Privacy policy

Version 1.0 · Last updated 26 August 2026

Draft. Placeholders in [SQUARE BRACKETS] must be completed and the whole document reviewed by a qualified data-protection adviser before publication — see placeholders to complete.

1. Who we are

One4All Accounts is a trading name of Oaks Media Limited, and this policy is given by Oaks Media Limited t/a One4All Accounts (“we”, “us”, “our”) — a company registered in England and Wales under company number 08674204, whose registered office is 4 King Street, Leicester, England, LE1 6RJ. Any contract you enter into is with Oaks Media Limited, not with One4All Accounts as a separate legal entity.

We are the data controller for the personal data described in this policy.

  • Contact for privacy matters: privacy@oaksmedia.co.uk
  • Data protection officer / responsible person: [NAME OR ROLE]
  • ICO registration number: [ICO REGISTRATION NUMBER]

This policy explains what personal data we collect when you use One4All Accounts at [PRODUCT URL], why we collect it, and what rights you have over it.

2. Scope

This policy covers the One4All Accounts web application, including its Making Tax Digital (MTD) features for Income Tax Self Assessment and VAT, its Companies House filing features, and its payroll features.

Where you use One4All Accounts as an accountant or agent acting for clients, you are the controller of your clients’ data and we act as your processor for that data. Our obligations in that role are set out in the data-processing terms in our terms and conditions.

3. Personal data we collect

3.1 Account and identity data

DataWhy we collect itLawful basis
Name, email address, password (hashed)Create and secure your accountContract
Company or practice name, roleGive you access to the right entitiesContract
Login timestamps, IP address, session tokensAuthenticate you, detect misuseLegitimate interests (security)

3.2 Tax and accounting data

To prepare and submit filings, we process data you enter or import, including:

  • Business and trading details, National Insurance number, Unique Taxpayer Reference (UTR), VAT registration number, Companies House number and authentication code
  • Ledger data: transactions, invoices, bank lines, journal entries, chart of accounts
  • Property and self-employment income and expenses
  • Payroll data for employees you pay, including names, addresses, NI numbers, dates of birth, pay and deductions

Lawful basis: performance of our contract with you, and compliance with a legal obligation where the data is required for a statutory filing. National Insurance numbers and payroll data are processed because they are necessary for the tax and social-security obligations we help you meet (UK GDPR Article 9(2)(b) where any special-category data arises).

3.3 HMRC fraud prevention data — please read

HMRC requires every piece of MTD software to send technical information about the device and connection used to make a submission. This is a legal condition of accessing HMRC’s APIs (section 3 of the Commissioners for Revenue and Customs Act 2005), and it is used by HMRC to detect fraudulent access to taxpayer records.

When you make an MTD submission through One4All Accounts, we collect from your browser and send to HMRC:

  • A device identifier — a random UUID we generate and store in your browser. It is not linked to any hardware identifier and does not identify you personally.
  • Your public IP address, and the port and timestamp of the connection
  • Your local (private) IP address as reported by your browser, where available
  • Screen width, height, colour depth and scaling factor
  • Browser window width and height
  • Your browser’s user-agent string, timezone and Do Not Track setting
  • The chain of IP addresses your request passed through to reach our servers
  • Your One4All Accounts user ID, and identifiers for our software and its version

We do not collect MAC addresses. We do not send a multi-factor authentication header because One4All Accounts authentication is single-factor, and we do not send licence identifiers because the product is not licensed per seat.

You cannot opt out of this collection and continue to use the MTD features — HMRC will reject submissions that do not carry these headers. If you do not wish this data to be sent, do not use One4All Accounts to file.

Lawful basis: compliance with a legal obligation, and our legitimate interest in providing software that meets HMRC’s terms of use.

3.4 Data we receive from HMRC and other third parties

When you connect One4All Accounts to HMRC, we receive and store data about you or your clients, including business details, filing obligations, submitted figures, tax calculations and liabilities. Where you connect a bank feed, we receive account and transaction data from your bank via the open banking provider you authorise.

3.5 Technical and usage data

We log application errors, request paths, response codes and timing. These logs can include your IP address and user ID. We use them to keep the service working and secure.

We do not use advertising cookies or third-party analytics trackers. The cookies we set are strictly necessary for authentication and session management.

4. How we use your data

We use personal data to:

  • Provide the service: keep your ledger, prepare filings, and submit them
  • Authenticate you and protect accounts against unauthorised access
  • Meet HMRC’s and Companies House’s conditions for using their systems
  • Maintain the audit trail we are required to keep for filings
  • Respond to your support requests
  • Notify you about service changes, outages and material updates to these terms

We do not sell personal data, and we do not use your tax or accounting data to train machine-learning models.

5. Who we share data with

RecipientWhat is sharedWhy
HM Revenue & CustomsFiling data, fraud prevention headersTo make the submissions you instruct
Companies HouseAccounts, confirmation statements, officer and company changesTo make the submissions you instruct
[HOSTING PROVIDER] ([HOSTING REGION])All application data, at restInfrastructure hosting
[EMAIL PROVIDER]Name, email addressTransactional email
[OPEN BANKING PROVIDER]Bank authorisation tokensBank feeds, where you enable them
Professional advisers, auditorsAs neededLegal and regulatory compliance

We will disclose data where we are legally required to, for example in response to a valid court order or statutory information notice.

International transfers. Your data is stored in [DATA LOCATION — e.g. the United Kingdom]. Where a supplier processes data outside the UK, we rely on the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for details.

6. How long we keep data

DataRetention
Tax and accounting records, filing submissions and their audit trail6 years from the end of the tax year they relate to, reflecting HMRC record-keeping requirements
Payroll records6 years from the end of the tax year
Fraud prevention header dataFor the life of the related submission record
Account and login dataFor the life of the account, then 12 months
Application and security logs[LOG RETENTION — e.g. 90 days]
Backups[BACKUP RETENTION — e.g. 35 days] on a rolling cycle

When you close your account we delete or anonymise your data on this schedule. We cannot delete data we are required to retain for a statutory filing before its retention period expires.

7. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify data that is inaccurate or incomplete
  • Erase data, where we have no continuing legal basis to keep it
  • Restrict or object to processing in certain circumstances
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent, where we rely on consent

To exercise any of these, email privacy@oaksmedia.co.uk. We respond within one month. We may ask you to verify your identity first.

If you are a client of an accountant who uses One4All Accounts, please contact your accountant first — they control your data and we act on their instructions.

Complaints. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to address your concern first.

8. Security

We protect your data with: encryption in transit (TLS 1.2+) and at rest; hashed passwords; short-lived access tokens with refresh; role-based access control scoped to the entities you are assigned to; an immutable audit log of filing actions; and least-privilege access for our staff, granted only where needed for support and recorded.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you without undue delay where the risk is high.

9. Automated decision-making

One4All Accounts performs automated tax calculations, and HMRC returns automated calculations to it. These are computational, not decisions producing legal effects about you within the meaning of Article 22 of the UK GDPR. You remain responsible for reviewing and approving every figure before submission.

10. Children

One4All Accounts is business software and is not directed at children. We do not knowingly collect data from anyone under 18 except where they appear as an employee in payroll data you enter.

11. Changes to this policy

We may update this policy. We will post the new version at [PRIVACY POLICY URL] and update the date above. For material changes we will notify you by email or in the application at least 30 days before they take effect.

12. Contact

Oaks Media Limited t/a One4All Accounts
4 King Street, Leicester, England, LE1 6RJ
privacy@oaksmedia.co.uk

Placeholders to complete

Entity is Oaks Media Limited, company number 08674204, registered office 4 King Street, Leicester, England, LE1 6RJ — taken from a web search of the Companies House register on 26 August 2026, not a direct read. Verify all three against the register before publishing; registered offices change, and a wrong one in a published legal document is a real problem.

[NAME OR ROLE] · [ICO REGISTRATION NUMBER] · [PRODUCT URL] · [PRIVACY POLICY URL] · [HOSTING PROVIDER] · [HOSTING REGION] · [EMAIL PROVIDER] · [OPEN BANKING PROVIDER] · [DATA LOCATION] · [LOG RETENTION] · [BACKUP RETENTION]

Also confirm before publishing:

  1. Whether you are registered with the ICO — if you process personal data electronically as a UK business you almost certainly must be, and the fee applies.
  2. That section 3.3 matches what the software actually sends. It was written from the fraud-header code as at this date; re-check if that changes.
  3. That the retention periods match your actual backup and log configuration.
  4. That the product name here matches the Developer Hub application name and the name on the landing page.