Privacy Notice
Last updated: May 2026
Product summary: we use company numbers, public Companies House data, and optional settings you enter. No accounting software, HMRC agent portal login, client bank data, or client financial records are needed for monitoring.
1. Who we are
PenaltyProof is operated by Chavannes Ltd (Company No. 17198260), a private limited company registered in England and Wales. We are the data controller for personal data processed through this service.
We are registered with the Information Commissioner's Office (ICO) under registration reference ZC142025.
Contact: privacy@penaltyproof.co.uk
2. What data we collect
- Email address — provided when you sign up, used to send filing alerts.
- UK company numbers — submitted by you so we can monitor your clients' Companies House filings.
- Stripe customer ID — generated when you subscribe to a paid plan, used to manage your subscription.
- Referral code — if you sign up via a referral link, we record which referral code was used to attribute the referral credit to the referring user. This is stored as a short alphanumeric code and contains no personal data about you.
- Charity number and charity name — if you choose to monitor charities, we store the charity number and charity name you add (public registry data fetched from the Charity Commission).
- Pension staging date — if you add pension staging dates, we store the staging date you provide for auto-enrolment re-enrolment tracking (employer data, not personal data).
- IP address and browser type — collected in our security audit log as a peppered HMAC hash (not stored in recoverable form). Used to detect and investigate suspicious account activity. Retained for 365 days and then deleted automatically.
- Secondary alert recipient email address — Pro plan users may optionally add a second email address to receive all filing alerts. This address is stored and used solely to deliver those alerts; it is not used for marketing and is deleted when you remove it or delete your account.
- Client contact email addresses — Pro plan users may optionally add a client's email address per monitored company to receive direct client nudge emails. You (the accountant) are responsible for having the client's consent to share their email address with us and for providing them with appropriate notice under Article 14 UK GDPR.
- Firm name, reply-to address, and firm address — Pro plan users may optionally add firm branding details for white-label email customisation. These are stored only for that purpose and deleted when you delete your account.
- ECCTA readiness metadata — if you use the ECCTA readiness workflow, we store role labels, role resource hashes, readiness status, target date, source URL, evidence-requested timestamp, last-reviewed timestamp, reviewer id, and optional internal notes you enter. Internal notes are workflow notes only. PenaltyProof does not store personal codes, identity documents, GOV.UK One Login state, ACSP evidence packs, filing credentials, authentication codes, or official Companies House verification status.
- Team workspace data — if you use Practice workspace features, we store workspace memberships, membership roles, linked account ids, invited email addresses, invited roles, inviter ids, invitation token hashes, expiry timestamps, accepted timestamps, revoked timestamps, and team lifecycle audit events. Invitation links are not stored in raw form; pending invitation token hashes are cleared when an invite is accepted, revoked, or superseded.
We do not collect financial data, tax records, or any information about your clients beyond their public Companies House company number, charity number, or pension staging date as described above.
3. Why we collect it (lawful basis)
- Contract performance (Article 6(1)(b) UK GDPR) — we process your email address, company numbers, and Stripe customer ID to deliver and bill for the monitoring and alert service you signed up for.
- Legitimate interest (Article 6(1)(f) UK GDPR) — we apply basic email normalisation to detect duplicate signups and prevent abuse, and we store referral codes to attribute referral credits. This processing is necessary for the security and integrity of the service and does not override your rights.
- Consent / soft opt-in (Regulation 22 PECR) — for marketing emails (filing tips, product updates, occasional promotional content) we rely on your explicit consent if you signed up to the Free plan, or on the PECR soft opt-in if you are a paying customer. You can withdraw consent or opt out at any time using the unsubscribe link in every marketing email; this does not affect the transactional emails described below.
3a. The two kinds of email you may receive
We split our emails into two categories so you always know what you can opt out of without losing the service you signed up for:
- Service / transactional emails — filing deadline alerts (overdue, due soon, advance warnings), weekly digests of your watchlist, email-verification links, password / magic-link sign-in, payment receipts, dunning notices for failed payments, trial-ending reminders, and account-deletion confirmations. These are part of the service you signed up for (Article 6(1)(b)) and continue regardless of your marketing preference.
- Marketing emails — filing tips, end-of-quarter summaries, new feature announcements, occasional promotional or upgrade-related messages, and onboarding tips. You can opt out at any point with the one-click List-Unsubscribe header or the link in every marketing email, and we will stop these immediately without affecting your service emails.
4. What we do with your data
We use your email address and company numbers to:
- Query the Companies House public API once daily (around 7am) for each company you monitor.
- Send you an email alert when a filing deadline is overdue or approaching, depending on your plan.
- Monitor PSC and officer changes using hash-based comparison (no personal data from those lists is stored — only a hash of the public record is retained to detect changes).
- Poll the Charity Commission API daily for annual return due dates, if you have charity monitoring enabled.
- Calculate and send CIS monthly return reminders on a calendar basis (standard 19th of the month), if CIS monitoring is enabled.
- Calculate and send pension re-enrolment alerts based on the staging date you provide (staging date + 3 years).
We do not sell, rent, or share your data with any third party for marketing purposes.
5. Third-party processors
We use the following sub-processors to deliver the service. All transfers outside the UK are covered by Standard Contractual Clauses (SCCs) or an equivalent UK transfer mechanism.
| Processor | Purpose | Country | Safeguard |
|---|---|---|---|
| Resend | Transactional email delivery | USA | SCCs |
| Stripe | Payment processing and subscription management | USA | SCCs |
| Railway | Application hosting and database | USA | SCCs |
| Cloudflare Turnstile | Bot detection on the signup form. Receives the Turnstile challenge token for server-side verification. | USA | SCCs |
| Companies House API | Public company data (read-only) | UK | UK public data — no transfer |
| Charity Commission API | Fetching annual return due dates for monitored charities | United Kingdom | UK public data — no transfer. Data shared: charity number (public identifier) |
| Sentry | Error monitoring and crash reporting | USA | SCCs |
| Plausible Analytics | Privacy-respecting website analytics (cookieless, no cross-site tracking). Receives page URL, referrer, and anonymised browser/device signals on each page load. Does not set cookies on penaltyproof.co.uk. | EU (Germany / Luxembourg) | SCCs |
6. Data retention
- Account data (email address and company numbers on your watchlist): When you request account deletion, your account is deactivated immediately — your filing alerts stop, and you can no longer access the service. We retain your data for up to 90 days after deletion. During this window, you may restore your account by contacting us. After 90 days, all account data is permanently and irreversibly deleted from our systems. Lawful basis for 90-day retention: We retain data during this window under our legitimate interest (Article 6(1)(f) UK GDPR) in enabling account restoration for users who change their mind, and to maintain audit logs for security and fraud-prevention purposes. You can request immediate hard-deletion by emailing privacy@penaltyproof.co.uk.
- Alert records (a log of filing deadline notifications sent to you) are retained for up to 2 years as an audit trail, then permanently deleted.
- Email send log records are retained for up to 90 days, then permanently deleted.
- Filing deadline snapshots (cached Companies House public data used to detect deadline changes) are retained for up to 12 months, then permanently deleted.
- PSC/officer snapshots (hashes only — no personal data) are retained for up to 12 months, then permanently deleted.
- Charity snapshots (annual return dates fetched from the Charity Commission register) are retained for up to 12 months, then permanently deleted.
- ECCTA readiness metadata (readiness status, target date, source URL, evidence-requested timestamp, last-reviewed timestamp, reviewer id, and optional internal notes) is retained while the relevant account and monitored company remain active, then removed through company deletion or account hard-purge.
- Team workspace data (workspace memberships, membership roles, invitation metadata, invitation token hashes, expiry timestamps, accepted timestamps, revoked timestamps, and team lifecycle audit events) is retained while the relevant workspace/account remains active. Invitation token hashes are cleared when an invite is accepted, revoked, or superseded. No age-based invitation-row purge is currently in place.
- Payment records are held by Stripe in accordance with their privacy policy and applicable financial regulations. We hold your Stripe customer ID only for as long as you have an active account.
- Security audit log (timestamps of sign-ins, sign-outs, link issuance, account changes, and DSAR submissions, with hashed IP and user-agent for incident investigation only) is retained for 365 days, then permanently deleted. Hashes are peppered with a server-side secret so raw client identifiers are never stored.
You may request deletion of your account at any time via /delete-account. Deletion stops all alerts immediately. For immediate hard-deletion of all data, contact privacy@penaltyproof.co.uk.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure — you can delete your account and all associated data at /delete-account at any time.
- Restriction of processing in certain circumstances.
- Data portability — receive your data in a machine-readable format.
- Object to processing based on legitimate interest.
To exercise any right other than deletion, contact privacy@penaltyproof.co.uk. We will respond within one calendar month.
8. Cookies
We use the following cookies:
| Name | Purpose | Content | Duration | Flags |
|---|---|---|---|---|
ref |
Referral tracking — records which referral code was used when a new user signs up via a referral link, so the referring accountant can receive their credit. | A short alphanumeric referral code. No personal data. | 30 days | HttpOnly, Secure, SameSite=Lax |
manage_session |
Maintains your authenticated account-management session after you click a magic link, so you do not need to re-request a link on every visit. | A signed session token; contains no personal data in cleartext. | 30 days, rolling | HttpOnly, Secure, SameSite=Lax |
These cookies are functional and contain no personal data. ref is set when you visit via a referral link (e.g. /refer/<code>) to apply referral credit at sign-up. manage_session is set after you click a magic link and is re-issued on authenticated account-management requests, for up to 30 days at a time.
You can block or clear cookies at any time in your browser settings. If ref is absent, referral credit cannot be applied at sign-up. If manage_session is absent, you will need to request a new management link more frequently.
9. Data Processing Agreement
If you are an accountant using PenaltyProof in a professional capacity, you can view our Data Processing Agreement.
10. Right to complain
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the UK's supervisory authority:
We would appreciate the opportunity to address your concerns before you contact the ICO.
© 2026 PenaltyProof
Chavannes Ltd · Registered in England and Wales · Company No. 17198260 · Registered office: Unit A, 82 James Carter Road, Mildenhall, IP28 7DE