2.1 Purpose
The Processor processes Personal Data solely for the purpose of providing the Services to the Controller, specifically: enabling accountancy practices to view, review, correct, and export their clients' expense, income, and mileage records as submitted through the PocketReceipt mobile application; to review quarterly periods (including requesting corrections and marking quarters as reviewed); to send structured messages to clients; to request and receive financial documents; to view and download receipt images; to record and store AML Customer Due Diligence (CDD) information in fulfilment of the Controller's obligations under the Money Laundering Regulations 2017 (MLR 2017); and to maintain an immutable audit trail of accountant actions within the Dashboard for compliance and fraud prevention purposes.
2.2 Types of Personal Data
- Client names and email addresses
- Receipt data: store names, amounts, dates, categories (HMRC SA103F aligned), VAT details, payment methods, capital item status, business purpose notes
- Receipt images (where client has enabled accountant access), viewable and downloadable by the accountant via the Dashboard
- Mileage records: journey dates, start/end addresses, start/end coordinates and (for GPS-recorded trips) the journey polyline, purposes, distances, durations, and vehicle details
- Income records: amounts, dates, source labels, references, notes, and linked quarter. Where the client creates an income record by marking an in-app invoice as paid, the source label and reference will typically contain the name of the client's own customer and the invoice number.
- Financial summaries and aggregated data
- Business settings: VAT status, business type, accounting basis
- Scan usage data (monthly and daily counts)
- CIS (Construction Industry Scheme) data: contractor names, gross amounts, materials, deductions, net payments, and statement references (where applicable)
- Document transfer data: document type, month/year, notes, and transfer status. Document images are stored temporarily in Firebase Storage (auto-deleted after 30 days) and accessed by the accountant via time-limited signed URLs only.
- Onboarding situation data: employment status, cash income indicator, bank account type, vehicle ownership
- Accountant messages: message text, category, priority, timestamps, acknowledgement status
- Accountant corrections: pending edits to receipt categories or mileage purposes, stored temporarily until applied to the client's local data
- AML CDD data (where the Controller records identity verification information under MLR 2017): identity verification status, document type (Passport or Driving Licence), verification date, risk rating (Low, Standard, or High), PEP (Politically Exposed Person) check status, and source of funds declaration
- Audit log entries: a record of each accountant action within the Dashboard, including action type, affected client ID, detail, timestamp, and accountant email. Entries are immutable.
2.3 Data Subjects
The Data Subjects are the Controller's clients who use the PocketReceipt mobile application and who have actively consented to link their account to the Controller's Dashboard.
2.4 Duration
Processing of each client's data continues while that client's link to the Controller is active and the client holds a paid Professional subscription or VIP access. When the client's plan ends, processing for that client is paused for up to 30 days and then ends (Section 10). When a client unlinks, or the Controller's Dashboard account is closed, Section 10 applies.