Legal
Privacy policy
Last updated 16 September 2026
This policy explains how Xegen Ltd collects and uses personal information when you use AccountLayer, visit our website or contact us. It also explains the rights you have under UK data protection law.
1. Who we are and how to contact us
AccountLayer is provided by Xegen Ltd, a company registered in Scotland (company number SC745778), registered office 5 South Charlotte Street, Edinburgh, EH2 4AN. In this policy, “we”, “us” and “our” mean Xegen Ltd.
We are the data controller for the personal information described in this policy, except where section 2 explains that we act as a processor for a business that uses AccountLayer.
To ask a question about privacy, or to make a request about your information, you can:
- use our contact form and choose the topic “Privacy or data request”; or
- write to us at Xegen Ltd, 5 South Charlotte Street, Edinburgh, EH2 4AN.
2. Our two roles: controller and processor
We are the controller for information about the people who use AccountLayer and our website: your account and sign-in details, billing, security and fraud prevention data, our server and application logs, and messages you send us. We decide how this information is used.
We are a processor for the business records that our customers enter into AccountLayer or import into it, such as details of their own customers, suppliers and staff. For those records, the business using AccountLayer is the controller. We handle them only to provide AccountLayer to that business, on its instructions and under the data processing terms in our Terms of service.
If your details appear in the records of a business that uses AccountLayer (for example, because you are one of its customers), that business is responsible for them, so please contact it first. If you contact us instead, we’ll pass your request on to it.
3. The information we collect
- Account information: your name, email address and password (stored only in a scrambled, one-way form called a hash), whether you have confirmed your email address, the businesses you belong to and your role in each. If you invite someone to a business, we store their email address and the role you gave them.
- Two-factor sign-in: the secret that links your authenticator app to your account (stored encrypted) and your backup codes (stored only as keyed hashes, so the codes themselves can’t be read back).
- Business and financial records: everything you and your team enter or import. This includes the business name and VAT details; customers and suppliers, with their names, email addresses and postal addresses; invoices, bills, credit notes and payments; bank account names, account numbers and sort codes; bank transactions; fixed assets; stock; and journal entries. These records can include personal information about other people.
- Tax identifiers and HMRC connections: your National Insurance number, Unique Taxpayer Reference and VAT registration number; the VAT returns and Income Tax updates you submit, and the receipts HMRC sends back; information we fetch from HMRC for you; and the access tokens that let AccountLayer act for you with HMRC (stored encrypted).
- Data imported from Xero: if you connect Xero, the records you import, including files attached to them, and the access tokens for the connection (stored encrypted).
- Connected apps: if you authorise an app such as CalloutWMS to use your AccountLayer data, which app it is, the permissions you gave it, who authorised it and when.
- Billing information: the business name and the email address of the person who set up billing, which we give to Stripe; and the business’s plan, subscription status and invoice details (numbers, amounts and dates). You enter card details on Stripe’s own pages, and we never see or store your full card number.
- Security information: your IP address, a device identifier, browser and screen details, and a record of sign-ins, failed sign-ins and important account and business events (our audit log, shown in the app as the activity log). Section 5 explains the fraud prevention data we send to HMRC.
- Contact form messages: your name, email address, the topic you choose, your message and when you sent it. We don’t store your IP address or browser details with your message. We use your IP address for a short time to limit how many messages can be sent in an hour.
- Server and application logs: technical records of requests to our website and of errors, which can include your IP address, the page you asked for, the time and your browser details.
Most of this information comes from you. Some comes from others: a colleague who invites you to a business or enters records, HMRC (for example, your tax obligations and calculations), Xero and apps you connect, and Stripe (for example, whether a payment has gone through).
4. How we use it and our lawful basis
UK data protection law only lets us use personal information when we have a lawful basis for doing so. We rely on these:
- Contract: we need the information to provide the service you or your business signed up for, or to take steps you ask for before signing up.
- Legal obligation: the law requires us to use it.
- Legitimate interests: we need it for a reasonable purpose of ours, or of someone else, that isn’t outweighed by your interests and rights. You can ask us how we weighed this up.
| Purpose | Information | Lawful basis |
|---|---|---|
| Providing AccountLayer: creating and running your account and businesses, and storing and working with your records | Account information, two-factor sign-in, business and financial records, connected apps | Contract |
| Submitting VAT returns and Income Tax updates to HMRC, and fetching information from HMRC, when you ask us to | Tax identifiers and HMRC connections, and the figures you submit | Contract |
| Sending HMRC the fraud prevention data it requires each time we connect to it for you (section 5) | Security information, including your IP address, device identifier and browser details | Legal obligation; Legitimate interests (helping HMRC and us prevent tax fraud) |
| Importing records from Xero, and letting apps you authorise use your data | Data imported from Xero, connected apps, business and financial records | Contract |
| Keeping accounts and the service secure: two-factor sign-in, limiting repeated sign-in attempts and contact messages, and keeping an audit log | Account information, two-factor sign-in, security information | Legitimate interests (protecting our customers and our service from misuse and fraud) |
| Billing: free trials, subscriptions and payments through Stripe | Billing information, account information | Contract |
| Sending service emails: confirming your email address, resetting your password, invitations to a business, and warnings before a read-only business is deleted | Account information, business name | Contract |
| Answering messages you send through our contact form | Contact form messages | Legitimate interests (replying to people who contact us); Contract, where you ask about your account |
| Running, monitoring and fixing the service | Server and application logs | Legitimate interests (keeping the service working and secure) |
| Keeping our own accounting and tax records | Billing information | Legal obligation |
| Meeting our legal duties, answering lawful requests from authorities, and establishing or defending legal claims | Any of the information above that is relevant | Legal obligation; Legitimate interests (protecting our legal rights) |
We don’t send marketing emails, and we don’t sell your personal information. We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
5. HMRC fraud prevention data
HMRC requires software that connects to its Making Tax Digital services to send fraud prevention data every time it connects. HMRC uses this data to detect and prevent tax fraud and to protect taxpayers’ accounts. When you use AccountLayer to connect to HMRC, fetch information from it or submit to it, we send:
- your public IP address and port, and when they were recorded;
- the device identifier stored in the
mtd_device_idcookie (see section 10); - your AccountLayer user identifier, which is the email address you sign in with;
- your browser’s details: its user agent, any plugins it reports and its Do Not Track setting;
- your screen size, colour depth and scaling, and your browser window size;
- your timezone;
- details of your two-factor sign-in: the type of check, when you completed it, and a reference that doesn’t reveal your codes or the secret behind them;
- details of AccountLayer itself, such as its name, its version and our server’s public IP address.
A small script on AccountLayer’s signed-in pages measures the browser, screen and timezone details and keeps them in the mtd_fraud_signals cookie, so they are ready whenever a page connects to HMRC. Apart from these cookies, we don’t keep a separate copy of the fraud prevention data we send. HMRC handles it under its own privacy notice.
7. International transfers
Our hosting and email delivery are in the UK. Stripe and Xero may process data outside the UK, including in the United States, under safeguards recognised by UK law, such as UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework, or the International Data Transfer Addendum. Their own privacy policies explain the safeguards they use.
8. How long we keep it
We keep personal information only for as long as we need it:
| Information | How long |
|---|---|
| A business’s records, including its tax identifiers, HMRC and Xero connections and imported files | Kept for as long as the business has an active plan, or is in its 14-day free trial |
| A read-only business (one whose free trial or plan has ended) and everything in it | Permanently deleted 12 months after it became read-only; owners are emailed 30 days and 7 days before. Deletion never happens less than 30 days after the first warning, or less than 7 days after the final warning, and choosing a plan before then stops it. |
| User accounts, including two-factor sign-in details and access you have given to connected apps | Account deleted when you no longer belong to any business (for example, when the last business you belong to is deleted) |
| Audit log of sign-ins and important events, including IP addresses | 13 months |
| Contact form messages | 24 months |
| Emails waiting to be sent, or that couldn’t be sent, including copies of contact form messages | Up to 30 days |
| Server and application logs | 90 days |
| Our own billing and accounting records | 6 years, as UK law requires |
When a business is deleted, we delete its records, attached files, connection details and audit log entries. Our audit log keeps a short note that the business was deleted, with its name, and that note is removed after 13 months like other entries. Deletion is permanent and can’t be undone.
You’re responsible for keeping your own business and tax records for as long as HMRC requires. Export them before a business is deleted.
9. Your rights
You have these rights over your personal information. Some apply only in certain circumstances.
- Access: to ask for a copy of the personal information we hold about you.
- Rectification: to ask us to correct information that is wrong or incomplete.
- Erasure: to ask us to delete your information. We may need to keep some of it, for example where the law requires us to.
- Restriction: to ask us to limit how we use your information, for example while we check whether it is accurate.
- Objection: to object to our use of your information where we rely on legitimate interests.
- Data portability: to receive information you gave us in a structured, commonly used, machine-readable format, or to ask us to send it to another organisation. Owners and accountants can also download a business’s records as CSV files at any time, using Export data under Setup in AccountLayer.
- Withdrawing consent: we don’t currently rely on consent, but if we ever ask for it, you can withdraw it at any time.
To make a request, use our contact form with the topic “Privacy or data request”, or write to us at our registered office. There’s normally no charge. We’ll respond within one month. If a request is complex, or you make several, we may need up to two more months, and we’ll tell you within the first month if so. We may need to check your identity before we act on a request, so that we don’t give your information to someone else.
For records we hold as a processor for a business (section 2), we’ll pass your request to the business that controls them, and help it respond.
11. How we keep it secure
- Connections to AccountLayer are encrypted in transit (HTTPS).
- Two-factor sign-in is required for every account.
- Passwords are stored only as hashes. Authenticator app secrets and the access tokens for HMRC and Xero connections are encrypted, and backup codes are stored as keyed hashes.
- Repeated failed sign-in attempts and wrong two-factor codes are limited.
- Each business’s records are kept separate, and people can only do what their role in that business allows.
- We keep an audit log of sign-ins and important account and business events.
- Access tokens issued to connected apps expire after 30 minutes, and an app’s access can be revoked at any time.
No system is completely secure. If a breach of personal information is likely to put your rights and freedoms at risk, we’ll tell the Information Commissioner’s Office, and tell you where the law requires, as soon as we can.
12. Children
AccountLayer is for businesses and for people aged 18 or over. We don’t knowingly collect personal information from children through our website or service. If you think a child has given us their information, please contact us and we’ll delete it.
13. Complaints
If you’re unhappy with how we have handled your personal information, please contact us first, so we can try to put it right.
You also have the right to complain to the UK regulator, the Information Commissioner’s Office (ICO):
- website: https://ico.org.uk
- helpline: 0303 123 1113
- post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
14. Changes to this policy
We may update this policy from time to time. If we make a material change, we’ll email account holders before it takes effect. The “Last updated” date at the top of this page shows when the policy last changed.