Pipernus Privacy Policy
Effective date: 28 July 2026
Last updated: 28 July 2026
Version: 1.0
This Privacy Policy explains how PIPERNUS GROUP LTD handles personal data when people visit our website, create or use a Pipernus account, contact us, or use our cloud accounting and tax software at https://www.pipernus.app (the “Service”).
PIPERNUS GROUP LTD is registered in England and Wales under company number 15880060. Our registered office is 103 Lonsdale Avenue, Wembley, England, HA9 7EW.
For privacy questions or to exercise a data-protection right, contact hello@pipernus.com.
1. Scope and our data-protection roles
Pipernus has different data-protection roles depending on why personal data is processed.
Pipernus as controller
We are a controller for personal data used to operate our websites and business, create and administer user accounts, manage subscriptions and billing, provide support, keep the Service secure, meet legal obligations and communicate about the Service. This means we decide why and how that data is processed.
Pipernus as processor
Our customers decide why and how the accounting, bookkeeping, tax, payroll, property, banking, document and client data in their workspaces is processed. For that Customer Data, the customer is normally the controller and Pipernus is its processor. We process it on the customer’s documented instructions, including instructions given through use of the Service, and under the Data Processing Terms in our Terms and Conditions.
Accountants and advisers
Where an accountancy firm, bookkeeper or tax adviser uses Pipernus for a client, that professional firm and/or its client determines the relevant controller responsibilities. Pipernus remains the processor for the Customer Data it hosts on their instructions.
If you are an employee, client, supplier, tenant or other person whose information was entered into Pipernus by one of our customers, that customer is normally the best first contact for a privacy request about the information in its workspace. We will assist the customer as required by applicable law and our contract.
2. Personal data we process
Depending on how you interact with Pipernus, we may process:
- Identity and contact data: name, business name, role, address, email address, telephone number and professional relationship.
- Account and access data: user identifier, company or workspace, permissions, authentication events, multi-factor authentication status and account recovery information. Passwords are stored by our authentication provider in protected form; we do not have access to a user’s plaintext password.
- Subscription and transaction data: plan, licence status, billing contact, invoices, payment status, tax information and limited payment metadata. Card and app-store payment details are handled by the relevant payment provider rather than stored in full by Pipernus.
- Customer Data: accounting entries, bank transactions, invoices, receipts, expenses, contacts, supplier and customer records, employee and payroll information, property records, taxpayer and business identifiers, tax calculations, source documents and other information entered into a workspace.
- HMRC connection and submission data: approved OAuth scopes, encrypted access and refresh tokens, National Insurance numbers, Unique Taxpayer References, VAT registration numbers, business identifiers, obligations, calculation and submission data, receipts, correlation identifiers and status information. Pipernus does not ask for or store HMRC Government Gateway passwords.
- Device, usage and security data: IP address, browser and device information, operating system, timestamps, session and audit events, diagnostic data, security alerts and information needed to prevent fraud and misuse.
- HMRC fraud-prevention data: where required for an HMRC API request, relevant user, device, connection, network and software information in the format required by HMRC’s fraud-prevention specification.
- Communications and support data: messages, support requests, feedback, call or meeting notes, and records needed to investigate and resolve an issue.
- Connected-service data: information exchanged when an authorised user connects a bank, payment service, app store, HMRC account or another supported provider.
- Website and preference data: essential cookies or local storage, consent choices and, where enabled lawfully, analytics or marketing information.
Customer Data may contain special-category data or other sensitive information because of the records a customer chooses to upload. Customers must only provide that information where they have a lawful basis and any additional condition required by law.
3. Where personal data comes from
We obtain personal data:
- directly from users, customers and people who contact us;
- from an organisation that creates or manages an account for a user;
- from files, records and instructions entered by authorised users;
- from HMRC and other connected services when a user authorises the connection;
- automatically from browsers, devices, servers, security controls and audit logs; and
- from payment, email, support and other service providers where needed to operate the Service.
4. Why we use personal data and our lawful bases
The lawful basis depends on the purpose and context. We use controller data as follows:
|
Purpose |
Typical lawful basis |
|---|---|
|
Create an account, provide the Service and administer a subscription |
Performance of a contract, or steps requested before entering a contract |
|
Authenticate users, manage permissions and protect accounts, customers and the Service |
Performance of a contract and our legitimate interests in providing a secure, reliable service |
|
Process charges, maintain billing records and manage payment or app-store subscriptions |
Performance of a contract and compliance with legal obligations |
|
Provide support, investigate faults and communicate service or security information |
Performance of a contract and our legitimate interests in supporting and improving the Service |
|
Connect to HMRC, transmit an authorised submission and maintain the related evidence and status |
Performance of a contract, compliance with applicable legal obligations and our legitimate interests in providing an auditable tax service |
|
Send HMRC fraud-prevention data with relevant API requests |
Performance of a contract and our legitimate interests in meeting HMRC’s security requirements and preventing fraud |
|
Monitor availability, diagnose errors, prevent abuse and investigate security incidents |
Our legitimate interests in maintaining a secure and reliable service and, where applicable, compliance with legal obligations |
|
Maintain business, tax, legal and compliance records and respond to lawful requests |
Compliance with legal obligations and our legitimate interests in establishing, exercising or defending legal rights |
|
Send direct marketing to business contacts |
Consent where required, or legitimate interests where permitted; every electronic marketing message provides an opt-out |
|
Use non-essential cookies or similar technology |
Consent where required by law |
Where we rely on legitimate interests, we consider the necessity and proportionality of the processing, the reasonable expectations of the people involved and the potential effect on their rights. You may object to this processing as explained in section 13.
Where Pipernus acts as a processor, the customer determines the purpose and lawful basis. We do not replace the customer’s responsibility to provide privacy information, respond to data-subject requests and issue lawful instructions.
5. HMRC and Making Tax Digital
When a user connects Pipernus to HMRC:
- HMRC presents the authorisation journey and the user approves specific OAuth permissions.
- Pipernus receives and securely stores the resulting tokens so it can perform authorised actions. We do not receive the user’s HMRC password.
- Pipernus retrieves or submits only the data required for the function the authorised user requests.
- Relevant HMRC API calls include fraud-prevention information required by HMRC. This may include information about the user, device, connection, network and software.
- We keep submission status, identifiers and evidence needed to show what was requested and how HMRC responded.
Users can revoke an HMRC authorisation through HMRC or the Service. Revocation does not require us to erase records that must be retained for security, legal or evidential purposes.
6. Automated extraction and artificial intelligence
Some optional features use automated extraction or artificial intelligence to read documents, suggest categories or assist with other tasks. If an authorised user chooses such a feature:
- the selected content and necessary instructions may be sent to a specialist service provider;
- the output may be incomplete or inaccurate and must be reviewed before it is posted, filed or relied upon; and
- Pipernus processes Customer Data for that feature as the customer’s processor and on the customer’s instruction.
Provider, location and contractual arrangements can change as the Service evolves. We do not rely on this Privacy Policy to authorise a materially different use of Customer Data. Current information about relevant sub-processors is available from hello@pipernus.com.
7. Who we share personal data with
We share only the information reasonably needed for the relevant purpose with:
- Cloud hosting and database providers. The primary Pipernus application and database hosting is configured in the European Economic Area (EEA) using Railway and Supabase.
- Payment and app-store providers. These providers process subscriptions, payment status, tax and limited account information. A customer’s own connected payment account is also governed by that provider’s terms.
- Email, support and communications providers. These providers deliver transactional messages and help us respond to users.
- Security, monitoring and diagnostic providers. These providers help detect faults, protect the Service and investigate incidents.
- Document-processing and artificial-intelligence providers. These providers process selected content only when the relevant feature is used.
- HMRC, banks and other connected services. We exchange information when an authorised user requests a supported connection or submission.
- Professional advisers, insurers, auditors and prospective transaction parties. Access is limited to what is necessary and subject to appropriate confidentiality protections.
- Courts, regulators, law-enforcement bodies and other authorities. We disclose information where required by law or where necessary to establish, exercise or defend legal rights.
We do not sell personal data.
8. Sub-processors
Where Pipernus acts as a processor, the customer gives the general authorisation described in our Data Processing Terms for us to use sub-processors needed to provide the Service. We require sub-processors to protect Customer Personal Data under written data-protection obligations.
Current sub-processor information, including the service category and relevant processing location, is available on request from hello@pipernus.com. We do not represent that every provider uses the same transfer mechanism or processing location.
9. International transfers
Our primary application and database hosting is configured in the EEA. The EEA is outside the United Kingdom, so personal data sent there is protected under the applicable UK adequacy regulations.
Some providers or support operations may process personal data in other countries. Before making a restricted transfer, we require an applicable legal mechanism and protections. Depending on the recipient and destination, this may include:
- UK adequacy regulations;
- the UK Extension to the EU-US Data Privacy Framework, but only where the US recipient is eligible and currently certified;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU Standard Contractual Clauses; or
- another mechanism permitted by UK data-protection law.
Where required, we also assess the destination and safeguards and apply supplementary measures. The correct mechanism is determined for the particular transfer; this Policy does not claim that one mechanism applies universally to every provider.
10. Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, contractual, legal, tax, accounting and dispute-resolution needs. The period depends on the type of data, sensitivity, risk, customer instructions and applicable law.
In particular:
- Controller account and subscription data is kept while the account is active and for a reasonable period afterwards for support, security, billing, legal and audit purposes.
- Customer Data is kept for the subscription term and any reasonable offboarding, export, deletion and protected-backup period specified by the contract or the customer’s lawful instruction.
- Protected backups are deleted or overwritten on the applicable backup cycle. Until then, retained data remains protected and is restored only for disaster recovery or legal necessity.
- Security, access and diagnostic records are kept for a period proportionate to detecting, investigating and evidencing incidents and abuse.
- Support and legal records are kept for as long as needed to resolve the matter and establish, exercise or defend rights.
Customers control the statutory retention of their own accounting and tax records. Pipernus does not assume that every item of Customer Data must be kept by Pipernus for a fixed six-year period. Customers should use available export functions and maintain the records required for their circumstances.
11. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. These include access controls, tenant isolation, encryption in transit, protected secrets and credentials, audit logging, monitoring, backup and incident-response processes.
No online service can guarantee absolute security. Users must protect their devices and credentials, use individual accounts, enable available multi-factor authentication and promptly report suspected compromise to hello@pipernus.com.
12. Cookies and similar technology
Pipernus uses essential cookies or similar local storage where needed for authentication, security, preferences and core Service functions. We request consent before using non-essential cookies where the law requires it. You can change browser settings or the consent controls made available on the relevant site, but blocking essential storage may prevent the Service from working.
13. Your data-protection rights
Subject to the conditions and exemptions in data-protection law, you may have the right to:
- be informed about how your personal data is used;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent where processing depends on consent, without affecting earlier lawful processing; and
- ask for human intervention where a qualifying solely automated decision has a legal or similarly significant effect.
To make a request, email hello@pipernus.com. We may need to verify your identity and clarify the request. We normally respond within one month, subject to lawful extensions for complex or numerous requests. Some rights are not absolute and may not apply to every item of data or purpose.
If the request concerns data controlled by a Pipernus customer, we may direct you to that customer and assist it with the response.
14. Complaints
Please contact us first so that we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
You may also have the right to complain to another competent data-protection authority, particularly if you live or work outside the United Kingdom.
15. Children
The Service is intended for business and professional users aged 18 or over. It is not directed to children. Customer Data may contain information about a child only where a customer has a lawful and necessary business, employment, accounting or tax reason to process it.
16. Changes to this Policy
We may update this Policy when the Service, law, providers or processing activities change. We will publish the updated version and change the date at the top. Where a change materially affects how we use personal data, we will provide additional notice where reasonably practicable or required by law.
17. Contact
PIPERNUS GROUP LTD
Company number: 15880060
Registered office: 103 Lonsdale Avenue, Wembley, England, HA9 7EW
Website: https://www.pipernus.com
Service: https://www.pipernus.app
Email: hello@pipernus.com