Privacy Policy

Last updated: 4 August 2026

1. Who We Are

DoneVAT is a product of DoneLabs Ltd, a company registered in England and Wales, company number 17056937. We provide Making Tax Digital software for VAT registered businesses in the United Kingdom, enabling VAT returns to be submitted directly to HMRC. For the purposes of UK data protection law, DoneLabs Ltd is the data controller for personal data collected through DoneVAT. We are registered with the Information Commissioner's Office, ICO Reg. No. ICO-0001353294. Registered office: DoneLabs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Contact: hello@donevat.co.uk

2. What Personal Data We Collect

We collect and process: Identity data (your email address), HMRC data (your VAT Registration Number and encrypted OAuth access and refresh tokens), Financial data (VAT transaction records including dates, descriptions, amounts and VAT rates, and bank transaction data where you connect an account via open banking), Submission data (your VAT return records and submission history), Payment data (your Stripe customer ID and subscription status), and Technical data (IP address, device identifier, browser information and timezone, collected for HMRC fraud prevention as described in section 6). We do not collect your HMRC password or your banking credentials.

3. How We Use Your Data and Our Lawful Basis

To provide the DoneVAT service, on the basis of contractual necessity: authenticating you with HMRC via OAuth 2.0, retrieving your VAT obligations, calculating your 9 box VAT return from your transaction records, and submitting your VAT returns to HMRC on your behalf. To comply with legal obligations: submitting fraud prevention header data to HMRC as required by law. To manage your account and subscription, on the basis of contractual necessity, including processing payments via Stripe and sending you service emails. To maintain and improve the security and reliability of the service, on the basis of our legitimate interests. We do not sell your data to third parties and we do not use your data for advertising.

4. HMRC Data and OAuth

DoneVAT uses OAuth 2.0 to connect to your HMRC account. We never store your Government Gateway username or password. We store encrypted OAuth access and refresh tokens solely to retrieve your VAT obligations and submit your VAT returns on your behalf. These tokens and your VAT Registration Number are encrypted at rest using AES-256-GCM encryption and transmitted over HTTPS. You can revoke this authorisation at any time through your HMRC online account.

5. Open Banking Data

Where you choose to connect a bank account, DoneVAT connects via TrueLayer, an FCA-authorised open banking provider. We request read-only access to your transaction history. We cannot and never will move money from your account. Bank transaction data is used only to help you identify and record VAT transactions for your returns. Connecting a bank account is optional and you can choose not to use this feature.

6. Fraud Prevention Data

HMRC requires all Making Tax Digital software providers to submit fraud prevention headers with every API call. This includes your device identifier, IP address, browser information and timezone. This is a legal requirement under the Delivery of Tax Information through Software (Ancillary Metadata) Regulations 2019 (SI 2019/360) and HMRC's Terms of Use. We have no discretion over this requirement.

7. Data Sharing

We share your personal data only where necessary to run the service: HMRC (to retrieve your VAT obligations and submit your VAT returns), TrueLayer (open banking, read-only, where you connect a bank account), Stripe (subscription payments), Neon (database hosting), Vercel (application hosting), Resend (transactional email), and Upstash (session and rate-limiting infrastructure). Each of these providers operates under its own privacy policy and data processing agreement. We do not sell, rent or share your personal data with any third party for marketing purposes.

8. Data Storage and Security

Your data is stored on Neon PostgreSQL infrastructure in the AWS Europe West 2 (London) region. Security measures include AES-256-GCM encryption at rest for your VAT Registration Number and HMRC tokens, HTTPS and TLS for all data in transit, HttpOnly and Secure session cookies, rate limiting on API endpoints, and access restricted to authenticated sessions only.

9. Data Retention

We retain your personal data for as long as your DoneVAT account is active. If you delete your account, your personal data, including your VAT transaction records, VAT return records and submission history, is deleted immediately and permanently, except where retention is required by law. Records of any data protection complaints you have raised are kept in anonymised form so we can evidence how they were handled. You remain responsible for keeping the records that support your VAT returns for the periods HMRC requires, so you should export any data you need before deleting your account.

10. Your Rights

Under UK GDPR you have the right of access to the personal data we hold about you, the right to rectification of inaccurate data, the right to erasure, the right to restrict processing, the right to data portability in a machine-readable format, and the right to object to processing. To exercise any of these rights, contact us at privacy@donelabs.co.uk. We will respond within one month of receiving your request, as required by UK GDPR.

11. Cookies

DoneVAT uses strictly necessary cookies only: a session cookie to maintain your login state, and a persistent device identifier cookie required for HMRC fraud prevention compliance. We do not use advertising cookies or third party tracking cookies.

12. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

13. Data protection complaints

You have the right to raise a formal data protection complaint if you are unhappy with how DoneLabs Ltd handles your personal data. This right is established under the Data (Use and Access) Act 2025 and UK GDPR.

To raise a complaint, sign in to your DoneVAT account and go to Account - the complaint form is in the Data Protection Complaint section at the bottom of the page. If you are unable to access your account, you can email us directly at privacy@donelabs.co.uk with the subject line 'Data Protection Complaint'.

We will acknowledge your complaint within 30 days of receipt and will keep you informed of progress and expected timeframes for resolution.

If you are not satisfied with our response, or if we have not responded within a reasonable time, you have the right to escalate your complaint to the Information Commissioner's Office (ICO). The ICO can be contacted at ico.org.uk or by calling 0303 123 1113.

14. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email. Continued use of DoneVAT after changes take effect constitutes acceptance of the updated policy.

15. Contact

For any privacy related queries, contact us at privacy@donelabs.co.uk or write to DoneLabs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.