Privacy Policy

How AtlastFMS handles personal data across the public website, accounts, financial workflows, support and connected services.

Version 2026-08-10.1 · Effective date: 10 August 2026

1. Who we are and when this policy applies

ATLASTFMS LTD (company number 17358373) is a private limited company registered in England and Wales. Its registered office is 66 Paul Street, London, England, United Kingdom, EC2A 4NA. “AtlastFMS”, “Atlast”, “we” and “us” mean ATLASTFMS LTD.

We are the controller for account, billing, website, security, support and product administration data. For personal data inside financial records that a business customer uploads or creates, the customer normally decides why that data is used and is the controller; we act as its processor to provide the service. We may separately act as controller where we must use limited data for security, billing, legal claims or our own legal obligations. See our Data Processing Addendum.

Privacy questions and rights requests: contact@atlastfms.com. We do not publish or require a director's personal contact details for this purpose.

2. Personal data we handle

  • Account and identity: name, business email, authentication identifiers and account status.
  • Business and financial records: business profiles, contacts, invoices, bills, transactions, bank data, uploaded documents, classifications, adjustments and audit history.
  • Tax workflow: VAT or income-tax identifiers, obligations, return data, user confirmations, HMRC receipts and safe submission references.
  • Connected-service data: HMRC, Open Banking, Google and Microsoft authorisation metadata, encrypted tokens, provider account identifiers, selected sender identity and connection status.
  • Billing and communications: plan and subscription status, payment-provider identifiers, invoices, delivery events, support messages and essential service communications.
  • Device, security and diagnostics: IP address, user agent, timestamps, request and security events, errors, and the device/network attributes described in section 6.
  • AI feature inputs and outputs: instructions, extracted document content, relevant business context and generated suggestions when an AI-assisted feature is used.

Financial records may contain data about a customer's clients, suppliers, workers, advisers or other contacts. Customers must have authority and a lawful basis to place that data in AtlastFMS. Please do not upload special-category or criminal-offence data unless it is necessary, lawful and appropriate for the selected workflow.

3. Where data comes from

We receive data directly from users; from their business records and devices; from authorised team members; and, when a user connects them, from HMRC, TrueLayer, participating banks, Google and Microsoft. Stripe supplies subscription and payment status, Resend supplies email delivery events, and service providers supply operational and security events. Providing account and core business data is contractual: without it, the relevant feature cannot operate. Optional connections and AI-assisted features can be left unused.

4. Purposes and lawful bases

PurposeUsual basis when we are controller
Create accounts, provide features, support users and manage subscriptionsContract
Secure the service, prevent fraud, diagnose faults and defend claimsLegitimate interests in operating a secure and reliable service; legal obligation where applicable
Maintain accounting evidence, billing records and required compliance recordsContract and legal obligation
Send essential account, invoice and service communicationsContract and legitimate interests
Optional direct marketing or non-essential device storage, if introducedConsent where required; neither is currently enabled on the public site

Where we are a processor, the customer's documented instructions—not our own independent purpose—govern the processing. Rights can differ by lawful basis.

5. Who receives data

We disclose only what is needed to service providers supporting AtlastFMS, including: Supabase for database, authentication and storage; Vercel for application hosting; OpenAI for selected AI-assisted processing; Resend for email delivery; and Stripe for subscription billing. TrueLayer processes data when a user connects a bank. Google or Microsoft receives the exact email, recipients and attachments the user reviews when the user chooses a connected Gmail or Microsoft 365/Outlook sender.

HMRC, banks and payment networks may act as independent controllers under their own notices. We may also disclose data to professional advisers, insurers, regulators, courts or law-enforcement bodies where necessary and lawful, or as part of a corporate transaction subject to suitable confidentiality and data-protection safeguards. We do not sell personal data.

6. HMRC connection and fraud-prevention data

HMRC access begins only when a user uses HMRC's authorisation flow. AtlastFMS uses the resulting authority within the scopes HMRC grants to retrieve information, prepare user-reviewed outcomes and, only where the live feature is authorised and the user confirms, transmit a submission. AtlastFMS is not HMRC and sandbox access is not HMRC production approval.

HMRC requires software to send fraud-prevention headers for relevant API requests. These can include device, browser, public network address and port, timestamps, connection method, screen or window attributes, and software-vendor data. Required values are validated server-side. OAuth tokens are encrypted at rest and are not returned to the browser. Disconnecting revokes the local grant and removes legacy token data; HMRC may separately retain or control its authorisation records.

7. Open Banking

If a user chooses to connect a bank through TrueLayer, the user is redirected to the provider or bank to authorise access. AtlastFMS can then retrieve authorised account, balance and transaction data. We do not ask users to give us their bank login password. A user can disconnect the integration, but accounting records already imported can remain until deleted or retained under the applicable account and legal rules.

8. AI-assisted features and human control

Selected document extraction and language-understanding features send the minimum relevant input and context to OpenAI. Outputs are suggestions or drafts. Deterministic financial rules, validation and explicit user confirmation remain responsible for material accounting and tax actions. AtlastFMS does not use AI to make solely automated decisions about individuals that produce legal or similarly significant effects, and AI output does not independently submit information to HMRC.

9. UK hosting and international transfers

The primary Supabase database project is configured in the London (eu-west-2) region. This is not a claim that all processing stays in the UK: Vercel, OpenAI, Stripe, Resend, TrueLayer, Google, Microsoft and their support or resilience systems may process data in other countries. Where UK restricted transfers occur, we require an applicable UK adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer risk assessment where required. Contact us to request relevant safeguard information.

10. Retention, export and deletion

  • HMRC, Google and Microsoft OAuth state is short-lived and single-use; connection tokens remain only while the authorisation is needed, are encrypted at rest, and are removed locally on disconnect. Google revocation is also requested remotely where available.
  • Financial and tax records are kept for the customer's account term and may need to be preserved for at least six years; some VAT schemes require ten years. Customers remain responsible for their statutory records.
  • Billing, contract-acceptance, security and dispute records are kept for the period reasonably needed for accounting, fraud prevention, legal claims and compliance.
  • Session storage normally clears when the browser session ends. Local preferences remain until the user clears them or the application removes them.

Authenticated exports are available for significant business and audit data. Account closure and deletion are currently handled through contact@atlastfms.com; there is no self-serve whole-account deletion control. We will delete or return processor data after closure unless law requires storage, and remove controller data when no longer necessary. Deletion from encrypted backups follows the backup lifecycle rather than occurring instantly, and restored data remains subject to the deletion instruction.

11. Security

Measures evidenced in the application include authenticated access, tenant-scoped row level security, server-only secrets, encrypted HMRC tokens, production HTTPS, rate-limiting, validation before sensitive transport, and append-only submission evidence. We restrict access by role and purpose. No online service can guarantee absolute security. Report a concern to contact@atlastfms.com without including passwords or access credentials.

12. Your rights

Depending on the processing and lawful basis, individuals may ask for access, correction, erasure, restriction, objection or portability, and may withdraw consent without affecting earlier lawful processing. You have the right to object to processing based on legitimate interests and to direct marketing. Send a request to contact@atlastfms.com. We may verify identity and authority. If the data sits in a customer's business records, contact that customer first where practical; we will assist the controller as required.

You can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

13. Cookies and browser storage

The public site currently uses no analytics or advertising trackers. Supabase sets strictly necessary authentication cookies when a user signs in. Authenticated product features also use local or session storage for interface preferences, workflow drafts, device continuity required for HMRC fraud-prevention data, and temporary progress. These technologies do not remove the customer's financial records from server storage. See the Cookie Notice for the inventory and controls.

14. Children

AtlastFMS is a business service for people aged 18 or over and is not directed to children. Customers should not place children's personal data in the service unless it is necessary and lawful for their business records.

15. Changes and contact

We will version and date material changes and use an appropriate account or service channel to give notice. Earlier versions will be retained where needed to show the terms that applied. Contact contact@atlastfms.com or write to ATLASTFMS LTD, 66 Paul Street, London, England, United Kingdom, EC2A 4NA.