Privacy & Data Protection

Privacy Policy

How we collect, use, and protect your personal data in accordance with UK GDPR and the Data Protection Act 2018.

Last updated: 06 September 2025
UK GDPR Compliant
1

Who We Are

11TaxAssist Ltd (company no. 16416027) is the data controller for personal data processed via our websites, products and services unless stated otherwise.

Registered address: 6 Alexander Court, Baker Street, Reading, England, RG1 7XZ Email: [email protected]
2

Scope of This Policy

This notice explains how we collect, use, share and protect personal data in accordance with the UK GDPR, the Data Protection Act 2018, and other applicable UK laws.

It covers data processed when you visit our website, contact us, or use our services.

3

The Data We Collect

We may collect and process the following categories of data:

  • Identity & contact data: name, email, telephone, postal address
  • Business data: company name, job title
  • Financial & tax data: tax references, invoices, payment details
  • Usage & technical data: IP address, device/browser info, log files, cookie identifiers
  • Communications: enquiries, support requests and feedback
We collect data directly from you and, where lawful, from third parties such as HMRC, Companies House, banks and payment processors.
4

Purposes and Lawful Bases

We process personal data to provide our services, comply with legal obligations, manage payments, protect systems, and ‐ with your consent ‐ send marketing communications.

Purpose Example Activities Lawful Basis
Provide & manage services Onboarding, filing, advice, support Contract
Legal & regulatory compliance HMRC/Companies House submissions, record keeping Legal obligation
Billing & payments Invoicing and payment processing Legitimate interests
Security & fraud prevention Access controls, logs, DDoS/WAF via CDN Legitimate interests
Marketing (optional) Newsletters, updates Consent
We do not use automated decision-making that produces legal or similarly significant effects without explicit consent.
5

Your UK GDPR Rights

Under UK GDPR you have the following rights regarding your personal data. To exercise any of these rights, contact us using the details in Section 11.

Right to Access

Request a copy of the personal data we hold about you.

Right to Rectify

Correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Restrict

Limit how we process your data in certain circumstances.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Data Portability

Receive your data in a structured, machine-readable format.

Withdraw Consent

Withdraw consent at any time where processing is consent-based.

6

Sharing Your Data

We share personal data only where necessary, under contracts imposing confidentiality and security obligations (data processors). Typical recipients include:

  • Public authorities: HMRC, Companies House (where required by law).
  • Payment processors & banks: to collect and manage payments.
  • IT & cloud providers: website hosting, email, storage, security/CDN (including Cloudflare).
  • Professional advisers: legal, accounting, insurance (where necessary).
We do not sell your personal data to any third party.
7

International Transfers

Some providers may process data outside the UK/EEA. Where this occurs, we implement appropriate safeguards such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (SCCs), or rely on adequacy regulations, and apply additional technical and organisational measures where appropriate.

Cloudflare (CDN & Security)

We use Cloudflare for TLS termination, WAF/DDoS mitigation and content delivery. Cloudflare may process limited operational and security metadata across its global network.

We have a data processing agreement in place with Cloudflare and rely on appropriate transfer mechanisms. Traffic between Cloudflare and our origin uses Full (strict) TLS encryption.
8

Security of Your Data

We implement defence-in-depth security measures to protect your personal data at every layer:

TLS (HTTPS) in transit and, where appropriate, encryption at rest

WAF, DDoS mitigation and bot protections via CDN

Access controls & MFA for all internal systems

Logging, patching and vulnerability management

Supplier due diligence and data processing agreements

9

Data Retention

We retain personal data only as long as necessary for the purpose it was collected and to meet legal or accounting requirements.

Category Typical Period Rationale
Tax & accounting records 6 years after relevant tax year Statutory requirements
Contracts & correspondence 6 years after contract end Limitation periods
Support tickets & logs 12‐24 months Operational / security
Marketing data Until consent withdrawn or 24 months inactivity Preference management
When retention ends, data is permanently deleted or irreversibly anonymised.
10

Cookies & Similar Technologies

We use cookies for core site functionality and security, and ‐ where you consent ‐ analytics and performance cookies.

  • Essential cookies: Required for the website to function, including security and session management. These cannot be disabled.
  • Analytics cookies: Used to understand how visitors interact with our site. Only set with your consent.
  • Marketing cookies: Used to deliver relevant advertisements. Only set with your explicit consent.
You can control cookies via your browser settings and/or our consent banner at any time.
11

Contact Us

To exercise your data rights, ask a question about this policy, or raise a concern, please contact us:

11TaxAssist Ltd 6 Alexander Court, Baker Street, Reading, England, RG1 7XZ
Email: [email protected] We aim to respond within 2 business days.
12

Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Website: ico.org.uk
  • Telephone: 0303 123 1113
We'd appreciate the chance to resolve your concerns first ‐ please contact us at [email protected] before escalating.
13

Changes to This Policy

We may update this notice occasionally. The latest version will always be published on our website and will show the "last updated" date at the top of this page.

Continued use of our services after any changes are posted constitutes your acceptance of the updated Privacy Policy.
HMRC Recognised Software

Ready to File Your MTD Returns?

Join thousands of UK businesses using 11TaxAssist to stay compliant with Making Tax Digital ‐ fast, simple, and HMRC‐recognized.

No hidden fees
HMRC-recognised
UK GDPR compliant
1,000+ UK users

Login

Sign Up

OTP Verification