Privacy Policy
Last updated: 13 August 2026
This policy explains how we collect, use and protect personal data in connection with the website at auno.ai and with the Auno platform. It is written to be read by anyone: visitors to this website, staff at the accountancy practices that use Auno, and the clients of those practices whose information is held in the platform.
1. Who we are
Auno is provided by Whyfield Limited, a company registered in England and Wales under company number 08901591, whose registered office is at Whyfield, Building A, Ground Floor, Green Court, Truro Business Park, Threemilestone, Truro, Cornwall, TR4 9LF.
- Data protection enquiries
- contact@auno.ai, for the attention of Adam Stringer
We have not appointed a statutory Data Protection Officer, as we are not required to do so. Data protection enquiries are handled by the contact above.
2. The two roles we play
Our responsibilities differ depending on whose data is involved, and it is worth being precise about this.
We are the controller for personal data about visitors to this website, about the individuals who hold accounts with us, and about people who contact us directly. For that data, we decide why and how it is processed, and this policy is the notice that applies.
We are a processor for the personal data that a customer practice puts into the platform about its own clients, their officers and shareholders, and its own staff. The practice is the controller of that data: it decides what to collect and why, and its own privacy notice governs it. We act on the practice's instructions under the data processing agreement accepted within the product. If you are a client of a practice that uses Auno and you want to exercise your data protection rights, please contact that practice in the first instance; we will support them in responding.
3. Personal data we handle
Across both roles, the platform handles the following categories of personal data.
| Category | What it includes |
|---|---|
| Identity and contact data | Names, job titles, email addresses, telephone numbers and postal addresses of practice staff, their clients, and the officers and shareholders of those clients. |
| Account and authentication data | Login credentials, authentication tokens, multi-factor codes, and records of sign-in activity. |
| Client and engagement records | Company and charity registration details, engagement scopes, services, checklists, compliance records and anti-money-laundering and customer due diligence records. |
| Financial data | Quotes, invoices, budgets, service schedules and billing configuration. We do not process payment card data. |
| Employment data | Work schedules, work locations, time sessions, skills, team membership and assignment records for the customer's own staff. |
| Communications content | Where a customer connects a Microsoft 365 mailbox or calendar, the email and calendar content that the integration is authorised to read, write or send. |
| Documents and correspondence | Letters, document packs, forms, form submissions, signatures and generated PDFs. |
| Technical data | IP address, browser and device information, and usage and diagnostic logs. |
We do not set out to collect special category data or data about criminal offences. However, where a practice connects a mailbox, the correspondence handled by that integration may incidentally contain such information. Practices are responsible for deciding whether to enable the integration and for the lawful basis on which they do so.
4. This website
This website is a set of static pages. It sets no cookies, runs no analytics or tracking, and asks you for no personal information. Our hosting provider records standard server logs, including IP addresses, which are used to operate and secure the site.
The site loads a web font from Google Fonts, which means your browser makes a request to Google's servers and Google will receive your IP address as part of that request.
If you email us, we will hold your message and contact details for as long as needed to deal with your enquiry and to keep a record of it.
5. Why we process personal data, and on what basis
- To provide the platform to our customers, and to administer accounts and support. Where you are our customer this is necessary for the performance of our contract with you; otherwise it rests on our legitimate interest in operating and supporting our service.
- To keep the service secure and reliable, including logging, diagnostics, backups and abuse prevention. This rests on our legitimate interest in protecting our service and the data in it.
- To improve the product, using analytics within the platform. This rests on our legitimate interest in understanding how the product is used. It does not apply to this website.
- To meet legal and regulatory obligations, including the requirements HMRC places on software used to make tax submissions.
- To respond to enquiries sent to us. This rests on our legitimate interest in answering people who contact us.
Where we act as a processor, the lawful basis for the underlying processing is determined by the customer practice, not by us.
6. HMRC and Making Tax Digital
Auno connects to HMRC so that practices can act for their clients: to check VAT registrations, retrieve filing obligations, and make submissions under Making Tax Digital. Connecting to HMRC requires the practice to authorise Auno through HMRC's own sign-in and consent process.
HMRC requires software that connects to its APIs to transmit a set of fraud prevention headers with each request. These describe the device and connection originating the request, and HMRC uses them to detect and investigate fraudulent access to its services. Sending them is mandatory; we cannot make submissions on a practice's behalf without them. The headers we send include:
- a device identifier generated by Auno for the browser in use;
- the public IP address and port from which the request originated, and the timestamp at which it was observed;
- the screen resolution, colour depth, scaling factor and browser window size of the device;
- the local timezone of the device;
- the identifier of the Auno user making the request, and the connection method used;
- the public IP address of our own servers and the details of any forwarding between them.
This information is sent to HMRC and is also retained by us in our service logs so that we can investigate submission problems. HMRC is an independent controller of the data it receives; its own privacy notice governs what it does with it.
7. Services you connect
Practices can connect Auno to the third-party services below. These connections are made deliberately by the practice, and data is exchanged under the permissions granted at the point of connection. Each of these organisations is an independent controller of the data it holds, and its own privacy notice applies.
| Service | What is exchanged |
|---|---|
| HM Revenue & Customs | Making Tax Digital submissions, agent authorisations, VAT registration checks and filing obligations. |
| Companies House | Company, officer and shareholder information. |
| Charity Commission | Registered charity information. |
| Xero | Accounting data exchanged with a connected Xero organisation. |
| Microsoft 365 | Mail and calendar access, under the permissions granted when the mailbox is connected. |
8. Artificial intelligence features
Some features use large language models supplied by third parties to draft text, extract information from documents, and answer questions about a practice's own records. Where a feature does this, the relevant content is sent to the model provider to generate a response.
We use providers on terms that prohibit them from using data submitted through their APIs to train their models. AI-generated output is a drafting aid: it is presented to a person to review, and it is not used to make automated decisions that produce legal effects or similarly significant effects for any individual.
9. Service providers
We use the following providers to run the service. They process personal data on our instructions, under contracts that impose confidentiality and security obligations.
| Provider | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Application and database server hosting | United Kingdom |
| Cloudflare | DNS, content delivery and object storage for uploaded files | United Kingdom and global network |
| Neon | Managed PostgreSQL database hosting | European Economic Area |
| Twilio SendGrid | Transactional email delivery | United States |
| PostHog | Product analytics and session replay within the platform. Not used on this website. | European Union |
| Google (Gemini API) | AI-assisted features | United States and European Economic Area |
| OpenAI | AI-assisted features, including the guidance engine | United States |
| GitHub | Handling and tracking in-product support requests | United States |
We may also disclose personal data to our professional advisers, or where we are required to do so by law, by a court, or by a regulator.
10. International transfers
Application and database hosting is in the United Kingdom and the European Economic Area. Some of the providers listed above are based in the United States. Where personal data is transferred outside the United Kingdom, we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on UK adequacy regulations where they apply, and we assess the transfer for any additional safeguards required.
11. How long we keep data
Where we act as a processor, retention is set by the customer practice. On termination of a customer's agreement, we return or delete the data we hold for them within 90 days, subject to any retention we are required by law to apply.
Where we act as a controller, we keep account data for as long as the account is active and for a reasonable period afterwards, enquiry correspondence for as long as needed to deal with the enquiry and keep a record of it, and operational logs for a limited period for security and diagnostic purposes. Backups are retained on a rolling cycle and are overwritten in the ordinary course.
12. How we protect data
Data is encrypted in transit, and at rest by our hosting and database providers. Each customer's data is held in a separate database. Access within the platform is controlled by role, access by our staff is limited to those who need it to operate and support the service, and administrative access to production systems is restricted to a private network. We log activity within the platform, and we keep backups.
13. Your rights
Under the UK GDPR you have the right to ask for access to your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise these rights in relation to data we hold as a controller, write to contact@auno.ai. We will respond within one month. If your data is held in the platform by an accountancy practice, please contact that practice, as they are the controller.
14. Cookies
This website uses no cookies. The Auno platform uses cookies that are strictly necessary to keep you signed in and to keep the service secure. Analytics within the platform are described in section 9.
15. Complaints
If you are unhappy with how we have handled your personal data, please tell us first so that we can try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113.
16. Changes to this policy
We may update this policy from time to time. The version in force is the one published here, with the date shown at the top. Where a change is significant, we will take reasonable steps to notify affected customers.