Test mode: we send filings to HMRC's and Companies House's test services, not the live ones, so nothing is filed.
FreeFilerBeta

Privacy Policy — FreeFiler beta

How Render Technologies Ltd uses data for FreeFiler beta.

Version v1.12 — effective from 2026-09-15


# Privacy Policy — FreeFiler beta

**Version v1.12 — effective from 15 September 2026**

## 1. The promise, before the detail

**We never sell your data, and we never hand your details or your figures to another business for that business's own purposes.**

There are no partner offers, no advertisers, and no data buyers. The only companies that touch your data are the suppliers in section 6, who run parts of the service on our instructions and may not use it for anything else, plus HMRC and Companies House, who are the whole point of filing.

If we ever suggest a partner service to you, we will decide what to show from your company's public profile only — never from your turnover, your profit, your tax, or any other figure from your return. That is permanent, not a beta position.

## 2. Who we are

FreeFiler at freefiler.co.uk is a beta service operated by Render Technologies Ltd ("we", "us"), company number 17088258, which is the data controller for the personal data described below. FreeFiler is a name Render Technologies Ltd trades under, not a separate company. Contact: privacy@freefiler.co.uk.

If we move your account or access to your filing records to another Render Technologies Ltd service or domain, including Render or `render.my`, Render Technologies Ltd remains responsible for the personal data described in this policy.

## 3. What we collect

- **Account data** — your email address, display name, and authentication identifier (via Clerk).
- **Company data** — the Companies House number or numbers you add to your account.
- **Directorship check data** — to add a company you confirm you are one of its currently-appointed directors. You pick yourself from that company's public list of active directors and enter the month and year of your birth and the date you were appointed. We check both against Companies House. What we keep is the officer you picked and whether each check matched; the month and year of birth themselves are not stored.
- **Filing data** — the CT600 form fields you complete, the assembled iXBRL accounts and iXBRL computation, the GovTalk envelope we send to HMRC, and HMRC's response (the IRmark when accepted, the error detail when rejected).
- **Companies House send data** — if you send your accounts to Companies House from your account page, we keep a record of that send: the submission number and transaction reference, the timestamp Companies House gave it, a fingerprint of the accounts document sent, and anything Companies House said in reply. The record deliberately holds no user identifier and no authentication code.
- **Provenance metadata** — which version of our pinned source material was in effect at the moment your filing was submitted, so the filing can be reconstructed years later byte-for-byte.
- **Operational records** — server request logs, an internal interaction journal (see section 7), and, during early beta, monitoring evidence about your filing journey.

## 4. What we do not collect

- We do not take payment information; FreeFiler is free of charge.
- We do not hold per-user HMRC Gateway credentials in our database. Transmission to HMRC uses Render Technologies Ltd's own vendor credentials.
- We do not store your company's own six-character Companies House authentication code. You type it for a single send to Companies House; it is passed straight through, and is never written to our database, our logs, your data export, or any analytics event.
- We do not put exact tax-form values, UTRs, raw CT600 XML, iXBRL files, GovTalk envelopes, or HMRC payload bodies into analytics or session replay. Exact filing values remain in Render's own systems and in the submitted filing record.

## 5. Why we hold it — lawful bases

Under UK GDPR Article 6 we rely on:

- **Article 6(1)(b) — performance of a contract** — to hold your account, your drafts, and your submitted filings so we can provide the service, so you can come back and see what you filed, and so a filing can be proved afterwards.
- **Article 6(1)(a) — consent** — for marketing emails only, if we later ask you to opt in separately. Accepting the terms does **not** consent you to marketing.

We do not rely on Article 6(1)(c), legal obligation. We are a software supplier. Your company is required to keep its own accounting records (Companies Act 2006, section 386) and the records it needs for its tax returns (Finance Act 1998, Schedule 18, paragraph 21).

## 6. Who we share it with

- **HMRC** — your CT600, iXBRL accounts, and iXBRL computation are transmitted to HMRC, to whom the company delivers its Company Tax Return.
- **Companies House** — two separate connections, and only the first happens automatically.
  - *Looking things up.* We query Companies House's public Data API to fill in your company's name, registered office, and last-filed accounts, and to check your directorship. This gives Companies House only the company number and the officer-list request.
  - *Sending.* If you choose to send your accounts to Companies House from your account page, we transmit the micro-entity accounts document, your company's name and number, the date the accounts were approved, and the company's own authentication code to the Companies House filing gateway. Those sends currently reach Companies House's **test** service only, so nothing sent through the service today reaches the public register, and you must still file your accounts with Companies House yourself. We will publish a new version of this policy before that changes.
- **Clerk** — authentication. Your sign-in credentials are managed by Clerk; we hold only Clerk's opaque user id.
- **Neon** — Postgres database hosting, with provider-managed encryption at rest.
- **Resend** — transactional email: account-lifecycle emails and accepted-filing receipts.
- **Sentry** — error monitoring. Production errors may be sent to Sentry with the request context needed to diagnose the fault. We strip tax form contents, iXBRL bodies, HMRC response bodies, full filing documents, cookies, and authorisation headers before an event is sent.
- **PostHog** — product analytics and optional masked support replay. See section 8: these are switched off, and nothing reaches PostHog while they are.
- **Codex/OpenAI** — during early beta we may ask an OpenAI-hosted Codex agent to review a short-lived signed evidence bundle for your filing journey, so we can check that sign-up, drafting, review, validation, submission, and result handling are working. The bundle is generated from our own systems and can include account and session identifiers, form progress, validation and submission status, interaction journal rows, and safe error summaries. It is for support, debugging, and safety checks, never advertising. The links expire and are not public.

- **Vercel** — hosting. The application runs on Vercel's platform, which necessarily handles the requests you make to it.

Those are the companies that handle your data on our behalf. Each acts on our instructions and may not use your data for its own purposes. If we add one, we will publish a new version of this policy.

## 7. The interaction journal

During beta we keep an internal journal of how the form was used, so we can see where the filing journey breaks. It records structured facts — which field changed, whether it was empty, roughly how long the value was, the validation state, checkbox and gate answers, save status, and what blocked a review or a submission. It does not record the raw value of a sensitive field; it records exact values only for checkboxes, gate options, and support preferences, which are safe to keep as typed.

**We would rather state this than hide it: the journal is not yet removed when you delete your account, and it is not yet deleted on a timer.** If you want it deleted, write to privacy@freefiler.co.uk and we will delete it.

## 8. Cookies, analytics, and session replay

We use cookies that are strictly necessary to sign you in and keep you signed in.

**Product analytics and session replay are off.** They are off by default in the code, and nothing about your behaviour reaches PostHog while they are. Analytics and support replay are not needed to provide the filing service, so we will not switch them on without asking for your consent separately — accepting the terms does not count as that consent. We will ask first and publish a new version of this policy. We do not use advertising cookies at all.

## 9. How long we keep it

We keep your account, your drafts, and your filing records for as long as you have an account with us. Nothing is deleted automatically after a set period; deletion happens when you ask for it.

You can hide any filing or draft from your account list at any time. Hiding never removes anything and you can bring it back. A filing that has been submitted cannot be deleted, by you or by us, because it is the record of what was sent to HMRC.

To remove the figures you entered, delete your account from your `/account` page. When you do, we:

1. Email you a confirmation with a seven-day grace period and a one-click cancellation link.
2. Include in that email a signed link to download an export of your data: your account profile, and per company a folder holding the CT600 XML, the iXBRL accounts, the iXBRL computation, the GovTalk envelope, and HMRC's response. The export covers the HMRC side of a filing; the record of a Companies House send is not in it yet, and you can ask us for it at privacy@freefiler.co.uk.
3. On confirmation, delete your login, your account, and your company memberships, and unlink the filings you submitted so they are no longer connected to you. Your drafts are deleted with them, unless another director of the same company still has an account — in which case that company's drafts stay with them.
4. Keep the evidence of what was sent: the generated CT600 XML, the iXBRL accounts and computation, the GovTalk envelope, the IRmark, timestamps, HMRC's response, any Companies House send evidence, and the provenance metadata. It is no longer connected to your account, and we keep it so a filing can still be proved if HMRC, Companies House, or you ever need it. We cannot edit those documents: a filed return names its company and the person who made its declaration, and altering the bytes would destroy the only proof of what was sent, so those names stay in the retained evidence.
5. Email you again to confirm the deletion is done.

The one thing that does not yet follow this route is the interaction journal in section 7, and you can ask us to delete that.

## 10. Your rights

Under UK GDPR you have the right to ask us to:

- give you access to your data — through your `/account` page, or by writing to privacy@freefiler.co.uk
- correct inaccurate data — change it in the form, or contact us
- erase your data — use "Delete my account" on `/account`, or write to us
- restrict processing, or give you the data you gave us in a machine-readable form — contact us

You also have the right to object to processing — contact us.

You have the right to complain to us, by writing to privacy@freefiler.co.uk, if you consider that how we handle your personal data infringes the UK GDPR.

If you consider that how we handle your personal data infringes the UK GDPR, you can complain to the Information Commissioner (ico.org.uk).

## 11. Changes to this policy

We publish a new version here when we make a material change, and the version number above moves each time.

## 12. Contact

Render Technologies Ltd<br>
Company number: 17088258<br>
Registered office: 39 Islingword Road, Brighton, BN2 9SF<br>
privacy@freefiler.co.uk

Complaints about privacy can be sent to privacy@freefiler.co.uk. You also have the right to complain to the Information Commissioner if you consider that our handling of your personal data infringes the UK GDPR.

FreeFiler beta is operated by Render Technologies Ltd.