Privacy Notice
Last updated: 27 June 2026
This notice explains how TaxHalo (“we”, “us”, “our”) collects, uses, and protects your personal data when you use our service. It is written to satisfy Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller is:
Invasive Security Limited(trading as TaxHalo)
Email: privacy@taxhalo.co.uk
2. What data we hold and why
2.1 Account data
When you register, we collect your email address, chosen password (hashed — never stored in plain text), full name (optional), and phone number (optional). This is necessary to create and manage your account.
Lawful basis: Article 6(1)(b) UK GDPR — performance of a contract with you.
Retention: For the lifetime of your account, plus 30 days after account closure to allow recovery. After that, email and name are pseudonymised; the account record is retained for 6 years to satisfy VAT and Companies Act accounting obligations.
2.2 Financial and tax data
To provide the TaxHalo service you enter income, expenses, and other tax-related records. We store these securely in our UK-hosted database (AWS eu-west-2, London).
Lawful basis: Article 6(1)(b) — performance of a contract.
Retention: Kept for at least 5 years after the relevant Self Assessment filing deadline (Taxes Management Act 1970 s.12B), aligned to 7 years for records submitted to HMRC. We will notify you before deletion.
2.3 HMRC connection
If you connect TaxHalo to HMRC via Making Tax Digital (MTD), we store OAuth access and refresh tokens (encrypted at column level using AES-256), your National Insurance number (also encrypted), and your HMRC business identifier. These are used solely to file updates and retrieve information on your behalf.
Lawful basis: Article 6(1)(c) — legal obligation (MTD ITSA filing requirements).
Retention: Until you disconnect HMRC, or 7 years from the end of the relevant tax year (Taxes Management Act 1970 s.12B), whichever is later.
2.4 Subscription and billing data
When you subscribe to a paid plan, we hold your subscription tier, billing interval, and subscription status. We do not store your card number or CVV — those stay entirely with Stripe (see §5 below). We store only non-sensitive card metadata: card brand (e.g. Visa), last four digits, and expiry date. Invoices we issue to you are retained for accounting purposes.
Lawful basis: Article 6(1)(b) — performance of a contract; Article 6(1)(c) — VAT and Companies Act accounting obligations for invoices.
Retention: Active subscription data is held for the lifetime of your subscription, plus 30 days after cancellation. Payment method metadata (card brand, last four, expiry) is deleted 30 days after cancellation. Invoices are retained for 6 years from the issue date (VAT Notice 700/21; Companies Act 2006 s.386).
2.5 Usage and diagnostic data
We log API calls and errors for operational monitoring. These logs contain no financial or tax data. They are retained for 90 days and then deleted.
Lawful basis: Article 6(1)(f) — legitimate interests (securing and improving the service).
3. Who we share your data with
3.1 HMRC
When you authorise an MTD submission, we transmit your income and expense records to HMRC on your behalf. HMRC acts as a joint controller for that data under Article 6(1)(c). We do not sell or share your data with HMRC for any other purpose.
3.2 Amazon Web Services (AWS — EMEA)
Our infrastructure runs on AWS in the eu-west-2 (London) region. AWS acts as a processor under a GDPR Data Processing Addendum. Your data does not leave the UK for processing by AWS.
3.3 Stripe, Inc. (United States)
We use Stripe to process subscription payments. When you add a payment method, your card details are sent directly to Stripe and stored on their servers. We receive only non-sensitive metadata (brand, last four, expiry). Stripe is certified to PCI DSS Level 1.
Stripe is based in the United States. The transfer of billing metadata to Stripe is covered by an International Data Transfer Agreement (IDTA) under UK GDPR Article 46(2)(d), executed between us and Stripe. You can review Stripe’s own privacy policy at stripe.com/gb/privacy.
3.4 Google Ireland Limited (Google AdSense/AdWords)
If you are on the Free plan and explicitly agree via the cookie consent banner shown in the app, we use Google AdSense/AdWords to show non-intrusive ads. Paid plans never show ads, and no advertising cookie or script is loaded unless you agree. Your lawful basis for this processing is your consent (Article 6(1)(a)), which you can withdraw at any time in Account settings.
Google’s ad-serving infrastructure is not confined to the UK/EU. This transfer is covered by Google’s Additional Data Processing Terms and the applicable UK international data transfer mechanism. You can review Google’s own privacy policy at policies.google.com/privacy.
4. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data where there is no overriding legal reason to retain it (see below).
- Restriction — ask us to limit how we use your data while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — where we rely on consent, you can withdraw it at any time (though this does not affect processing already carried out).
4.1 Right to erasure — important limitations
We will erase your personal data on request, subject to the following legal retention obligations we cannot override:
- Tax records, HMRC submission payloads, and National Insurance number — retained for up to 7 years from the end of the relevant tax year (Taxes Management Act 1970 s.12B). Erasure of these records during that period would put you in breach of your legal obligations as a taxpayer.
- Invoices — retained for 6 years from issue (VAT Notice 700/21; Companies Act 2006 s.386).
- PAYE income-stream records — retained for 6 years from the end of the relevant tax year (ITEPA 2003; PAYE Regulations 2003).
Outside these obligations, we will erase all other personal data within 30 days of a valid request.
5. Security
We apply the following safeguards:
- All data in transit is encrypted with TLS 1.2 or higher.
- Sensitive fields (HMRC tokens, National Insurance number) are encrypted at column level using AES-256 with AWS KMS customer-managed keys.
- Database storage is encrypted at rest using AWS RDS encryption.
- Card data never touches our systems — Stripe handles it directly in scope of PCI DSS Level 1.
- We apply row-level security to ensure one tenant’s data is never accessible to another.
- We report any personal data breach to the Information Commissioner’s Office (ICO) within 72 hours, as required by UK GDPR Article 33.
6. Cookies
This marketing website does not set any tracking or analytics cookies. The TaxHalo app at app.taxhalo.co.uk uses a session cookie strictly necessary for authentication.
The TaxHalo app shows occasional, non-intrusive third-party ads (Google AdSense/AdWords) to Free plan users only — paid plans are always ad-free. Advertising cookies and scripts are only loaded if you explicitly agree via the cookie consent banner shown in the app; you can change your choice at any time in Account settings. If you do not agree, no advertising cookie or script is loaded and no ad is shown. See section 3.4 below for details of Google’s role.
7. How to exercise your rights or make a complaint
To make a subject access request, request erasure, or raise any data protection concern, contact us at:
We will respond within one calendar month.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO):
Information Commissioner’s OfficeWycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
ico.org.uk/make-a-complaint/
Tel: 0303 123 1113
8. Changes to this notice
We may update this notice from time to time. Material changes will be communicated by email at least 14 days before they take effect. The current version is always available at taxhalo.co.uk/privacy.