Privacy Policy
Last updated: 6 August 2026
1. Who We Are
BureauFlow Limited (“we”, “us”, “our”) is the data controller responsible for your personal data. We are a company registered in England and Wales (company number 17378706), providing a payroll bureau management platform (“the Service”). For any data protection queries, contact us at support@bureauflow.co.uk.
2. What Data We Collect
We collect and process the following categories of personal data:
Account Data
Your name, email address, and password (hashed) when you register for an account.
Profile Data
Your profile photo (optional), display name, and account preferences.
Client Data
Information you enter about your payroll clients, including company names, PAYE references, contact details, payroll configurations, and employee counts. This data is entered and controlled by you.
Usage Data
Information about how you interact with the Service, including pages visited, features used, and timestamps of activity.
Technical Data
IP address, browser type, device information, and cookies (see Section 10).
3. How We Use Your Data
- Providing and maintaining the Service, including user authentication and data storage
- Sending you important service notifications (e.g., security alerts, changes to terms)
- Sending payroll deadline reminders and notifications you have opted into
- Improving the Service based on usage patterns and feedback
- Processing payments for paid tier subscriptions
- Responding to your support requests and enquiries
- Complying with legal obligations
4. Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), we process your data on the following legal bases:
Contract (Article 6(1)(b))
Processing necessary to perform our contract with you (providing the Service).
Legitimate Interests (Article 6(1)(f))
Processing necessary for our legitimate interests, such as improving the Service, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
Consent (Article 6(1)(a))
Where you have given specific consent, such as opting into marketing communications. You may withdraw consent at any time.
Legal Obligation (Article 6(1)(c))
Where we need to process data to comply with a legal obligation.
5. Third-Party Processors
We use the following third-party services to operate the Service. Each processes data on our behalf under appropriate data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Vercel | Application hosting and deployment | Global CDN (EU primary) |
| Stripe | Payment processing (paid tier only) | US/EU |
| Resend | Transactional email delivery | US |
We may update this list from time to time. The current list is always available on this page.
6. Our Role: Controller and Processor
For the personal data described in Section 2 that relates to you as a user of the Service (account, profile, usage, and technical data), BureauFlow Limited acts as the data controller.
For client and employee data that you enter into the Service in the course of running your payroll practice, you (or your organisation) are the data controller and BureauFlow Limited acts as a data processor, processing that data only on your documented instructions in order to provide the Service. A Data Processing Agreement is available upon request for customers requiring one — contact support@bureauflow.co.uk.
7. AI and Automated Processing
The Service includes Penny, an AI assistant that answers questions about the data you hold in the Service. When you use Penny, the content of your query and relevant data from your account may be processed by AI infrastructure providers engaged under contract as sub-processors, solely to generate a response to you. This data is not used to train third-party AI models.
We do not make decisions based solely on automated processing that produce legal effects concerning you or that similarly significantly affect you.
8. Data Storage and Security
Your data is stored securely using industry-standard encryption. All data is encrypted in transit (TLS 1.2+) and at rest. Database access is protected by Row Level Security policies that ensure you can only access data belonging to your own account or organisation.
We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These include access controls, regular security reviews, and secure development practices.
9. Data Breach Notification
If a personal data breach occurs, we will assess its risk to individuals and, where required by applicable law, notify the supervisory authority (the Information Commissioner’s Office) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to affected individuals, we will inform them without undue delay.
10. Cookies
Essential Cookies
Required for authentication and security. These cannot be disabled as the Service will not function without them.
Preference Cookies
Store your settings such as theme preference (light/dark mode). These improve your experience but are not strictly necessary.
We do not use advertising cookies or third-party tracking cookies. We do not sell your data to advertisers or data brokers.
11. Your Rights Under GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”)
- Right to Data Portability: Request your data in a structured, machine-readable format
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at support@bureauflow.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
12. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you close your account, we will delete your data within 90 days, except where we are required to retain it for legal or regulatory purposes.
Client data you enter into the Service is deleted when you delete it or when your account is closed. We do not retain backups of deleted data beyond our standard backup rotation period (30 days).
13. International Transfers
Some of our third-party processors (see Section 5) are based outside the UK and EU. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the Information Commissioner’s Office, and adequacy decisions where applicable.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the Service. The “Last updated” date at the top of this page indicates when the policy was last revised.
For any privacy-related questions or concerns, contact our data protection team at support@bureauflow.co.uk.