Practice Back Office

Terms and data processing terms

These are the terms of Practice Back Office. Asking to try it commits you to nothing; they apply once your practice's owner accepts them in the account, before any client's data is uploaded. Questions: practice@vitersoft.com.

1. What we do and what you do

  • You upload a client's bank statement export and, if you have it, the client's previous categorisation. Our code applies your rules and your corrections; a qualified reviewer decides the remaining lines or writes a question for the client; our code adds up the totals per HMRC category for the quarterly update period.
  • We prepare figures. We do not submit anything to HMRC, we are not your client's agent, and we never contact your client. You check the figures, you decide what to send, and you submit the quarterly update through your own HMRC-recognised software.
  • This is not tax advice and not legal advice. We make no accounting or tax adjustments. Figures cover only the bank accounts you upload.
  • Price during the pilot: £10 per client per quarter. You pay only for a quarter you accept after reading the report; we invoice you after you accept. A quarter you mark as not usable costs nothing.

2. Data processing terms (UK GDPR Article 28)

  • Roles. Your practice is the controller of your clients' personal data in what you upload; we process it on your behalf as your processor.
  • Subject-matter and duration. Preparing quarterly Making Tax Digital figures for the clients you add, for as long as your practice has an account here. Bank lines are deleted 60 days after upload, original files 30 days after upload, and everything at once when you delete a client or your practice.
  • Nature and purpose. Storing, reading, categorising and adding up bank-statement lines, and showing the result to your practice and our reviewer. No other purpose: no marketing, no profiling, no training of models, no sale.
  • Types of personal data. Bank transaction lines (date, description, amount) of your client's business; your client reference (we ask for your own code, not a name); the names and e-mail addresses of your staff who use the service.
  • Categories of data subjects. Your clients (sole traders and landlords), the people named in their bank descriptions, and your staff.
  • (a) Instructions. We process only on your documented instructions — what you upload and ask for on these screens, and what you write to us — unless UK law requires otherwise, in which case we tell you first unless the law forbids it.
  • (b) Confidentiality. Everyone who can see your data — the founder and the reviewer — is under a written duty of confidentiality.
  • (c) Security (Article 32). Data is encrypted in transit; files are in private storage reachable only through short-lived signed links; only the server reaches the database; each request is checked against your practice; sign-in is by one-time link, no passwords.
  • (d) Sub-processors. You authorise the sub-processors listed below. We will tell you before adding or replacing one, and you may object. Each is bound to the same data protection obligations, and we remain liable to you for them.
  • (e) Data subjects' rights. We help you answer a request from your client — for example by deleting a client's lines at once from the client screen.
  • (f) Assistance with Articles 32–36. We tell you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data, and help with a data protection impact assessment if you need one.
  • (g) End of the service. You can delete a client or the whole practice at any time on these screens; that deletes the data and the files at once. Export the report and the CSV files first if you want to keep them.
  • (h) Audit. We give you the information you need to show compliance with this Article and answer your questions about it; write to us to arrange an inspection.

Sub-processors you authorise:

  • Cloudflare, Inc. — hosting of the application (USA/EU)
  • Supabase, Inc. — database and file storage (EU, Frankfurt)
  • Sendinblue SAS (Brevo), 9-17 rue Salneuve, 75017 Paris — sign-in and notification e-mail; it receives e-mail addresses only
  • OpenRouter, Inc. — routes a reviewer-requested category suggestion to a model provider that keeps no data (zero data retention); it receives bank-line descriptions and the direction of the money only
  • PostHog Inc. (EU cloud, Germany) — counts of product events; it receives no personal data
  • Our reviewer — a qualified accountant working for us under a written confidentiality duty

3. Anti-money laundering

  • You confirm that your practice is supervised for anti-money laundering by HMRC or a professional body, and that you have named that supervisor to us.
  • We work only for supervised practices and never deal directly with your clients: questions for a client come to you, and you decide whether and how to ask them.
  • You include this service in your anti-money laundering controls and procedures. If our reviewer comes to know or suspect money laundering or terrorist financing in what you upload, the reviewer reports it to your money laundering reporting officer (MLRO), and we follow your MLRO's instructions. Your practice remains responsible for customer due diligence on your clients.
  • This is our reading of HMRC's guidance for accountancy service providers whose customers are all supervised; HMRC has not confirmed it to us, and it is not legal advice. If any of it does not hold, we will register with HMRC before carrying on.

4. Everything else

  • These terms were written by us, not by a lawyer.
  • Our liability to you for a figure is limited to the price you paid for that quarter. Nothing here limits liability that the law does not allow to be limited.
  • English law applies.

Version 2026-10-03. Written by us, not by a lawyer.