This policy explains what personal data dragonfin collects when you use our Making Tax Digital submission service, what we do with it, and the rights you have under UK GDPR and the Data Protection Act 2018.
1. Who we are
Company number: 16928030 (England & Wales)
Registered office: 21 Thornhill Road, Ickenham, Uxbridge, Middlesex, UB10 8SG
Data controller for the dragonfin service.
Contact: [email protected]
2. What we collect and why
Account and identity
- Client identifier — a random UUID we generate when you first register your device. Not linked to your name or National Insurance number.
- Ed25519 public key — the cryptographic identity of your dragonfin client. Only the public half; the private half never leaves your device.
- Device hint — a short label you choose (e.g. "office Pi") so you can identify your own devices in your account.
HMRC authorisation
- HMRC OAuth tokens — access and refresh tokens issued by HMRC when you authorise dragonfin to file on your behalf. Held encrypted at rest on our infrastructure. Used only to transmit your submissions to HMRC.
- HMRC scope grants — a record of which HMRC APIs you have authorised (e.g. read-only tax information, submit tax returns).
Fraud Prevention Headers (required by HMRC)
HMRC's Fraud Prevention Headers standard requires us to transmit certain technical metadata about the device raising each submission — device ID, timezone, IP address, MAC address of the network interface, connection method. This is an HMRC anti-fraud requirement, not our choice. We transmit this data to HMRC with each submission and do not retain it on our systems beyond the audit hash described below.
Billing
- Stripe customer identifier — a reference issued by our payment provider Stripe. We do not see or store your card details; Stripe processes payments directly.
- Subscription tier and expiry — which product you have (£79 Self / £149 AI Assisted / Human Review) and when it expires.
- Order history — dates, amounts, tier for each purchase. Retained for six years to satisfy UK tax law record-keeping requirements.
Support tickets
- When you raise a support ticket, we hold the message text you send us, any replies from our support team, and metadata about the ticket (created date, category, resolution).
- Support tickets stay in your account until resolved, then are retained for six years for audit purposes.
3. What we deliberately do NOT collect or store
- No bank details. Stripe holds card and bank data; we do not see it.
- No third-party analytics. No Google Analytics, no Facebook Pixel, no advertising trackers, no session recording tools.
- No cross-site cookies. The only cookie we set is a HttpOnly session cookie in our admin console — customer flows use no browser cookies at all.
- No marketing lists. We do not add you to email marketing or share your address with third parties.
4. Legal basis for processing (UK GDPR Article 6)
- Contract — processing needed to deliver the service you have signed up for (transmit submissions, hold HMRC authorisations, run support).
- Legal obligation — records retained for six years under UK tax law and HMRC vendor requirements.
- Legitimate interest — Fraud Prevention Headers required by HMRC for us to operate as an approved software vendor.
5. Who we share data with
- HMRC — this is the point of the service. Your submissions and the Fraud Prevention Headers go to HMRC's Making Tax Digital APIs at api.service.hmrc.gov.uk.
- Stripe (Stripe Payments UK, Ltd) — processes your payments. Stripe's own privacy policy applies at stripe.com/gb/privacy.
- Cloudflare — routes traffic to our servers. Cloudflare sees the metadata of your connection (IP address, request timing) but not the encrypted contents of your submissions.
We do not share your data with anyone else. We do not sell data. We do not permit third parties to advertise to you on the strength of your dragonfin account.
6. Where your data is held
dragonfin runs on sovereign UK-and-EU infrastructure operated by the DragonFire fleet. Servers are located in the United Kingdom and Germany (both UK-GDPR-adequate jurisdictions). Data is not transferred outside these jurisdictions.
7. How we protect your data
- TLS 1.2+ encryption for every network connection, including to HMRC.
- OAuth tokens encrypted at rest on our filesystem.
- Ed25519 digital signatures verify every submission originates from your registered device.
- Server-side session tokens; no long-lived credentials in your browser.
- Admin access is bearer-token or session-cookie authenticated, role-gated, and logged.
8. How long we keep data
| Client identifier + public key | Until you deregister the device |
| HMRC OAuth tokens | Until you revoke or they expire |
| Order records | Six years (UK tax law requirement) |
| Submission audit hashes | Six years (HMRC audit requirement) |
| Support tickets | Six years after resolution |
| Financial submission content | Not retained (discarded after transmission) |
9. Your rights under UK GDPR
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct anything inaccurate.
- Erasure — ask us to delete your data. This applies except where we are legally required to retain records (see section 8).
- Portability — request your data in a machine-readable format.
- Restriction and objection — limit or object to specific processing.
- Complaint — complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We ask that you contact us first so we can put things right.
To exercise any of these rights, email [email protected]. We will respond within one calendar month.
10. Changes to this policy
If we change how we process personal data in a way that affects you, we will publish an updated version of this policy with a new "Last updated" date and notify active customers in-app before the change takes effect.
11. Contact
General enquiries: [email protected]
Postal: Dragonfire Technologies Limited, 21 Thornhill Road, Ickenham, Uxbridge, Middlesex, UB10 8SG