Privacy Policy
Last updated: March 2026
1. Who we are
This software is operated by Meta Eight Ltd for its own internal business use, including the submission of VAT returns to HMRC under Making Tax Digital (MTD). Meta Eight Ltd is the data controller for all personal and financial data processed by this system.
Contact: [email protected]
2. What data we hold
This system processes and stores:
- Financial transaction data (invoices, payments, bank transactions)
- Supplier and customer contact details (names, addresses)
- VAT return data submitted to HMRC
- User account credentials (hashed passwords, session tokens)
- HMRC OAuth tokens used to authenticate MTD submissions
- Device and browser context collected for HMRC fraud prevention headers
3. Why we hold it
Data is held for the following purposes:
- Legal obligation: VAT records and submissions required under HMRC Making Tax Digital
- Legitimate interests: Internal financial management and accounting
- Contractual necessity: Maintaining supplier and customer records
4. Where data is stored
All data is stored in Microsoft Azure infrastructure located in the UK South region (London). No data is transferred outside the United Kingdom.
5. How long we keep it
Financial and VAT records are retained for a minimum of 6 years in accordance with HMRC requirements. User session data is removed on logout or expiry. HMRC OAuth tokens are retained only while active.
6. Who has access
Access to this system is restricted to authorised employees and directors of MetaEight Ltd. Access is controlled by username and password authentication. No data is shared with third parties except HMRC as required for MTD VAT submissions.
7. Your rights
Under UK GDPR you have the right to access, correct, or request deletion of personal data we hold about you. To exercise these rights, contact us at the address above. Note that some data cannot be deleted where retention is required by law (e.g. VAT records).
8. Security
We take reasonable technical measures to protect data, including encrypted connections (HTTPS), hashed credential storage, and access controls. In the event of a data breach that poses a risk to individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours and affected parties as required.
9. Changes to this policy
This policy may be updated from time to time. The date at the top of this page reflects the most recent revision.