Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of our Terms and Conditions and applies whenever you use the #GoFile software to process personal data about other people on your behalf – for example the directors, employees, clients or customers of the businesses you file for. It sets out our obligations to you as a processor under Article 28 of the UK GDPR.

You do not need to sign anything: by using the Software you accept this DPA.

1. Parties and roles

1.1 This DPA is between GOFILE Ltd., a company registered in England and Wales under number 13521210, trading as #GoFile (“we”, “us”, the “Processor”), and the customer that holds the #GoFile account (“you”, the “Customer”).

1.2 You are the controller of the Customer Personal Data unless you process that data on behalf of another controller. We are your processor, and where you are yourself acting as a processor we act as your sub-processor. You confirm that you have the authority to appoint us on the terms of this DPA.

1.3 For personal data about you and your own users – your account details, billing, support correspondence and marketing preferences – we are an independent controller and our Privacy Policy applies instead of this DPA.

2. Definitions

  • Data Protection Laws means the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable, the EU General Data Protection Regulation, each as amended or replaced.
  • Customer Personal Data means personal data that you, or anyone acting for you, enter into or upload to the Software, or that the Software receives from HMRC or Companies House on your instruction.
  • Software means the #GoFile service at secure.gofile.co.uk and any related services we provide to you.
  • Subprocessor means a third party we engage to process Customer Personal Data on our behalf.
  • Personal Data Breach, controller, processor, data subject and processing have the meanings given in the Data Protection Laws.

3. Details of the processing

Subject matter – the preparation, storage and submission of tax returns, company filings, payroll information and related records for the businesses you manage in the Software.

Duration – for as long as you hold a #GoFile account, plus the retention periods described in clause 9.

Nature and purpose – collection, storage, organisation, calculation, transmission to HMRC and Companies House, retrieval, and deletion, solely to provide the Software to you.

Categories of data subjects – your staff and users; directors, shareholders, partners and employees of the businesses you file for; your clients and their staff where you act as an agent; and other individuals whose details appear in returns, filings or supporting records.

Categories of personal data – names and contact details; dates of birth; National Insurance numbers, Unique Taxpayer References and other tax identifiers; employment, pay, pension and benefit details; financial and accounting information; company officer and shareholding details; and the contents of documents you upload.

Special category data – the Software may process limited special category data where this is included in payroll or supporting records, for example health information relating to statutory sick pay. Where you provide special category data, you are responsible for ensuring that you have an appropriate lawful basis under Article 6 and condition for processing under Article 9, together with any additional condition required by the Data Protection Act 2018.

4. Our obligations as processor

We will:

4.1 Follow your instructions. Process Customer Personal Data only on your documented instructions, which are the Terms, this DPA and the actions you take in the Software, unless we are required to do otherwise by law, in which case we will tell you first unless the law prevents it. We will tell you if we believe an instruction breaches the Data Protection Laws.

4.2 Keep it confidential. Ensure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality and receives appropriate data protection guidance.

4.3 Keep it secure. Implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Annex 2 summarises these measures. We may update them while continuing to meet our obligations under the Data Protection Laws.

4.4 Help you meet data subject rights. Assist you, by appropriate technical and organisational measures and taking into account the nature of the processing, in responding to requests from data subjects to exercise their rights. If a data subject contacts us directly about Customer Personal Data, we will refer them to you and will not respond on your behalf unless you ask us to.

4.5 Help you meet your other obligations. Assist you in meeting your obligations relating to security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner or other applicable supervisory authority, taking into account the nature of the processing and the information available to us.

4.6 Delete or return the data. At the end of the services, delete or return Customer Personal Data as described in clause 9.

4.7 Demonstrate compliance. Make available the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR, and allow for and contribute to audits as described in clause 8.

5. Subprocessors

5.1 You give us general written authorisation to engage the Subprocessors listed on our subprocessors page, which forms Annex 3 to this DPA.

5.2 We will inform you by email or through the Software of intended additions or replacements of Subprocessors before the change takes effect, giving you an opportunity to object, and will update that page accordingly.

5.3 If you object to a new Subprocessor on reasonable data protection grounds, tell us and we will discuss your concern in good faith. If we cannot resolve it, you may stop using the affected services by closing your account.

5.4 We will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for the performance of each Subprocessor’s obligations.

5.5 HMRC and Companies House are not Subprocessors. They receive data only because you instruct us to submit it, and they act as independent controllers under their own privacy notices.

6. Personal data breaches

6.1 If we become aware of a Personal Data Breach affecting Customer Personal Data, we will notify you without undue delay, as the Data Protection Laws require.

6.2 Our notification will describe, so far as we know at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. We will provide further information in phases as it becomes available.

6.3 We will cooperate with you and take reasonable steps to help you meet your own notification obligations to the Information Commissioner or other applicable supervisory authority and to data subjects. We will not notify a supervisory authority or data subjects on your behalf unless you ask us to or the law requires us to.

7. International transfers

7.1 The Software’s database, uploaded documents and backups are hosted in the United Kingdom. Data is delivered to you and your authorised users wherever you access the Software. Subprocessors may process data in the locations described in Annex 3. Where a transfer requires safeguards under the Data Protection Laws, we use an applicable adequacy decision or other permitted transfer mechanism.

8. Information and audits

8.1 We will answer reasonable written requests for information about our processing of Customer Personal Data and our security measures within a reasonable time.

8.2 If, having reviewed the information provided, you reasonably believe that an audit is necessary to verify our compliance with this DPA, you may conduct one, or appoint an independent auditor bound by confidentiality to do so, not more than once in any 12-month period unless required by a supervisory authority, following a Personal Data Breach, or where you reasonably suspect a material breach of this DPA. Audits must be requested with at least 30 days’ written notice, unless a shorter period is reasonably required by a supervisory authority or following a Personal Data Breach, conducted during normal business hours, limited to what is needed to verify compliance, and carried out at your cost. Audits may not extend to the systems of our Subprocessors, whose own certifications and reports we will provide where we are able to.

9. Retention, return and deletion

9.1 Before closing your account, save any returns, filings and records you need to keep using the download options available in the Software. You may also request return of Customer Personal Data at the end of the services.

9.2 At the end of the services, we will delete or return Customer Personal Data at your choice, and delete existing copies, subject to clause 9.4.

9.3 When you close your account, or ask us in writing, we will delete Customer Personal Data from our active systems within 3 business days, subject to clause 9.4.

9.4 Customer Personal Data may remain temporarily in routine backups after deletion from our active systems. Those copies will remain protected, will not be restored or otherwise processed except where necessary for backup, security or disaster recovery purposes, and will be deleted as the backups are overwritten in the ordinary course. We will retain Customer Personal Data after the end of the services only where UK law requires us to store it.

10. Your obligations

You will:

  • ensure that you have a lawful basis, and where required the authority of your own clients, to provide Customer Personal Data to us and to instruct its processing;
  • ensure that your instructions comply with the Data Protection Laws and that the Customer Personal Data is accurate and up to date;
  • keep your account credentials secure and manage who in your organisation has access;
  • tell us promptly if you receive a data subject request or regulatory enquiry that needs our help; and
  • be responsible for your own compliance with the Data Protection Laws as controller or processor, as applicable.

11. Liability

Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms and Conditions. Nothing in this DPA limits either party’s liability where it cannot lawfully be limited.

12. General

12.1 This DPA applies for as long as we process Customer Personal Data on your behalf and survives the end of the Terms until that processing ends.

12.2 If there is a conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA prevails.

12.3 We may update this DPA to reflect changes in the law or in the Software. We will publish the new version on this page. We will notify you of material changes before they take effect, and no update will materially reduce the protection of Customer Personal Data.

12.4 This DPA is governed by the law of England and Wales.

Annexes

  • Annex 1 – Details of the processing: clause 3 above.
  • Annex 2 – Technical and organisational measures: access controls, encryption of protected database data and connections to the Software, backups, and application security controls appropriate to the processing risks. Information needed to demonstrate compliance is available under clause 8.
  • Annex 3 – Authorised Subprocessors: our subprocessors page.

Contact

For anything relating to this DPA, contact us through the contact form or by a support message from within your account, marking your message “Data protection”.

5.0/5 Rated 5.0/5 from 205 verified customer reviews
★★★★★
“Was let down my usual MTD Bridging company, who promised delivery by 7 August - so in panic looked elsewhere and was impressed by Gofile's user friendly interface.”
— Zosia N., Sole trader · Income Tax
★★★★★
“Fairly straight forward. Tutorials very helpful.”
— Ann A., Sole trader · Income Tax
★★★★★
“Very easy and user friendly. Very fast response from support.”
— , Sole trader · Income Tax