Privacy Policy
InvoClouds is used to prepare and file tax returns and company documents. That means we handle information that matters — VAT figures, Corporation Tax computations, company officer details, dates of birth. This page explains what we collect, why we have it, how long we keep it, and what you can ask us to do with it. We have tried to write it in plain English rather than legal boilerplate.
Who we are
InvoClouds is operated by Invo Clouds Limited, a company registered in England and Wales (company number 17318591), with its registered office at 85 Dunstall Hill, Wolverhampton, WV6 0SR, United Kingdom.
We are registered with the Information Commissioner's Office under registration number [[ICO_REG_NUMBER]]. For anything to do with privacy or your data, write to privacy@invoclouds.com.
Two different roles we play
This distinction matters, so it is worth being clear about it up front.
For your own account — your name, your email address, your billing details, your login history — we are the data controller. We decide what to collect and why, and this policy governs it.
For the data you put into the platform about other people — your clients, their company officers, their financial figures — we are the data processor. You are the controller. We only act on your instructions, and your own privacy notice is what governs that data. If one of your clients asks us directly about their information, we will point them back to you.
What we collect and why
| What | Examples | Why | Lawful basis |
|---|---|---|---|
| Account details | Name, email, phone number, hashed password | To create your account and keep it secure | Contract |
| Billing details | Billing address, subscription and invoice records, payment references | To take payment and meet our own accounting obligations | Contract / Legal obligation |
| Filing data | VAT registration numbers, UTRs, company registration numbers, officer names, dates of birth, addresses, financial figures | To prepare and submit filings to HMRC and Companies House | Contract / Legal obligation |
| HMRC fraud prevention data | IP address, device and browser identifiers, screen and timezone information, local timestamps, user IDs | HMRC requires this on every submission (see the section below) | Legal obligation |
| Technical and audit data | Login records, IP addresses, action audit trail, error logs | To keep the platform secure and investigate problems | Legitimate interests |
| Things you send us | Support emails, chat messages, attachments | To answer your question | Legitimate interests |
Our lawful basis, in short
Most of what we do rests on contract — we cannot deliver the service you have paid for without processing your data. Some of it rests on legal obligation, because HMRC and Companies House require certain information to be submitted and retained. A smaller amount rests on legitimate interests: keeping the platform secure, preventing abuse, and answering support requests. We have balanced those interests against your rights and consider the processing proportionate.
We do not rely on consent to run the service. The one place consent applies is marketing email, and you can withdraw it at any time using the unsubscribe link or by emailing us. Withdrawing it will not affect your account.
Data HMRC requires us to send
HMRC requires all Making Tax Digital software to send a set of "fraud prevention headers" with every API call. These describe the device and connection used to make a submission — your public IP address, device identifiers, browser details, screen dimensions, local timezone and timestamps, and the user account that triggered the submission.
This is not optional and we cannot switch it off. HMRC uses it to detect fraudulent filings and protect taxpayers. The full specification is published on HMRC's developer site. We collect only what the specification asks for, we send it directly to HMRC, and we do not use it for any other purpose.
Filings become public at Companies House
Where you use InvoClouds to file with Companies House, please be aware that most of what is filed goes onto the public register and stays there. Director names, service addresses, month and year of birth, shareholding details and filed accounts are all publicly searchable. Residential addresses and full dates of birth are normally suppressed from public view, but they are still held by Companies House. This is a consequence of company law, not a choice we make, and once information is on the register we cannot remove it — that is a matter for Companies House.
Who else sees your data
- HM Revenue & Customs — for VAT (MTD) and Corporation Tax submissions
- Companies House — for company filings
- Our hosting provider — servers located in [[SERVER_LOCATION]]
- [[PAYMENT_PROVIDER]] — handles card payments; we never see or store your full card number
- Professional advisers and regulators — only where we are legally required to disclose
We do not sell personal data. We do not hand it to anyone for their own marketing. We do not share it between customers — each account's data is isolated at the database level.
Where your data lives
Customer data is stored on servers in [[SERVER_LOCATION]]. Where any transfer outside the UK is unavoidable, we rely either on UK adequacy regulations or on the UK International Data Transfer Agreement, or its Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
How long we keep things
- Tax and filing records — six years from the end of the relevant accounting period, because HMRC requires it
- Account and billing records — for as long as your account is open, then six years
- Technical logs and audit trails — twelve months
- Support correspondence — two years
- Marketing contacts — until you withdraw consent
This is worth being direct about: closing your account does not wipe your filing history. We are legally required to retain it, and we will, in a restricted archive that is not used for anything else.
How we protect it
- All traffic to and from the platform is encrypted in transit using TLS
- Access tokens and sensitive fields are encrypted at rest; passwords are hashed, never stored in readable form
- Every customer's data is isolated at row level, so no account can reach another account's records
- Staff access is role-based and limited to what the job actually requires
- Administrative actions are logged and reviewable
- We review our security controls regularly and act on what we find
Your rights
Under the UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything that is wrong
- delete data, where we are not required to keep it
- restrict how we use it while a dispute is resolved
- hand it over in a portable, machine-readable format
- stop processing that relies on legitimate interests, where you object
Email privacy@invoclouds.com and we will respond within one month. There is no charge unless a request is clearly excessive or repetitive.
If your request concerns data that one of our customers uploaded about you, we will forward it to them, because they are the controller for that information.
Cookies
We use session cookies to keep you logged in and to protect forms against cross-site request forgery. These are strictly necessary and cannot be turned off without breaking the service. Where we use any analytics cookies, we ask for your consent first and you can change your mind at any time.
Automated decisions
We do not make decisions about you by automated means alone that produce legal effects or similarly significant effects. Tax calculations performed by the software are just that — calculations. They are yours to review and approve before anything is filed.
If something goes wrong
If we suffer a personal data breach that is likely to result in a risk to people's rights, we notify the Information Commissioner's Office within 72 hours, and we tell affected individuals directly where the risk is high. Where the incident touches HMRC submissions, we also notify HMRC within 72 hours through their Developer Hub, with a named contact and a direct phone number. If you want to report something to us, see our security reporting page.
Complaints
If you are unhappy with how we have handled your data, please tell us first — most things are quicker to fix directly. If you are still not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or by phoning 0303 123 1113.
Complaining to the ICO does not affect any other legal remedy available to you.
Changes to this policy
When we change this policy we update the review date at the top of the page. If a change materially affects how we use your data, we will tell you by email rather than relying on you to notice.