Terms of Service

Last updated: 27 September 2026

These terms, together with any order form we agree with you, form the contract under which we provide the Xorrix platform to your firm. They include our data processing terms in Schedule 1. Please read them carefully. If you accept them on behalf of a firm, you confirm that you have authority to bind it.

1. About these terms

Xorrix is a brand name of EMERALD PIN LTD, a company registered in England and Wales, company number 14326917, whose registered office is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“we”, “us”, “our”).

The platform is for businesses only, principally UK accountancy and tax advisory firms. It is not offered to consumers. By subscribing, you confirm that you are acting for the purposes of your trade, business or profession.

If an order form or other signed agreement between you and us conflicts with these terms, the order form or signed agreement wins, but only for the point on which they conflict. Schedule 1 (data processing terms) wins over anything else on data protection.

2. Definitions

  • Customer, you or your: the firm or business that subscribes to the platform.
  • Authorised users: your partners, employees and contractors whom you invite to use the platform under your account.
  • Customer data: all data, documents and content that you or your authorised users (or your clients, through links you send them) put into the platform, and the outputs generated from it for you.
  • Client-facing links: proposals, intake forms, document requests, portals, signing and authorisation pages and report links that you send to your clients through the platform.
  • Order form: the order, quote or subscription confirmation that sets out your plan, fees and subscription term.
  • Data protection laws: the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any other law on personal data that applies to the processing.
  • AI features: features of the platform that use machine-learning models to extract, classify, summarise, draft, review or answer questions.

3. The service and plans

We offer the platform on our Enterprise plan. Your order form states the features and modules included in your subscription.

All data about your clients is stored in your own data store (section 10). We hold only the account and platform information needed to run the service.

We may add, improve or remove features from time to time. If we remove a feature that is material to your plan, we will give you at least 30 days’ notice and, if the change significantly reduces what you receive, you may terminate the affected subscription and receive a pro rata refund of prepaid fees for the remaining term.

4. Accounts, users and sign-in

  • Access is by invitation. Your firm’s administrators invite authorised users and decide what each user can see and do.
  • Authorised users sign in through a supported single sign-on provider using a work account. We do not create, receive or store passwords. Each user must use an account under their own name, and you are responsible for making sure your users keep those accounts secure, including by using two-step verification.
  • You are responsible for your authorised users, for everything done under your account, and for removing access promptly when someone leaves your firm or no longer needs it.
  • Tell us without delay at info@xorrix.com if you suspect any unauthorised access to your account.
  • Our support staff can view your account only if one of your firm’s owners or administrators has granted support access in the platform. You can revoke that grant at any time. Support access is logged.

5. Fees and payment

  • You will pay the subscription fees and any other charges set out in your order form. Unless the order form says otherwise, fees are invoiced in advance for each billing period and are payable within 30 days of the invoice date.
  • Fees are stated exclusive of VAT, which you will pay in addition at the applicable rate.
  • If you do not pay an undisputed invoice on time, we may charge interest under the Late Payment of Commercial Debts (Interest) Act 1998 and, after giving you notice, suspend the service under section 18.
  • If you dispute an invoice in good faith, tell us within 14 days of receiving it and pay the undisputed part. We will work with you to resolve the dispute promptly.
  • We may change our fees with effect from the start of your next subscription term by giving you at least 30 days’ written notice. If you do not accept the change, you may end the subscription at the end of the current term.
  • Except as these terms expressly provide, fees are non-refundable.

6. Customer data

  • You own your customer data. We do not acquire any rights in it other than those you give us in these terms.
  • You grant us a non-exclusive, worldwide, royalty-free licence, for the duration of the contract and any period after it needed to return or delete data, to host, copy, transmit, process and display customer data only as needed to provide, secure and support the platform for you and to comply with law.
  • For personal data within customer data, you are the controller and we are your processor. Schedule 1 applies.
  • You are responsible for the accuracy, quality and lawfulness of customer data, and for having the right to give it to us, including giving your clients any privacy information required by data protection laws.
  • We will not sell customer data, use it to train third-party AI models, or use it for advertising.
  • We may create and use aggregated usage and performance statistics (for example, counts of calls, errors, storage used and response times) that do not identify you, your users or your clients, to operate, meter and improve the platform.

7. Acceptable use

You must not, and must make sure your authorised users do not:

  • use the platform in breach of any law, regulation or professional rule, or to process data you have no right to process;
  • upload anything that is malicious, infringing, defamatory or obscene, or that contains malware;
  • attempt to gain unauthorised access to the platform, other customers’ data or our systems, or probe, scan or test their vulnerability without our written consent;
  • interfere with or disrupt the platform, including by excessive automated requests, or circumvent rate limits, plan restrictions or security controls;
  • copy, reverse engineer, decompile or create derivative works of the platform, except to the extent the law does not allow this to be restricted;
  • use the platform, or outputs from it, to build a competing product, or extract our statutory content, rules or prompts in bulk;
  • resell, sublicense or provide the platform to anyone other than your authorised users, or share sign-in credentials;
  • upload special category personal data or criminal offence data unless it is genuinely necessary for the professional service you are providing and you have a lawful basis for it.

8. Professional responsibility

  • The platform is a tool for qualified professionals. We do not provide legal, tax, accounting, valuation or financial advice, and nothing in the platform is advice from us to you or your clients.
  • Calculations, valuations, eligibility assessments, transfer pricing positions, VAT analyses, draft agreements, letters and reports produced by the platform are drafts. A suitably qualified person at your firm must review them, and you decide whether and how to rely on them.
  • You remain solely responsible for the advice you give, the work you sign off, and anything you submit to HM Revenue & Customs, Companies House or any other authority, including valuations submitted for agreement, scheme notifications and returns.
  • Tax rules, thresholds and rates in the platform are maintained with care and cited where possible, but laws change and may be applied differently to particular facts. You should check that the rules applied are current and appropriate for your client.
  • You are responsible for your own regulatory obligations, including anti-money laundering checks, engagement terms with your clients and professional indemnity insurance.

9. AI features

  • AI features run on models we provide through carefully selected AI providers, which are our sub-processors. Your firm does not need to supply its own AI provider.
  • We use these providers on terms under which prompts and outputs are processed only to return a response, and are not retained by the provider or used by it to train its models.
  • Numbers and statutory tests in the platform are computed by deterministic rules and engines, not by AI models. AI is used for language work such as extracting information from documents, drafting, summarising and answering questions. AI output can still be incomplete or wrong, and section 8 applies to it.
  • Some features learn from your firm’s own corrections and house positions (for example, valuation playbook rules and firm knowledge-base entries). That learning is stored within your account and used only for your firm.
  • Separately, our staff may review firm-authored knowledge-base guidance and publish a generalised version of it to the knowledge base shared by all customers. Before publication the guidance is rewritten so that it contains no client names, figures or other information that identifies you, your clients or any individual. If you do not want your firm’s guidance considered for this, tell us at info@xorrix.com and we will exclude it.
  • We keep metadata about AI use (not the content of prompts or responses) for metering and reliability.

10. Your data store

  • You provide, and pay for, your own data store, as described in your contract and our onboarding documentation. All data about your clients is stored there. You own and control it, not us.
  • We access your data store only to provide the service, using credentials that we store encrypted. We run no code in your data store.
  • You are responsible for your data store, including its security, availability, configuration (including backups) and costs, and for your agreement with its provider.
  • You can revoke our access at any time. If you do, or if your data store becomes unavailable or is deleted, the platform will stop working for your firm until access is restored. This does not reduce the fees payable, and we are not liable for any resulting loss.
  • Features that need your data store will not work until it is connected and verified. We will not store your client data elsewhere in the meantime.

11. Third-party services and integrations

The platform can connect to services you choose to use, such as Companies House and your firm’s own data store (section 10). When you switch on an integration, you instruct us to send the relevant data to that service. The provider of that service is not our sub-processor, its own terms apply to your use of it, and we are not responsible for its acts or omissions. The platform also uses public reference data sources (such as exchange rates and market prices) to which no customer personal data is sent.

12. Availability, support and changes to the service

  • We will use reasonable efforts to make the platform available at all times, apart from planned maintenance (which we will try to schedule outside UK business hours) and events outside our reasonable control.
  • We do not offer a service level agreement or service credits unless your order form expressly includes them.
  • We provide support by email during UK business hours and will use reasonable efforts to respond promptly.
  • We keep regular backups of our own systems, which hold account and platform information. Backups of your client data are governed by your own arrangements for your data store (section 10). Backups are for disaster recovery; they are not a substitute for your own records.

13. Confidentiality

Each party will keep the other’s confidential information confidential, use it only to perform or receive the service, and disclose it only to its personnel, sub-processors and professional advisers who need to know it and are bound by equivalent obligations. Customer data is your confidential information. These obligations do not apply to information that is or becomes public other than through a breach, was already lawfully known to the recipient, is independently developed, or is lawfully received from a third party without restriction. A party may disclose confidential information when required by law or a regulator, giving the other party notice where lawful. These obligations last for the contract and five years after it ends.

14. Intellectual property

  • We and our licensors own all intellectual property rights in the platform, including its software, engines, statutory rule packs, prompts, templates, knowledge base and documentation.
  • We grant you a non-exclusive, non-transferable right, for the subscription term, for your authorised users to use the platform for your firm’s internal business and to deliver services to your clients.
  • You own the documents and reports you produce with the platform for your clients, subject to our rights in any templates and standard wording embedded in them, which you may use for that purpose.
  • If you give us feedback or suggestions, we may use them without restriction or payment.

15. Warranties and disclaimers

  • We warrant that we will provide the platform with reasonable skill and care and that it will perform materially as described in our documentation. If it does not, we will use reasonable efforts to correct it; if we cannot within a reasonable time, either party may terminate the affected subscription and we will refund prepaid fees for the remaining term. This is your sole remedy for breach of this warranty.
  • Each party warrants that it has the authority to enter into this contract and will comply with the laws that apply to it in performing it.
  • Except as expressly set out in these terms, all warranties, conditions and terms implied by statute or common law are excluded to the extent permitted by law. We do not warrant that the platform will be uninterrupted or error-free, or that outputs (including AI output) will be complete, accurate or fit for any particular filing or purpose.

16. Limitation of liability

  • Nothing in these terms limits or excludes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded by law.
  • Neither party is liable for any loss of profits, revenue, business, goodwill or anticipated savings, or for any indirect or consequential loss, however arising.
  • We are not liable for losses arising from your professional advice or filings, from your failure to review outputs as section 8 requires, or from your own data store being unavailable, our access to it being revoked, or its deletion.
  • Subject to the first point above, each party’s total liability arising out of or in connection with this contract, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the total fees paid and payable by you in the 12 months before the event giving rise to the claim. This cap does not apply to your obligation to pay fees.

17. Indemnities

  • We will defend you against any claim by a third party that your use of the platform in accordance with these terms infringes that party’s UK intellectual property rights, and pay any damages finally awarded or agreed in settlement. This does not apply to claims caused by customer data, by your modification or misuse of the platform, or by combination with anything we did not supply. If such a claim is made, we may modify the platform so it no longer infringes, obtain a licence, or terminate the affected service and refund prepaid fees for the remaining term.
  • You will defend us against any claim by a third party arising from customer data, your instructions to us under Schedule 1, or your or your users’ breach of section 7, and pay any damages finally awarded or agreed in settlement.
  • The indemnified party must notify the other promptly, give it sole control of the defence and settlement, provide reasonable help at the other’s cost, and make no admission without consent. These indemnities are subject to section 16.

18. Suspension

We may suspend access to all or part of the platform, for as short a time as reasonably possible:

  • if an undisputed invoice remains unpaid 14 days after we have given you written notice of non-payment;
  • if we reasonably believe your account is being used in breach of section 7 or is compromised; or
  • where needed to prevent a threat to the security or integrity of the platform or other customers’ data, or where required by law.

We will give you notice before suspending where reasonably practicable, and will restore access once the reason has been resolved. Suspension does not delete customer data.

19. Term and termination

  • The contract starts when you accept these terms or sign an order form, and continues for the subscription term in your order form. Unless the order form says otherwise, it then renews automatically for successive periods of the same length unless either party gives at least 30 days’ written notice before the end of the current term.
  • Either party may terminate the contract immediately by written notice if the other commits a material breach that is not capable of remedy, or is not remedied within 30 days of written notice requiring it; or if the other becomes insolvent, enters administration or liquidation, makes an arrangement with its creditors, or ceases to trade.

20. Effect of termination

  • On termination, your right to use the platform ends and all unpaid fees become due.
  • Your client data remains yours and stays in your own data store. We will delete our configuration for your firm and stop accessing your data store. You should then revoke our access to it.
  • For 30 days after termination, you may ask us to return any customer data we hold in our own systems to you in a commonly used format.
  • After that 30-day period, we will delete customer data we hold in our own systems from our live systems within a further 30 days, unless the law requires us to keep it. Copies in our backups are removed within 35 days after deletion from live systems, and are kept secure and not used in the meantime.
  • Sections 6, 13, 14, 16, 17, 20, 22 and 23 and Schedule 1 (for as long as we hold customer personal data) survive termination.

21. Changes to these terms

We may update these terms from time to time. We will give your firm’s administrators at least 30 days’ notice by email or in the platform of any change that materially affects you, unless the change is required sooner by law. If you object to a material change, you may terminate the contract by notice before the change takes effect and we will refund prepaid fees for the remaining term. Otherwise the updated terms apply from the date stated. The current version is always available at xorrix.com/terms.

22. General

  • Assignment and subcontracting. You may not assign or transfer the contract without our consent, which we will not unreasonably withhold. We may assign it to an affiliate or to a buyer of all or part of our business on notice to you. We may use subcontractors, subject to Schedule 1, and remain responsible for them.
  • Force majeure. Neither party is liable for a delay or failure caused by events beyond its reasonable control, such as failures of utilities, internet or hosting providers, industrial action, government action, pandemic, fire or flood. Payment obligations are not affected. If the event lasts more than 60 days, either party may terminate on written notice.
  • Notices. Notices must be in writing. We will send notices to the email address of your firm’s account owner or the contact in your order form. You should send notices to info@xorrix.com, or by post to our registered office. Email notices are treated as received on the next business day after sending.
  • Entire agreement. These terms and your order form are the entire agreement between us on their subject and replace any earlier discussions. Neither party has relied on any statement not set out in them, but this does not limit liability for fraud.
  • Variation and waiver. Other than under section 21, a variation must be in writing and agreed by both parties. A failure or delay in exercising a right is not a waiver of it.
  • Severance. If any provision is found invalid or unenforceable, the rest remains in force.
  • Third-party rights. No one other than you and us has any right to enforce these terms under the Contracts (Rights of Third Parties) Act 1999.
  • Relationship. Nothing in these terms creates a partnership, joint venture or agency between the parties.

23. Governing law and jurisdiction

These terms and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with them are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.

24. Using this website

If you are simply visiting xorrix.com or booking a demo, sections 7 (as it applies to the website), 13 and 23 apply to your use of the website. The website is provided for information about Xorrix and is not advice. To the extent permitted by law, we are not liable for any loss arising from your use of the website. Our Privacy Policy explains how we handle personal data.

Schedule 1: Data processing terms

This schedule sets out the terms required by Article 28(3) of the UK GDPR. It applies whenever we process personal data within customer data on your behalf.

1. Roles

You are the controller (or a processor acting for your own client, in which case we are your sub-processor and you will pass on the relevant commitments). We are your processor. Each party will comply with its obligations under data protection laws.

2. Subject matter, duration, nature and purpose

  • Subject matter: providing the Xorrix platform to you under these terms.
  • Duration: the term of the contract, plus the period after termination until we have deleted or returned customer data under section 20.
  • Nature: hosting, storage, retrieval, organisation, structuring, analysis (including by AI features), calculation, generation of documents and reports, transmission (such as emails and client-facing links), backup, restoration and deletion.
  • Purpose: enabling you to manage your practice and deliver accountancy, tax, share-scheme, valuation, transfer pricing and VAT services to your clients.

3. Types of personal data

Depending on how you use the platform: names, job titles, contact details and addresses; company and shareholding information; employee, director, shareholder and option-holder details; share and option grants, vesting and valuation information; payroll data including salary; tax references such as Unique Taxpayer References and National Insurance numbers; financial statements, transaction and sales data; correspondence, notes, tasks and time records; documents you or your clients upload; electronic signatures with the associated signing evidence (such as IP address, device information and time of signing); and any other personal data you choose to upload. You should not upload special category or criminal offence data except as section 7 allows.

4. Categories of data subjects

Your clients and prospective clients and their directors, shareholders, employees, option holders, investors, customers and other contacts; your authorised users; and other individuals whose data appears in documents you upload.

5. Instructions

We will process customer personal data only on your documented instructions, which are these terms, your order form and your use and configuration of the platform, unless the law requires otherwise (in which case we will tell you first unless the law prohibits it). We will tell you promptly if we believe an instruction infringes data protection laws.

6. Confidentiality

We will make sure that everyone we authorise to process customer personal data is bound by a duty of confidentiality, and that access is limited to those who need it to provide, secure or support the platform.

7. Security

We will implement appropriate technical and organisational measures to protect customer personal data, as required by Article 32 of the UK GDPR, including those in Annex A. We may update these measures provided the overall level of protection is not reduced.

8. Sub-processors

  • You give us general authorisation to engage sub-processors. Our current sub-processors are set out in your contract and are available on request (Annex B).
  • We will give you at least 30 days’ notice (by email to your account owner or in the platform) before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. We will then discuss the objection in good faith; if we cannot address it, you may terminate the affected service and we will refund prepaid fees for the remaining term.
  • We will impose data protection obligations on each sub-processor that are no less protective than those in this schedule, and remain liable to you for its performance.

9. Assistance

  • Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures, to respond to requests from individuals exercising their rights. If we receive such a request directly, we will pass it to you without undue delay and will not respond ourselves except to tell the individual to contact you.
  • We will provide reasonable help with your obligations on security, personal data breach notification, data protection impact assessments and prior consultation with the Information Commissioner’s Office, taking into account the information available to us.

10. Personal data breaches

We will notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting customer personal data. We will give you the information you reasonably need to meet your own notification obligations, as it becomes available, and take reasonable steps to contain and remedy the breach.

11. Deletion and return

At the end of the contract, we will delete or return customer personal data as set out in section 20, and delete existing copies unless the law requires us to keep them.

12. Information and audits

We will make available the information reasonably necessary to demonstrate compliance with this schedule, including answers to security questionnaires and a summary of our security measures. If that is not enough to demonstrate compliance, or a regulator requires it, we will allow and contribute to an audit by you or an independent auditor bound by confidentiality, on at least 30 days’ notice, no more than once a year (except after a personal data breach or at a regulator’s request), during business hours and in a way that minimises disruption and protects other customers’ data. Each party bears its own costs.

13. International transfers

Customer personal data is primarily processed in the UK and the EEA. We will transfer customer personal data outside the UK only where the transfer complies with data protection laws, for example to a country covered by UK adequacy regulations, or under the ICO’s International Data Transfer Agreement or standard contractual clauses with the UK Addendum, supported by a transfer risk assessment where required.

14. Your data store

Your client data is stored in your own data store (section 10), which you obtain under your own arrangements. The provider of your data store is your provider, not our sub-processor. We act as your processor when we access and process that data.

15. Liability

Each party’s liability under this schedule is subject to section 16. Nothing in this schedule limits any rights an individual has directly under data protection laws.

Annex A: Security measures

  • Encryption: data is encrypted in transit and at rest. Credentials we use to access your data store are stored encrypted.
  • Access control: invitation-only accounts, single sign-on, role-based permissions within each firm, least-privilege access, and separation of each firm’s data. Our staff can access a firm’s account only with the firm’s support-access grant.
  • Logging: logs of significant account and data actions, and of AI usage (metadata only).
  • Backups: regular, encrypted backups of our own systems.
  • People: everyone who works for us is bound by confidentiality obligations.

Further detail of the technical and organisational measures we apply is set out in your contract and is available on request.

Annex B: Sub-processors

Our current list of sub-processors, and the technical and organisational measures we apply, are set out in your contract and are available on request from info@xorrix.com.

Contact

Questions about these terms: info@xorrix.com, or by post to EMERALD PIN LTD, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.