SpiralHQ
Legal & trust

Privacy Policy

Your financial data is sensitive, and we treat it that way. This policy explains what we collect, why, and the rights you have over it. We are the data controller for the information described here.

Terms of Service Privacy Policy
Updated 1 July 2026 v2.4
1

Who we are

Spiral HQ Ltd is the controller of the personal data described in this policy. We are registered in England and Wales and registered with the Information Commissioner’s Office (ICO). You can reach our Data Protection team at privacy@spiralhq.co.

2

What we collect

We collect information you give us (name, email, business details), the financial data you enter or import (invoices, expenses, customers), transaction data from connected bank feeds via Open Banking, and technical usage data such as device and log information.

CategoryExamplesWhy we hold it
AccountName, email, business name, VAT numberTo run your account and support you
FinancialInvoices, expenses, tax figuresTo provide the core service
BankingRead-only transaction dataTo reconcile payments automatically
UsageDevice, log and analytics dataTo keep Spiral secure and improve it
3

Why we use it and our legal basis

We process your data to provide and maintain the service (performance of our contract with you), to meet legal and tax obligations such as MTD submissions and record-keeping (legal obligation), and to secure, support and improve Spiral (our legitimate interests). Where we rely on consent — for example some marketing — you can withdraw it at any time.

4

Open Banking and your bank data

When you connect a bank account, you authorise the connection on your bank’s own secure page through regulated Open Banking providers. Spiral receives read-only access to transaction data — we never receive your banking credentials and can never initiate payments or move money.

You can disconnect a bank feed at any time from your settings, which stops any further data being shared with us.

5

Who we share it with

We share data with HMRC when you submit returns, with any accountant or team member you invite, and with trusted sub-processors who help us run Spiral (for hosting, payments and analytics) under strict data-protection contracts. We do not, and will never, sell your personal data.

6

How we protect it

We protect your data with 256-bit encryption in transit and at rest, store it in UK and EU data centres, and enforce strict internal access controls with audit logging. We run regular security testing and hold our providers to the same standards.

7

How long we keep it

We keep your data while your account is active. After you close it, we retain financial records for as long as UK tax law requires — generally up to six years — and then delete or anonymise your data. You can request earlier deletion of anything not subject to a legal retention duty.

8

Your rights

Under UK GDPR you have the right to access, correct, export, delete or restrict processing of your personal data, and to object to certain processing. To exercise any of these, email privacy@spiralhq.co and we will respond within one month.

If you’re unhappy with how we’ve handled your data, you can complain to the ICO at ico.org.uk — though we’d always like the chance to put things right first.

9

Cookies

We use essential cookies to keep you signed in and the service working, and optional analytics cookies to understand usage. You can manage non-essential cookies through our cookie banner and your browser settings at any time.

10

Contact us

For any question about this policy or your data, contact our Data Protection team at privacy@spiralhq.co. We update this policy from time to time and will notify you of material changes.

This document was last updated on 1 July 2026 (v2.4). Previous versions are available on request.