Privacy Policy
Last updated: 27 September 2026
This policy explains how we collect, use and protect personal data when you visit our website, ask for a demo, use the Xorrix platform as a member of a firm, or receive a link from a firm that uses Xorrix. It also explains your rights under UK data protection law.
1. Who we are
Xorrix is a brand name of EMERALD PIN LTD, a company registered in England and Wales, company number 14326917, whose registered office is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“we”, “us”, “our”).
Xorrix is software for UK accountancy and tax advisory firms. For privacy questions or to exercise your rights, email info@xorrix.com.
2. Our two roles
- We are the controller for personal data about website visitors, people who request a demo, users of the platform (the staff of our customer firms) for account, security and billing purposes, business contacts at our customers and suppliers, and our marketing.
- We are a processor for the data that firms put into the platform about their own clients and contacts. The firm is the controller of that data and decides how it is used; we process it only on the firm’s instructions under a data processing agreement (Schedule 1 of our Terms of Service).
If you are a client of an accountancy or tax firm that uses Xorrix, your firm is responsible for your data. Please contact your accountant or adviser with questions or requests about it. If you contact us, we will pass your request to the firm.
3. What we collect
Website visitors
Our website does not use analytics, advertising or tracking cookies. When you visit, our hosting provider processes technical data needed to deliver the site and keep it secure, such as your IP address, browser and device type, the pages requested and the time of the request, in server logs.
Demo requests and enquiries
When you book a demo or contact us, we collect your name, work email, firm name, phone number if you give it, and your message, plus any later correspondence with you.
Platform users (staff of our customer firms)
- Account data: your name, work email address, profile picture and account identifier from the sign-in provider you use (section 5), your firm, role and permissions, and who invited you.
- Usage and security data: sign-in sessions, IP address and browser information, audit logs of significant actions (for example, creating, changing, signing or deleting records), and metadata about AI feature use (such as volume and timing, but not the content).
- Work data: timesheet entries, tasks, notes, messages and other content you create. This forms part of your firm’s data, which we process for your firm.
Billing and contract contacts
Names, job titles and contact details of the people at our customers who sign contracts, receive invoices or manage the account, and records of invoices and payments.
Clients of our customer firms (we are the processor)
Firms upload and create data about their clients to deliver their services. Depending on the services, this can include names and contact details; company, shareholding and option information; employee and payroll data; tax references such as Unique Taxpayer References and National Insurance numbers; financial and sales transaction data; valuations; and documents. We process this only for the firm, as described in section 2.
People who receive links from a firm
Firms use Xorrix to send their clients links to view and sign proposals; complete intake questionnaires (for example for SEIS/EIS advance assurance, valuations, VAT and transfer pricing reviews); upload documents in response to requests; use a client portal and message the firm; sign agent authorisations and agreements; and view reports. When you use these links, we collect what you enter or upload, and technical data such as your IP address and browser. If you sign electronically, we record your signature together with the date and time, your IP address and browser information as evidence of signing. The firm that sent you the link is the controller of this data.
Where the data comes from
Mostly from you directly. Account data also comes from the sign-in provider you use when you sign in, and from your firm when it invites you. Firms may give us information about their clients and contacts, and may look up public company information from Companies House through the platform.
4. How we use it and our lawful bases
This section covers data for which we are the controller.
| Purpose | Data | Lawful basis |
|---|---|---|
| Delivering and securing the website | Technical data and server logs | Legitimate interests: running a secure website |
| Responding to demo requests and enquiries, and following up | Enquiry details and correspondence | Legitimate interests: responding to business enquiries and promoting our service to firms |
| Creating and managing user accounts, signing you in and providing the platform | Account data, usage data | Contract, where you are our customer; otherwise legitimate interests in providing the service your firm has subscribed to |
| Keeping the platform secure, preventing abuse and investigating incidents | Usage and security data, audit logs | Legitimate interests: security and fraud prevention; legal obligation to keep personal data secure |
| Metering AI and storage use, and improving reliability and performance | Metadata about usage (not content) | Legitimate interests: operating and improving the service |
| Billing, contract administration and accounting records | Billing and contract contact data | Contract; legal obligation to keep accounting records |
| Service and account emails (such as invitations, notifications and changes to terms) | Name, email address | Contract or legitimate interests in running the service |
| Product news and marketing to business contacts | Name, work email, firm | Legitimate interests; you can opt out at any time. Where the law requires consent, we will ask for it |
| Complying with law and responding to lawful requests; establishing or defending legal claims | Any relevant data | Legal obligation; legitimate interests |
We do not sell personal data and we do not make decisions about individuals based solely on automated processing that have legal or similarly significant effects.
5. How you sign in
Platform users sign in through a third-party single sign-on provider, using an existing work account. When you do, the provider tells us your name, email address, profile picture and an account identifier, and confirms that your email address is verified. We use this only to sign you in and to show who you are within your firm’s account. We never receive or store your password, and we do not get access to your email, files, calendar or other data held with that provider. The provider’s handling of your data is governed by its own privacy policy. You can remove Xorrix’s access in your account settings with that provider, but you will then be unable to sign in.
6. AI and your data
- AI features use models from carefully selected AI providers, which act as our sub-processors under contract.
- We use these providers on terms under which they process a request only to return a response, and do not retain it or use it to train their models.
- We do not use customer data to train third-party AI models.
- Where a firm corrects the AI or records a house position, that learning is stored in the firm’s own account and used only for that firm. Our staff may create generalised guidance from firm-authored knowledge-base entries for all customers, but only after removing client names, figures and anything else that identifies a firm, client or individual.
- AI output is a draft for a qualified professional at the firm to review. The firm, not Xorrix, is responsible for the advice it gives and for anything it submits to HMRC or other authorities.
8. International transfers
Personal data is primarily processed in the UK and the European Economic Area (EEA). Some of our service providers may process personal data outside the UK and EEA.
Where personal data is transferred outside the UK or EEA, we make sure it is protected as the law requires, using appropriate safeguards such as UK adequacy regulations, the ICO’s International Data Transfer Agreement, or standard contractual clauses (with the UK Addendum), supported by a transfer risk assessment where required. Contact us for more information about the safeguards that apply.
9. How long we keep it
| Data | How long |
|---|---|
| Website server logs | As set by our hosting provider, typically no more than 30 days |
| Demo requests and enquiries | 24 months after our last contact with you, unless you become a customer |
| Sign-in sessions | Up to 30 days, or until you sign out |
| User account data, audit logs and usage metadata | While your firm’s account is active; deleted with the firm’s data after the contract ends (see below) |
| Billing, invoice and contract records | Six years after the end of the financial year they relate to, to meet legal and tax obligations |
| Firms’ client data | Held in the firm’s own data store for as long as the firm chooses. When the contract ends, it stays in the firm’s data store, and we delete our configuration for the firm and stop accessing it |
| Other firm data held in our own systems | As the firm decides while the contract lasts. After it ends, the firm has 30 days to ask for a copy, and we then delete it from live systems within a further 30 days |
| Backups of our own systems | Kept for a limited period; deleted data is removed from backups within 35 days of deletion from live systems |
| Backups of firms’ client data | Governed by the firm’s own arrangements for its data store |
We may keep data for longer where the law requires it or to deal with a legal claim.
10. How we protect it
- Encryption in transit and at rest.
- Invitation-only accounts, single sign-on, role-based permissions, and separation of each firm’s data.
- Access controls based on least privilege. Credentials we use to access a firm’s data store are stored encrypted, and the firm can revoke our access at any time. Our staff can access a firm’s account only when the firm grants support access, which it can revoke.
- Logging of significant actions, and protections against abuse.
- Client-facing links that cannot be guessed, which the firm can revoke or replace at any time.
- Regular, encrypted backups of our own systems.
- Confidentiality obligations for everyone who works for us.
No system is completely secure. If a personal data breach affects data we process for a firm, we will tell the firm without undue delay so that it can meet its own obligations. Where we are the controller, we will notify the Information Commissioner’s Office and affected individuals when the law requires it.
12. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected or incomplete data completed;
- have your data erased in certain circumstances;
- restrict how we use your data in certain circumstances;
- object to our use of your data where we rely on legitimate interests, and to direct marketing at any time;
- data portability, where we process data you gave us by automated means on the basis of contract or consent;
- withdraw consent at any time, where we rely on consent;
- not be subject to decisions based solely on automated processing that significantly affect you.
To exercise a right, email info@xorrix.com. We may need to confirm your identity. We will respond within one month, which can be extended by up to two further months for complex requests. There is normally no fee. If your request concerns data a firm holds about you as its client, we will pass it to that firm, which is responsible for responding.
13. Children
Our website and platform are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children for our own purposes. Firms may occasionally hold data about minors in their clients’ records (for example, as shareholders); the firm is the controller of that data.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new “last updated” date and, for material changes, tell platform users by email or in the platform.
15. Contact and complaints
Email info@xorrix.com or write to EMERALD PIN LTD, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113.