Privacy Policy

Last updated: 27 September 2026

This policy explains how we collect, use and protect personal data when you visit our website, ask for a demo, use the Xorrix platform as a member of a firm, or receive a link from a firm that uses Xorrix. It also explains your rights under UK data protection law.

1. Who we are

Xorrix is a brand name of EMERALD PIN LTD, a company registered in England and Wales, company number 14326917, whose registered office is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“we”, “us”, “our”).

Xorrix is software for UK accountancy and tax advisory firms. For privacy questions or to exercise your rights, email info@xorrix.com.

2. Our two roles

  • We are the controller for personal data about website visitors, people who request a demo, users of the platform (the staff of our customer firms) for account, security and billing purposes, business contacts at our customers and suppliers, and our marketing.
  • We are a processor for the data that firms put into the platform about their own clients and contacts. The firm is the controller of that data and decides how it is used; we process it only on the firm’s instructions under a data processing agreement (Schedule 1 of our Terms of Service).

If you are a client of an accountancy or tax firm that uses Xorrix, your firm is responsible for your data. Please contact your accountant or adviser with questions or requests about it. If you contact us, we will pass your request to the firm.

3. What we collect

Website visitors

Our website does not use analytics, advertising or tracking cookies. When you visit, our hosting provider processes technical data needed to deliver the site and keep it secure, such as your IP address, browser and device type, the pages requested and the time of the request, in server logs.

Demo requests and enquiries

When you book a demo or contact us, we collect your name, work email, firm name, phone number if you give it, and your message, plus any later correspondence with you.

Platform users (staff of our customer firms)

  • Account data: your name, work email address, profile picture and account identifier from the sign-in provider you use (section 5), your firm, role and permissions, and who invited you.
  • Usage and security data: sign-in sessions, IP address and browser information, audit logs of significant actions (for example, creating, changing, signing or deleting records), and metadata about AI feature use (such as volume and timing, but not the content).
  • Work data: timesheet entries, tasks, notes, messages and other content you create. This forms part of your firm’s data, which we process for your firm.

Billing and contract contacts

Names, job titles and contact details of the people at our customers who sign contracts, receive invoices or manage the account, and records of invoices and payments.

Clients of our customer firms (we are the processor)

Firms upload and create data about their clients to deliver their services. Depending on the services, this can include names and contact details; company, shareholding and option information; employee and payroll data; tax references such as Unique Taxpayer References and National Insurance numbers; financial and sales transaction data; valuations; and documents. We process this only for the firm, as described in section 2.

People who receive links from a firm

Firms use Xorrix to send their clients links to view and sign proposals; complete intake questionnaires (for example for SEIS/EIS advance assurance, valuations, VAT and transfer pricing reviews); upload documents in response to requests; use a client portal and message the firm; sign agent authorisations and agreements; and view reports. When you use these links, we collect what you enter or upload, and technical data such as your IP address and browser. If you sign electronically, we record your signature together with the date and time, your IP address and browser information as evidence of signing. The firm that sent you the link is the controller of this data.

Where the data comes from

Mostly from you directly. Account data also comes from the sign-in provider you use when you sign in, and from your firm when it invites you. Firms may give us information about their clients and contacts, and may look up public company information from Companies House through the platform.

4. How we use it and our lawful bases

This section covers data for which we are the controller.

PurposeDataLawful basis
Delivering and securing the websiteTechnical data and server logsLegitimate interests: running a secure website
Responding to demo requests and enquiries, and following upEnquiry details and correspondenceLegitimate interests: responding to business enquiries and promoting our service to firms
Creating and managing user accounts, signing you in and providing the platformAccount data, usage dataContract, where you are our customer; otherwise legitimate interests in providing the service your firm has subscribed to
Keeping the platform secure, preventing abuse and investigating incidentsUsage and security data, audit logsLegitimate interests: security and fraud prevention; legal obligation to keep personal data secure
Metering AI and storage use, and improving reliability and performanceMetadata about usage (not content)Legitimate interests: operating and improving the service
Billing, contract administration and accounting recordsBilling and contract contact dataContract; legal obligation to keep accounting records
Service and account emails (such as invitations, notifications and changes to terms)Name, email addressContract or legitimate interests in running the service
Product news and marketing to business contactsName, work email, firmLegitimate interests; you can opt out at any time. Where the law requires consent, we will ask for it
Complying with law and responding to lawful requests; establishing or defending legal claimsAny relevant dataLegal obligation; legitimate interests

We do not sell personal data and we do not make decisions about individuals based solely on automated processing that have legal or similarly significant effects.

5. How you sign in

Platform users sign in through a third-party single sign-on provider, using an existing work account. When you do, the provider tells us your name, email address, profile picture and an account identifier, and confirms that your email address is verified. We use this only to sign you in and to show who you are within your firm’s account. We never receive or store your password, and we do not get access to your email, files, calendar or other data held with that provider. The provider’s handling of your data is governed by its own privacy policy. You can remove Xorrix’s access in your account settings with that provider, but you will then be unable to sign in.

6. AI and your data

  • AI features use models from carefully selected AI providers, which act as our sub-processors under contract.
  • We use these providers on terms under which they process a request only to return a response, and do not retain it or use it to train their models.
  • We do not use customer data to train third-party AI models.
  • Where a firm corrects the AI or records a house position, that learning is stored in the firm’s own account and used only for that firm. Our staff may create generalised guidance from firm-authored knowledge-base entries for all customers, but only after removing client names, figures and anything else that identifies a firm, client or individual.
  • AI output is a draft for a qualified professional at the firm to review. The firm, not Xorrix, is responsible for the advice it gives and for anything it submits to HMRC or other authorities.

7. Who we share it with

We use carefully selected service providers to run Xorrix, in the following categories: hosting and infrastructure, AI processing, email delivery, authentication and sign-in, and security and monitoring. They act on our instructions under written contracts that require them to protect personal data. Details of our sub-processors are provided to customers in their contract, and are available on request from info@xorrix.com.

We may also share personal data:

  • with the data store each firm provides for its own client data (see below);
  • with third-party services that your browser contacts when you use certain pages (for example, to record your IP address on an electronic signature record, or to load map data for some reports). These services receive your IP address;
  • with our professional advisers, such as lawyers, accountants and insurers;
  • with law enforcement, regulators, courts or other authorities where the law requires it or to protect our rights, users or the public;
  • with a buyer or investor, and their advisers, in connection with a sale, merger or reorganisation of our business, under confidentiality obligations.

Each firm that uses Xorrix stores the data about its clients in a data store that the firm owns and controls, not Xorrix. The firm can revoke our access to it at any time. We process that data only to provide the service to the firm, and we run no code in the firm’s data store. The credentials we use to access it are stored encrypted. We keep only the account and platform information needed to run the service, such as sign-in details, firms, users and invitations, plan and configuration, and records of usage and significant actions.

8. International transfers

Personal data is primarily processed in the UK and the European Economic Area (EEA). Some of our service providers may process personal data outside the UK and EEA.

Where personal data is transferred outside the UK or EEA, we make sure it is protected as the law requires, using appropriate safeguards such as UK adequacy regulations, the ICO’s International Data Transfer Agreement, or standard contractual clauses (with the UK Addendum), supported by a transfer risk assessment where required. Contact us for more information about the safeguards that apply.

9. How long we keep it

DataHow long
Website server logsAs set by our hosting provider, typically no more than 30 days
Demo requests and enquiries24 months after our last contact with you, unless you become a customer
Sign-in sessionsUp to 30 days, or until you sign out
User account data, audit logs and usage metadataWhile your firm’s account is active; deleted with the firm’s data after the contract ends (see below)
Billing, invoice and contract recordsSix years after the end of the financial year they relate to, to meet legal and tax obligations
Firms’ client dataHeld in the firm’s own data store for as long as the firm chooses. When the contract ends, it stays in the firm’s data store, and we delete our configuration for the firm and stop accessing it
Other firm data held in our own systemsAs the firm decides while the contract lasts. After it ends, the firm has 30 days to ask for a copy, and we then delete it from live systems within a further 30 days
Backups of our own systemsKept for a limited period; deleted data is removed from backups within 35 days of deletion from live systems
Backups of firms’ client dataGoverned by the firm’s own arrangements for its data store

We may keep data for longer where the law requires it or to deal with a legal claim.

10. How we protect it

  • Encryption in transit and at rest.
  • Invitation-only accounts, single sign-on, role-based permissions, and separation of each firm’s data.
  • Access controls based on least privilege. Credentials we use to access a firm’s data store are stored encrypted, and the firm can revoke our access at any time. Our staff can access a firm’s account only when the firm grants support access, which it can revoke.
  • Logging of significant actions, and protections against abuse.
  • Client-facing links that cannot be guessed, which the firm can revoke or replace at any time.
  • Regular, encrypted backups of our own systems.
  • Confidentiality obligations for everyone who works for us.

No system is completely secure. If a personal data breach affects data we process for a firm, we will tell the firm without undue delay so that it can meet its own obligations. Where we are the controller, we will notify the Information Commissioner’s Office and affected individuals when the law requires it.

11. Cookies and similar technologies

We use only cookies and browser storage that are strictly necessary to provide the service you ask for. We do not use analytics or advertising cookies, so we do not ask for cookie consent. If we ever add non-essential cookies, we will ask for your consent first.

NameWherePurposeDuration
xorrix.session_token and related xorrix.* cookiesPlatformKeep you signed in and protect sign-in (including the temporary state used during sign-in)Up to 30 days
xorrix_active_companyPlatformRemember which client you are working onSession
xorrix_switch_firm, xorrix_switch_editPlatform (Xorrix support staff only)Record which firm a support user is viewing, with the firm’s permissionSession
Browser local storagePlatformRemember display preferences, saved views and a running task timerUntil cleared

Our marketing website at xorrix.com sets no cookies.

12. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected or incomplete data completed;
  • have your data erased in certain circumstances;
  • restrict how we use your data in certain circumstances;
  • object to our use of your data where we rely on legitimate interests, and to direct marketing at any time;
  • data portability, where we process data you gave us by automated means on the basis of contract or consent;
  • withdraw consent at any time, where we rely on consent;
  • not be subject to decisions based solely on automated processing that significantly affect you.

To exercise a right, email info@xorrix.com. We may need to confirm your identity. We will respond within one month, which can be extended by up to two further months for complex requests. There is normally no fee. If your request concerns data a firm holds about you as its client, we will pass it to that firm, which is responsible for responding.

13. Children

Our website and platform are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children for our own purposes. Firms may occasionally hold data about minors in their clients’ records (for example, as shareholders); the firm is the controller of that data.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new “last updated” date and, for material changes, tell platform users by email or in the platform.

15. Contact and complaints

Email info@xorrix.com or write to EMERALD PIN LTD, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113.