← Back

Privacy Policy

Last updated: 23 September 2026

1. Who We Are

Qwikr ("we", "us", "our") is a cloud-based accounting platform operated in the United Kingdom. We are registered with the Information Commissioner's Office (ICO).

We act in two capacities: we are the data controller for your account, billing, and usage data; and we are a data processor for the financial and taxpayer records you (or your accountancy practice) store in the Service, which we process only on your instructions and on your behalf.

2. What Data We Collect

We collect the following categories of personal data:

3. How We Use Your Data

We use your personal data to:

3a. HMRC Connection & Tokens

When you connect a business or client to HMRC, you authorise Qwikr through your Government Gateway account using HMRC's OAuth process. We never see or store your Government Gateway password. HMRC issues us scoped access and refresh tokens (limited to the tax services you authorised, e.g. VAT or Self Assessment), which we store encrypted at rest. We use these tokens only when you or your authorised users initiate retrievals or submissions. You can revoke our access at any time — by disconnecting within the Service or via your Government Gateway account at HMRC — after which the stored tokens cease to function and are deleted.

4. Legal Basis for Processing

Under UK GDPR, we process your data on the following bases:

5. Data Sharing

We do not sell your personal data. We share data with:

6. Data Retention

Financial and tax records are retained for as long as your account is active, plus 7 years after closure, to comply with UK financial record-keeping requirements. Records you delete in the Service are permanently removed after one year — seven years for financial records — unless a record that must still be kept refers to them, in which case they are kept for as long as that record is. When someone asks for their personal data to be erased, it is erased straight away except for what their retained financial records must show, which is erased when those records reach the end of their retention period. Other account data is not yet deleted automatically when an account closes: email privacy@qwikr.tax and we will delete it, subject to the same retention rules. HMRC access and refresh tokens are deleted immediately when you disconnect a client from HMRC or close your account.

7. Your Rights

Under UK GDPR you have the right to:

To exercise these rights, email privacy@qwikr.tax. We will respond within 30 days.

8. Cookies

We use strictly necessary session cookies to keep you logged in, and analytics cookies to understand how the Service is used. You can disable analytics cookies at any time via your browser settings.

9. Security

We use TLS encryption for all data in transit, AES-256 encryption for data at rest, and enforce role-based access controls. We conduct regular security reviews and penetration testing.

Breach notification: in the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and will inform affected users without undue delay, in accordance with UK GDPR Articles 33–34.

10. International Transfers

Your data is stored in UK/EEA data centres. Where we engage processors outside the UK/EEA, we ensure appropriate safeguards are in place under UK GDPR Articles 46-47.

11. Changes to This Policy

We may update this policy periodically. We will notify you by email of any material changes at least 30 days before they take effect.

12. Contact & Complaints

For privacy queries: privacy@qwikr.tax.
If you are unsatisfied with our response, you have the right to complain to the ICO at ico.org.uk.