Privacy Policy

Your data and how we use it

Introduction

This privacy policy applies between you, the User of this Website and Keepr, the owner and provider of this Website. Keepr takes the privacy of your information very seriously. This privacy policy applies to our use of any and all Data collected by us or provided by you in relation to your use of the Website. Please read this privacy policy carefully.

Who We Are

Keepr is a UK-based service that provides flexible invoicing and expense management tools for freelancers and small businesses. For the purposes of data protection legislation, Keepr is the "data controller" of your personal information.

Data We Collect

  1. We may collect and process the following data:
    1. Name, job title, and contact details
    2. Business or company information (e.g. logo, registered name)
    3. Client data and invoice/expense content
    4. Financial data (e.g. Stripe identifiers — not card details)
    5. Technical data such as IP address, browser type, and device info
    6. Usage data — pages visited, feature usage, and navigation flows
    7. Tax identifiers (e.g. National Insurance Number) when you use Making Tax Digital features
    8. Device and connection data collected for HMRC fraud prevention compliance (see "HMRC Making Tax Digital" section below)
    9. Questions and messages you send to our support chat and in-app AI assistant, the responses provided, and — for the in-app assistant — a record of any actions it carries out at your request (such as creating or editing an invoice, expense, or client)

Lawful Basis for Processing

We process your data in accordance with the UK GDPR under the following bases:

  • Contract: To provide our invoicing service to you
  • Consent: For optional features such as marketing emails or cookie tracking
  • Legitimate Interest: To improve and secure the service
  • Legal Obligation: For compliance with tax or financial laws

How We Use Your Data

  1. To create and manage your Keepr account
  2. To process payments (via third-party processors)
  3. To deliver support and service updates
  4. To comply with accounting and legal obligations
  5. To analyse usage and improve functionality
  6. To answer your questions and carry out tasks at your request through our support chat and in-app AI assistant, to improve our help content, and to keep a record of assistant interactions for support, service improvement, and security (including detecting misuse)
  7. To submit income and expense data to HMRC on your behalf via Making Tax Digital (when you opt in)

Data Retention

We retain personal data for as long as your account is active. After cancellation, we retain financial data (invoices, expenses, income records) for up to 6 years to comply with UK tax law. Other personal data is deleted within 3 months of cancellation unless required by law to retain it longer.

Assistant conversations: the messages you exchange with the in-app AI assistant are retained for up to 60 days — so your conversation history is available across your devices and to help us support, improve, and secure the feature — after which the conversation content is automatically deleted. A record of the actions the assistant carried out at your request is kept with the affected records (for example, the invoice or expense concerned) for the periods described above.

Making Tax Digital submissions: records of every quarterly update, annual submission, and final declaration sent to HMRC on your behalf — including the figures, the HMRC response, and HMRC’s correlation identifier — are retained for at least 6 years from the end of the relevant tax year, as required by UK tax record-keeping rules and HMRC’s software vendor terms of use.

Your Rights

Under UK GDPR, you have the right to:

  • Access your data
  • Rectify incorrect data
  • Request erasure
  • Restrict or object to processing
  • Withdraw consent (where applicable)
  • Data portability

To exercise any of these rights, email info@keepr.co.uk.

Third Parties and Transfers

We use third-party services such as:

  • HMRC (Making Tax Digital — income, expense, and tax data submitted on your behalf; fraud prevention headers required by law)
  • Stripe (payment processing and Stripe Connect for invoice payments)
  • Anthropic (the AI features — the assistant, receipt scanning, bank statement extraction, and our support chat. When you use one of these, the content it needs is sent to Anthropic's API so it can produce the answer. Depending on the feature that can include figures and descriptions from your records, client and project names, receipt photographs, and bank statement documents. It is used to generate your result and is not used to train their models. This processing takes place in the United States.)
  • SparkPost (email delivery — invoices, quotes, payment reminders and account emails, including the recipient's address and the contents of the message)
  • TrueLayer (open banking / bank account linking)
  • Google Analytics (website analytics, only with consent)
  • Google Ads (remarketing, only with consent)
  • Facebook / Meta Pixel (marketing analytics, only with consent)
  • 20i Web Hosting (UK shared hosting; origin servers physically located in the UK)
  • Cloudflare (DNS and content delivery; requests transit Cloudflare's global edge network on the way to our UK origin servers, but customer data is not persisted at the Cloudflare edge)

If we transfer your data outside the UK, we ensure it is done under legally valid mechanisms such as Standard Contractual Clauses.

Where Your Data Is Stored

All customer data — including invoices, expenses, time tracking entries, project records, and encrypted HMRC tokens — is stored on UK-based shared hosting infrastructure provided by 20i. Our database and application servers are physically located in the United Kingdom.

Inbound web requests are proxied through Cloudflare's global edge network for DNS resolution, TLS termination, and basic CDN caching of static assets. Cloudflare does not persist customer data — only short-lived caching of public assets — and customer requests for application logic are forwarded to our UK origin for processing.

Two things leave the UK, and only when you use the feature that needs them. Email you send through Keepr — invoices, quotes and reminders — is delivered by SparkPost. The AI features send the content they need to Anthropic in the United States: the assistant, receipt scanning, bank statement extraction, and the support chat. Nothing is sent to either unless you use that feature, and neither is used for AI training. Your records themselves continue to live on our UK infrastructure.

Cookies

Our site uses cookies to enhance your experience. These include:

  • Essential cookies: Required for functionality (session, CSRF protection)
  • Analytics cookies: To understand usage (Google Analytics, only with consent)
  • Marketing cookies: For remarketing (Google Ads, Facebook Pixel, only with consent)

You can manage cookie preferences through our cookie banner or your browser settings. Analytics and marketing cookies are only loaded after you accept via the cookie banner.

HMRC Making Tax Digital

If you choose to use Keepr's Making Tax Digital (MTD) features, we act as MTD-compatible third-party software to submit your income and expense data to HMRC on your behalf. This involves the following data processing:

Data shared with HMRC:

  • Your National Insurance Number (used to identify your HMRC account)
  • Income and expense totals derived from your Keepr records (submitted quarterly and in a final end-of-year declaration)
  • Your HMRC business ID (retrieved during the connection process)

HMRC fraud prevention headers:

HMRC legally requires all MTD software to collect and transmit fraud prevention data with every API call. This is not optional — it is a condition of using any MTD-compatible software. The data collected includes:

  • Your public IP address and port
  • Browser user agent string
  • Screen dimensions, colour depth, and window size
  • Device timezone
  • A device identifier (a random UUID stored in your browser)
  • Your Keepr user ID
  • Our server's public IP address

This data is transmitted directly to HMRC and is not stored by Keepr beyond the duration of the API request. For full details of HMRC's fraud prevention requirements, see HMRC's fraud prevention specification.

OAuth tokens:

When you connect your HMRC account, we store encrypted OAuth access and refresh tokens in our database. These tokens allow Keepr to communicate with HMRC on your behalf. Tokens are automatically refreshed and are deleted when you disconnect your HMRC account.

Lawful basis: We process this data under Contract (to provide the MTD service you have opted into) and Legal Obligation (fraud prevention headers are required by UK law).

Security

We take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal data. This includes HTTPS in transit, field-level encryption at rest for sensitive identifiers (including National Insurance numbers and HMRC OAuth tokens), hashed passwords, CSRF protection on state-changing endpoints, server-side input sanitisation, and access control. However, transmission over the internet is never completely secure.

Active sessions: For each login, we record the IP address, browser or app name, and time of last use so you can review and revoke active sessions from your Account page. This information is kept for as long as the session is active (up to 30 days) and is deleted when the session is revoked or expires. The lawful basis for this processing is Legitimate Interest (account security).

Security Incidents and Breach Notification

If we become aware of a personal data breach affecting your information, we will:

  • Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where the breach is likely to result in a risk to your rights and freedoms, as required by the UK General Data Protection Regulation.
  • Notify HMRC within 72 hours where the breach affects data we hold or process in connection with Making Tax Digital, in line with HMRC's Developer Hub Terms of Use.
  • Notify affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

We maintain an internal incident response process covering detection, triage, containment, notification, and post-incident review. Incident records are retained for at least 24 months for audit purposes.

Reporting a Security Issue (Responsible Disclosure)

If you discover a security vulnerability in Keepr — or have evidence of a security risk that affects our customers — we want to hear from you. Please email security@keepr.co.uk with:

  • A description of the issue and the potential impact
  • Steps to reproduce, if relevant
  • Your contact details (so we can acknowledge and follow up)

We commit to acknowledging valid security reports within 3 working days, keeping you updated as we investigate, and not pursuing legal action against good-faith security researchers who give us reasonable time to remediate before public disclosure. We do not currently operate a paid bug bounty programme, but we publicly credit researchers (with permission) where appropriate.

Third-Party Links

This website may link to other websites. We have no control over these and are not responsible for their content or privacy policies. You should read their policies separately.

Business Transfers

In the event Keepr is acquired or merged, your data may be transferred to the new owner in accordance with this policy.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted here and your continued use of the site will constitute acceptance.

Contact

If you have any questions or requests regarding this privacy policy, please contact us at info@keepr.co.uk.

Last updated: 28 August 2026