Your data, protected

Privacy Policy

Last updated 27 June 2026

This policy explains how MediCalc Financial Services Ltd(“MediCalc”, “we”, “us”) collects, uses, stores and protects your personal data, and the rights you have under the UK GDPR and the Data Protection Act 2018. It applies to our website and our secure client portal.

We are the data controller for the personal data described below. If you have any questions, contact us at compliance@medicalc.co.uk.

Who we are

MediCalc Financial Services Ltd (Companies House registration 17192172), registered at 18 Santers Lane, Potters Bar, EN6 2BU. We are a CIMA Practising Certificate Holder. Our registration with the Information Commissioner's Office (ICO) is in progress.

The personal data we collect

Depending on how you interact with us, we may collect:

  • Enquiry / quote data— your name, email, phone number, business type, company/practice name, expected turnover, how you keep records, the service you're interested in, and anything you write in your message.
  • Client account data (if you become a client) — contact and company details, and information needed to provide our services: financial records, invoices, transactions, documents you upload, NHS pension and tax information, and identity/AML verification (KYC) data.
  • Bank transaction data — if you connect a bank account via Open Banking, transaction data we use to keep your books reconciled (with your explicit consent, which you can withdraw).
  • Technical data — strictly-necessary session cookies that keep you logged in, and basic server logs. We do not use advertising or analytics trackers.

How we use your data, and our lawful basis

PurposeLawful basis (UK GDPR Art. 6)
Responding to your enquiry / preparing a quoteLegitimate interests / steps prior to a contract
Providing accountancy, tax, payroll and pension-analysis servicesPerformance of a contract
Meeting legal and regulatory duties (HMRC, Companies House, anti-money-laundering)Legal obligation
Verifying identity (AML/KYC)Legal obligation
Open Banking bank-feed connectionConsent (withdrawable at any time)
Keeping our records and securing our systemsLegitimate interests

We only collect the minimum data needed for each purpose, and we do not use your data for automated decision-making or profiling.

Who we share data with (sub-processors)

We never sell your data. We share it only with trusted providers who process it on our behalf, under contract, to deliver our service:

  • Neon — secure database hosting (data stored in the UK/EU region).
  • Vercel — website and application hosting.
  • names.co.uk — our email provider, used to correspond with you.
  • Resend — transactional email delivery (e.g. notifying us of your enquiry).
  • Anthropic — AI used to read text from documents you upload (OCR). Only the document content needed for that task is processed.
  • Our Open Banking provider — a regulated account-information provider used only if you choose to connect a bank account, to retrieve the transaction data needed to keep your books reconciled.

We also share data with HMRC, Companies House and other authorities where required by law, and with our professional regulator (CIMA) where applicable. Some providers may process data outside the UK; where they do, appropriate safeguards (such as UK International Data Transfer Agreements or adequacy decisions) are in place.

How long we keep your data

We keep personal data only as long as necessary for the purpose it was collected, and to meet our legal obligations:

  • Enquiries that don't become clients — kept for up to 12 months, then deleted.
  • Client records — kept for the duration of our engagement and then for the period required by law and our professional obligations (typically 6–7 years for accounting and tax records, and 5 years after the end of the relationship for AML records).

Specific retention periods will be confirmed in your engagement letter.

Your rights

Under UK GDPR you have the right to:

  • be informed about how your data is used (this policy);
  • request a copy of the data we hold about you (right of access);
  • have inaccurate data corrected (rectification);
  • request deletion of your data where there's no legal reason to keep it (erasure);
  • restrict or object to certain processing;
  • request your data in a portable format (data portability);
  • withdraw consent at any time, where we rely on consent.

To exercise any of these, email compliance@medicalc.co.uk. We will respond within one month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk), though we'd ask you to contact us first so we can put things right.

How we protect your data

Your data is encrypted in transit (HTTPS) and sensitive information (such as AML/KYC and uploaded documents) is encrypted at rest. Access to the client portal is protected by individual logins, and your data is only ever visible to you and your accountant — never to other clients. We keep an audit trail of access to sensitive records.

Cookies

We use only strictly-necessary cookies— a secure session cookie that keeps you signed in to the portal. These are exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR) because the service can't function without them. We do not use advertising, analytics or third-party tracking cookies, so there is no cookie banner to accept.

Changes to this policy

We may update this policy from time to time. The “last updated” date at the top shows when it was last reviewed. Material changes affecting how we use your data will be communicated to clients directly.