1. Who is responsible for your data
AtlastFMS is currently operated by Himmat Atwal. For account administration, product operation, support, security and direct customer communications, Himmat Atwal is the intended data controller.
Contact: contact@atlastfms.com or 07510 495955.
Legal review: Confirm the operator's full legal status, service address, ICO registration details, and when AtlastFMS acts as controller or processor for customer business records before publication.
2. Scope
This policy applies to the AtlastFMS website, account, dashboard, support and connected services. It covers personal data about account holders, authorised business users, contacts appearing in business records and people who contact AtlastFMS. It does not replace the privacy duties of a customer business for the records it controls.
3. Data we process
- Account and contact data, including name, email, support details and authentication state.
- Business profile, subscription, onboarding and service-preference data.
- Accounting records, transactions, invoices, bills, documents, bank-import data and audit history.
- VAT registration details, obligations, returns, reviewed figures, submission status and HMRC receipts or safe references.
- HMRC OAuth authorisation metadata and encrypted access or refresh tokens.
- Support messages, security events, service diagnostics and product-usage records.
Customer records may contain personal data about customers, suppliers, employees, advisers or other business contacts. The customer remains responsible for having a lawful basis to enter and use that information.
4. HMRC fraud-prevention information
When a user chooses to connect to or communicate with HMRC, AtlastFMS builds the fraud-prevention headers required by HMRC. Depending on the transaction, these may describe the client device, browser or user agent, public network address and port, timestamps, connection method, screen or window characteristics, and AtlastFMS vendor information. Required values are validated before an HMRC request is sent.
Secret values and raw headers are not intended to appear in browser results, customer-facing evidence or application logs. HMRC receives the required header information as an independent controller under its own privacy responsibilities.
5. Why we process data and lawful bases
- To create and secure accounts and provide requested services — performance of a contract.
- To maintain digital records and prepare user-reviewed HMRC-ready outcomes — performance of a contract and, where applicable, legal obligations.
- To prevent fraud, investigate misuse, protect customers and improve reliability — legitimate interests.
- To operate billing, support and essential service communications — performance of a contract and legitimate interests.
- To send optional marketing or use non-essential cookies — consent where required.
Legal review: Confirm the controller/processor allocation and lawful basis for each processing activity, including any special-category or criminal-offence data that customers could upload.
6. HMRC connections and identifiers
HMRC access is initiated by the user through HMRC's OAuth authorisation service. AtlastFMS uses the resulting authority only for the functions the user selects and the scopes HMRC grants. VAT identifiers and return information are used to retrieve obligations, prepare or submit user-confirmed returns, and show safe outcomes.
OAuth tokens are stored using server-only authenticated encryption. Decrypted tokens are used only where needed for an authorised server request and are not returned to the browser. Disconnecting removes legacy token data and marks the encrypted grant revoked locally. HMRC may separately retain or control the user's authorisation.
7. Service providers and international processing
AtlastFMS uses suppliers for database, authentication and storage, application hosting, email delivery, payments, document or AI-assisted processing, and optional connected services. Supabase hosts the current primary database project in West Europe (London), eu-west-2.
Other providers, their support teams, logs or resilience systems may process data outside the UK. AtlastFMS therefore does not claim UK-only processing. Appropriate contractual and transfer safeguards must be confirmed for each relevant provider.
Legal review: Approve the complete named subprocessor list, purposes, locations, transfer mechanisms and notification process. Confirm the production application-hosting, email, payment, AI and monitoring providers.
8. Security
Current technical measures include authenticated access, user-scoped row-level security, server-only secrets, encrypted HMRC OAuth tokens, HTTPS in production, validation before HMRC transport, rate limiting, and append-only submission evidence. No service can guarantee absolute security, and controls are reviewed as the product changes.
9. Retention and account closure
The policy target is to retain VAT and supporting accounting records for at least six years, measured from the date or accounting period required by applicable VAT record-keeping rules. Longer periods may apply to particular schemes, disputes, investigations or legal holds.
OAuth state is short-lived and single-use. Access and refresh tokens are retained only while needed for an authorised connection and are revoked or removed when the connection is withdrawn, the grant expires, or the account is closed, subject to secure operational and backup procedures.
On account closure, AtlastFMS intends to provide a reasonable export opportunity and delete or anonymise data that no longer needs to be held. Statutory records, security evidence, disputes and backup copies may require different treatment.
Legal review: Confirm the exact six-year trigger, any ten-year scheme requirement, account-closure window, backup expiry, legal-hold process and which party is responsible for retaining customer VAT records.
10. Your rights
Depending on the circumstances, individuals may have rights to be informed, access their data, correct it, request erasure or restriction, object, receive portable data, and withdraw consent. Requests can be sent to contact@atlastfms.com. Identity and authority may need to be verified, and some rights are limited where retention is required by law or affects another controller's records.
11. Cookies and similar storage
AtlastFMS uses essential cookies or equivalent browser storage for authentication, security, session continuity and user preferences. Non-essential analytics or marketing technologies must not be enabled without an appropriate notice and consent mechanism where required.
Legal review: Complete a production cookie and browser-storage inventory, including retention and provider details, before publication.
12. AI-assisted processing
Some AtlastFMS features may use AI-assisted services to interpret user instructions, extract information from documents or suggest draft actions. AI suggestions do not own accounting or tax treatment and should not submit information to HMRC. Users must review and confirm material financial and tax outcomes before action. Deterministic product rules and confirmation controls remain responsible for those actions.
Legal review: Confirm the final AI provider list, data-use settings, retention, international transfers and whether any processing requires a data-protection impact assessment.
13. Questions and complaints
Contact contact@atlastfms.com first so the issue can be investigated. Individuals may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
14. Changes to this policy
Material changes will be dated and communicated through an appropriate product or account channel. Earlier versions should be retained where needed to show which terms applied at a particular time.