Skip to content

Legal

Privacy policy

Last updated 16 September 2026

This policy explains how Xegen Ltd collects and uses personal information when you use AccountLayer, visit our website or contact us. It also explains the rights you have under UK data protection law.

1. Who we are and how to contact us

AccountLayer is provided by Xegen Ltd, a company registered in Scotland (company number SC745778), registered office 5 South Charlotte Street, Edinburgh, EH2 4AN. In this policy, “we”, “us” and “our” mean Xegen Ltd.

We are the data controller for the personal information described in this policy, except where section 2 explains that we act as a processor for a business that uses AccountLayer.

To ask a question about privacy, or to make a request about your information, you can:

  • use our contact form and choose the topic “Privacy or data request”; or
  • write to us at Xegen Ltd, 5 South Charlotte Street, Edinburgh, EH2 4AN.

2. Our two roles: controller and processor

We are the controller for information about the people who use AccountLayer and our website: your account and sign-in details, billing, security and fraud prevention data, our server and application logs, and messages you send us. We decide how this information is used.

We are a processor for the business records that our customers enter into AccountLayer or import into it, such as details of their own customers, suppliers and staff. For those records, the business using AccountLayer is the controller. We handle them only to provide AccountLayer to that business, on its instructions and under the data processing terms in our Terms of service.

If your details appear in the records of a business that uses AccountLayer (for example, because you are one of its customers), that business is responsible for them, so please contact it first. If you contact us instead, we’ll pass your request on to it.

3. The information we collect

  • Account information: your name, email address and password (stored only in a scrambled, one-way form called a hash), whether you have confirmed your email address, the businesses you belong to and your role in each. If you invite someone to a business, we store their email address and the role you gave them.
  • Two-factor sign-in: the secret that links your authenticator app to your account (stored encrypted) and your backup codes (stored only as keyed hashes, so the codes themselves can’t be read back).
  • Business and financial records: everything you and your team enter or import. This includes the business name and VAT details; customers and suppliers, with their names, email addresses and postal addresses; invoices, bills, credit notes and payments; bank account names, account numbers and sort codes; bank transactions; fixed assets; stock; and journal entries. These records can include personal information about other people.
  • Tax identifiers and HMRC connections: your National Insurance number, Unique Taxpayer Reference and VAT registration number; the VAT returns and Income Tax updates you submit, and the receipts HMRC sends back; information we fetch from HMRC for you; and the access tokens that let AccountLayer act for you with HMRC (stored encrypted).
  • Data imported from Xero: if you connect Xero, the records you import, including files attached to them, and the access tokens for the connection (stored encrypted).
  • Connected apps: if you authorise an app such as CalloutWMS to use your AccountLayer data, which app it is, the permissions you gave it, who authorised it and when.
  • Billing information: the business name and the email address of the person who set up billing, which we give to Stripe; and the business’s plan, subscription status and invoice details (numbers, amounts and dates). You enter card details on Stripe’s own pages, and we never see or store your full card number.
  • Security information: your IP address, a device identifier, browser and screen details, and a record of sign-ins, failed sign-ins and important account and business events (our audit log, shown in the app as the activity log). Section 5 explains the fraud prevention data we send to HMRC.
  • Contact form messages: your name, email address, the topic you choose, your message and when you sent it. We don’t store your IP address or browser details with your message. We use your IP address for a short time to limit how many messages can be sent in an hour.
  • Server and application logs: technical records of requests to our website and of errors, which can include your IP address, the page you asked for, the time and your browser details.

Most of this information comes from you. Some comes from others: a colleague who invites you to a business or enters records, HMRC (for example, your tax obligations and calculations), Xero and apps you connect, and Stripe (for example, whether a payment has gone through).

4. How we use it and our lawful basis

UK data protection law only lets us use personal information when we have a lawful basis for doing so. We rely on these:

  • Contract: we need the information to provide the service you or your business signed up for, or to take steps you ask for before signing up.
  • Legal obligation: the law requires us to use it.
  • Legitimate interests: we need it for a reasonable purpose of ours, or of someone else, that isn’t outweighed by your interests and rights. You can ask us how we weighed this up.
Purpose Information Lawful basis
Providing AccountLayer: creating and running your account and businesses, and storing and working with your records Account information, two-factor sign-in, business and financial records, connected apps Contract
Submitting VAT returns and Income Tax updates to HMRC, and fetching information from HMRC, when you ask us to Tax identifiers and HMRC connections, and the figures you submit Contract
Sending HMRC the fraud prevention data it requires each time we connect to it for you (section 5) Security information, including your IP address, device identifier and browser details Legal obligation; Legitimate interests (helping HMRC and us prevent tax fraud)
Importing records from Xero, and letting apps you authorise use your data Data imported from Xero, connected apps, business and financial records Contract
Keeping accounts and the service secure: two-factor sign-in, limiting repeated sign-in attempts and contact messages, and keeping an audit log Account information, two-factor sign-in, security information Legitimate interests (protecting our customers and our service from misuse and fraud)
Billing: free trials, subscriptions and payments through Stripe Billing information, account information Contract
Sending service emails: confirming your email address, resetting your password, invitations to a business, and warnings before a read-only business is deleted Account information, business name Contract
Answering messages you send through our contact form Contact form messages Legitimate interests (replying to people who contact us); Contract, where you ask about your account
Running, monitoring and fixing the service Server and application logs Legitimate interests (keeping the service working and secure)
Keeping our own accounting and tax records Billing information Legal obligation
Meeting our legal duties, answering lawful requests from authorities, and establishing or defending legal claims Any of the information above that is relevant Legal obligation; Legitimate interests (protecting our legal rights)

We don’t send marketing emails, and we don’t sell your personal information. We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects on you.

5. HMRC fraud prevention data

HMRC requires software that connects to its Making Tax Digital services to send fraud prevention data every time it connects. HMRC uses this data to detect and prevent tax fraud and to protect taxpayers’ accounts. When you use AccountLayer to connect to HMRC, fetch information from it or submit to it, we send:

  • your public IP address and port, and when they were recorded;
  • the device identifier stored in the mtd_device_id cookie (see section 10);
  • your AccountLayer user identifier, which is the email address you sign in with;
  • your browser’s details: its user agent, any plugins it reports and its Do Not Track setting;
  • your screen size, colour depth and scaling, and your browser window size;
  • your timezone;
  • details of your two-factor sign-in: the type of check, when you completed it, and a reference that doesn’t reveal your codes or the secret behind them;
  • details of AccountLayer itself, such as its name, its version and our server’s public IP address.

A small script on AccountLayer’s signed-in pages measures the browser, screen and timezone details and keeps them in the mtd_fraud_signals cookie, so they are ready whenever a page connects to HMRC. Apart from these cookies, we don’t keep a separate copy of the fraud prevention data we send. HMRC handles it under its own privacy notice.

6. Who we share it with

Our suppliers

These companies handle personal information for us, under contracts that require them to protect it and to use it only to provide their services to us:

  • OVH hosts AccountLayer, its database and its files, in a data centre in London, UK.
  • Amazon Web Services delivers our emails through Amazon SES, in its London region. This includes the emails we send you and the copy of each contact form message that is sent to our own inbox.
  • Stripe processes payments. You enter your card details on Stripe’s pages, and we never see or store your full card number. Stripe also uses some payment information for its own purposes, such as preventing fraud and meeting its legal duties, under its own privacy policy.

Services you choose to connect

When you connect them, we exchange information with HMRC, Xero, CalloutWMS and other API apps you authorise, which handle your information under their own terms and privacy policies. For example, we send HMRC the returns and updates you submit, and we receive the records you import from Xero. An app you authorise can use the AccountLayer data covered by the permissions you gave it until its access is revoked under Setup, Connected apps.

People in your business

People who belong to a business can see its records, depending on their role. Owners and accountants can also see the business’s activity log, which shows who did what and when.

Others, where necessary

  • Our professional advisers, such as lawyers, accountants and insurers, where they need it to advise or protect us.
  • HMRC, the police, courts, regulators and other authorities, where the law requires us to share it.
  • A buyer or successor, if we sell or reorganise all or part of our business. They would have to use your information in line with this policy.

We don’t sell your personal information to anyone.

7. International transfers

Our hosting and email delivery are in the UK. Stripe and Xero may process data outside the UK, including in the United States, under safeguards recognised by UK law, such as UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework, or the International Data Transfer Addendum. Their own privacy policies explain the safeguards they use.

8. How long we keep it

We keep personal information only for as long as we need it:

Information How long
A business’s records, including its tax identifiers, HMRC and Xero connections and imported files Kept for as long as the business has an active plan, or is in its 14-day free trial
A read-only business (one whose free trial or plan has ended) and everything in it Permanently deleted 12 months after it became read-only; owners are emailed 30 days and 7 days before. Deletion never happens less than 30 days after the first warning, or less than 7 days after the final warning, and choosing a plan before then stops it.
User accounts, including two-factor sign-in details and access you have given to connected apps Account deleted when you no longer belong to any business (for example, when the last business you belong to is deleted)
Audit log of sign-ins and important events, including IP addresses 13 months
Contact form messages 24 months
Emails waiting to be sent, or that couldn’t be sent, including copies of contact form messages Up to 30 days
Server and application logs 90 days
Our own billing and accounting records 6 years, as UK law requires

When a business is deleted, we delete its records, attached files, connection details and audit log entries. Our audit log keeps a short note that the business was deleted, with its name, and that note is removed after 13 months like other entries. Deletion is permanent and can’t be undone.

You’re responsible for keeping your own business and tax records for as long as HMRC requires. Export them before a business is deleted.

9. Your rights

You have these rights over your personal information. Some apply only in certain circumstances.

  • Access: to ask for a copy of the personal information we hold about you.
  • Rectification: to ask us to correct information that is wrong or incomplete.
  • Erasure: to ask us to delete your information. We may need to keep some of it, for example where the law requires us to.
  • Restriction: to ask us to limit how we use your information, for example while we check whether it is accurate.
  • Objection: to object to our use of your information where we rely on legitimate interests.
  • Data portability: to receive information you gave us in a structured, commonly used, machine-readable format, or to ask us to send it to another organisation. Owners and accountants can also download a business’s records as CSV files at any time, using Export data under Setup in AccountLayer.
  • Withdrawing consent: we don’t currently rely on consent, but if we ever ask for it, you can withdraw it at any time.

To make a request, use our contact form with the topic “Privacy or data request”, or write to us at our registered office. There’s normally no charge. We’ll respond within one month. If a request is complex, or you make several, we may need up to two more months, and we’ll tell you within the first month if so. We may need to check your identity before we act on a request, so that we don’t give your information to someone else.

For records we hold as a processor for a business (section 2), we’ll pass your request to the business that controls them, and help it respond.

10. Cookies

Cookies are small files that a website stores in your browser. AccountLayer uses these cookies:

Name Purpose How long
PHPSESSID Keeps you signed in during a visit, and carries short messages between pages (for example, confirming that your contact message was sent). Ends when you close your browser
REMEMBERME Keeps you signed in if you leave “Remember me on this device” ticked when you sign in. You’ll still be asked for a code from your authenticator app. 2 weeks
mtd_device_id Identifies your device in the fraud prevention data HMRC requires (section 5). Set once you sign in. 10 years
mtd_fraud_signals Holds screen and browser details for HMRC’s fraud prevention data (section 5). Written on signed-in pages. 1 year, renewed each time you open a signed-in page
csrf-token_… Stops another website from submitting some of our forms, such as the contact form, without your knowledge. The name may start with __Host-. Removed once the form has been sent, or when you close your browser

All of these are strictly necessary, so we don’t ask for consent. We don’t use analytics or advertising cookies.

When you pay or manage your subscription, you use Stripe’s pages (Stripe Checkout and Stripe’s billing portal). Stripe Checkout sets its own cookies on Stripe’s site, under Stripe’s cookie policy.

11. How we keep it secure

  • Connections to AccountLayer are encrypted in transit (HTTPS).
  • Two-factor sign-in is required for every account.
  • Passwords are stored only as hashes. Authenticator app secrets and the access tokens for HMRC and Xero connections are encrypted, and backup codes are stored as keyed hashes.
  • Repeated failed sign-in attempts and wrong two-factor codes are limited.
  • Each business’s records are kept separate, and people can only do what their role in that business allows.
  • We keep an audit log of sign-ins and important account and business events.
  • Access tokens issued to connected apps expire after 30 minutes, and an app’s access can be revoked at any time.

No system is completely secure. If a breach of personal information is likely to put your rights and freedoms at risk, we’ll tell the Information Commissioner’s Office, and tell you where the law requires, as soon as we can.

12. Children

AccountLayer is for businesses and for people aged 18 or over. We don’t knowingly collect personal information from children through our website or service. If you think a child has given us their information, please contact us and we’ll delete it.

13. Complaints

If you’re unhappy with how we have handled your personal information, please contact us first, so we can try to put it right.

You also have the right to complain to the UK regulator, the Information Commissioner’s Office (ICO):

  • website: https://ico.org.uk
  • helpline: 0303 123 1113
  • post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

14. Changes to this policy

We may update this policy from time to time. If we make a material change, we’ll email account holders before it takes effect. The “Last updated” date at the top of this page shows when the policy last changed.