Privacy Policy

Last updated: 13 August 2026

This policy explains how we collect, use and protect personal data in connection with the website at auno.ai and with the Auno platform. It is written to be read by anyone: visitors to this website, staff at the accountancy practices that use Auno, and the clients of those practices whose information is held in the platform.

1. Who we are

Auno is provided by Whyfield Limited, a company registered in England and Wales under company number 08901591, whose registered office is at Whyfield, Building A, Ground Floor, Green Court, Truro Business Park, Threemilestone, Truro, Cornwall, TR4 9LF.

Data protection enquiries
contact@auno.ai, for the attention of Adam Stringer

We have not appointed a statutory Data Protection Officer, as we are not required to do so. Data protection enquiries are handled by the contact above.

2. The two roles we play

Our responsibilities differ depending on whose data is involved, and it is worth being precise about this.

We are the controller for personal data about visitors to this website, about the individuals who hold accounts with us, and about people who contact us directly. For that data, we decide why and how it is processed, and this policy is the notice that applies.

We are a processor for the personal data that a customer practice puts into the platform about its own clients, their officers and shareholders, and its own staff. The practice is the controller of that data: it decides what to collect and why, and its own privacy notice governs it. We act on the practice's instructions under the data processing agreement accepted within the product. If you are a client of a practice that uses Auno and you want to exercise your data protection rights, please contact that practice in the first instance; we will support them in responding.

3. Personal data we handle

Across both roles, the platform handles the following categories of personal data.

CategoryWhat it includes
Identity and contact dataNames, job titles, email addresses, telephone numbers and postal addresses of practice staff, their clients, and the officers and shareholders of those clients.
Account and authentication dataLogin credentials, authentication tokens, multi-factor codes, and records of sign-in activity.
Client and engagement recordsCompany and charity registration details, engagement scopes, services, checklists, compliance records and anti-money-laundering and customer due diligence records.
Financial dataQuotes, invoices, budgets, service schedules and billing configuration. We do not process payment card data.
Employment dataWork schedules, work locations, time sessions, skills, team membership and assignment records for the customer's own staff.
Communications contentWhere a customer connects a Microsoft 365 mailbox or calendar, the email and calendar content that the integration is authorised to read, write or send.
Documents and correspondenceLetters, document packs, forms, form submissions, signatures and generated PDFs.
Technical dataIP address, browser and device information, and usage and diagnostic logs.

We do not set out to collect special category data or data about criminal offences. However, where a practice connects a mailbox, the correspondence handled by that integration may incidentally contain such information. Practices are responsible for deciding whether to enable the integration and for the lawful basis on which they do so.

4. This website

This website is a set of static pages. It sets no cookies, runs no analytics or tracking, and asks you for no personal information. Our hosting provider records standard server logs, including IP addresses, which are used to operate and secure the site.

The site loads a web font from Google Fonts, which means your browser makes a request to Google's servers and Google will receive your IP address as part of that request.

If you email us, we will hold your message and contact details for as long as needed to deal with your enquiry and to keep a record of it.

5. Why we process personal data, and on what basis

Where we act as a processor, the lawful basis for the underlying processing is determined by the customer practice, not by us.

6. HMRC and Making Tax Digital

Auno connects to HMRC so that practices can act for their clients: to check VAT registrations, retrieve filing obligations, and make submissions under Making Tax Digital. Connecting to HMRC requires the practice to authorise Auno through HMRC's own sign-in and consent process.

HMRC requires software that connects to its APIs to transmit a set of fraud prevention headers with each request. These describe the device and connection originating the request, and HMRC uses them to detect and investigate fraudulent access to its services. Sending them is mandatory; we cannot make submissions on a practice's behalf without them. The headers we send include:

This information is sent to HMRC and is also retained by us in our service logs so that we can investigate submission problems. HMRC is an independent controller of the data it receives; its own privacy notice governs what it does with it.

7. Services you connect

Practices can connect Auno to the third-party services below. These connections are made deliberately by the practice, and data is exchanged under the permissions granted at the point of connection. Each of these organisations is an independent controller of the data it holds, and its own privacy notice applies.

ServiceWhat is exchanged
HM Revenue & CustomsMaking Tax Digital submissions, agent authorisations, VAT registration checks and filing obligations.
Companies HouseCompany, officer and shareholder information.
Charity CommissionRegistered charity information.
XeroAccounting data exchanged with a connected Xero organisation.
Microsoft 365Mail and calendar access, under the permissions granted when the mailbox is connected.

8. Artificial intelligence features

Some features use large language models supplied by third parties to draft text, extract information from documents, and answer questions about a practice's own records. Where a feature does this, the relevant content is sent to the model provider to generate a response.

We use providers on terms that prohibit them from using data submitted through their APIs to train their models. AI-generated output is a drafting aid: it is presented to a person to review, and it is not used to make automated decisions that produce legal effects or similarly significant effects for any individual.

9. Service providers

We use the following providers to run the service. They process personal data on our instructions, under contracts that impose confidentiality and security obligations.

ProviderPurposeLocation
Oracle Cloud InfrastructureApplication and database server hostingUnited Kingdom
CloudflareDNS, content delivery and object storage for uploaded filesUnited Kingdom and global network
NeonManaged PostgreSQL database hostingEuropean Economic Area
Twilio SendGridTransactional email deliveryUnited States
PostHogProduct analytics and session replay within the platform. Not used on this website.European Union
Google (Gemini API)AI-assisted featuresUnited States and European Economic Area
OpenAIAI-assisted features, including the guidance engineUnited States
GitHubHandling and tracking in-product support requestsUnited States

We may also disclose personal data to our professional advisers, or where we are required to do so by law, by a court, or by a regulator.

10. International transfers

Application and database hosting is in the United Kingdom and the European Economic Area. Some of the providers listed above are based in the United States. Where personal data is transferred outside the United Kingdom, we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or on UK adequacy regulations where they apply, and we assess the transfer for any additional safeguards required.

11. How long we keep data

Where we act as a processor, retention is set by the customer practice. On termination of a customer's agreement, we return or delete the data we hold for them within 90 days, subject to any retention we are required by law to apply.

Where we act as a controller, we keep account data for as long as the account is active and for a reasonable period afterwards, enquiry correspondence for as long as needed to deal with the enquiry and keep a record of it, and operational logs for a limited period for security and diagnostic purposes. Backups are retained on a rolling cycle and are overwritten in the ordinary course.

12. How we protect data

Data is encrypted in transit, and at rest by our hosting and database providers. Each customer's data is held in a separate database. Access within the platform is controlled by role, access by our staff is limited to those who need it to operate and support the service, and administrative access to production systems is restricted to a private network. We log activity within the platform, and we keep backups.

13. Your rights

Under the UK GDPR you have the right to ask for access to your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise these rights in relation to data we hold as a controller, write to contact@auno.ai. We will respond within one month. If your data is held in the platform by an accountancy practice, please contact that practice, as they are the controller.

14. Cookies

This website uses no cookies. The Auno platform uses cookies that are strictly necessary to keep you signed in and to keep the service secure. Analytics within the platform are described in section 9.

15. Complaints

If you are unhappy with how we have handled your personal data, please tell us first so that we can try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113.

16. Changes to this policy

We may update this policy from time to time. The version in force is the one published here, with the date shown at the top. Where a change is significant, we will take reasonable steps to notify affected customers.