Skip to main content

Privacy Policy

Last updated: 23 August 2026

1. Data Controller

No Fear Tech Ltd (Company No. 16758357) is the data controller for personal data processed through the My LTD Accounts service. Our registered address is 6 Mallard Way, Dereham, Norfolk NR19 1FJ.

Contact: hello@myltdaccounts.co.uk

2. What Data We Collect

Account data: Name, email address, authentication identifiers, company name, and team role. Authentication credentials are handled by our authentication provider; we do not receive your plaintext password. The current beta does not collect payment-card data.

Financial and tax data: Invoices, expenses, receipts, bank transactions, VAT registration number, VAT records, returns, obligations, submission receipts, and other accounting records you enter into the Service.

Connected-service data: Open Banking account and transaction data where you authorise a bank connection, and encrypted OAuth credentials used to maintain authorised HMRC and banking connections.

Security and MTD fraud-prevention data: IP address and collection time, originating port when supplied by our hosting infrastructure, browser user agent, persistent device identifier, screen and window dimensions, time zone, service user identifier, forwarding information, product version, and verified multi-factor method, authentication time, and hashed factor reference. HMRC requires relevant data to be sent with MTD API requests.

Usage data: Pages visited and device or browser information. Optional Google Analytics and Vercel Analytics load only after you accept analytics in our cookie banner.

Communication data: Messages sent via our contact form or support channels.

3. Legal Basis for Processing

We process your data under the following legal bases (UK GDPR):

  • Contract: To provide the Service you signed up for.
  • Legitimate interest: To improve the Service, prevent fraud, and provide support.
  • Legal obligation: To comply with tax, accounting, and regulatory requirements.
  • Consent: For marketing communications (you can opt out at any time).

4. How We Use Your Data

  • To provide, maintain, and improve the Service
  • To manage authentication and authorised team invitations
  • To deliver contact-form messages and essential service communications
  • To provide customer support
  • To detect and prevent fraud or abuse
  • To connect to HMRC, retrieve VAT obligations, refresh authorisation, and submit a finalised VAT return when you instruct us
  • To meet HMRC fraud-prevention and software audit requirements
  • To comply with legal obligations

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Supabase — authentication, database, storage, and server functions
  • Vercel (website hosting) — for serving the application
  • Resend (email) — for delivering contact-form messages where configured
  • TrueLayer — where you choose to connect an account through Open Banking
  • HM Revenue & Customs — where you authorise MTD access or instruct us to retrieve or submit VAT information
  • Google Analytics and Vercel Analytics — only after you accept optional analytics

We require service providers to process data under contractual and legal safeguards. A current sub-processor and hosting-region record is available on request.

6. Data Retention

We retain account data while your account is active and for a limited period needed for support, disputes, and legal obligations. Accounting and VAT records are normally retained for at least six years where tax rules require it. Immutable HMRC submission evidence may be retained for that legal period. OAuth credentials are removed when you disconnect a service or when they are no longer required. Contact messages are retained only as long as needed to resolve the enquiry. You may request deletion of data that we are not legally required to keep.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data
  • Portability — receive your data in a machine-readable format
  • Restriction — limit how we process your data
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — where processing is based on consent

To exercise any right, email hello@myltdaccounts.co.uk. We will respond within 30 days.

8. Data Security

Implemented measures include TLS in transit, provider-managed encryption at rest, application-level AES-GCM encryption for HMRC and Open Banking OAuth tokens, tenant isolation through database row-level security, role-based access controls, append-only filing evidence, and dependency scanning. Production monitoring, incident response, backup restoration, and independent security testing must be verified before live MTD filing. No internet service can guarantee absolute security.

9. International Transfers

Our providers may process data in the UK, EEA, or other regions. Before production launch we will verify the actual hosting and support regions, document each transfer, and put an appropriate UK transfer mechanism in place where an adequacy decision does not apply. You can request the current deployment record; do not rely on this beta for live taxpayer data until that record is published.

10. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

11. HMRC Authorisation and Automated Processing

HMRC access uses OAuth. We cannot view your Government Gateway password. You can disconnect HMRC from the Service, although HMRC may require you to revoke access separately. VAT calculations and record checks are automated, but you must review the nine boxes and make the legal declaration before submission. We do not use solely automated decision-making that produces legal or similarly significant effects about you.

12. Changes

We may update this policy from time to time. We will notify you of material changes by email. The "last updated" date at the top indicates the most recent revision.