DII DII Accounts Clear records for small businesses
Privacy notice

How DII Accounts handles your personal data

This notice explains what personal data DII Accounts collects, why we collect it, the lawful bases we rely on, who we share it with, how long we keep it, and the rights you have under the UK GDPR and the Data Protection Act 2018.

UK GDPR and Data Protection Act 2018 Controller: Dhruvi Infinity Inspiration Ltd Contact: legal@dii.ltd ICO registration: ZB941604

Your analytics preference

Optional analytics is undecided and remains off. No analytics event, visitor identifier, attribution, or location lookup is created unless you choose to enable it.

Essential and security cookies remain available for sign-in, saved preferences, request protection, and service safety. They are not controlled by the optional analytics choice.

Who we are

Dhruvi Infinity Inspiration Ltd is the data controller for the personal data described in this notice. DII Accounts is the accounting product operated by that company.

For any privacy question, or to exercise any of the rights set out below, write to legal@dii.ltd or to the registered office address at the foot of this page. We have not appointed a Data Protection Officer; the address above reaches the people responsible for data protection.

Where you use DII Accounts to keep records about your own customers, suppliers, employees, or subcontractors, you are the controller of that information and we act as your processor. This notice describes both roles and says which applies in each section.

What personal data we hold

These categories reflect what the application actually stores.

  • Account and identity data. Your email address, a hashed password, email confirmation state, sign-in failure counts and account lock state, password reset state, your marketing email preference, and any account suspension record. If you sign in with Google or Microsoft, we also store the provider name, the provider's account identifier for you, the email address the provider returns, and the profile fields it includes.
  • Organisation and membership data. The workspaces you belong to, your role in each one (viewer, operator, accountant, admin, or owner), invitations you sent or received, and the business profile you complete during setup — including business type, trading details, statutory addresses, responsible people, and tax registration references such as a VAT number or UTR.
  • Accounting records. The records you create or import: contacts, invoices and invoice lines, quotes, bills, credit notes, expenses, payments, settlements and allocations, bank accounts and bank transactions, journal entries and lines, payroll batches and cost lines, VAT codes, drafts, obligations and liabilities, and reporting snapshots. These frequently contain personal data about other people, such as a customer's name, address, and contact details.
  • Uploaded documents and attachments. Files you attach to records, files you upload to the AI Accountant, and the file metadata that goes with them.
  • Business mailbox data. If you connect a business mailbox, the encrypted mailbox address, encrypted provider tokens, and bounded message metadata for messages that discovery flags as potentially accounting-related. This is described in its own section below.
  • Inbound email data. Messages sent to a document intake address, held with their attachments so you can turn them into records.
  • Audit events. A record of significant actions in a workspace: who acted (a user or an API token), what they acted on, when, the request identifier, and the IP address the request came from.
  • Analytics data. Only if you enable optional analytics. Described in its own section below.
  • Billing data. Your workspace's Stripe customer and subscription identifiers, plan and subscription status. We do not hold your card details — see Payments below.

Why we use it, and our lawful bases

  • To provide the service (contract). Creating and running your account, keeping your accounting records, producing reports and exports, supporting collaboration with an accountant, and providing support. Without this data we cannot provide the product.
  • To keep the service and its users safe (legitimate interests). Authenticating sign-in, locking accounts after repeated failed attempts, rate-limiting and abuse protection, keeping an audit trail of significant actions, and investigating misuse or security incidents. Our interest is in operating a secure multi-tenant accounting service; we consider this proportionate because the data involved is limited to what security requires.
  • To bill you (contract). Managing subscriptions and payments through Stripe.
  • Optional analytics and approximate location (consent). Nothing is recorded unless you choose to enable it, and you can withdraw at any time using the controls at the top of this page.
  • Product and service emails (contract), and marketing emails (consent). Service emails such as confirmation, password reset, and account notices are necessary to run your account. Marketing emails are governed by the preference on your account and can be switched off at any time.
  • To meet legal obligations (legal obligation). Where we are required to retain records, including for tax and accounting purposes, or to respond to a lawful request.

HMRC data and OAuth tokens

DII Accounts organises records for review. It does not currently submit them to HMRC. The application holds no live HMRC production credentials and does not file returns on your behalf.

Where an HMRC OAuth token exists in a workspace, it is encrypted at rest using AES-256-GCM with a key derived from the application's secret key base, and is never written to the database or to logs in plain text. Outbound HMRC network access is closed by default and is refused unless it is explicitly enabled for the runtime; production is closed structurally rather than by configuration, and the test environment can never open an HMRC socket at all.

If you begin an HMRC connection, the application also sets a device identifier cookie. HMRC requires client software to send fraud prevention headers that identify the originating device; the cookie holds a random identifier for that purpose only and contains nothing about you.

If and when HMRC grants production access and submission is switched on, we will update this notice before any return leaves the application.

Business mailbox connections

This is the most sensitive processing in the product, so it is bounded tightly and described in full.

  • Only an admin or owner can connect a mailbox, and only for their own workspace. API tokens cannot start or use a mailbox connection.
  • Read consent and send consent are separate. Connecting a mailbox for reading grants a read-only scope. Sending on your behalf requires a second, explicit consent with its own scope. Neither is implied by signing in with Google or Microsoft — mailbox consent uses its own application registration and its own scope set.
  • Discovery is bounded. A discovery run looks back over a period you choose from a fixed set (30, 90, or 365 days) and stops at hard per-run limits on pages, candidates, and running time, with a further whole-sweep ceiling. It reads message metadata to identify messages that may be accounting-related; it does not sweep your mailbox without limit.
  • Message content is not warehoused. The application never persists raw HTML, the full MIME message, remote images, or attachments you did not select. Stored metadata such as the sender and subject is sanitised and length-bounded before it is written.
  • Credentials are encrypted. Mailbox addresses, access tokens, and refresh tokens are encrypted at rest with AES-256-GCM under versioned, purpose-separated keys. These fields are excluded from the models' serialised output and from log parameters, and the objects that hold them redact the material when inspected.
  • Nothing becomes an accounting record automatically. A discovered message is a candidate awaiting review. A person in your workspace must review it and explicitly confirm, correct, or ignore the proposal, and must explicitly select an attachment before it is staged. Sending a message requires a separate confirmation recorded against a named user.
  • Short retention for the by-products. An unfinished OAuth attempt is retained for 10 minutes, an unresolved candidate for 30 days, a dismissed candidate for 7 days, and an unconfirmed send intent for 24 hours.
  • You can disconnect. Revoking a connection stops further access; send consent can be revoked on its own without disconnecting reading.

Payments

Payments are processed by Stripe. Card details are entered on Stripe's own hosted checkout and billing portal pages, never on a DII Accounts page — no card number, expiry, or security code is ever submitted to, processed by, or stored in this application. What we store is the Stripe customer and subscription identifier for your workspace, your plan, and its status. When a workspace first subscribes, we pass the billing user's email address to Stripe so it can create a customer record. Stripe acts as an independent controller for its own payment and fraud purposes; see Stripe's privacy policy at stripe.com/privacy.

Analytics and approximate location

Optional analytics is off until you enable it, and every statement below applies only once you have.

A signed, first-party browser identifier helps count landing visits and journeys without calling it a person or a confirmed unique human. Events may include timestamps, landing paths, referrer-derived source, campaign parameters, and bounded signup or conversion stages.

When a person is signed in, eligible analytics events may be linked to their user and organisation records. Those signed-in events are not anonymous.

The identifier is used only for aggregate service statistics and product improvement. DII Accounts does not use advertising scripts, cross-site tracking, or individual advertising profiles. Analytics metadata is filtered before it is stored, so values that look like passwords, tokens, secrets, card data, tax references, or national insurance numbers are not written into analytics records.

For eligible public analytics, Rails resolves the request address through its trusted-proxy processing. The address is sent transiently to MaxMind solely to obtain an approximate country, region, and city. The application stores only coarse names and codes, an approximate accuracy radius, resolution status, provider name, and resolution time.

The application does not retain, hash, mask, enqueue, or return the address, coordinates, postal code, network, ISP, ASN, complete user agent, or provider response. VPNs, proxies, mobile networks, and shared networks can produce an unknown, country-only, or inaccurate result. Location must never be used to identify a person, household, street address, or exact physical position.

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

Cookies and similar technologies

These are the cookies and browser storage this application sets. There are no advertising or third-party tracking cookies.

NameSet byPurposeDuration
Rails session cookie DII Accounts (essential) Keeps you signed in and holds the workspace you are currently viewing, plus cross-site request forgery protection. Encrypted. A signed-in session times out after 30 minutes of inactivity. Browser session
remember_user_token DII Accounts (essential, only if you choose "remember me") Signs you back in on return without re-entering your password. Invalidated when you sign out. 7 days
dii_analytics_preference DII Accounts (essential) Records whether you allowed or refused optional analytics, so we do not ask again and do not process analytics against your choice. Signed. 5 years
dii_visitor_token DII Accounts (optional analytics) A random first-party identifier used to group page views into a visit. Only set once you enable analytics, and deleted immediately when you turn analytics off. Signed. 1 year
dii_analytics_opt_out DII Accounts (essential, legacy) An older opt-out marker still honoured as a refusal if your browser holds one. It is deleted as soon as you record a preference. Until a preference is recorded
hmrc_device_id DII Accounts (essential, HMRC connection only) A random device identifier used to build the fraud prevention headers HMRC requires from client software. Contains no personal data. Signed. Long-lived (Rails permanent cookie, 20 years)
Browser local and session storage DII Accounts (essential, signed-in workspace) Remembers whether the guide panel and the AI Accountant side panels are open. Stays in your browser and is never sent to us. Until you clear site data (session storage: until the tab closes)

All cookies above are set as HTTP-only where the browser does not need to read them, use SameSite=Lax, and are marked Secure in production, where the whole site is served over HTTPS only.

Who we share data with

We do not sell personal data and we do not share it for advertising. We use these processors and providers:

  • Amazon Web Services — object storage for uploaded documents and attachments, written with server-side encryption.
  • Stripe — subscription billing and payment processing.
  • Microsoft and Google — only where you choose to use them: sign-in with a Microsoft or Google account, and business mailbox connections to Microsoft Graph or Gmail.
  • Mailgun — inbound document email routing.
  • MaxMind — approximate location lookup for optional analytics only.
  • HMRC — no data is sent to HMRC today. See the HMRC section above.
  • Your own accountant or team members — people you invite into your workspace, at the access level you give them.

We will also disclose data where we are legally required to do so, or to establish, exercise, or defend legal claims.

Where your data is processed, and international transfers

The application and its database run in the European Economic Area, and uploaded documents are held in the United Kingdom. DII Accounts is hosted on Heroku, and both the application and the PostgreSQL database that holds your workspace run in Heroku's eu region, which is located in Ireland. Uploaded documents and attachments are held in Amazon S3 in the eu-west-2 region, which is London.

This covers everything you put into the workspace: your account and sign-in details, your organisation and business profile, contacts and their names, addresses, emails and tax numbers, invoices, bills, payments, journals, the chart of accounts, bank transactions, VAT working data, uploaded documents, content retrieved from a connected business mailbox, audit events, and anything you type into the AI Accountant.

This changed on 30 August 2026. Before that date the application and database ran in Heroku's us region, and this notice said so. If you placed records into the product before that date, they were processed in the United States until they were migrated. We are telling you rather than quietly updating the page.

The safeguard we rely on for that transfer

A transfer from the United Kingdom to Ireland is covered by the UK's adequacy regulations for the European Economic Area, so no separate transfer agreement is required for it. Documents held in London do not leave the United Kingdom at all.

Open item, stated plainly. Heroku is a Salesforce product, and Salesforce is a United States company. Choosing an EU region does not by itself rule out access by a processor's staff outside the EEA for support or administration. Salesforce publishes a Data Processing Addendum which applies the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses to transfers governed by UK data protection law, and that is the mechanism we would rely on for any such access. We have not completed our own confirmation that that addendum is executed and in force for our specific account, so we are not going to claim that it is. Until that confirmation is on file we treat that safeguard as under review. If you need the current position before you put records into the product, ask at legal@dii.ltd and we will tell you where it stands rather than assert something we cannot show you.

The other providers

Most of the other providers listed above are also established outside the UK. Where personal data is transferred to them, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses in our contract with that provider.

How long we keep it

Where the application enforces a period, we state it. Where it does not, we say so rather than invent one.

  • Analytics events: 13 months. A daily bounded process removes only events strictly older than that cutoff; events exactly on the cutoff are kept.
  • Inbound document emails: 90 days. The retained message payload is purged once that period expires.
  • Business mailbox by-products: unfinished OAuth attempts 10 minutes, unresolved candidates 30 days, dismissed candidates 7 days, unconfirmed send intents 24 hours.
  • Account, organisation, accounting records, uploaded documents, and audit events: the application does not currently enforce an automatic deletion period for these. They are retained for the life of the account and deleted on request, subject to any period we are legally required to keep them for. Posted accounting entries are immutable by design and are corrected by reversal rather than edited, so an erasure request over posted history is handled by deleting the account's data as a whole rather than by amending individual entries.

How we protect it

  • Tenant isolation. The workspace is the security boundary. Records are scoped to an organisation at the model layer, and every request is checked against an authorisation policy before data is read or written; controllers that skip that check fail the build.
  • Role-based access. Access within a workspace follows the membership role you were given, and sensitive operations such as connecting a mailbox require an admin or owner.
  • Encryption. Provider credentials — HMRC OAuth tokens, business mailbox tokens and addresses — are encrypted at rest with AES-256-GCM under purpose-separated keys. Passwords are stored as hashes, never in recoverable form. The site is served over HTTPS only in production, and uploaded documents are stored with server-side encryption.
  • Audit trail. Significant actions are recorded with the actor, the record, the time, and the request context, and are checked for organisation consistency as they are written.
  • Log hygiene. Passwords, tokens, secrets, mailbox addresses, message subjects and senders, bank account numbers, and tax references such as UTR, VAT number, and national insurance number are filtered out of application logs.
  • Abuse protection. Sign-in and sensitive endpoints are rate-limited, and accounts lock after repeated failed sign-in attempts.

Your rights

Under the UK GDPR you have the right to be informed, and the rights of access, rectification, erasure, restriction, portability, and objection, as well as rights concerning automated decision-making. DII Accounts does not make automated decisions producing legal or similarly significant effects about you.

  • Access. Ask us for a copy of your personal data at legal@dii.ltd. We respond within one month. Most of what a workspace holds is already available to you through the export described under portability below.
  • Rectification. Most account and business details can be corrected in the product directly. For anything you cannot reach, write to us.
  • Erasure. An admin or owner can raise an erasure request from Your data and rights in the workspace. That records a dated request, audited against your workspace, and it is the route we act on; you can also write to us. Raising a request does not delete anything by itself, and nothing is deleted automatically: we come back to you within one month, tell you what we are required to keep and why — UK tax records generally have to be kept for six years after the end of the accounting period they relate to — and confirm when the rest has been removed. Posted accounting entries are immutable by design and are removed as part of deleting a workspace's data rather than amended individually.
  • Portability. An admin or owner can download the workspace's accounting records from Your data and rights in the workspace, as a ZIP of CSV files with a JSON manifest: contacts, invoices and their lines, bills and their lines, payments, bank transactions, journal entries and lines, and the chart of accounts. CSV and JSON are structured, commonly used, machine-readable formats, and the export is not behind a paid plan. It covers the whole history of the workspace, not a reporting period. Attachments and uploaded document files are not bundled into it — ask us for those. For a machine-readable copy of anything else, ask us.
  • Restriction and objection. Ask us to restrict processing, or object to processing based on our legitimate interests, by writing to us with the reason.
  • Withdrawing consent. Optional analytics can be switched off at the top of this page at any time, which deletes the analytics visitor identifier immediately. Marketing emails can be switched off in your email preferences or from the unsubscribe link in any marketing email. A connected business mailbox can be disconnected, and send consent revoked separately, from the workspace. Withdrawing consent does not affect processing carried out before you withdrew it.

If you are asking about data held in a workspace that belongs to someone else — for example, because you are a customer of a business that uses DII Accounts — that business is the controller and you should contact it directly. We will help it respond.

Complaints

If you are unhappy with how we have handled your personal data, tell us first at legal@dii.ltd so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

Changes to this notice

If we change how we use personal data, we will update this page and change the last reviewed date below. Where a change materially affects you, we will tell you by email or in the product before it takes effect.