Privacy policy
Version 1.0 · Last updated 26 August 2026
Draft. Placeholders in [SQUARE BRACKETS] must be completed and the whole document reviewed by a qualified data-protection adviser before publication — see placeholders to complete.
1. Who we are
One4All Accounts is a trading name of Oaks Media Limited, and this policy is given by Oaks Media Limited t/a One4All Accounts (“we”, “us”, “our”) — a company registered in England and Wales under company number 08674204, whose registered office is 4 King Street, Leicester, England, LE1 6RJ. Any contract you enter into is with Oaks Media Limited, not with One4All Accounts as a separate legal entity.
We are the data controller for the personal data described in this policy.
- Contact for privacy matters: privacy@oaksmedia.co.uk
- Data protection officer / responsible person: [NAME OR ROLE]
- ICO registration number: [ICO REGISTRATION NUMBER]
This policy explains what personal data we collect when you use One4All Accounts at [PRODUCT URL], why we collect it, and what rights you have over it.
2. Scope
This policy covers the One4All Accounts web application, including its Making Tax Digital (MTD) features for Income Tax Self Assessment and VAT, its Companies House filing features, and its payroll features.
Where you use One4All Accounts as an accountant or agent acting for clients, you are the controller of your clients’ data and we act as your processor for that data. Our obligations in that role are set out in the data-processing terms in our terms and conditions.
3. Personal data we collect
3.1 Account and identity data
| Data | Why we collect it | Lawful basis |
|---|---|---|
| Name, email address, password (hashed) | Create and secure your account | Contract |
| Company or practice name, role | Give you access to the right entities | Contract |
| Login timestamps, IP address, session tokens | Authenticate you, detect misuse | Legitimate interests (security) |
3.2 Tax and accounting data
To prepare and submit filings, we process data you enter or import, including:
- Business and trading details, National Insurance number, Unique Taxpayer Reference (UTR), VAT registration number, Companies House number and authentication code
- Ledger data: transactions, invoices, bank lines, journal entries, chart of accounts
- Property and self-employment income and expenses
- Payroll data for employees you pay, including names, addresses, NI numbers, dates of birth, pay and deductions
Lawful basis: performance of our contract with you, and compliance with a legal obligation where the data is required for a statutory filing. National Insurance numbers and payroll data are processed because they are necessary for the tax and social-security obligations we help you meet (UK GDPR Article 9(2)(b) where any special-category data arises).
3.3 HMRC fraud prevention data — please read
HMRC requires every piece of MTD software to send technical information about the device and connection used to make a submission. This is a legal condition of accessing HMRC’s APIs (section 3 of the Commissioners for Revenue and Customs Act 2005), and it is used by HMRC to detect fraudulent access to taxpayer records.
When you make an MTD submission through One4All Accounts, we collect from your browser and send to HMRC:
- A device identifier — a random UUID we generate and store in your browser. It is not linked to any hardware identifier and does not identify you personally.
- Your public IP address, and the port and timestamp of the connection
- Your local (private) IP address as reported by your browser, where available
- Screen width, height, colour depth and scaling factor
- Browser window width and height
- Your browser’s user-agent string, timezone and Do Not Track setting
- The chain of IP addresses your request passed through to reach our servers
- Your One4All Accounts user ID, and identifiers for our software and its version
We do not collect MAC addresses. We do not send a multi-factor authentication header because One4All Accounts authentication is single-factor, and we do not send licence identifiers because the product is not licensed per seat.
You cannot opt out of this collection and continue to use the MTD features — HMRC will reject submissions that do not carry these headers. If you do not wish this data to be sent, do not use One4All Accounts to file.
Lawful basis: compliance with a legal obligation, and our legitimate interest in providing software that meets HMRC’s terms of use.
3.4 Data we receive from HMRC and other third parties
When you connect One4All Accounts to HMRC, we receive and store data about you or your clients, including business details, filing obligations, submitted figures, tax calculations and liabilities. Where you connect a bank feed, we receive account and transaction data from your bank via the open banking provider you authorise.
3.5 Technical and usage data
We log application errors, request paths, response codes and timing. These logs can include your IP address and user ID. We use them to keep the service working and secure.
We do not use advertising cookies or third-party analytics trackers. The cookies we set are strictly necessary for authentication and session management.
4. How we use your data
We use personal data to:
- Provide the service: keep your ledger, prepare filings, and submit them
- Authenticate you and protect accounts against unauthorised access
- Meet HMRC’s and Companies House’s conditions for using their systems
- Maintain the audit trail we are required to keep for filings
- Respond to your support requests
- Notify you about service changes, outages and material updates to these terms
We do not sell personal data, and we do not use your tax or accounting data to train machine-learning models.
5. Who we share data with
| Recipient | What is shared | Why |
|---|---|---|
| HM Revenue & Customs | Filing data, fraud prevention headers | To make the submissions you instruct |
| Companies House | Accounts, confirmation statements, officer and company changes | To make the submissions you instruct |
| [HOSTING PROVIDER] ([HOSTING REGION]) | All application data, at rest | Infrastructure hosting |
| [EMAIL PROVIDER] | Name, email address | Transactional email |
| [OPEN BANKING PROVIDER] | Bank authorisation tokens | Bank feeds, where you enable them |
| Professional advisers, auditors | As needed | Legal and regulatory compliance |
We will disclose data where we are legally required to, for example in response to a valid court order or statutory information notice.
International transfers. Your data is stored in [DATA LOCATION — e.g. the United Kingdom]. Where a supplier processes data outside the UK, we rely on the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for details.
6. How long we keep data
| Data | Retention |
|---|---|
| Tax and accounting records, filing submissions and their audit trail | 6 years from the end of the tax year they relate to, reflecting HMRC record-keeping requirements |
| Payroll records | 6 years from the end of the tax year |
| Fraud prevention header data | For the life of the related submission record |
| Account and login data | For the life of the account, then 12 months |
| Application and security logs | [LOG RETENTION — e.g. 90 days] |
| Backups | [BACKUP RETENTION — e.g. 35 days] on a rolling cycle |
When you close your account we delete or anonymise your data on this schedule. We cannot delete data we are required to retain for a statutory filing before its retention period expires.
7. Your rights
Under the UK GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase data, where we have no continuing legal basis to keep it
- Restrict or object to processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent, where we rely on consent
To exercise any of these, email privacy@oaksmedia.co.uk. We respond within one month. We may ask you to verify your identity first.
If you are a client of an accountant who uses One4All Accounts, please contact your accountant first — they control your data and we act on their instructions.
Complaints. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to address your concern first.
8. Security
We protect your data with: encryption in transit (TLS 1.2+) and at rest; hashed passwords; short-lived access tokens with refresh; role-based access control scoped to the entities you are assigned to; an immutable audit log of filing actions; and least-privilege access for our staff, granted only where needed for support and recorded.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you without undue delay where the risk is high.
9. Automated decision-making
One4All Accounts performs automated tax calculations, and HMRC returns automated calculations to it. These are computational, not decisions producing legal effects about you within the meaning of Article 22 of the UK GDPR. You remain responsible for reviewing and approving every figure before submission.
10. Children
One4All Accounts is business software and is not directed at children. We do not knowingly collect data from anyone under 18 except where they appear as an employee in payroll data you enter.
11. Changes to this policy
We may update this policy. We will post the new version at [PRIVACY POLICY URL] and update the date above. For material changes we will notify you by email or in the application at least 30 days before they take effect.
12. Contact
Oaks Media Limited t/a One4All Accounts
4 King Street, Leicester, England, LE1 6RJ
privacy@oaksmedia.co.uk
Placeholders to complete
Entity is Oaks Media Limited, company number 08674204, registered office 4 King Street, Leicester, England, LE1 6RJ — taken from a web search of the Companies House register on 26 August 2026, not a direct read. Verify all three against the register before publishing; registered offices change, and a wrong one in a published legal document is a real problem.
[NAME OR ROLE] · [ICO REGISTRATION NUMBER] · [PRODUCT URL] · [PRIVACY POLICY URL] · [HOSTING PROVIDER] · [HOSTING REGION] · [EMAIL PROVIDER] · [OPEN BANKING PROVIDER] · [DATA LOCATION] · [LOG RETENTION] · [BACKUP RETENTION]
Also confirm before publishing:
- Whether you are registered with the ICO — if you process personal data electronically as a UK business you almost certainly must be, and the fee applies.
- That section 3.3 matches what the software actually sends. It was written from the fraud-header code as at this date; re-check if that changes.
- That the retention periods match your actual backup and log configuration.
- That the product name here matches the Developer Hub application name and the name on the landing page.