Data Processing Agreement - TinyTax

Data Processing Agreement

Last updated: 29 April 2026

1. About this agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("you", "Controller") and TinyTax Ltd (registered in England, company no. 15863077) ("we", "Processor") and applies to our processing of Personal Data on your behalf when you use the TinyTax service ("Service").

It applies automatically when you accept the Terms of Service. No counter-signature is required. It is governed by the same law and jurisdiction as the Terms of Service (England and Wales).

Capitalised terms not defined here have the meanings given in the UK GDPR and the Data Protection Act 2018.

2. Roles, scope and duration

You are the Controller of the Personal Data you submit to the Service. We are the Processor and process the Personal Data only on your documented instructions, as set out in the Terms of Service, this DPA, and the configuration choices you make within the Service.

ItemDetail
Subject matter Provision of the TinyTax Service: preparation and submission of UK Corporation Tax (CT600) returns and Companies House annual accounts and confirmation statements.
Duration For as long as you have an account with us, plus the post-termination retention periods set out in §11 below.
Nature and purpose of processing Storage, retrieval, transformation, generation of statutory documents (CT600 XML, iXBRL accounts, computations), transmission to HMRC and Companies House on your instruction, customer support, and operational analytics.
Types of Personal Data Identification and contact data (name, email address); company-officer data (director names, addresses where required by HMRC or Companies House); financial data attached to a named individual where applicable; account credentials and authentication data; support correspondence; transient transmission credentials (Government Gateway).
Categories of Data Subjects You; your colleagues authorised to use the account; directors, secretaries and members of the companies you file for; individuals named in correspondence with our support team.

3. Your obligations as Controller

  • You confirm that your collection and provision of Personal Data to the Service complies with applicable data protection law and that you have the legal basis to instruct us to process it.
  • You are responsible for the lawfulness, accuracy and completeness of the Personal Data you submit and for responding to Data Subjects in respect of their personal data, with the assistance described in §8.
  • You retain control over your account configuration, the data you upload, and the timing and content of any submission to HMRC or Companies House.

4. Our obligations as Processor

We will:

  • Process Personal Data only on your documented instructions, including in respect of transfers of Personal Data outside the United Kingdom, except where required to do so by law (in which case we will inform you of that legal requirement before processing, unless prohibited from doing so).
  • Ensure that personnel authorised to process Personal Data are bound by appropriate confidentiality obligations and are familiar with the data protection requirements applicable to the Service.
  • Implement and maintain appropriate technical and organisational measures designed to protect Personal Data, as set out in §6.
  • Engage sub-processors only in accordance with §7.
  • Assist you, taking into account the nature of the processing, with your obligations under §8 and §9 of this DPA.
  • Make available to you the information necessary to demonstrate compliance with this DPA, principally through the trust documentation we publish (this DPA, the Sub-processor List, the Security page) — see §10.
  • At your choice, delete or return all Personal Data at the end of the agreement, as set out in §11.

5. Confidentiality

We will treat all Personal Data as confidential and will limit access to those of our personnel and sub-processor personnel who need access to perform the Service. Each such person is bound by a written confidentiality obligation of no less protection than this DPA imposes on us.

6. Security measures

We implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Current measures are described at /legal/security and include encryption in transit, restricted production access, monitored hosting, regular backups and time-bound retention of authentication credentials.

We may update these measures from time to time provided that the level of protection is not materially decreased.

7. Sub-processors

You provide general authorisation for us to engage the sub-processors listed at /legal/sub-processors to process Personal Data in connection with the Service.

We will give you at least 14 days' advance notice of any intended addition or replacement of a sub-processor by updating the published list. If you object to the new sub-processor on legitimate data-protection grounds, you may notify us within 14 days. Where the affected service cannot reasonably be provided without the new sub-processor, you may terminate the affected portion of the Service and receive a refund for any unused prepaid period.

Each sub-processor is bound by a written agreement that imposes data protection obligations equivalent in substance to those in this DPA. We remain responsible to you for the performance of each sub-processor's obligations.

8. Assistance with data subject rights

Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from Data Subjects exercising their rights under the UK GDPR (access, rectification, erasure, restriction, portability, objection). The Service provides in-product account closure; for data export, rectification or any other rights request, contact and we will respond within the timeframes set out in §11 and the Privacy Policy.

9. Assistance with breach notification, DPIA and prior consultation

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting your data, and provide you with the information reasonably required for you to comply with your obligations under Articles 33 and 34 of the UK GDPR.

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment ("DPIA") and any prior consultation with the Information Commissioner's Office ("ICO") that you are required to carry out in respect of the Service.

10. Audit

You may verify our compliance with this DPA by reviewing the trust documentation we publish: this DPA, the Sub-processor List, the Security page, and any answers we provide to specific written questions you send to . As a self-serve subscription product we do not accommodate on-site audits or third-party audit firms at the standard subscription tier.

11. End of agreement

On termination, you may request an export of your data by emailing before instructing deletion. Within 30 days of the later of (a) your written instruction to delete and (b) account termination, we will delete or anonymise Personal Data held in active production systems. Backups containing Personal Data are deleted on the next backup-cycle rotation following the active deletion, and pre-rotation backups are not restored unless required by law.

We will retain the minimum Personal Data required by law (typically the filing record for the periods set out in Privacy Policy §2.4) and confirm completion in writing.

12. International transfers

Where we transfer Personal Data outside the United Kingdom, we rely on the UK adequacy regulations (for transfers to EEA countries) or on the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses (for transfers to other third countries). Current transfer destinations and mechanisms for each sub-processor are listed at /legal/sub-processors.

13. Liability

Our liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service §5, except to the extent that such limitation is prohibited by applicable law.

14. Changes to this DPA

We may update this DPA from time to time. Where a change materially affects your rights, we will notify you in advance and you may terminate the Service for that reason within 30 days of the notice. Continued use of the Service after the effective date constitutes acceptance.

15. Contact

For questions about this DPA, our processing of your data, or to make a request under any of the sections above, contact .

Registered office: 20 Wenlock Road, London, N1 7GU, England.