Privacy Policy

Last updated: January 2025

SimpleMTD Ltd ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

SimpleMTD Ltd is the data controller for personal data collected through our services.

Company Registration: 12345678

Contact: hello@simplemtd.co.uk

Address: [Your registered address]

2. Information We Collect

Information you provide directly:

  • Email address (when you sign up for our checklist or service)
  • Name (if provided)
  • Business information (business name, type, VAT status)
  • Contact preferences

Information collected automatically:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on pages
  • Referring website

3. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: When you sign up for our email list or download resources
  • Contract: To provide services you've requested
  • Legitimate interests: To improve our services and communicate with customers
  • Legal obligation: To comply with applicable laws and regulations

4. How We Use Your Information

  • Send you the MTD Readiness Checklist you requested
  • Provide updates about SimpleMTD and Making Tax Digital
  • Respond to your enquiries
  • Improve our website and services
  • Send marketing communications (with your consent)
  • Comply with legal obligations

5. Who We Share Your Data With

We may share your data with:

  • Service providers: Including SendGrid (email), Supabase (database), Vercel (hosting)
  • Analytics providers: Google Analytics (anonymised data)
  • Legal authorities: When required by law

We never sell your personal data to third parties.

6. Data Retention

We retain your personal data for:

  • Email addresses: Until you unsubscribe or request deletion
  • Customer data: Duration of service plus 6 years (for tax records)
  • Analytics data: 26 months

7. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data
  • Restriction: Request limited processing of your data
  • Portability: Receive your data in a portable format
  • Object: Object to processing of your data
  • Withdraw consent: Withdraw consent at any time

To exercise these rights, contact us at hello@simplemtd.co.uk

8. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • SSL encryption for data transmission
  • Secure database storage with encryption at rest
  • Regular security audits
  • Limited access to personal data
  • Regular staff training on data protection

9. Cookies

We use cookies to:

  • Remember your preferences
  • Analyse website traffic (Google Analytics)
  • Track marketing effectiveness (Facebook Pixel)

You can control cookies through your browser settings.

10. International Data Transfers

Some of our service providers operate outside the UK. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the ICO.

11. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our website.

13. Complaints

If you have concerns about how we handle your data, please contact us first at hello@simplemtd.co.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

14. Contact Us

For any questions about this Privacy Policy or your personal data:

Email: hello@simplemtd.co.uk

Address: [Your registered address]