Purposes and lawful basis
We use data to provide the service, manage subscriptions, support users, protect the platform and comply with legal obligations. Depending on the context, the lawful basis may include contract, legitimate interests, legal obligation or consent.
- For client data entered by a practice, the practice is normally responsible for deciding what data is collected and why.
- PracticeComply acts as a processor for those client workflow records unless we need to process data for our own legal or security purposes.
- If a practice uses Companies House sync, we process public company data returned by Companies House, such as company profile, registered office, filing due dates, officers and PSC names.
Sharing
We only share data where needed to run the service, process payments, deliver email, comply with law or protect the platform.
- Stripe processes payment and subscription information.
- Hosting and email providers may process operational data needed to provide the service.
- Companies House may receive the company number being synced so public company data can be retrieved.
Practice Intelligence and deterministic workflow assistance
Where a practice enables Practice Intelligence, PracticeComply uses workflow records already stored in the service—such as task and document-request status, due dates, review state, upload metadata, client assignments, safe Companies House alert/due-date status and allowlisted activity timestamps—to calculate current workflow insights, Client Attention, assigned-portfolio workload and observed workflow-event counts. These calculations are deterministic and performed within PracticeComply; no external AI provider receives this data. The feature does not analyse uploaded file contents, HMRC tokens or data, Stripe or payment data, or raw Companies House payloads, and it does not make tax, legal, accounting, filing, compliance-risk or staff-performance decisions. Communication Draft uses selected task and document-request facts to prepare a local draft for human review; the draft is not automatically sent or stored. Team Workload describes current work linked to assigned client portfolios and is not staff ranking, productivity scoring, performance scoring or peer comparison.
- ('heading', 'Practice Intelligence and deterministic workflow assistance')
- ('text', 'Where a practice enables Practice Intelligence, PracticeComply uses workflow records already stored in the service—such as task and document-request status, due dates, review state, upload metadata, client assignments, safe Companies House alert/due-date status and allowlisted activity timestamps—to calculate current workflow insights, Client Attention, assigned-portfolio workload and observed workflow-event counts. These calculations are deterministic and performed within PracticeComply; no external AI provider receives this data. The feature does not analyse uploaded file contents, HMRC tokens or data, Stripe or payment data, or raw Companies House payloads, and it does not make tax, legal, accounting, filing, compliance-risk or staff-performance decisions. Communication Draft uses selected task and document-request facts to prepare a local draft for human review; the draft is not automatically sent or stored. Team Workload describes current work linked to assigned client portfolios and is not staff ranking, productivity scoring, performance scoring or peer comparison.')
Security metadata
We process security metadata needed to protect accounts, investigate abuse, support users and maintain billing integrity.
- This may include login and account security events, 2FA status and recovery code metadata.
- Plaintext recovery codes are not stored.
- Upload metadata, billing events and security events may be retained where needed for support, abuse prevention, accounting or legal obligations.
- For an HMRC sandbox action, JavaScript user agent, device UUID, screen properties, UTC offset and window size are collected for fraud prevention. The signed action context expires after five minutes; the device UUID remains in that browser so the device can be recognised consistently.
Retention and deletion
We keep account, client and upload records while the service is being provided and for a reasonable period afterwards where needed for support, security, accounting or legal reasons.
- A practice can request export or deletion of its account data.
- Some records may need to be retained where required by law or billing obligations.
Your rights
You may have rights to access, correct, delete, restrict or object to processing of your personal data. Contact support@practicecomply.co.uk to make a request.
- If you are a client of an accountant or bookkeeper, we may need to refer your request to that practice.
- You can also contact the UK Information Commissioner's Office if you have concerns about data protection.