Privacy policy
Last updated: 2026-06-23
1. Who we are
VATflow is operated by United Fintec Limited, a company registered in England and Wales (Companies House registration number 10216969).
Registered office: 3 Greer Garson Road, Denham, Uxbridge, UB9 5FP, United Kingdom.
United Fintec Limited determines the purposes and means by which personal data is processed for the operation of the VATflow service. Where VATflow is used by an accountant to file on behalf of their own clients, United Fintec acts as a processor for that client data — see section 3 below.
2. ICO registration
United Fintec Limited is registered with the Information Commissioner’s Office (ICO) as a data controller under reference ZC139359 (valid until 04 May 2027).
3. Controller and processor roles
Who is the “controller” and who is the “processor” for a given set of data depends on how VATflow is being used:
- Your account and the running of the service. United Fintec Limited is the controllerfor the data needed to operate VATflow — your account details, sign-in and security records, and billing information.
- A business filing its own VAT. When a business owner or employee uses VATflow to file for their own company, that business is the controller of its own company and VAT data, and United Fintec Limited is the processor acting on its instructions.
- An accountant filing for clients.When an accountant uses VATflow to file on behalf of their clients — under their own HMRC Agent Services Account authorisation — the accountant is the data controller for their client data, and United Fintec Limited is the processoracting on the accountant’s instructions. The accountant is responsible for the lawful basis, client notices, and data-subject rights in respect of their clients.
In every case United Fintec processes data only to provide the service, to meet its legal obligations, and on the documented instructions of the relevant controller. Sub-processors we engage are listed in section 8.
4. Data we collect
To provide VATflow we collect:
- Email address and password hash (for account access).
- VAT registration numbers (VRNs) and trading names for the companies you file for.
- VAT return data (boxes 1–9) that you submit through VATflow.
- HMRC OAuth access and refresh tokens (encrypted at rest) authorising VATflow to call HMRC’s Making Tax Digital API on your behalf. VATflow never sees, receives, or stores your HMRC sign-in credentials(your Government Gateway user ID or password) — you sign in directly with HMRC, and HMRC returns only a time-limited authorisation token to VATflow.
- Billing information for paid subscriptions (plan, company count, payment status). Card and bank-mandate details are handled directly by our payment processors (see section 8); VATflow does not store your full card number or bank details.
- IP address (one-way hashed) for rate-limiting and abuse prevention; we do not store raw IP addresses.
- Security audit-event logs (sign-in attempts, password changes, multi-factor enrolment events).
- Fraud-prevention metadata required by HMRC under the Finance Act 2021 (device characteristics, time-zone, browser and screen attributes). This data is transmitted to HMRC with every API call as part of HMRC’s mandatory header requirements.
5. Lawful basis for processing
We process personal data under UK GDPR Article 6 as follows:
- Contract— processing necessary to deliver the VATflow MTD submission service you have signed up for.
- Legal obligation— transmission of fraud-prevention headers to HMRC under the Finance Act 2021 and HMRC’s terms of use.
- Legitimate interest— security audit logs and rate-limiting to protect your account and the service against abuse.
6. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data we hold:
- Encryption in transit. All data transmitted between your browser, VATflow, and HMRC is encrypted using TLS.
- Encryption at rest. Data stored in our database is encrypted at rest. HMRC OAuth tokens are additionally encrypted by VATflow with AES-256-GCM before storage.
- Multi-factor authentication. We require multi-factor authentication (MFA) on accounts that initiate VAT submissions, and offer it to all users.
- Access controls. Access to your data within the application is restricted to your own account (and, for accountants, the clients you are authorised for) by row-level security; administrative access is limited and logged.
7. Where data is stored
Your core account and VAT data is stored at rest in the United Kingdom, in Supabase (AWS eu-west-2 / London region). Personal data is also processed in transit by our application servers — both the web application layer and the backend API — which run in the United Kingdom (London). No personal data is retained on these application servers.
A limited set of personal data is processed by sub-processors that operate outside the United Kingdom — see sections 8 and 12.
8. Sub-processors
We use the following third-party processors to deliver VATflow. Each processes personal data only to provide its specific function to us, under a contract that requires it to protect that data:
- Supabase— database, authentication, and file storage (United Kingdom — AWS London).
- Fly.io— backend application and API hosting (United Kingdom — London).
- Vercel— web application hosting (United Kingdom region).
- Cloudflare— DNS, content delivery, and bot / CAPTCHA protection (global edge network).
- Resend— delivery of account and security emails (e.g. sign-in verification, password reset).
- Sentry— application error and performance monitoring (European Union region).
- Stripe— card payment processing for paid subscriptions (engaged when you take out a paid plan).
- GoCardless— Direct Debit processing for paid subscriptions (engaged when you set up a Direct Debit).
We review this list as our service evolves and will update it here when a sub-processor is added or removed.
9. How long we keep data
- VAT return records— retained for six years from the end of the relevant accounting period, in line with HMRC’s record-keeping requirements (VAT Notice 700/22).
- Security audit logs— retained for 90 days, then automatically deleted.
- Account data— retained for as long as your account is active. On account closure, personal identifiers are scrubbed; VAT submission records are retained for the six-year HMRC retention period as required by law.
10. Your rights under UK GDPR
Under UK GDPR you have the right to:
- Access the personal data we hold about you (Subject Access Request).
- Have inaccurate or incomplete data corrected.
- Request erasure of your data (subject to our legal obligation to retain VAT records for six years).
- Restrict or object to certain processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time where processing relies on consent.
If your personal data is processed by VATflow on behalf of an accountant who files for you, that accountant is the controller for your data and you should direct these requests to them in the first instance; we will support them in responding.
11. How to exercise your rights
To exercise any of the rights above, email contact@unitedfintec.com with the subject line “Data Subject Request”. We will acknowledge your request within 5 working days and respond within one calendar month, as required by UK GDPR.
12. International data transfers
Your core account and VAT data is stored and processed in the United Kingdom. A limited set of personal data is, however, processed by sub-processors located outside the United Kingdom — for example application error monitoring (Sentry, European Union) and payment processing for paid subscriptions. Where data is transferred outside the UK, we rely on an adequacy regulation or on appropriate safeguards (such as the UK International Data Transfer Agreement or Addendum, or Standard Contractual Clauses) as required by UK GDPR. Data transmitted to HMRC’s Making Tax Digital API stays within the United Kingdom.
13. Cookies
VATflow uses essential session cookies only. We do not use analytics cookies, advertising cookies, or any third-party tracking. The cookies we set are required to keep you signed in and to remember the active company you are filing for.
14. Contacting the ICO
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.
ico.org.uk · helpline 0303 123 1113
15. Updates to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes that affect how we process your personal data will be communicated by email to the address associated with your account at least 14 days before the change takes effect.