Next Making Tax Digital quarterly update deadline: 7 November 2026.Start filing now

Privacy Policy – aligned.tax

Last updated: 11th September 2026

1. Who We Are

This Privacy Policy explains how Aligned Logic Ltd ("we", "our", "us") collects, uses, stores, and shares your personal data when you use the aligned.tax platform ("Service").

Data Controller: Aligned Logic Ltd Registered Address: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF Company Number: 17081706 Data Protection Contact: hello@aligned.tax

We are not required to appoint a Data Protection Officer, but you may contact us at the address above with any data protection query.

2. What This Policy Covers

This policy applies to personal data we collect through the Service, our website at aligned.tax, and related communications. It applies to all users including individual taxpayers, accountants, bookkeepers, and agents using the Service on behalf of clients.

Where an accountant or agent uploads client data, the accountant or agent acts as the data controller for that client data and we act as a data processor. Our Data Processing Agreement governs that relationship separately.

3. Personal Data We Collect

3.1 Data you provide directly

3.2 Data we collect automatically

3.3 Data collected for HMRC fraud prevention

HMRC legally requires all Making Tax Digital software to collect and transmit fraud prevention headers with every API request. This includes:

This data is transmitted directly to HMRC and is not stored by us beyond the duration of the API request.

3.4 Data we receive from third parties

3.5 Product analytics and session playback

The public website uses cookie-free aggregate website measurement to count visits and understand traffic sources. This measurement does not use cookies or persistent identifiers, and we do not use it to follow people across websites or days.

If you enable Analytics in the cookie settings, we also use a consent-based product analytics service on the public website. It records page views, approved campaign parameters, and clicks on links to app.aligned.tax. This is off until you actively consent. Session recording is disabled on the public website.

In the app, consented product analytics helps us understand where people complete or leave signup, onboarding, spreadsheet upload, mapping, review, and submission journeys. The service receives a pseudonymous browser or internal aligned.tax user ID, bounded milestone names, safe enum or count summaries, browser and device metadata, sanitised page addresses, constrained link and button interactions, and optional survey answers you choose to submit. Survey prompts ask you not to include tax figures or personal information in free text. Dynamic route identifiers, query strings, and fragments are removed from page addresses.

Masked session playback records layout and interaction patterns. All text, element attributes, and inputs are masked, and spreadsheet content, file and sheet names, cells and ranges, mapping values, tax and HMRC data, financial figures, receipt references, and other sensitive result areas are excluded from capture. We also collect page visits and page exits, dead and repeated clicks, and bounded technical categories for unhandled browser errors. Raw error messages, source context, console logs, network headers, and request or response bodies are not collected.

We do not enable form-change or form-submit automatic capture, heatmaps, performance capture, console recording, cross-origin iframe recording, or network payload capture. You can withdraw consent at any time using the Cookie settings link in the site footer or Settings > Help us improve aligned.tax. Withdrawal stops future analytics and session playback and clears analytics data stored in your browser. It does not affect the lawfulness of processing before withdrawal.

3.6 Account security evidence

For successful login and logout events, we may use a network-intelligence service to derive country, autonomous system number (ASN), network organisation, connection type, user type, and indicators for anonymous VPN, hosting provider, public proxy, residential proxy, and Tor exit node use. The service receives the source IP address over an encrypted connection when a cached result is not available.

These indicators are advisory evidence for human security investigations. They may be incomplete or inaccurate. We do not automatically suspend accounts or make legal or similarly significant decisions from location, hosting, VPN, proxy, residential, or Tor indicators.

4. How We Use Your Data and Our Lawful Basis

The UK GDPR requires us to have a lawful basis for each processing activity. The table below sets out our purposes and the corresponding lawful basis.

PurposeWhat we doLawful basis
Account creation and managementRegister your account, authenticate you, manage your subscriptionPerformance of contract (Article 6(1)(b))
Service deliveryTransform spreadsheet data, prepare financial summaries, transmit data to HMRC on your instructionPerformance of contract (Article 6(1)(b))
HMRC submissionsSubmit quarterly updates and other authorised MTD for Income Tax data to HMRCPerformance of contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c))
HMRC fraud preventionCollect and transmit device and connection data as required by The Income Tax (Digital Requirements) RegulationsLegal obligation (Article 6(1)(c))
AI categorisationProvide automated categorisation suggestions for financial transactionsPerformance of contract (Article 6(1)(b))
Phone verificationVerify your phone number via SMS for two-factor authenticationPerformance of contract (Article 6(1)(b))
Audit and complianceMaintain submission logs, user confirmations, and system event recordsLegal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f))
SecurityDetect and prevent fraud, misuse, or security incidentsLegitimate interest (Article 6(1)(f))
Error monitoringTrack application errors to maintain service reliability (with automatic PII redaction)Legitimate interest (Article 6(1)(f))
Aggregate website analyticsMeasure public page visits and traffic sources without cookies or persistent identifiersLegitimate interest (Article 6(1)(f))
Product analytics and service improvementAnalyse consented public website visits, privacy-safe journey milestones and masked app session playback to improve the ServiceConsent (Article 6(1)(a))
Advertising measurementMeasure whether an online advert led to a registration or filing action, only after you enable advertising measurementConsent (Article 6(1)(a))
CommunicationsSend service notifications, submission confirmations, security alerts, and policy updatesPerformance of contract (Article 6(1)(b))
Customer supportReceive, track and respond to support enquiries, and keep a history of that correspondencePerformance of contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f))
Customer relationship managementMaintain contact records, sales pipeline and engagement history to operate and improve the customer relationshipLegitimate interest (Article 6(1)(f))
MarketingSend product updates or feature announcements (only with your separate consent)Consent (Article 6(1)(a))
Payment processingProcess subscription payments and manage billingPerformance of contract (Article 6(1)(b))

Where we rely on legitimate interest, our interest is in operating and securing the Service. We have assessed that this does not override your rights and freedoms. You may contact us to request details of our balancing assessment.

5. AI and Automated Processing

The Service uses artificial intelligence to suggest categorisations for financial transactions and to assist with mapping spreadsheet columns to HMRC-required fields. This processing is automated but does not produce legal or similarly significant effects because:

When using AI features, we send transaction descriptions, column names, and category labels to our AI providers. We do not send National Insurance Numbers, names, or other direct personal identifiers to AI providers.

We do not use automated decision-making that produces legal effects without human intervention.

6. Who We Share Your Data With

We share personal data only where necessary to deliver the Service or where required by law.

6.1 HMRC

RecipientPurposeSafeguards
HMRCSubmitting financial data and fraud prevention headers under Making Tax DigitalUK government body; data stays in the UK; legally mandated

6.2 Service providers and other recipients

We use carefully selected service providers to operate and protect the Service. They may process only the information necessary to provide their services and must protect it under contract. We may share information with the following categories of recipient:

Recipient categoryWhy information is sharedTypes of information involved
Cloud hosting and storage servicesHost, store, back up and deliver the ServiceAccount information, uploaded records, tax return information, service configuration and technical logs as necessary to operate the Service
Communications and customer-operations servicesSend service and consented marketing messages, manage customer relationships, and receive and answer support enquiriesContact details, communication content, consent records, engagement information and limited filing-status metadata
Payment and subscription servicesTake payments, manage subscriptions and prevent payment fraudContact, order and subscription information and payment tokens; payment-card details are handled by the payment provider
Security, fraud-prevention and error-monitoring servicesProtect accounts and the Service, diagnose faults and investigate abuseAccount identifiers, device and network information, security events and redacted technical logs
Analytics and advertising-measurement servicesWith consent where required, understand use of the Service and measure campaignsConsent state, website or product usage, device and browser information, campaign attribution and pseudonymous identifiers; not tax return content
AI-assisted product servicesProvide mapping, categorisation and other clearly identified AI-assisted featuresOnly the data required for the feature, such as transaction descriptions, column headings and category labels; not direct tax identifiers
Professional advisers, insurers, regulators and public authoritiesObtain advice, establish or defend legal claims, comply with law and make filings a customer authorisesThe information reasonably necessary for the relevant purpose

We do not sell your personal data to any third party. We do not share personal data for marketing purposes without your consent.

6.3 Changes to service providers

We may change individual providers within these categories. Where there is a material change in how a category of recipient processes personal data, we will update this policy and notify you by email or through the Service where appropriate.

7. International Transfers

Some service providers process information outside the United Kingdom. Where this happens, we rely on UK adequacy regulations or use approved contractual safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.

You may contact us for more information about the safeguards relevant to your information.

8. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.

Data categoryRetention periodReason
Account data (name, email, phone)Duration of account plus 12 monthsContract performance and reasonable follow-up
Submission records and audit logs7 years from date of submissionTax record-keeping obligations
Financial data in spreadsheetsDuration of account; deleted on termination unless legal retention appliesService delivery
HMRC authorisation tokensUntil revoked by user or expiryService delivery
Payment records7 years from transaction dateFinancial record-keeping and tax obligations
Uploaded filesDuration of account; deleted on terminationService delivery
Device and usage logs12 months from collectionSecurity and service improvement
Encrypted IP address evidence for account security90 days from collectionTime-limited human investigation of suspected account misuse
Account security event metadata, including 2FA events, HMAC-protected correlation values and derived network intelligence12 months from collectionSecurity investigation and incident accountability
Error-monitoring data90 days from collectionDiagnose faults and protect reliability
Customer relationship and marketing recordsDuration of the relationship plus 12 monthsOperate the relationship and demonstrate consent
Support correspondence24 months from closureMaintain support history and resolve recurring issues
Advertising measurement consent stateDuration of the accountDemonstrating the current consent decision
Product analytics events12 months from collectionUnderstand and improve use of the Service
Masked session playback30 days from collectionDiagnose user-experience problems
Advertising-measurement identifiers and campaign attributionUp to 90 daysMeasure consented campaigns and prevent duplicate conversion records

Upon account termination, we delete or anonymise personal data in accordance with the periods above, unless retention is required by law.

9. Your Rights

Under the UK GDPR, you have the following rights:

To exercise any of these rights, contact us at hello@aligned.tax. We will respond within one month. In certain circumstances we may extend this by a further two months, in which case we will inform you.

We will not charge a fee for responding to a request unless it is manifestly unfounded or excessive.

10. Right to Complain

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Website: ico.org.uk Helpline: 0303 123 1113

We would appreciate the opportunity to address your concerns before you contact the ICO.

11. Cookies and Tracking Technologies

Our website and Service may use cookies and similar technologies. Cookies are small text files placed on your device.

11.1 Essential cookies

These are necessary for the Service to function, including session management and authentication. They do not require consent.

11.2 Analytics cookies

We use optional analytics storage only after you enable Analytics. On the public website, this supports page-view and app-link measurement without session recording. In the app, it supports product analytics and masked session playback as described in section 3.5. We also measure aggregate public website visits without cookies or persistent identifiers.

11.3 Advertising measurement cookies

If you enable Advertising measurement, first-party cookies may be used for up to 90 days to connect an advert click with a later filing action and to pass bounded first-touch and latest-touch campaign information between our website and the Service. We do not use this choice for remarketing or personalised advertising.

Advertising and analytics storage are denied by default. When Advertising measurement is denied, the advertising-measurement technology is not loaded and no advertising-measurement request is sent.

11.4 Managing cookies

Use the Cookie settings link in the site footer to accept, reject or change optional purposes. In the app, you can also control product analytics through Settings > Help us improve aligned.tax. Withdrawing Advertising measurement consent immediately stops future measurement events, expires accessible advertising and campaign cookies, and deletes stored campaign attribution from aligned.tax. It does not affect the lawfulness of processing before withdrawal, and a conversion request already received by the advertising-measurement service cannot be recalled through the cookie control. You can also control cookies through your browser settings. Disabling essential cookies may affect your ability to use the Service.

12. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

No system is completely secure. We cannot guarantee absolute security but we take reasonable steps to protect your data.

13. Children

The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.

The Service may contain links to third-party websites including HMRC. We are not responsible for the privacy practices of these websites. We encourage you to read their privacy policies.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or through the Service before the changes take effect.

The date at the top of this policy indicates when it was last updated.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Email: hello@aligned.tax Post: Aligned Logic Ltd, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF