UK GDPR
Data is processed lawfully under the UK GDPR. Subject access, deletion and portability are first-class features.
Compliance
AccBooks AI is designed for UK GDPR, HMRC MTD and Companies House from day one, with controls aligned to SOC 2 and ISO 27001.
Data is processed lawfully under the UK GDPR. Subject access, deletion and portability are first-class features.
Built to file VAT returns under Making Tax Digital with the same controls HMRC requires.
Controls map to the SOC 2 Trust Services Criteria — security, availability, confidentiality.
Information-security management aligned to ISO 27001 — risk register, access reviews, incident response.
Filings packs aligned to FRS 102/105 with full audit trail.
Independent third-party pen tests with remediation tracked publicly via the status page.
All customer data is stored in UK data centres. Backups are encrypted and stored in a separate UK region. We do not transfer customer data outside the UK without explicit consent.
AWS (eu-west-2)
Application hosting & database — London, UK
Cloudflare
Edge network & DDoS protection — Global edge, UK ingress
Stripe
Subscription billing — UK / EU
We provide a Data Processing Agreement to every paying customer who needs one — typically signed within 24 hours.