Privacy notice
Practice Back Office prepares quarterly Making Tax Digital figures from bank statements for accounting practices. Two kinds of personal data pass through it: the name, role and work e-mail of the people at a practice who use an account, and the data in what a practice uploads about its clients — bank transaction lines of a sole trader or landlord, which can name people they paid or who paid them. For the first we are the controller. For the second the practice is the controller and we are its processor, under the data processing terms its owner accepts before anything is uploaded.
Who is responsible
Data controller for this service: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. You can also complain to the Information Commissioner's Office (ico.org.uk).
What is stored, and why
- The practice's name, its size, its anti-money-laundering supervisor and the answers on the request form — to answer the request and to know we may work for it.
- The name, role and work e-mail of each person on the account, and the terms the owner accepted — to run the account.
- Each client's reference (the practice's own code — we ask for no name) and kind of income.
- The uploaded bank statements and previous categorisation, in private storage, and the lines read from them in the browser — to prepare the figures.
- The practice's rules, each person's decision on a line, questions for the client, and the published reports.
- Counts of how the tool is used: numbers and categories, never a name, a description or an amount.
We do not store IP addresses. No automated decision about anyone is made: a qualified person reviews every quarter, and the practice decides what to submit.
How long
Original files are deleted 30 days after upload. The bank lines and previous-categorisation lines read from them are deleted 60 days after upload. A published report — the totals, the questions for the client and the categorised lines of the update period as published — stays until the practice deletes that client or its account. A practice can delete a client, or its whole account, at any time: that removes everything at once, and we count each of our tables and the storage afterwards to confirm nothing is left. An account nobody ever signed in to is removed after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else sees it
- Cloudflare, Inc. (USA and EU) — runs the application.
- Supabase (EU, Frankfurt) — the database and the private file storage. Only our server can read them; the public keys hold no rights at all.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (trading as Brevo) — sends sign-in links, invitations and the message that figures are ready, to the practice's own people only. No message carries a description or an amount from a bank line; a “figures ready” message names the practice's own client reference. Brevo puts an invisible image in every letter it sends, so it registers when a letter is opened; we cannot switch it off per message. The sign-in link itself is not rewritten.
- OpenRouter, Inc. (USA) — only when our reviewer asks for category suggestions: the descriptions of up to sixty undecided bank lines and whether money came in or went out — no amount, no date, no client reference, no e-mail. Requests go only to model providers that keep nothing they are sent (zero data retention), so nothing is stored or used to train a model. We have no separate data processing agreement with OpenRouter; if a practice does not want its lines to go to it, it tells us and the reviewer works without suggestions.
- PostHog (EU, Germany) — the usage counts above, without cookies or profiles.
- Our reviewer — a qualified accountant working for us under a written duty of confidentiality, who reads the lines of the quarters sent for preparation.
Where a recipient processes data outside the UK and the EEA, the transfer is covered by Standard Contractual Clauses and the UK Addendum.
We never contact a practice's clients, and we never send anything to HMRC.
Cookies
One: the sign-in cookie, which holds the practice and the person and nothing else. The analytics run without cookies and without local storage, so there is no banner to click.
Your rights
Under UK GDPR you can ask for a copy of what we hold about you, have it corrected, or have it deleted. A practice's client, or a person named in a client's bank lines, should ask the practice first: it is the controller, and we act on its instructions — it can delete a client's data at once. Write to privacy@vitersoft.com or practice@vitersoft.com and a person answers.