Skip to main content
Back to home

Privacy Policy

Version 2.2 — Last updated: 29 June 2026

1. Introduction

Option To VAT Limited, trading as OneSixth ("we", "our", "us"), is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). This policy explains how we collect, use, share and safeguard your information.

This service is intended for use by UK-based accounting professionals and businesses. It is not intended for children, and we do not knowingly collect personal data relating to anyone under 18.

2. Controller, Processor and DPO

The data controller for our own administrative data (such as billing contacts and account creation) is Option To VAT Limited (company number 15668306; VAT registration number 523 3658 94), registered in England & Wales, with registered office at One Express C/O Beever And Struthers, 1 George Leigh Street, Manchester, M4 5DL, United Kingdom. We are registered with the UK Information Commissioner's Office under registration number ZC197273.

When we process your clients' or employees' personal data on your behalf as part of running margin VAT, TOMS or Partial Exemption calculations, we act as a processor and you act as the controller. Those activities are governed by our Data Processing Agreement (download PDF).

Our Data Protection Officer can be reached at dpo@onesixth.app. For data subject rights requests, email privacy@onesixth.app.

3. Information We Collect

  • Identity data: name, email, role, accounting platform user ID (Xero, QuickBooks Online, Sage, FreeAgent).
  • Account data: hashed credentials, OAuth tokens (encrypted), passkey identifiers, session metadata.
  • Accounting data (as processor): invoices, bills, journals, contacts and tax codes from your connected accounting platform necessary to compute and post margin VAT, TOMS and Partial Exemption adjustments.
  • HMRC VAT account data: where you connect an HMRC Making Tax Digital VAT account, your VAT obligations, returns, liabilities and payments, retrieved on your authority to support filing reconciliation and the VAT calendar.
  • Billing data: billing contact, subscription tier, invoice history. Card details are processed by Stripe; we never see your full card number.
  • Technical data: IP address, browser type, device information, referring URL, operational logs.
  • Support data: contents of your messages to our support team.

4. Lawful Basis for Processing

PurposeLawful basis (Art. 6 UK GDPR)
Provide the OneSixth service under your subscriptionContract
Authenticate users (email, SSO, passkeys)Contract
Service security, fraud prevention, abuse detectionLegitimate interests
Service-related communications (billing, security, important updates)Contract / legitimate interests
Optional analytics or marketing communicationsConsent
Maintain accounting and audit recordsLegal obligation

5. How We Use Your Data

  • Authenticate you via email/password, Google SSO, Xero SSO or passkeys.
  • Read and process accounting data from your connected platforms on your authority.
  • Calculate and post margin VAT, TOMS and Partial Exemption journal entries.
  • Manage firms, organisations, team members and roles.
  • Provide support and respond to enquiries.
  • Maintain audit logs to evidence compliance.

6. Data Sharing

We do not sell your personal data and we do not use your accounting data to train AI models. We share data only with:

  • Your connected accounting platforms (Xero, QuickBooks Online, Sage, FreeAgent) — to read records and post journals on your authority.
  • HMRC (HM Revenue & Customs) — where you connect an HMRC Making Tax Digital VAT account, we exchange OAuth tokens and read your VAT obligations, returns, liabilities and payments on your authority. HMRC is an independent controller of your VAT records.
  • Sub-processors listed at /sub-processors (hosting, billing, transactional email, CRM and error monitoring).
  • Analytics providers (PostHog, Google Analytics and Microsoft Clarity) — only after you accept analytics cookies (see section 11).
  • Error monitoring (Sentry) — to detect and diagnose faults, on the basis of our legitimate interest in a secure, reliable service (see section 11).
  • CRM (Airtable) — when you sign up to our newsletter, request beta access or contact us, we record your enquiry details in Airtable.
  • Professional advisers (lawyers, auditors) under confidentiality where strictly necessary.
  • Authorities where required by UK law or to protect our rights.

7. Retention

CategoryRetention period
Account & identity dataDuration of subscription + 12 months
VAT calculations, journals & audit logs6 years (HMRC record-keeping)
Billing records & invoices6 years (Companies Act / HMRC)
OAuth tokensUntil you disconnect the integration
Operational logsUp to 90 days
Marketing consent recordsUntil consent withdrawn + 24 months

You may request earlier deletion at any time, subject to legal retention obligations.

8. International Transfers

Your core application data is stored in the European Union. Our product analytics (PostHog Cloud EU) and error monitoring (Sentry EU region) are also hosted in the European Union. Some sub-processors and independent controllers process data in the United States — in particular Microsoft Clarity, Google Analytics and Airtable. Where transfers outside the UK occur, we rely on the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses (SCCs), or an applicable adequacy decision recognised by the UK government.

9. Security & Breach Notification

We implement appropriate technical and organisational measures, described on our Security page. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify affected individuals without undue delay.

10. Your Rights

Under UK GDPR, you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent at any time.

How to make a request. Email privacy@onesixth.app with the subject line "Data subject request" and tell us which right you wish to exercise. We may ask for proof of identity to protect your data.

Our response times. We acknowledge every request within 5 working days and substantively respond within one calendar month of verifying your identity, as required by Article 12(3) UK GDPR. We may extend by a further two months for complex or numerous requests and will tell you why.

Statutory retention overrides erasure. Where you ask us to erase data that we are legally required to keep — in particular VAT margin scheme records, TOMS workings, and posted journals retained for 6 years under HMRC rules — we will restrict processing to legal-obligation purposes only and complete erasure once the retention period expires. We explain this in our DPA.

Where we act as a processor on your behalf, requests from your end users should normally be directed to you as the controller; we will assist you in responding.

If you are unhappy with how we have handled your request, you may complain to the UK Information Commissioner's Office at ico.org.uk.

11. Cookies, analytics and error monitoring

See our Cookie Policy for full details. You can manage your preferences at any time on the Cookie Preferences page.

We use PostHog for product analytics to understand how the application is used and improve it. PostHog is hosted on PostHog Cloud EU (Frankfurt), so the data is stored in the European Union. When you are signed in we may associate analytics events with your user ID and email. PostHog runs across both our public website and the signed-in application, and we redact sensitive URL parameters (such as OAuth codes and tokens) before any URL is sent. It is only initialised after you accept analytics cookies.

We use Google Analytics 4 to measure traffic and understand how visitors find and use our site, with IP anonymisation enabled and sensitive URL parameters redacted. This is only collected after you accept analytics cookies. For more information, see Google's Privacy Policy and how Google uses data when you use its partners' sites.

We partner with Microsoft Clarity to capture how you use and interact with our public website through behavioural metrics, heatmaps and session replay, which we use to improve our products and services. To minimise data and protect confidentiality, Clarity runs only on public marketing, content and legal pages — never on the sign-in, sign-up or authenticated application screens — so your clients' financial data is never recorded. This website usage data is captured using first- and third-party cookies and other tracking technologies, and is only collected after you accept analytics cookies. For more information about how Microsoft collects and uses your data, see the Microsoft Privacy Statement.

We use Sentry for application error monitoring and performance diagnostics, hosted in Sentry's EU data region. Sentry receives error events, stack traces and browser/device metadata, and — when you are signed in — your user ID and email, so we can triage account-specific faults. We do not enable Sentry session replay. Error monitoring relies on our legitimate interest in keeping the service secure, stable and reliable rather than on cookie consent, and Sentry does not set cookies.

12. Automated decision-making

OneSixth performs automated VAT calculations from your data, but these are not "solely automated decisions producing legal effects" within the meaning of Article 22 UK GDPR — every calculation is reviewable and editable by you, and you remain responsible for the journal you post and the VAT return you submit.

13. Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the chance to address your concerns first.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email or in-app notification at least 30 days in advance where reasonably possible. The version number and effective date at the top of this page will always be current.