Privacy Notice
LetFile is software that helps UK landlords meet their Making Tax Digital for Income Tax obligations. This notice explains what personal data we process, why, our lawful basis, where it is held, and your rights. It is written to meet UK GDPR and the Data Protection Act 2018.
1. What we collect
- Account data: your name and email address.
- Tax data you enter: property income and expenses, ownership shares, your National Insurance number and tax references. This is sensitive financial data and we treat it accordingly.
- HMRC authorisation: OAuth access and refresh tokens that let us file on your behalf. We never see or store your Government Gateway password.
- Fraud-prevention data: device identifiers, IP address, browser and connection metadata. HMRC legally requires us to send this with each submission (the fraud-prevention headers, SI 2019/360).
- Usage data: basic server logs for security and reliability.
2. Why, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Provide the filing service (store records, submit to HMRC) | Performance of our contract with you |
| Act on your behalf with HMRC | Your authorisation via OAuth |
| Send fraud-prevention header data to HMRC | Legal obligation (SI 2019/360) |
| Deadline reminders and service emails | Contract and legitimate interests |
| Security, fraud prevention, troubleshooting | Legitimate interests |
3. Where your data is processed (server locations)
LetFile runs on Google Cloud Platform. We use sub-processors under data processing agreements; we do not sell your data.
| Provider | Role | Location |
|---|---|---|
| Google Cloud (Cloud Run) | Application compute | europe-west1 (Belgium, EU) |
| Google Cloud (Firestore) | Database (your records, tokens) | europe-west2 (London, UK) |
| Resend | Transactional / reminder email | EU/US (email delivery) |
| Cloudflare | DNS and network | Global edge |
| HMRC | Recipient of your submissions | UK |
4. International transfers
Your records and tokens are stored in the UK (London) and the application runs in the EU (Belgium); the UK recognises the EU as adequate. Where any sub-processor transfers data outside the UK/EU, that transfer relies on an adequacy decision or appropriate safeguards (such as the UK IDTA or Standard Contractual Clauses).
5. Retention
- Tax records: kept while your account is active and for at least the statutory record-keeping period (broadly 5 years and 10 months after the relevant tax year) to support compliance, then deleted.
- OAuth tokens: kept until you withdraw authorisation or close your account, then deleted.
6. Security
We encrypt data in transit (TLS) and we encrypt the most sensitive fields (OAuth tokens and your National Insurance number) at rest with AES-256, on top of the platform's own at-rest encryption. Access is on a least-privilege basis and secrets are held in Google Secret Manager. No system is perfectly secure, but we take appropriate technical and organisational measures and will notify you and the ICO of any qualifying breach within 72 hours.
7. Your rights
You can access, correct, export, delete or restrict your data, object to processing, and withdraw consent (which stops future filings). Inside LetFile you can export an owner's data and delete it directly; you can also disconnect an owner from HMRC at any time. To exercise any right, contact privacy@letfile.co.uk. You can complain to the ICO.
8. Automated decisions
We do not make solely automated decisions with legal or similarly significant effects. Tax estimates are indicative; you review and confirm every submission.
LetFile is software, not tax advice, and is not affiliated with HMRC. You remain responsible for your own return. See our Terms of Service.