Privacy Notice

Notice version: privacy-notice-2026-09-02-r9
Effective date: 2 September 2026

Summary

This notice explains how DutySharp collects and uses personal data relating to visitors of dutysharp.co.uk, recipients of our business-to-business outreach, and invited practices using the hosted pilot at app.dutysharp.co.uk. It is written in plain British English and applies from the effective date above. Earlier notices are replaced by this version.

This notice describes what the current pilot actually does. It distinguishes data for which DutySharp is the controller from client and case data that an invited practice controls and DutySharp processes on that practice's behalf.

1. Data controller and contact

The controller responsible for the processing described in this notice is Ivo Stoykov trading as DutySharp.

Privacy contact: hello@dutysharp.co.uk
ICO registration reference: ZC201109
Postal address: Ivo Stoykov / DutySharp, Unit 170054, PO Box 7169, Poole, BH15 9EL

Where this notice refers to an invited practice acting as its own controller, that practice is responsible for its own client and case data and for its own privacy obligations to its clients. DutySharp acts as a processor on behalf of that practice only to the extent described in section 6 and in the versioned Data Processing Agreement.

2. What this notice covers

This notice covers personal data processed in two roles:

3. Public access requests (DutySharp as controller)

When a visitor submits the public request-access form on dutysharp.co.uk, DutySharp processes:

Purpose: to evaluate whether the practice is a fit for the hosted pilot, to respond to the request, to operate the request-access review workflow, and to prevent fraud and automated abuse.

Lawful basis: the form carries an optional consent checkbox. Ticking it is not required to submit a request, and a request submitted without it is still processed.

PECR: a reply about the visitor's own request is solicited correspondence, not unsolicited electronic marketing. Any wider marketing to that address would be governed by the outreach rules in section 4.

Withdrawing consent, objecting, and opting out: a visitor can ask DutySharp to stop contacting them about their request at any time by emailing hello@dutysharp.co.uk — by withdrawing consent where it was given, or by objecting to the processing where DutySharp relies on legitimate interests. Neither affects the lawfulness of processing beforehand. DutySharp may still need to keep minimal records under legitimate interests for fraud prevention, audit, and legal-defence purposes.

Submitted requests are stored in a Cloudflare D1 database used only for this intake and review workflow. They are not published or shared with third parties for marketing.

Turnstile verification flow: the request-access form includes a Cloudflare Turnstile token. The Pages Function sends the Turnstile token together with the visitor's raw IP address to Cloudflare's siteverify service for verification. Neither the Turnstile token nor the raw IP address is stored. After verification, DutySharp stores only the salted SHA-256 hash of the IP address and the user agent described above.

4. B2B outreach and prospect records (DutySharp as controller)

DutySharp conducts limited, targeted business-to-business outreach to UK accountancy practices that appear to fit the pilot's target profile. Outreach records may include practice name, professional role, professional or business contact details, source reference, review status, and notes from prior interactions.

Purpose: to identify practices that may benefit from the pilot and to invite them in a targeted, low-volume way.

UK GDPR lawful basis: DutySharp relies on legitimate interests for processing B2B outreach records. The interest is narrowly scoped: identifying and inviting practices that plausibly benefit from a UK accountancy workflow tool, and recording the source and status of each contact for review and suppression.

PECR and electronic marketing: the Privacy and Electronic Communications Regulations (PECR) govern the sending of electronic mail for marketing, separately from the UK GDPR lawful basis. Under PECR, electronic marketing may be sent to corporate subscribers (limited companies, LLPs, and similar bodies) without prior consent, provided the recipient is given a clear opt-out on every message and the address was obtained in the course of a commercial relationship or public professional listing. Sole traders and most ordinary partnerships are individual subscribers under PECR; electronic marketing to them requires PECR consent or a valid soft opt-in. DutySharp's outreach policy treats sole traders and personal email addresses more cautiously than corporate business addresses and suppresses any recipient who opts out.

5. Invited firm users, authentication, and account data (DutySharp as controller)

For an invited practice, DutySharp — as controller — processes the following account and operational data, separate from the practice's controlled client/case/file data:

Purpose: to operate the hosted pilot, authenticate invited firm users, administer accounts, maintain service and security, improve the pilot, and respond to support and feedback.

Lawful basis: legitimate interests for operating the pilot, authenticating firm users, account administration, securing the service, improving the product, handling support, and processing feedback and product usage data. The invited practice's acceptance of the Pilot Terms governs the pilot access; DutySharp relies on legitimate interests rather than Article 6(1)(b) for the firm user's account and authentication data because the user may be acting on behalf of the contracting practice rather than as the contracting party.

5.1 Login codes and device sessions

The hosted pilot uses passwordless email-code authentication:

When a device is displaced, the new device explains that it signed out another device, and the displaced device explains the reason on its next request and asks the user to verify again. Security emails include the sign-in time and a support route, but do not expose raw IP information.

5.2 Future billing and subscription records (not yet active)

Paid billing is not currently active. When DutySharp activates it, the following controller-side data will be processed for the First Tier subscription:

Purpose: to collect payment, grant paid access, manage renewals and cancellations, recover failed payments, produce invoices, calculate tax where DutySharp becomes registered, and reconcile transactions into GnuCash.

Lawful basis: contract (Article 6(1)(b)) only where the billing contact is personally the contracting party (for example a sole trader). Where the billing contact represents a practice that is the contracting party, DutySharp relies on legitimate interests for billing-contact designation, subscription administration, and payment-related service communications. Legitimate interests also apply to fraud prevention, abuse detection, and service security. Legal obligation applies to statutory tax, accounting, and invoicing record-keeping.

Recipients: Stripe and the applicable Stripe group entities process payment details, Customer records, Subscriptions, invoices, and tax results. DutySharp does not receive or store complete payment-card numbers, bank-account numbers, or CVC values; Stripe holds those. DutySharp stores only stable internal identifiers, subscription status, invoice references, and transaction summaries needed to make access decisions and reconcile accounts. GnuCash remains the accounting ledger; Stripe payouts and fees are reconciled into it.

The Stripe Checkout Session and Customer Portal flows are designed but not yet live. The paid Subscription Terms version subscription-terms-2026-07-29 are published as the reference text for that subscription, but billing and Checkout are not live: until activation there is no live charging, no VAT collection, no Stripe Tax registration, and no subscription in force under those terms.

6. Data processed for an invited practice as controller (practice data)

When an invited practice uses the hosted pilot, the practice typically creates or imports records about its own clients, companies, contacts, blocked cases, missing items, and case activity. That client and case data is controlled by the practice, not by DutySharp. DutySharp processes it on the practice's behalf as a processor for the agreed pilot purpose and follows the practice's reasonable instructions within the pilot.

This notice does not assign DutySharp a controller lawful basis for the practice's client data. Practices remain responsible for telling their own clients how their data is handled, for their own lawful bases, and for their own client-facing privacy notices. The controller-processor terms for that practice data are set out in the versioned Data Processing Agreement (data-processing-agreement-2026-07-21), and pilot terms are set out on the Pilot Terms page (pilot-terms-2026-08).

The hosted pilot records, used under the practice's control, typically include:

Draft outputs are prepared for practitioner review and copy/paste into the practitioner's own workflow. The pilot does not send chase messages to clients automatically, and it does not automatically deliver generated drafts to clients. The practitioner decides whether, when, and how to use any draft.

7. Sources of personal data

DutySharp obtains personal data from the following sources:

8. Recipients and providers

DutySharp does not sell personal data. Personal data is shared only with the recipients described here and with the providers that run the current pilot infrastructure.

Known deployed providers used by the current pilot, described by function:

The public site uses Cloudflare Turnstile for bot verification on the request-access form. Turnstile may process a visitor's browser and network information to assess whether the submission is from a real person; the verification flow is described in section 3.

For practice-controlled client and case data, the approved sub-processor chain and transfer safeguards are recorded in Schedule 4 of the DPA.

9. Processing locations and international transfers

The personal data DutySharp controls is processed primarily in the United Kingdom:

Provider corporate, support, and sub-processor personnel may access data from outside the United Kingdom in limited circumstances. The applicable Article 46 transfer safeguards for the providers in Schedule 4 of the DPA (AWS, Cloudflare, Neon, and others) are recorded there, including the AWS UK GDPR Addendum, Cloudflare Customer DPA, and Databricks/Neon DPA.

Stripe is not currently in that Schedule. If Stripe billing is activated, transfers to Stripe and the applicable Stripe group entities will be governed by Stripe's applicable Data Processing Agreement and Data Transfers Addendum, including the UK Addendum and other relevant transfer mechanisms described in Stripe's UK legal documentation.

DutySharp does not claim that all provider support, corporate, or sub-processor access is UK-only.

10. Direct marketing objection and opt-out

You have the right to object to direct marketing at any time, including B2B outreach, and DutySharp will honour that objection. To opt out, email hello@dutysharp.co.uk with "Marketing opt-out" in the subject line, or reply to any outreach message asking to stop.

When you opt out, DutySharp normally retains a minimal do-not-contact record — your email address and the source of the opt-out — even when other marketing data are erased, because that record is needed to honour the objection and to ensure future outreach and follow-ups are not sent to you. That record is not used for marketing. Any erasure request relating to the do-not-contact record is assessed under the statutory conditions and exceptions that apply to retaining data necessary to uphold an absolute objection.

11. Retention

DutySharp keeps personal data only for as long as necessary for the purposes described in this notice, unless a longer period is required by law.

11.1 End-of-service lifecycle for practice-controlled data

When a practice's service actually ends, DutySharp follows the controller-processor lifecycle in section 12 of the DPA:

12. Your rights

Under UK GDPR you have the following rights, subject to the conditions and exceptions set out in the law. They are not absolute: some rights apply only in certain situations, some can be restricted, and some are balanced against DutySharp's and others' legitimate grounds.

For practice-controlled client data processed on a practice's behalf, rights requests about that client data should normally be directed to the practice, which is the controller for that data. DutySharp will assist practices where required by the processing relationship.

To exercise any of these rights, email hello@dutysharp.co.uk. DutySharp may need to verify your identity before responding.

13. Right to complain to the ICO

If you are not satisfied with how DutySharp handles a concern about your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO's official complaint guidance is at https://ico.org.uk/make-a-complaint/. Contacting the ICO does not remove your right to use other remedies.

14. Website analytics and bot protection

The public site uses Cloudflare Web Analytics, which provides aggregate page-visit and performance measurement. Cloudflare Web Analytics does not use cookies for behavioural advertising. It is enabled through Cloudflare's automatic injection for the dutysharp.co.uk hostname; the repository does not contain a manual analytics beacon or token.

The request-access form uses Cloudflare Turnstile for bot verification. The verification flow is described in section 3.

15. Changes to this notice

When this notice changes, DutySharp will update the version identifier and effective date at the top of the page and publish the new version at https://dutysharp.co.uk/privacy. Material changes will be reflected before, or at the same time as, the related change in processing.