Data processing, security, and DPA
This guide answers the questions that come up most often from accountants, advisers and procurement teams reviewing TinyTax before they sign up.
Where to find our trust documentation
Everything is published — no NDA, no portal, no sales call required.
- Terms of Service: https://tinytax.co.uk/terms
- Privacy Policy: https://tinytax.co.uk/privacy
- Data Processing Agreement (DPA): https://tinytax.co.uk/legal/dpa
- Sub-processor list: https://tinytax.co.uk/legal/sub-processors
- Security page: https://tinytax.co.uk/legal/security
Controller and Processor roles
You are the Controller of the data you put into TinyTax — your company filings, your colleagues' contact details, the directors of the companies you file for. We are the Processor and process that data only on your documented instructions, as set out in the DPA.
The DPA applies automatically when you accept the Terms of Service at sign-up. There is nothing to counter-sign.
Sub-processors and hosting
Our current sub-processor list is published at https://tinytax.co.uk/legal/sub-processors. It identifies every third-party service provider that handles Personal Data on our behalf, what they do, where they are located, and the transfer mechanism that covers each one.
We give at least 14 days' advance notice of any change to the sub-processor list, with a 14-day objection window for legitimate data-protection grounds.
Retention and deletion
Retention periods by data type are published in our Privacy Policy at https://tinytax.co.uk/privacy §2.4. Headlines:
- Filings (CT600, accounts, computations): 7 years (HMRC requirement)
- Account and billing records: 7 years (Companies Act / VAT)
- Support tickets: 3 years
- Server and audit logs: 90 days
Bespoke contracts and NDAs
TinyTax is a self-serve subscription product. We do not sign bespoke contracts, master services agreements, amended terms or third-party NDAs at the standard subscription tier. Confidentiality is in our published Terms of Service and DPA. This is the same posture as Xero, QuickBooks, FreeAgent and Sage at their self-serve SMB tiers — a customer's own DPA template, an MSA red-line, or an NDA is not something we accommodate.
If your procurement process requires negotiated paper, we may not be the right fit for your organisation.
Certifications
We do not currently hold ISO 27001 or SOC 2 certification. Our published trust documentation (Terms, Privacy, DPA, Sub-processor list, Security page) is the basis on which we sell the service. If your procurement requires a certified provider, please factor that into your decision.
Common questions
Do you sign DPAs? Our DPA is the published one at https://tinytax.co.uk/legal/dpa. It applies automatically on sign-up. We don't counter-sign customer-supplied DPAs.
Will you sign our NDA? No, see "Bespoke contracts and NDAs" above.
Where is data stored? Production hosting is in Germany (Hetzner Falkenstein). Off-site backups are held in Cloudflare R2, encrypted before they leave production. Full breakdown at https://tinytax.co.uk/legal/sub-processors.
Is data encrypted? In transit, yes (TLS 1.2+). Database backups are encrypted before they leave production and held off-site (Cloudflare R2), protected at rest by the provider's access controls. Application secrets and stored credentials (such as OAuth tokens) are encrypted with AES-256 using keys held outside the database. Full detail at https://tinytax.co.uk/legal/security.
Can we audit you? You can review the trust documentation and ask written questions to [email protected]. We don't accommodate on-site audits or third-party audit firms at the standard subscription tier.
What happens to data when I cancel? See Privacy Policy §2.5 for the deletion process and timelines, and DPA §11 for the contractual position. Filing records are retained for the statutory periods even after deletion of the account profile.
Was this guide helpful?
Thanks for your feedback!