Your data, and how we look after it
Intertax Group · Last updated July 2026 · Applies to the Intertax CRM software.
Handling your tax affairs means we hold some of your most sensitive information — your income, your identifiers, your correspondence with HMRC. We treat that as a responsibility, not just a legal box to tick. This policy sets out, in plain terms, exactly what we collect, why, who we share it with, and how we keep it safe. If anything here is unclear, ask us — we would rather explain than leave you guessing.
The short version
- We only collect what we need to act as your accountant and tax agent.
- We never sell your data, or use it for anything other than serving you.
- HMRC data is accessed only with your authorisation, and the keys to it are encrypted.
- Everything is encrypted in transit and at rest, and seen only by staff who need it.
- You can ask to see, correct, or delete your data at any time.
01Data controller
Intertax Group (“we”, “us”, “our”) operates the Intertax CRM (“the software”). We are registered with the UK Information Commissioner’s Office as a data controller and process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
02What data we process
The software processes:
- Client tax records: names, contact details, tax identification numbers (UTRs, VRNs, PAYE references), business and personal income details, filing history.
- Staff records: employee names, email addresses, roles, and access logs.
- HMRC integration data: HMRC authorisation tokens (encrypted), VAT and Self-Assessment liabilities and obligation dates, and Companies House company information.
- Communications: client emails, WhatsApp messages, timesheets, and task records.
03Lawful basis
We process personal data on the lawful basis of contract (providing tax accounting services under engagement with our clients) and legal obligation (tax filing, reporting to HMRC, and statutory compliance). Some processing is based on legitimate interests (business administration, security, and service improvement), in a way that never overrides your rights.
04How we use HMRC data
Where you have authorised Intertax to act as your agent, our software connects to HMRC through HMRC’s official Making Tax Digital APIs, using secure OAuth 2.0 authorisation. We access only what we need to manage your tax affairs — such as your VAT and Self-Assessment balances and due dates. The access keys HMRC issues are stored encrypted, are never shared, and are used solely to serve you. We do not sell, profile, or repurpose HMRC-derived data, and you can withdraw your authorisation with HMRC at any time.
05Data retention
- Active client records: retained for the duration of the engagement plus 6 years (UK tax statute of limitations).
- Former client records: retained for 6 years from the end of engagement, then securely deleted.
- HMRC tokens: retained until revoked, or up to 18 months (the OAuth refresh cycle), then deleted.
- Staff records: retained while employed, plus 6 years for statutory compliance.
06Third parties (data processors)
We share data with:
- HMRC: via OAuth 2.0 integration, to fulfil your tax obligations.
- Companies House: to retrieve company information via their public API.
- Cloud infrastructure (Vercel, Supabase): our hosting providers, bound by data-processing agreements, operating in the UK/EU with encryption at rest and in transit (TLS 1.2+).
We do not sell or share personal data with third parties for marketing or unrelated purposes.
07Your rights (UK GDPR)
You have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate data.
- Erasure: request deletion, subject to legal and tax retention obligations.
- Portability: receive your data in a portable format.
- Objection: object to processing based on legitimate interests.
To exercise these rights, contact us at info@liongm.com. We will respond within one month.
08Security
We implement organisational and technical measures to protect personal data:
- Encrypted storage (AES-256) and transmission (TLS 1.2+).
- HMRC access and refresh tokens encrypted before storage.
- Role-based access control and authenticated sign-in.
- Fraud-prevention header validation as required by HMRC.
- Access logging and audit trails.
- Breach reporting within 72 hours to the ICO and affected parties as required by UK GDPR.
09Data breach & complaints
If we discover a personal-data breach, we will notify the ICO — and HMRC where HMRC data is affected — within 72 hours of becoming aware of it, and affected individuals where required.
If you believe we have mishandled your personal data, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113 — though we hope you will give us the chance to put things right first.
10International transfers
Data is processed and stored primarily in the UK/EU. Any international transfers, where necessary, are protected by Standard Contractual Clauses or UK adequacy determinations approved under UK data-protection law.
11Contact us
For privacy questions, concerns, or to exercise your rights:
Intertax Group
Email: info@liongm.com
Web: www.intertaxgroup.com
© 2026 Intertax Group. We may update this policy from time to time; the date above shows the latest version. Your continued use of the software after changes constitutes acceptance.