PracticeComply is built for small UK accountancy and bookkeeping practices that need a practical way to manage client compliance tasks and document requests.
PracticeComply is operated by NOCTIS STUDIOS LIMITED, company number 16940486. Support is available at support@practicecomply.co.uk or +44 7713 950125.
This page explains the current product boundaries clearly so a practice can decide whether the portal is suitable for its workflow.
Protection layers
Controls practices can understand
01
2FA
TOTP 2FA available for practice users
02
Recovery codes
Codes are shown once, are not stored in plain text and each code can be used once.
03
Roles and permissions
Sensitive actions remain restricted by existing roles and access controls.
04
Protected uploads
Client files are stored outside the public static website.
05
Activity history
Key client, request, upload and task actions are recorded.
06
Private token links
Client portal links allow replies without a full account and must remain confidential.
Data lifecycle and operations
What happens to data in the product
Data handled by the product
PracticeComply may store practice account details, client organisation names, contact names, contact emails, language preference, compliance status, task notes, document requests, client uploads and support messages.
Do not upload sensitive identity documents unless you are satisfied the workflow is appropriate for that purpose.
PracticeComply is focused on status tracking, task workflow and document intake, not HMRC filing or ACSP identity document storage.
If a practice uses Companies House sync, PracticeComply may fetch public company profile, officers and PSC data from Companies House for that client record.
Access control and two-factor authentication
Two-factor authentication (2FA) is available to practice users. Recovery codes are generated during setup, shown once, and each code can be used once. Sensitive account actions are also restricted by the platform’s existing role and permission controls.
Practice users need to log in to view their dashboard, client records and uploaded files.
Clients use private token links to respond without a full user account. Practice-user 2FA does not apply to those token links, so they must be treated as confidential.
Practice users should use strong passwords and keep mailbox access secure.
Storage and transmission
The public site is served over HTTPS. Uploaded files are stored in protected application storage rather than the public static website folder.
Only authorised practice users can download uploaded files from the dashboard.
Client uploads are limited to 20MB per file.
Allowed upload types are ordinary business document and image formats such as PDF, JPG, PNG, DOC, DOCX, XLS, XLSX, CSV and TXT.
Executable, script and other risky file types are blocked.
Operational access is limited to maintaining and supporting the service.
Subprocessors and third-party services
PracticeComply uses named third-party infrastructure and service providers for hosting, payment processing, email delivery and domain/email services where needed.
Application hosting: EU-hosted server infrastructure, currently using Hetzner-hosted infrastructure.
Stripe is used for subscription checkout and billing.
Namecheap Private Email and related email infrastructure may process email metadata and message content when requests are sent.
Companies House may be queried for public company data when a practice manually syncs a client by company number.
Operational security status
PracticeComply documents the security controls that are active in the current product and keeps operational responsibilities explicit.
Activity log: PracticeComply records key activity events such as client creation, request updates, request emails, reminders, client uploads, file downloads, upload reviews and task changes.
Rate limiting is applied to login, 2FA, password reset and client upload flows.
Admin 2FA reset actions are logged.
Upload retention: uploaded files remain available while the account and client record are active unless deleted or removed through support.
Backups: operational backups are used for service recovery and are not a long-term customer archive.
File limits: the portal is intended for ordinary business documents and notes; risky or unsupported files may be rejected or removed.
Deletion, export and support access
Practices need a clear exit path and a clear support boundary when client data is involved.
Owners and Admins can download self-service CSV exports for clients, requests, tasks, activity and uploads.
A complete account export or deletion request remains a support-assisted process, subject to limited legal, billing and security retention.
Operational CSV exports are not complete database backups and do not include secrets, tokens or 2FA materials.
Support access is limited to operating, debugging and supporting the service.
Some billing, legal, abuse-prevention or security records may need to be retained for a limited period.
Suspicious item review boundary
The suspicious invoice, email and link area is a manual review queue for the practice, not an automated safety guarantee.
PracticeComply does not guarantee that a message, link, invoice or file is safe or dangerous.
Practices remain responsible for their own checks, advice and client communication.
FAQ
Security and data questions
Can I export my data?
Yes. Owners and Admins can download self-service CSV exports for clients, requests, tasks, activity and uploads. These operational exports are not a complete database backup and do not include secrets, tokens or 2FA materials.
Should clients upload passports or driving licences?
Only if the practice has specifically requested them and confirmed that this workflow is appropriate for that purpose.
Is there an audit log?
Yes. PracticeComply records key client, request, upload, reminder and task actions as activity events so the practice can see what happened and when.
Does PracticeComply automatically detect scams?
No. PracticeComply provides a manual review queue so a practice can record and review suspicious invoices, emails or links. It does not guarantee that an item is safe or dangerous.
Can a practice delete clients and files?
Practices can manage client records and uploaded files through the product or request deletion through support. Some operational or legal records may need limited retention.
Is two-factor authentication available?
Yes. Practice users can enable TOTP two-factor authentication. Recovery codes are displayed once, are not stored in plain text, and each code can be used once.
Have a question?
Ask support before adding client data
Email us if you need to clarify product boundaries, export or deletion before starting.