with HMRC’s fraud prevention header requirements;
  • maintain an audit trail of actions taken within your account for security purposes;
  • respond to your support enquiries.

We do not use your data for marketing, profiling, or automated decision-making, and we do not sell your data to any third party.

5. Who We Share Your Data With

Your data is shared only with HMRC, via their Making Tax Digital APIs, to the extent necessary to submit your returns and retrieve your obligations and calculations. This sharing is required by law (MTD for Income Tax).

We do not share your data with any other third party, including analytics providers, advertising networks, or data brokers.

In the event that Riskview Technology is acquired or merges with another organisation, your data may be transferred to that organisation. We will notify you before this occurs.

6. International Transfers

Your data is processed and stored within the United Kingdom. HMRC’s API infrastructure is operated within the UK. We do not transfer your personal data outside the UK.

7. How Long We Keep Your Data

Data type Retention period
Financial transactions and submission records Minimum 6 years after the 31 January submission deadline for the relevant tax year, in line with HMRC record-keeping requirements
HMRC OAuth tokens Until revoked by you via Government Gateway or until your account is deleted
Audit log entries 6 years (append-only; not deleted or modified)
Account data (name, email) Until account deletion is requested and fulfilled
Technical/fraud prevention data 6 years (HMRC may request this data for compliance investigations)

8. Security Measures

We implement the following technical and organisational security measures:

  • Encryption in transit: All communications use TLS (HTTPS).
  • Encryption at rest: NINO and OAuth tokens are encrypted using AES-128 (Fernet). The database is encrypted at rest.
  • Password hashing: Passwords are hashed using bcrypt with a minimum cost factor of 12. Plain-text passwords are never stored.
  • Account lockout: Accounts are locked after 5 consecutive failed login attempts to protect against brute-force attacks.
  • Access controls: All data access is restricted to the authenticated owner. Row-level ownership checks are enforced on every database query.
  • CSRF protection: All state-changing requests require a valid CSRF token.
  • Rate limiting: Sensitive endpoints are rate-limited per IP address and per user.
  • Input validation: All user-supplied input is validated and sanitised server-side before processing.

9. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectification — request correction of inaccurate data;
  • Erasure — request deletion of your data (subject to legal retention obligations);
  • Portability — receive your data in a machine-readable format;
  • Restriction — request that we restrict processing of your data in certain circumstances;
  • Objection — object to processing based on legitimate interests;
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at # Data protection / DPO contact email. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint .

10. Requesting Data Export or Account Deletion

You may export your data at any time via Settings → Export My Data in the application. The export includes your transactions, submissions, obligations, and profile details in machine-readable CSV and JSON formats.

You may delete your account at any time via Settings → Profile → Delete Account. This immediately removes your personal details and HMRC tokens. Financial records are retained for a minimum of 6 years as required by HMRC.

For any further data rights request, contact # Data protection / DPO contact email. We will respond within one calendar month.

11. Security Breach Notification

In the event of a personal data breach, we will:

  • notify the ICO within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms;
  • notify HMRC within 72 hours in accordance with the HMRC Developer Hub Terms of Use;
  • notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. Cookies

This application uses a single session cookie to maintain your authenticated session. This cookie is:

  • strictly necessary for the service to function;
  • marked HttpOnly (not accessible to JavaScript);
  • marked Secure in production (sent only over HTTPS);
  • set with SameSite=Lax to mitigate CSRF risks;
  • automatically expired after 8 hours of inactivity.

We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to you by email or by a prominent notice within the application. The “effective date” at the top of this page indicates when the policy was last revised.

14. Contact Us

For any data protection enquiry or to exercise your rights, please contact:
Email: # Data protection / DPO contact email
Address: # e.g. 1 Example Street, London, EC1A 1BB

To report a security vulnerability, email # Security vulnerability disclosure email or see our security.txt.


© Riskview Technology. Last updated: # e.g. 16 June 2026. See also our Terms of Service.