Privacy Policy
1. What this policy covers
This policy explains what personal data we collect when you use Quarvex, why we collect it, who we share it with and your rights under UK data protection law (UK GDPR and the Data Protection Act 2018).
2. Data we collect
- Account data. Your name, email address, password (stored hashed), and company details you provide.
- Accounting data. The invoices, bills, contacts, expenses, payroll, CIS, VAT and Self Assessment records you create in the Service. This can include personal data about your customers, suppliers, employees and subcontractors; for that data you are the controller and we process it on your instructions.
- Bank transaction data. If you connect a bank feed, transaction data is retrieved through a regulated open-banking provider with your explicit consent. We never see or store your online-banking credentials.
- Payment data. Subscription payments and Pay Now card payments are processed by Stripe. We do not store full card numbers; Stripe handles card data under its own PCI-DSS compliance.
- Documents you upload. Receipts and invoices you upload for AI scanning are processed to extract accounting fields.
- Usage and technical data. Log data such as IP address, browser type and actions in the Service, used for security and troubleshooting.
3. Why we process it
- To provide the Service (contract): running your books, generating documents, filing returns you approve.
- To submit filings to HMRC (contract and legal obligation): VAT, RTI payroll, CIS and Self Assessment submissions are sent to HMRC under the authorisation you grant.
- To take payment (contract): subscription billing via Stripe.
- To keep the Service secure (legitimate interests): fraud prevention, abuse detection, backups.
- To communicate with you (legitimate interests / consent): service messages always; product news only if you opt in, with unsubscribe in every email.
4. Who we share data with
We share data only with processors needed to run the Service: our hosting provider (UK/EU data centres), Stripe (payments), our open-banking provider (bank feeds), our email delivery provider (sending invoices, statements and service emails), and HMRC (the filings you submit). We do not sell personal data. We may disclose data where the law requires.
5. Cookies and local storage
The marketing site uses no advertising or tracking cookies. We store a single preference in your browser's local storage to remember your light or dark theme choice. The app uses strictly necessary cookies for login sessions and security.
6. How long we keep data
We keep your data while your account is active. After a subscription ends we retain data for a reasonable period so you can export it, then delete or anonymise it. Records we must keep for legal, tax or accounting reasons are retained for the statutory period. Backups are kept off-site, encrypted, and cycle out on a fixed schedule.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. We maintain off-site backups. No system is perfectly secure, but if a breach affects your data we will notify you and the ICO as the law requires.
8. Your rights
You have the right to access your personal data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. To exercise any right, email support@quarvex.com. We respond within one month. You can also complain to the ICO at ico.org.uk, though we would appreciate the chance to resolve the issue first.
9. Changes to this policy
If we make material changes we will notify you in the Service or by email before they take effect. The effective date at the top of this page always shows the current version.
10. Contact
Britannia Digital Limited · Registered in England & Wales, company number 17253824 · support@quarvex.com