Privacy Notice
Noviqent Accountancy — information for account holders and their clients' contacts
- Organisation
- Noviqent Ltd
- Company number
- 17232197
- ICO registration
- ZC225920
- Publication
- Public-facing
1. Who provides this Service
Noviqent Ltd provides Noviqent Accountancy. For the financial data a Customer enters about its own business (or, for an accountancy practice, its clients' businesses), the Customer is normally the data controller and Noviqent acts as its data processor, operating the Service on the Customer's instructions.
For account administration, billing, service security and the operation of the Noviqent Accountancy website itself, Noviqent acts as an independent controller.
2. Information processed
- Account details: name, email address, hashed password (or Google sign-in identifier).
- Organisation details: business name, VAT registration number, Companies House number, VAT scheme.
- Ledger data entered by the Customer: chart of accounts, journal entries, contacts, invoices, bills, credit notes.
- Bank data: statement lines imported by CSV/OFX upload, or, where connected, via a bank feed integration using the Customer's own bank credentials.
- Billing data: GoCardless customer and mandate references (Noviqent does not store bank account numbers directly — these are held by GoCardless).
- Usage and security information: login timestamps, IP address, and API request logs.
3. How the information is used
To provide the ledger, reporting and reconciliation functionality of the Service, including calculating VAT, Self Assessment and CIS figures from data the Customer enters.
To operate billing, including the 30-day free trial and recurring Direct Debit collection via GoCardless.
To maintain security, including detecting fraud, abuse or unauthorised access.
To communicate service updates — including when direct HMRC submission becomes available for a tax scheme the Customer uses.
4. HMRC submission and this Notice
The Service does not currently transmit any data to HMRC. Ledger and report data stays within Noviqent's own systems until the Customer (or their accountant) manually submits a return through HMRC's own services. Once direct HMRC submission (Making Tax Digital) is enabled for a Customer's organisation, this Notice will be updated to describe what is sent to HMRC, when, and under what authorisation (Government Gateway OAuth, granted directly by the Customer to HMRC — Noviqent never holds the Customer's HMRC login credentials).
5. Legal basis
Where Noviqent is the controller, the relevant lawful bases are performance of a contract (operating the Customer's account and billing), and legitimate interests (service security and fraud prevention). Where Noviqent is a processor for the Customer's own ledger data, the Customer determines its own lawful basis for that processing.
6. Sharing and sub-processors
- GoCardless — billing and Direct Debit collection.
- Cloud hosting infrastructure used to run the Service.
- Transactional email provider — sent only account, billing and notification messages, not ledger or financial data.
- Bank feed providers (once enabled), used only to retrieve statement data the Customer has authorised.
7. Retention
Ledger and financial data is retained for as long as the account remains active, and for a reasonable period afterwards to allow export, consistent with UK statutory record-keeping requirements for accounting records (generally at least 6 years). Account and billing records are retained in line with applicable tax and accounting law.
8. Your rights
Where you are the account holder, you can access, correct, export or request deletion of your data through the Service or by contacting Noviqent directly. Where your data appears in someone else's ledger (for example, as a contact on an invoice), requests should ordinarily be directed to that organisation as the data controller in the first instance.
9. Contact and complaints
Contact Noviqent at hello@noviqent.co.uk with any privacy question or request. You may also complain to the Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.