Privacy policy

How HAMILTONN LTD collects, uses, shares and protects information when providing AAA WebFiling.

Last updated: 4 September 2026.

Controller and service operator: HAMILTONN LTD, company number 15023569, registered office at Flat 1 117 Station Road, Edgware, England, HA8 7JG. AAA WebFiling is independent software and not part of Companies House.

Questions about this notice or requests concerning personal information can be sent by post to our registered office above. Signed-in users can also use the support-ticket system so that a request can be linked securely to the relevant account. Our contact page shows the current support routes available through the service.

1. Scope of this policy

This policy applies to the public AAA WebFiling website and the authenticated software service, including company portfolios, Companies House information and supported filings, HMRC VAT features where enabled, client forms and authority records, support, billing and related security and audit functions.

Our role under data-protection law can depend on the activity. HAMILTONN LTD acts as a controller for matters such as account administration, service security, billing, fraud prevention and our own legal obligations. Where a professional user uploads or manages information about its own clients and instructs us to process that information solely to provide the service, HAMILTONN LTD may also act as a processor on that user's behalf. The professional user remains responsible for determining whether it has authority and a lawful basis to provide client information to the service.

2. Information we collect or receive

Depending on the features used, we may process the following categories of information:

  • Account and identity information: name, email address, user role, account status, login and multi-factor-authentication records and other information needed to administer access.
  • Company and portfolio information: company number, company name, status, registered office, accounts and confirmation-statement dates, filing history, officers, persons with significant control, share information and other company records.
  • Filing credentials and identity-verification information: where a supported filing requires them, company authentication codes, Companies House personal codes, dates of birth and related filing identifiers. These are treated as filing credentials or protected operational data and should not be placed in public notes or support messages.
  • Client and authority information: contacts, addresses, client forms, uploaded documents, signatures, powers or authorities and related records where those features are used.
  • Transaction and billing information: plan, invoice, payment status, transaction references and billing history. Raw payment-card details are not intended to be stored in the AAA WebFiling application database when hosted checkout is used.
  • Support and communications: support tickets, messages, attachments and operational correspondence.
  • Technical and security information: IP address, request and session information, browser and device information, timestamps, audit events and security records used to operate and protect the service.

3. Information obtained from Companies House and other sources

Company profile, officer, person-with-significant-control, filing-history and related information may be obtained from Companies House or other public-register interfaces. Information being publicly available does not automatically mean it stops being personal data when it relates to an identifiable living person.

We may also receive information from a customer, accountant, company secretary, law firm, authorised agent, officer or other person using the service on behalf of a company. Users who provide information about another person must ensure they are permitted to do so.

4. HMRC VAT information

Where HMRC VAT features are enabled, AAA WebFiling connects to HMRC only after the relevant user completes the HMRC authorisation process for the VAT registration number concerned. Depending on the authorised functions, the service may process the VAT registration number, HMRC authorisation metadata, VAT obligations, VAT return figures, submitted returns, liabilities, payments, customer information, submission receipts, correlation references and audit records.

HMRC OAuth access and refresh tokens are sensitive credentials. The application is designed to store these using encrypted application fields and not expose them in ordinary page output, logs or customer-facing records.

5. HMRC fraud-prevention information

HMRC requires software using the VAT Making Tax Digital API to send specified fraud-prevention information. When an authorised HMRC VAT request is made through our browser-based service, information sent to HMRC can include:

  • the connection method used by the software;
  • browser user-agent information;
  • a persistent device identifier generated for the browser;
  • public IP address, source port and relevant timestamps;
  • screen dimensions, scaling factor, colour depth and browser-window size;
  • timezone information;
  • AAA WebFiling user identifiers associated with the request;
  • multi-factor-authentication information, including the authentication type, time and a non-plain-text unique reference;
  • server/vendor forwarding information, public server IP, product name and product version; and
  • other fraud-prevention data required by HMRC for the relevant connection method where applicable.

The browser device identifier may be kept in browser local storage so the same browser can be recognised consistently for HMRC fraud-prevention purposes. We do not use this HMRC device identifier for advertising. HMRC receives and processes fraud-prevention information under its own legal responsibilities and privacy arrangements.

6. Why we use personal information and our lawful bases

We use personal information only where we have a lawful basis appropriate to the activity. Depending on the context, this can include:

  • Contract: to create and administer an account, provide requested software functions, process billing, provide support and carry out a filing or data-retrieval instruction.
  • Legal obligation: where processing or retention is required to meet applicable accounting, tax, legal, regulatory or record-keeping obligations.
  • Legitimate interests: to operate and secure the service, prevent fraud and misuse, maintain audit evidence, troubleshoot failures, improve reliability and protect HAMILTONN LTD, customers and public-authority integrations. We consider the impact on individuals before relying on this basis.
  • Consent: where we specifically ask for consent for an optional activity and consent is the appropriate legal basis. An HMRC OAuth authorisation is also the technical permission that enables the software to access the HMRC functions approved by the user; it is not automatically the same thing as consent as a UK GDPR lawful basis.

7. WhatsApp communications

Where a user has provided a WhatsApp number, opted in, and the relevant account and platform permissions allow the feature, AAA WebFiling may use the Meta WhatsApp Business Platform to send authorised service communications such as filing, support, security or billing notifications. Information transmitted for this purpose can include the destination phone number, an approved message template and the information needed to populate that template. Meta may also send delivery, read, failure and inbound-message webhook events back to AAA WebFiling.

WhatsApp is optional. Users can withdraw their WhatsApp preference through the service where that control is available. Withdrawing WhatsApp consent does not prevent us using another lawful communication method where a message is necessary for the service or a legal obligation.

8. Who we share information with

We share information only where necessary for the service, a user instruction, security or a legal requirement. Recipients can include:

  • Companies House for supported company-information and filing functions;
  • HMRC for authorised VAT API functions and required fraud-prevention data;
  • hosting and infrastructure providers used to operate the service, including Hamiltonn-managed IONOS/Plesk infrastructure;
  • payment providers, including Stripe where hosted payment functions are enabled;
  • email, communications and electronic-signature providers where a user chooses a feature that requires them;
  • professional advisers, auditors, insurers, law-enforcement bodies or regulators where disclosure is reasonably necessary or legally required.

We do not sell customer tax records or give advertisers access to customer VAT return data.

9. Hosting and international transfers

The primary AAA WebFiling application is deployed on Hamiltonn-managed IONOS/Plesk infrastructure. We do not make a blanket promise that every backup, email, payment, signature, communications or other third-party processing operation remains in one country. Some service providers may process information outside the United Kingdom.

Where a transfer of personal data is restricted by UK data-protection law, HAMILTONN LTD will assess the transfer and use an appropriate lawful transfer mechanism or safeguard where required. Further information about the categories of service provider used for a particular feature can be requested through the contact page.

10. Retention

We keep information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, tax, security, dispute-resolution and evidential requirements. The criteria differ by record type:

  • account and portfolio information is generally retained while the account or business relationship remains active and for a reasonable period afterwards;
  • filing, VAT submission, receipt, billing and audit evidence may be retained for the period reasonably needed to meet statutory record-keeping, accounting, tax, limitation and dispute requirements;
  • HMRC tokens are replaced, revoked or cease to be usable when authorisation is refreshed, revoked or otherwise ends, subject to technical and audit requirements;
  • security and diagnostic records are retained according to operational need and the seriousness of the event;
  • documents and client records may be retained until deletion, account closure or the end of a required professional or statutory retention period.

Where a fixed retention period is not appropriate, we use the criteria above and periodically review whether continued retention remains necessary.

11. Security

Controls used by the current service include HTTPS, authenticated access controls, time-limited email login verification, request throttling, encrypted storage for selected sensitive fields, server-side validation, audit records and separate safety gates for higher-risk filing integrations. More detail is available on our security page. No internet or cloud service can guarantee absolute security.

12. Cookies, sessions and browser storage

The service uses cookies or equivalent browser storage that are necessary for functions such as authentication, session security and request protection. The HMRC VAT browser workflow can also use local storage for the persistent device identifier described above. At the date of this notice, the public website does not intentionally use advertising cookies. If non-essential analytics or advertising technologies are introduced, this notice and any required consent mechanism will be updated.

13. Automated decisions

AAA WebFiling does not currently use personal information to make solely automated decisions that produce legal or similarly significant effects on an individual. Automated validation and security controls may block an invalid, unsafe or unauthorised request before it is sent to an external authority.

14. Your data-protection rights

Depending on the processing and lawful basis, you may have rights to request access, correction, erasure, restriction, portability or other action in relation to your personal information. Where processing is based on consent, you may withdraw that consent. These rights are subject to statutory conditions and exemptions.

Your right to object: where we rely on legitimate interests, you may object to that processing. We will consider the objection and stop the processing where the law requires us to do so.

To exercise a right, write to HAMILTONN LTD at the registered office shown at the top of this notice or, if you have an account, use the signed-in support system. We may need to verify identity and authority before disclosing or changing protected account, company or tax information.

15. Complaints

If you are concerned about how we use personal information, please contact HAMILTONN LTD first so we can investigate. You also have the right to complain to the Information Commissioner's Office. The ICO can be contacted at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, or through its website.

16. Children

AAA WebFiling is designed for companies, business owners and professional or authorised users, not for direct use by children. A statutory or client record may nevertheless contain information relating to a younger person where that information is lawfully required for the relevant business or filing purpose.

17. Changes to this policy

We review this policy when the service, integrations or legal requirements change. Material new uses of personal information will be reflected in an updated notice before or when the new processing begins, as required by law. The date at the top identifies the current published version.