Legal
Privacy Notice
Last updated: 7 October 2026
This notice describes the actual free, invite-only Simple Self-Employed beta. It does not claim final UK GDPR compliance and should receive professional review before external beta access is enabled.
1. Who is responsible
Simple Self-Employed is a trading brand for a pre-incorporation project. Lockgate Solutions Ltd is an intended future company but is not currently incorporated and is not the current controller.
The natural-person or other current controller identity is awaiting operator and legal confirmation. That identity must be added before external beta access is enabled; it has not been replaced with a fictitious company.
Correspondence address: 4 Lockgate Mews, Manchester, M4 6GF, United Kingdom. Privacy and data-rights requests: privacy@simpleselfemployed.co.uk. Product support: support@simpleselfemployed.co.uk.
2. Information we use
Clerk processes account and authentication information, such as your email address, name, sign-in method, session information and security signals. Simple Self-Employed stores the Clerk user identifier plus available name and email details to keep each workspace separate.
Depending on how you use the beta, we store bank and card account labels, transaction dates, descriptions and amounts, categories, rules, income sources, PAYE and payslip figures, dividends, self-employed and property records, allowances, tax payments, student-loan plan information, tax estimates, notes, household-planning information and export metadata.
CSV files are parsed to show a preview and create normalised transaction records. The database retains the source filename and the normalised date, description, amount, account, duplicate key and resulting classification. It does not retain complete arbitrary source rows or unused CSV columns after import.
Payslip PDFs are processed to suggest fields for you to check; the PDF itself is not retained by the application. Accountant exports are generated when requested. They are not a complete subject-access export.
The normal profile does not store a National Insurance number. If you connect to HMRC development functionality, the separately supplied National Insurance number and OAuth tokens are stored in application-level encrypted form, with only the last four characters available for display.
Technical records may include request, security and error logs held by our providers. We do not use an analytics or advertising SDK in the beta.
3. Why we use information and lawful bases
We use account and financial information to provide the beta you request: creating a private workspace, importing and reviewing records, producing estimates and exports, and providing support. The intended lawful basis is performance of the beta service agreement.
We use limited technical, security and operational information to keep the service secure, diagnose faults, prevent misuse and improve reliability. The intended lawful basis is legitimate interests, balanced against the sensitivity of financial information.
We may process information to meet legal obligations or respond to lawful requests. We will seek consent where a future activity genuinely requires it. The operator must confirm this lawful-basis mapping with a professional adviser.
Automated calculations combine recorded information using configured tax rules. They produce planning estimates, not decisions with legal or similarly significant effects, and you can review and correct the inputs.
4. HMRC functionality
Production HMRC filing is not available to beta users. Separately enabled sandbox or development flows may send test or user-authorised information to HMRC APIs. Simple Self-Employed does not currently submit your production quarterly updates or tax return.
5. Service providers
Clerk provides authentication and identity services. Vercel hosts and runs the application and may hold runtime and security logs. Neon hosts the PostgreSQL database in AWS Europe (London), region eu-west-2. The current Neon project uses PostgreSQL 17 on the Free plan and displays six hours of project database history retention. That setting is not a promise that every provider copy or log is deleted after six hours.
HMRC receives information only when an applicable HMRC sandbox, development or future authorised production interaction is used, or where disclosure is legally required.
Provider subprocessors and processing locations can change. Some processing may occur outside the United Kingdom. Where restricted transfers occur, the relevant provider terms, data-processing agreements and transfer safeguards must be checked and maintained by the operator. Current contractual arrangements remain an operator confirmation item.
6. Browser storage
Clerk uses cookies and related storage needed for authentication, session continuity and security. HMRC OAuth uses a short-lived, secure state cookie during connection. HMRC fraud-prevention headers use a persistent device identifier where that integration is enabled.
Simple Self-Employed also stores selected tax-year, MTD-message and onboarding-session preferences in your browser. These are functional preferences, not advertising or analytics tracking. See the Browser storage notice for details and a control that clears Simple Self-Employed preferences without signing you out.
7. Retention
We keep active account and financial information while needed to provide the beta, unless you delete working records or request closure. Export metadata and provider logs are retained according to operational need and provider settings. We will not claim a fixed deletion period until provider, legal and security requirements have been confirmed.
Account closure is currently a verified manual process. Database history, logs and provider-held copies may take additional time to expire under provider controls. Real production HMRC submission evidence is outside the beta erasure procedure and needs a separately approved retention policy before production filing is enabled.
8. Security
Controls include authenticated workspace separation, encrypted HTTPS connections, managed hosting and database access controls. HMRC credentials and the HMRC National Insurance number use application-level encryption. Most other financial fields are not individually encrypted by the application, so we do not claim that everything stored is field-encrypted.
No online service can guarantee absolute security. Report a suspected security issue to support@simpleselfemployed.co.uk.
9. Your rights
Depending on the circumstances, UK data-protection law may give you rights of access, correction, erasure, restriction, objection and portability, and rights relating to consent and automated decision-making.
Email privacy@simpleselfemployed.co.uk to make a request or request account closure. We may need to verify your identity. These requests are handled manually; product exports are not represented as a complete subject-access response.
You can complain to the Information Commissioner's Office at ico.org.uk, although we would welcome the opportunity to address your concern first.
10. Changes and contact
We may update this notice as the beta, providers or legal operator change. Material changes will be communicated where appropriate. Privacy questions and rights requests: privacy@simpleselfemployed.co.uk.