0
Skip to Content
suiteSheets
FAQs
Free Templates
Hub
About Us
suiteSheets
FAQs
Free Templates
Hub
About Us
FAQs
Free Templates
Hub
About Us

Privacy and Data Protection Policy

Last updated: 20 March 2025

This policy explains how suiteSheets collects, uses, and protects your personal data. We are committed to handling your information lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

suiteSheets is a Making Tax Digital (MTD) bridging software service registered in the United Kingdom. We provide spreadsheet-based record-keeping and HMRC submission tools for sole traders and landlords.

For the purposes of UK data protection law, suiteSheets is the data controller in respect of personal data collected through this service.

If you have any questions about how we handle your personal data, please contact us:

suiteSheets
Email: contact@suitesheets.co.uk
Website: www.suitesheets.co.uk


2. Our commitment to UK GDPR

Yes - suiteSheets complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are committed to handling your personal data lawfully, fairly, and transparently, and to upholding your rights as a data subject. Our processing of personal data is governed by the seven principles of UK GDPR:

  • Lawfulness, fairness and transparency
  • Purpose limitation - we only use your data for the purposes described in this policy
  • Data minimisation - we collect only what is necessary
  • Accuracy - we keep your data up to date where relevant
  • Storage limitation - we retain data only for as long as your account is active
  • Integrity and confidentiality - we protect your data against unauthorised access or loss
  • Accountability - we take responsibility for demonstrating compliance

3. What personal data we collect

3.1 Account information

  • Your name and email address, used to create and manage your suiteSheets account
  • Authentication credentials (passwords are stored in encrypted form and never in plain text)

3.2 HMRC and tax reference data

  • Your HMRC Unique Taxpayer Reference (UTR) or National Insurance number where required for MTD submission
  • Your VAT registration number if applicable
  • Business name and income type classification (self-employed or property landlord)
  • MTD obligation period dates and submission reference identifiers returned by HMRC

3.3 Payment information

  • Billing details processed via Stripe, our third-party payment provider
  • We do not store your full card number, CVV, or payment credentials - these are handled exclusively by Stripe

3.4 Usage data

  • Information about how you interact with the suiteSheets service, such as login activity and feature usage
  • Technical data including browser type, device type, and IP address, collected via analytics tools

3.5 What we do not collect or retain

We do not retain the financial figures or records from your uploaded spreadsheets. Spreadsheet files uploaded for processing are used solely to extract the summary data required for your MTD submission and are not stored on our systems after processing is complete.


4. Lawful basis for processing

We rely on the following lawful bases under UK GDPR Article 6:

  • Contract performance - processing your name, email, HMRC reference data, and payment information is necessary to provide the suiteSheets service you have subscribed to
  • Legal obligation - we may process data to comply with applicable UK law, including HMRC requirements
  • Legitimate interests - we use usage and analytics data to improve the service and ensure security, where this does not override your rights
  • Consent - where we send you optional communications such as product updates, we will obtain your consent and give you a clear way to withdraw it

5. How we use your personal data

  • Creating and managing your suiteSheets account
  • Facilitating your MTD submissions to HMRC via the approved software pathway
  • Processing your subscription payment
  • Sending you transactional communications relating to your account
  • Improving and maintaining the suiteSheets service through aggregated, anonymised usage analysis
  • Complying with legal and regulatory obligations

We will not use your personal data for purposes incompatible with those listed above, and we will not sell your personal data to any third party.


6. Third-party data processors

We share your personal data with a small number of trusted third-party processors who act on our instructions and are bound by appropriate data processing agreements:

Processor Purpose
Stripe Payment processing. Certified to PCI-DSS Level 1. Your payment data is processed and stored by Stripe in accordance with their privacy policy.
Squarespace Our public-facing website. May collect standard web analytics data such as IP addresses and page visits.
Email service provider Transactional emails relating to your account and submissions. No financial data is included in these communications.
Analytics provider Aggregated, anonymised usage data to help us improve the service (which may include Google Analytics).
Cloud hosting provider Hosting of the suiteSheets application and account data, operating within the UK or EEA.

We do not transfer your personal data outside the UK or EEA unless appropriate safeguards are in place, such as UK adequacy regulations or UK International Data Transfer Agreements (IDTAs).


7. Data retention

We retain your personal data for as long as your suiteSheets account remains active. If you close your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain certain records by law (for example, financial transaction records, which may be retained for up to six years in line with HMRC requirements).

Uploaded spreadsheet files are not retained after processing is complete.


8. Your rights under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access - request a copy of the personal data we hold about you
  • Right to rectification - ask us to correct inaccurate or incomplete data
  • Right to erasure - ask us to delete your personal data where there is no legitimate reason to continue processing it
  • Right to restriction - ask us to restrict processing in certain circumstances
  • Right to data portability - request your data in a structured, machine-readable format
  • Right to object - object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making - we do not use your personal data for automated decision-making that produces legal or similarly significant effects

To exercise any of these rights, please contact us at contact@suitesheets.co.uk. We will respond within one calendar month. We may need to verify your identity before fulfilling a request.

You will not be charged a fee for exercising your rights unless your request is clearly unfounded or excessive, in which case we may charge a reasonable fee or decline to respond.


9. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted storage of account credentials
  • HTTPS encryption for all data in transit
  • Access controls limiting who within suiteSheets can access personal data
  • Regular review of our security practices

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and notify you directly where required by law.


10. Cookies

suiteSheets uses cookies and similar technologies to operate the service and analyse usage. For full details, please see our Cookie Policy at app.suitesheets.co.uk/cookies.


11. Complaints

If you are unhappy with how we have handled your personal data, please contact us first at contact@suitesheets.co.uk and we will do our best to resolve the matter.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk


12. Changes to this policy

About‍ ‍Contact‍ ‍Terms ‍Privacy ‍