Privacy Notice
Notice version: privacy-notice-2026-09-02-r9
Effective date: 2 September 2026
Summary
This notice explains how DutySharp collects and uses personal data relating to visitors of dutysharp.co.uk, recipients of our business-to-business outreach, and invited practices using the hosted pilot at app.dutysharp.co.uk. It is written in plain British English and applies from the effective date above. Earlier notices are replaced by this version.
This notice describes what the current pilot actually does. It distinguishes data for which DutySharp is the controller from client and case data that an invited practice controls and DutySharp processes on that practice's behalf.
1. Data controller and contact
The controller responsible for the processing described in this notice is Ivo Stoykov trading as DutySharp.
Privacy contact: hello@dutysharp.co.uk
ICO registration reference: ZC201109
Postal address: Ivo Stoykov / DutySharp, Unit 170054, PO Box 7169, Poole, BH15 9EL
Where this notice refers to an invited practice acting as its own controller, that practice is responsible for its own client and case data and for its own privacy obligations to its clients. DutySharp acts as a processor on behalf of that practice only to the extent described in section 6 and in the versioned Data Processing Agreement.
2. What this notice covers
This notice covers personal data processed in two roles:
- DutySharp as controller — public access requests; reviewed B2B outreach and prospect records; invited firm users, firm-bound invitations, authentication, device sessions and account administration; service communications; feedback; product usage and audit events; support and security logs; future billing and subscription records when activated; and Cloudflare Web Analytics and Turnstile on the public site.
- DutySharp as processor for an invited practice — practice-controlled company, case, contact, missing-item, secure upload, and file records, with the practice as controller for that data.
3. Public access requests (DutySharp as controller)
When a visitor submits the public request-access form on dutysharp.co.uk, DutySharp processes:
- full name;
- work email (stored in lower case);
- practice name;
- professional role (owner/manager/accountant/other), if the visitor selects one;
- the selected primary workflow blocker, if the visitor selects one;
- practice website (optional);
- additional message (optional);
- whether the visitor ticked the optional contact-consent checkbox;
- submission timestamp;
- a salted SHA-256 hash of the visitor's IP address (the raw IP is not stored);
- the request's user agent;
- review workflow status and timestamps, operator review note, and an export timestamp used when an approved request is handed off for invitation.
Purpose: to evaluate whether the practice is a fit for the hosted pilot, to respond to the request, to operate the request-access review workflow, and to prevent fraud and automated abuse.
Lawful basis: the form carries an optional consent checkbox. Ticking it is not required to submit a request, and a request submitted without it is still processed.
- Where the visitor ticks the box, DutySharp treats that as the visitor's specific consent to be contacted about that pilot request, and relies on it for the contact purpose. That consent is specific to contact about the request; it is not consent for unrelated marketing or for unrelated processing.
- Where the visitor does not tick the box, DutySharp relies on legitimate interests for replying, because a visitor who submits this form is asking to be contacted about pilot access and the reply is the response to that request.
- In both cases DutySharp relies on legitimate interests for fit assessment, request and review records, and fraud/abuse prevention and service security.
PECR: a reply about the visitor's own request is solicited correspondence, not unsolicited electronic marketing. Any wider marketing to that address would be governed by the outreach rules in section 4.
Withdrawing consent, objecting, and opting out: a visitor can ask DutySharp to stop contacting them about their request at any time by emailing hello@dutysharp.co.uk — by withdrawing consent where it was given, or by objecting to the processing where DutySharp relies on legitimate interests. Neither affects the lawfulness of processing beforehand. DutySharp may still need to keep minimal records under legitimate interests for fraud prevention, audit, and legal-defence purposes.
Submitted requests are stored in a Cloudflare D1 database used only for this intake and review workflow. They are not published or shared with third parties for marketing.
Turnstile verification flow: the request-access form includes a Cloudflare Turnstile token. The Pages Function sends the Turnstile token together with the visitor's raw IP address to Cloudflare's siteverify service for verification. Neither the Turnstile token nor the raw IP address is stored. After verification, DutySharp stores only the salted SHA-256 hash of the IP address and the user agent described above.
4. B2B outreach and prospect records (DutySharp as controller)
DutySharp conducts limited, targeted business-to-business outreach to UK accountancy practices that appear to fit the pilot's target profile. Outreach records may include practice name, professional role, professional or business contact details, source reference, review status, and notes from prior interactions.
Purpose: to identify practices that may benefit from the pilot and to invite them in a targeted, low-volume way.
UK GDPR lawful basis: DutySharp relies on legitimate interests for processing B2B outreach records. The interest is narrowly scoped: identifying and inviting practices that plausibly benefit from a UK accountancy workflow tool, and recording the source and status of each contact for review and suppression.
PECR and electronic marketing: the Privacy and Electronic Communications Regulations (PECR) govern the sending of electronic mail for marketing, separately from the UK GDPR lawful basis. Under PECR, electronic marketing may be sent to corporate subscribers (limited companies, LLPs, and similar bodies) without prior consent, provided the recipient is given a clear opt-out on every message and the address was obtained in the course of a commercial relationship or public professional listing. Sole traders and most ordinary partnerships are individual subscribers under PECR; electronic marketing to them requires PECR consent or a valid soft opt-in. DutySharp's outreach policy treats sole traders and personal email addresses more cautiously than corporate business addresses and suppresses any recipient who opts out.
5. Invited firm users, authentication, and account data (DutySharp as controller)
For an invited practice, DutySharp — as controller — processes the following account and operational data, separate from the practice's controlled client/case/file data:
- firm identity, firm name, and firm-bound invitation state, including operator-managed firm access links;
- firm user identity, login email, status (active or deactivated), activated/deactivated timestamps, and short-lived login-code state used for authentication;
- recognised device-session digests (session-token hash, user-agent hash, IP hash, created, last-seen, expiry, and revocation timestamps), used to keep one active session per email;
- account administration, including trial start and trial expiry, firm-member limits, and support-mediated billing-contact designation;
- product usage events and feedback submissions;
- support communications and security logs;
- service communications relating to the pilot, including deletion-date reminders and device-security notices.
Purpose: to operate the hosted pilot, authenticate invited firm users, administer accounts, maintain service and security, improve the pilot, and respond to support and feedback.
Lawful basis: legitimate interests for operating the pilot, authenticating firm users, account administration, securing the service, improving the product, handling support, and processing feedback and product usage data. The invited practice's acceptance of the Pilot Terms governs the pilot access; DutySharp relies on legitimate interests rather than Article 6(1)(b) for the firm user's account and authentication data because the user may be acting on behalf of the contracting practice rather than as the contracting party.
5.1 Login codes and device sessions
The hosted pilot uses passwordless email-code authentication:
- A login code is valid for 10 minutes, can be used only once, and is consumed at verification. DutySharp stores only a hash of the code, never the plain code after issue.
- A firm-bound access link is reusable for 30 days from issue, until it is revoked, or until five distinct emails have verified through it. Opening the link does not register a user; successful email-code verification does.
- A recognised device session lasts up to 14 days. Only one active device session is permitted per verified email. Signing in on a new device requires fresh email verification and, on success, revokes every earlier active session for that email.
- The third new-device activation for the same email within a rolling two-hour window creates a prominent user warning and an operator-visible security event. It does not, by itself, block access or trigger an account-level cooldown.
- An IP address change within the same valid device session does not revoke the session. DutySharp does not treat an IP address or user-agent change as proof of identity, sharing, or unauthorised access. We record only salted hashes of IP addresses and user agents; raw IP values are not published in user-facing security notices or retained in logs.
When a device is displaced, the new device explains that it signed out another device, and the displaced device explains the reason on its next request and asks the user to verify again. Security emails include the sign-in time and a support route, but do not expose raw IP information.
5.2 Future billing and subscription records (not yet active)
Paid billing is not currently active. When DutySharp activates it, the following controller-side data will be processed for the First Tier subscription:
- billing-contact identity (the first verified user becomes the initial billing contact; later changes are support-mediated and notified to the old contact and other registered users);
- Stripe Customer, Subscription, Price/Product, invoice, payment status, and billing-period references retained as a local projection;
- transaction references, tax results (when applicable), and records needed for invoicing and accounting reconciliation;
- founding-price eligibility evidence recorded by DutySharp so the server can select the correct Stripe Price.
Purpose: to collect payment, grant paid access, manage renewals and cancellations, recover failed payments, produce invoices, calculate tax where DutySharp becomes registered, and reconcile transactions into GnuCash.
Lawful basis: contract (Article 6(1)(b)) only where the billing contact is personally the contracting party (for example a sole trader). Where the billing contact represents a practice that is the contracting party, DutySharp relies on legitimate interests for billing-contact designation, subscription administration, and payment-related service communications. Legitimate interests also apply to fraud prevention, abuse detection, and service security. Legal obligation applies to statutory tax, accounting, and invoicing record-keeping.
Recipients: Stripe and the applicable Stripe group entities process payment details, Customer records, Subscriptions, invoices, and tax results. DutySharp does not receive or store complete payment-card numbers, bank-account numbers, or CVC values; Stripe holds those. DutySharp stores only stable internal identifiers, subscription status, invoice references, and transaction summaries needed to make access decisions and reconcile accounts. GnuCash remains the accounting ledger; Stripe payouts and fees are reconciled into it.
The Stripe Checkout Session and Customer Portal flows are designed but not yet live. The paid Subscription Terms version subscription-terms-2026-07-29 are published as the reference text for that subscription, but billing and Checkout are not live: until activation there is no live charging, no VAT collection, no Stripe Tax registration, and no subscription in force under those terms.
6. Data processed for an invited practice as controller (practice data)
When an invited practice uses the hosted pilot, the practice typically creates or imports records about its own clients, companies, contacts, blocked cases, missing items, and case activity. That client and case data is controlled by the practice, not by DutySharp. DutySharp processes it on the practice's behalf as a processor for the agreed pilot purpose and follows the practice's reasonable instructions within the pilot.
This notice does not assign DutySharp a controller lawful basis for the practice's client data. Practices remain responsible for telling their own clients how their data is handled, for their own lawful bases, and for their own client-facing privacy notices. The controller-processor terms for that practice data are set out in the versioned Data Processing Agreement (data-processing-agreement-2026-07-21), and pilot terms are set out on the Pilot Terms page (pilot-terms-2026-08).
The hosted pilot records, used under the practice's control, typically include:
- tracked companies, blocked cases, case labels, client/contact context, missing-item notes, and case timeline/audit entries;
- generated draft outputs (chase messages, checklists, status summaries) that the practitioner reviews before use;
- secure upload requests created by the practitioner and the uploaded files and file metadata received through those requests;
- audit evidence for those records, such as file download and delete events.
Draft outputs are prepared for practitioner review and copy/paste into the practitioner's own workflow. The pilot does not send chase messages to clients automatically, and it does not automatically deliver generated drafts to clients. The practitioner decides whether, when, and how to use any draft.
7. Sources of personal data
DutySharp obtains personal data from the following sources:
- Direct submissions: the public request-access form, email replies to hello@dutysharp.co.uk, feedback submitted in the app, and direct replies to outreach messages.
- Invited practices: firms accepted into the pilot enter their own firm, company, contact, and case data into the hosted pilot.
- Public professional and business sources: publicly available accountancy directories and professional listings used to identify and review outreach prospects.
- Companies House: public company information (name, number, status, accounts and confirmation statement dates) retrieved via the Companies House API for tracked companies.
- Prior interactions: notes and status records from previous outreach, replies, and pilot conversations.
- Stripe: when billing is activated, Stripe will supply Customer, Subscription, invoice, and payment objects through the Checkout Session, Customer Portal, and webhooks. Tax-result objects will be supplied only when applicable, depending on whether Stripe Tax is activated.
8. Recipients and providers
DutySharp does not sell personal data. Personal data is shared only with the recipients described here and with the providers that run the current pilot infrastructure.
Known deployed providers used by the current pilot, described by function:
- Cloudflare — public website hosting, request-access backend (Pages and D1), bot protection (Turnstile), web analytics, and object storage for secure uploads (Cloudflare R2).
- Neon — hosted PostgreSQL database for the pilot application.
- Amazon Web Services (AWS) — application hosting (Amazon ECS on AWS Fargate behind an AWS-managed load balancer) and application logging (Amazon CloudWatch Logs with an explicit 30-day retention) for the pilot service, in the AWS
eu-west-2(London, UK) region. - Purelymail — outbound email delivery for pilot login codes, device-security notices, service messages, and future billing notifications.
- Companies House API — source of public company information for tracked companies.
- Stripe and the applicable Stripe group entities — payment processor, subscription lifecycle, invoices, and tax calculation when billing is activated. Not currently active.
The public site uses Cloudflare Turnstile for bot verification on the request-access form. Turnstile may process a visitor's browser and network information to assess whether the submission is from a real person; the verification flow is described in section 3.
For practice-controlled client and case data, the approved sub-processor chain and transfer safeguards are recorded in Schedule 4 of the DPA.
9. Processing locations and international transfers
The personal data DutySharp controls is processed primarily in the United Kingdom:
- AWS: the ECS application runtime, Application Load Balancer, ECR images, Secrets Manager values, and CloudWatch logs are deployed in the AWS
eu-west-2(London, UK) region. Application logs are held with an explicit 30-day retention. - Neon: the hosted PostgreSQL database is in Neon's
aws-eu-west-2(London, UK) region. - Cloudflare R2: uploaded file bytes are stored in the
obliga-app-uploadsbucket, configured for EU jurisdiction with public access disabled. - Purelymail: email delivery servers are hosted through AWS; Purelymail does not publish a binding processing region.
- Stripe: when activated, Stripe and the applicable Stripe group entities process payment, Customer, Subscription, and invoice data on Stripe's own infrastructure, subject to Stripe's data processing terms and the Stripe Data Transfers Addendum.
Provider corporate, support, and sub-processor personnel may access data from outside the United Kingdom in limited circumstances. The applicable Article 46 transfer safeguards for the providers in Schedule 4 of the DPA (AWS, Cloudflare, Neon, and others) are recorded there, including the AWS UK GDPR Addendum, Cloudflare Customer DPA, and Databricks/Neon DPA.
Stripe is not currently in that Schedule. If Stripe billing is activated, transfers to Stripe and the applicable Stripe group entities will be governed by Stripe's applicable Data Processing Agreement and Data Transfers Addendum, including the UK Addendum and other relevant transfer mechanisms described in Stripe's UK legal documentation.
DutySharp does not claim that all provider support, corporate, or sub-processor access is UK-only.
10. Direct marketing objection and opt-out
You have the right to object to direct marketing at any time, including B2B outreach, and DutySharp will honour that objection. To opt out, email hello@dutysharp.co.uk with "Marketing opt-out" in the subject line, or reply to any outreach message asking to stop.
When you opt out, DutySharp normally retains a minimal do-not-contact record — your email address and the source of the opt-out — even when other marketing data are erased, because that record is needed to honour the objection and to ensure future outreach and follow-ups are not sent to you. That record is not used for marketing. Any erasure request relating to the do-not-contact record is assessed under the statutory conditions and exceptions that apply to retaining data necessary to uphold an absolute objection.
11. Retention
DutySharp keeps personal data only for as long as necessary for the purposes described in this notice, unless a longer period is required by law.
- Public access requests: retained while the request-access review workflow is active and for a reasonable period afterwards to demonstrate that the request was handled and to support fraud/abuse investigation. Once a request is approved and handed off, the export timestamp is recorded; the request row is retained for review evidence rather than deleted immediately.
- B2B outreach records: retained while outreach and follow-up are active. When you opt out, a minimal do-not-contact record is retained as described in section 10.
- Login codes: 10-minute validity, one-time use. The stored hash is retained as consumed/expired evidence for a short operational period and is then eligible for deletion.
- Firm-bound access links: usable for 30 days from issue, until revoked, or until five distinct emails have verified through the link. The underlying invitation state is retained for the life of the firm's relationship with DutySharp.
- Device sessions: up to 14 days from creation, or until revoked earlier by a fresh verified login, manual revocation, or account closure. Salted IP/user-agent hashes are retained only within the session record.
- Session-replacement and security events: retained for a reasonable period to support security investigation, audit, and operator review of the third-activation-within-two-hours warning.
- Firm-user account and authentication records: retained for the life of the account and a reasonable period after closure for audit, legal defence, and support purposes.
- Support communications, product usage events, and audit logs: retained for pilot operation, product improvement, security investigation, and legal defence. Structured application logs sent to AWS CloudWatch Logs have an explicit 30-day retention.
- Upload requests: have an expiry date set by the practitioner when the request is created; an expired or revoked request stops accepting new uploads but does not by itself delete files already received.
- Uploaded file bytes: removed when a practitioner deletes the file from the case workflow. Metadata and audit entries about the file (filename, checksum, upload, download, and delete evidence) are retained after the file bytes are deleted.
- Practice-controlled client/case data: retained while the practice has an active pilot or paid account, then handled in line with the end-of-service lifecycle below.
- Future billing and tax records: when billing is activated, Stripe Customer, Subscription, invoice, payment, and tax records will be retained for the periods required by tax, accounting, and legal obligations.
11.1 End-of-service lifecycle for practice-controlled data
When a practice's service actually ends, DutySharp follows the controller-processor lifecycle in section 12 of the DPA:
- 30-day inaccessible window: the practice's operational data is kept inaccessible for 30 days. DutySharp tells the practice's verified contact the exact scheduled deletion date.
- Reminders: DutySharp sends reminders 14 and 7 days before the scheduled deletion date.
- Controlled return or earlier deletion: during the window the verified contact may request a controlled export/return of the firm's data, or earlier deletion. An export request should be made at least seven days before the scheduled deletion date. If a verified export request is already in progress, deletion is paused until delivery, and the single-use download remains available for seven days.
- Operational deletion: after the window ends, or on a verified earlier-deletion request, DutySharp deletes the practice's operational database records in Neon and the stored file objects in Cloudflare R2.
- Provider backup expiry: once operational deletion completes, provider-held backup or snapshot copies are put beyond use and removed through the documented provider retention and expiry cycle rather than instantly.
- Separately justified records: DutySharp may retain separately justified billing/tax records and minimum security or audit evidence that do not include the practice's client, case, or file content.
12. Your rights
Under UK GDPR you have the following rights, subject to the conditions and exceptions set out in the law. They are not absolute: some rights apply only in certain situations, some can be restricted, and some are balanced against DutySharp's and others' legitimate grounds.
- Access — ask what personal data DutySharp holds about you and receive a copy.
- Rectification — ask for inaccurate or incomplete personal data to be corrected.
- Erasure — ask for personal data to be deleted where there is no compelling reason to keep it.
- Restriction — ask for processing to be restricted in certain circumstances.
- Portability — receive some personal data you provided in a structured, machine-readable format, where applicable.
- Objection — object to processing based on legitimate interests, including an absolute right to object to direct marketing at any time.
- Withdrawal of consent — where consent is the genuine basis for a specific activity, withdraw consent at any time without affecting the lawfulness of processing before the withdrawal.
For practice-controlled client data processed on a practice's behalf, rights requests about that client data should normally be directed to the practice, which is the controller for that data. DutySharp will assist practices where required by the processing relationship.
To exercise any of these rights, email hello@dutysharp.co.uk. DutySharp may need to verify your identity before responding.
13. Right to complain to the ICO
If you are not satisfied with how DutySharp handles a concern about your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO's official complaint guidance is at https://ico.org.uk/make-a-complaint/. Contacting the ICO does not remove your right to use other remedies.
14. Website analytics and bot protection
The public site uses Cloudflare Web Analytics, which provides aggregate page-visit and performance measurement. Cloudflare Web Analytics does not use cookies for behavioural advertising. It is enabled through Cloudflare's automatic injection for the dutysharp.co.uk hostname; the repository does not contain a manual analytics beacon or token.
The request-access form uses Cloudflare Turnstile for bot verification. The verification flow is described in section 3.
15. Changes to this notice
When this notice changes, DutySharp will update the version identifier and effective date at the top of the page and publish the new version at https://dutysharp.co.uk/privacy. Material changes will be reflected before, or at the same time as, the related change in processing.
Related legal pages
- Hosted Pilot Terms — version
pilot-terms-2026-08. - Data Processing Agreement — version
data-processing-agreement-2026-07-21; sets out the controller-processor terms for practice-controlled data. - Subscription Terms — version
subscription-terms-2026-07-29; the separate paid First Tier contract. Published as the reference text; live charging is not enabled.