How aihtax processes personal data
URL: /privacy · Last updated: 25 September 2026
This Privacy Policy explains how aihtax ("we", "us", or "our") collects, uses, stores, and shares personal data when you use our website and bookkeeping / Making Tax Digital (MTD) services (the "Service"). It is written for users in the United Kingdom and reflects the UK GDPR and the Data Protection Act 2018.
By creating an account or using the Service you acknowledge this policy. If you do not agree, please do not use the Service.
The data controller for personal data processed through the Service is Sebastian Toke-Nichols, trading as aihtax. For privacy questions and requests, email [email protected].
If we appoint a Data Protection Officer or nominate a representative, we will update this policy and publish those details here.
This policy covers personal data relating to:
Business and financial records you upload may include personal data about third parties (for example tenants, suppliers, or employees). You are responsible for ensuring you have a lawful basis to provide that data to us for processing on your behalf as part of the Service.
Depending on how you use the Service, we may process:
We process personal data only where we have a lawful basis, including:
Do not upload documents or data you are not authorised to process. You remain responsible for reviewing figures before any HMRC submission.
Where enabled for your deployment, we may use automated tools (including OCR and optional AI models) to extract fields from receipts, suggest categories, or assist matching. These features support your bookkeeping workflows; they do not replace your review, and they are not used to make solely automated decisions that produce legal or similarly significant effects about you without human involvement.
We do not sell personal data. These processors handle it on our behalf, under written contracts, and only to provide the Service:
Fly.io
Neon
Upstash (through Fly.io)
Cloudflare
Google (Gmail)
Google (Gemini API)
Resend
Sentry
PostHog
We also share data with:
Workspace owners and authorised agents may access personal data within shared workspaces according to the permissions you configure.
Your account, business and bookkeeping data, and the documents you upload, are stored and processed in the United Kingdom and the European Economic Area, which the UK recognises as giving adequate protection. Two things can go further: Cloudflare delivers the website from its global network, so your connection may be handled close to wherever you are browsing from; and emails you send to our privacy, security or accessibility addresses are kept in a Gmail mailbox, which Google may store in the United States. Where a processor stores or accesses personal data outside the UK or EEA, we rely on the safeguards in its terms.
We retain personal data for as long as needed to provide the Service and for a reasonable period afterwards to resolve disputes, enforce agreements, and meet legal or tax record-keeping needs. You may request deletion of your account; we will delete or anonymise personal data unless we must retain it (for example completed HMRC filings metadata, billing records, or security logs). Content you chose to keep for tax compliance may need longer retention under UK law — you should export records you are required to keep before closing an account.
We implement technical and organisational measures appropriate to the risk, including encrypted transport (TLS), access controls, password hashing, and encryption of sensitive tokens (such as HMRC OAuth credentials) where the product implements encryption. No method of transmission or storage is completely secure; please use a strong unique password and enable two-factor authentication when offered.
Under UK data protection law you may have the right to:
To exercise these rights, email [email protected]. We may need to verify your identity before responding. HMRC filings you already submitted remain subject to HMRC rules and cannot be recalled through this product alone.
We use essential browser storage to keep you signed in and operate the Service. Optional product analytics (PostHog) and error diagnostics (Sentry) run only if you accept them on the cookie banner, and neither is loaded if you choose essential only. Details are in our Cookie Notice.
The Service is intended for business and adult users. We do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us so we can delete it.
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be notified in-product or by email. Continued use after an update constitutes acceptance of the revised policy where permitted by law.
Privacy questions and requests, including access, correction and deletion: email [email protected]. You do not need an account to write to us. Please include enough detail for us to locate your account (for example the email you registered with).
Security problems: email [email protected]. You do not need an account with us to report one. Our policy, and what we commit to in return, is published at /.well-known/security.txt.
See also our Cookie Notice and Terms and Conditions.