Draft for legal review

Privacy Policy

How AtlastFMS expects to collect, use, protect and retain personal data when providing its financial record-keeping and Making Tax Digital workflow.

Not yet final: this page is an implementation draft, is not legal advice, and must be approved before production publication. Items labelled “Legal review” or “Operator review” remain unresolved.

Draft date: 10 July 2026

1. Who is responsible for your data

AtlastFMS is currently operated by Himmat Atwal. For account administration, product operation, support, security and direct customer communications, Himmat Atwal is the intended data controller.

Contact: contact@atlastfms.com or 07510 495955.

Legal review: Confirm the operator's full legal status, service address, ICO registration details, and when AtlastFMS acts as controller or processor for customer business records before publication.

2. Scope

This policy applies to the AtlastFMS website, account, dashboard, support and connected services. It covers personal data about account holders, authorised business users, contacts appearing in business records and people who contact AtlastFMS. It does not replace the privacy duties of a customer business for the records it controls.

3. Data we process

  • Account and contact data, including name, email, support details and authentication state.
  • Business profile, subscription, onboarding and service-preference data.
  • Accounting records, transactions, invoices, bills, documents, bank-import data and audit history.
  • VAT registration details, obligations, returns, reviewed figures, submission status and HMRC receipts or safe references.
  • HMRC OAuth authorisation metadata and encrypted access or refresh tokens.
  • Support messages, security events, service diagnostics and product-usage records.

Customer records may contain personal data about customers, suppliers, employees, advisers or other business contacts. The customer remains responsible for having a lawful basis to enter and use that information.

4. HMRC fraud-prevention information

When a user chooses to connect to or communicate with HMRC, AtlastFMS builds the fraud-prevention headers required by HMRC. Depending on the transaction, these may describe the client device, browser or user agent, public network address and port, timestamps, connection method, screen or window characteristics, and AtlastFMS vendor information. Required values are validated before an HMRC request is sent.

Secret values and raw headers are not intended to appear in browser results, customer-facing evidence or application logs. HMRC receives the required header information as an independent controller under its own privacy responsibilities.

5. Why we process data and lawful bases

  • To create and secure accounts and provide requested services — performance of a contract.
  • To maintain digital records and prepare user-reviewed HMRC-ready outcomes — performance of a contract and, where applicable, legal obligations.
  • To prevent fraud, investigate misuse, protect customers and improve reliability — legitimate interests.
  • To operate billing, support and essential service communications — performance of a contract and legitimate interests.
  • To send optional marketing or use non-essential cookies — consent where required.

Legal review: Confirm the controller/processor allocation and lawful basis for each processing activity, including any special-category or criminal-offence data that customers could upload.

6. HMRC connections and identifiers

HMRC access is initiated by the user through HMRC's OAuth authorisation service. AtlastFMS uses the resulting authority only for the functions the user selects and the scopes HMRC grants. VAT identifiers and return information are used to retrieve obligations, prepare or submit user-confirmed returns, and show safe outcomes.

OAuth tokens are stored using server-only authenticated encryption. Decrypted tokens are used only where needed for an authorised server request and are not returned to the browser. Disconnecting removes legacy token data and marks the encrypted grant revoked locally. HMRC may separately retain or control the user's authorisation.

7. Service providers and international processing

AtlastFMS uses suppliers for database, authentication and storage, application hosting, email delivery, payments, document or AI-assisted processing, and optional connected services. Supabase hosts the current primary database project in West Europe (London), eu-west-2.

Other providers, their support teams, logs or resilience systems may process data outside the UK. AtlastFMS therefore does not claim UK-only processing. Appropriate contractual and transfer safeguards must be confirmed for each relevant provider.

Legal review: Approve the complete named subprocessor list, purposes, locations, transfer mechanisms and notification process. Confirm the production application-hosting, email, payment, AI and monitoring providers.

8. Security

Current technical measures include authenticated access, user-scoped row-level security, server-only secrets, encrypted HMRC OAuth tokens, HTTPS in production, validation before HMRC transport, rate limiting, and append-only submission evidence. No service can guarantee absolute security, and controls are reviewed as the product changes.

9. Retention and account closure

The policy target is to retain VAT and supporting accounting records for at least six years, measured from the date or accounting period required by applicable VAT record-keeping rules. Longer periods may apply to particular schemes, disputes, investigations or legal holds.

OAuth state is short-lived and single-use. Access and refresh tokens are retained only while needed for an authorised connection and are revoked or removed when the connection is withdrawn, the grant expires, or the account is closed, subject to secure operational and backup procedures.

On account closure, AtlastFMS intends to provide a reasonable export opportunity and delete or anonymise data that no longer needs to be held. Statutory records, security evidence, disputes and backup copies may require different treatment.

Legal review: Confirm the exact six-year trigger, any ten-year scheme requirement, account-closure window, backup expiry, legal-hold process and which party is responsible for retaining customer VAT records.

10. Your rights

Depending on the circumstances, individuals may have rights to be informed, access their data, correct it, request erasure or restriction, object, receive portable data, and withdraw consent. Requests can be sent to contact@atlastfms.com. Identity and authority may need to be verified, and some rights are limited where retention is required by law or affects another controller's records.

11. Cookies and similar storage

AtlastFMS uses essential cookies or equivalent browser storage for authentication, security, session continuity and user preferences. Non-essential analytics or marketing technologies must not be enabled without an appropriate notice and consent mechanism where required.

Legal review: Complete a production cookie and browser-storage inventory, including retention and provider details, before publication.

12. AI-assisted processing

Some AtlastFMS features may use AI-assisted services to interpret user instructions, extract information from documents or suggest draft actions. AI suggestions do not own accounting or tax treatment and should not submit information to HMRC. Users must review and confirm material financial and tax outcomes before action. Deterministic product rules and confirmation controls remain responsible for those actions.

Legal review: Confirm the final AI provider list, data-use settings, retention, international transfers and whether any processing requires a data-protection impact assessment.

13. Questions and complaints

Contact contact@atlastfms.com first so the issue can be investigated. Individuals may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

14. Changes to this policy

Material changes will be dated and communicated through an appropriate product or account channel. Earlier versions should be retained where needed to show which terms applied at a particular time.