What Mini Accounts holds about you, why, for how long, who else receives it, where it is processed, and how to see, correct or delete it. For miniaccounts.uk, the application served there, and the app installed from it.
← Back to Mini Accounts · Log inMini Accounts is provided in the United Kingdom by Aulakh Accounting and Technology Solutions, a sole proprietorship of Kulwinder Singh, Chartered Accountant (India), VPO Gurney Kalan, Budhlada, District Mansa, Punjab 151502, India. For the details on this page we are the controller under the UK General Data Protection Regulation and the Data Protection Act 2018, which apply to us because we offer the service to people in the United Kingdom. We are established in India, have no establishment in the United Kingdom, and have not appointed a representative in the United Kingdom under Article 27 of UK GDPR. We have no data protection officer; the proprietor answers for everything on this page.
One address for everything about your data — a question, a request or a complaint: support@miniaccounts.uk, or by post to the address above. The telephone number is on the Contact page.
The Indian service at miniaccounts.in is a separate portal with its own notice, its own database and its own storage.
We set one cookie, to keep you signed in. There is no advertising, no analytics, no tracking pixel and no third-party script anywhere in this website or the application.
The lawful basis for each item is given in the second column: contract means it is needed to provide the service you registered for (Article 6(1)(b)); legal obligation means the law requires us to keep it (Article 6(1)(c)); legitimate interests means we need it to keep the service secure and to answer for what we did, and we have judged that it does not override your interests (Article 6(1)(f)); consent means you asked for it and can withdraw (Article 6(1)(a)). Giving us your name, email address and mobile number is a condition of having an account: without them we cannot open one, confirm it or write to you about it.
| What | Why, and on what basis | How long |
|---|---|---|
| Your account: the business or practice name, the kind of account, your email address, mobile number and country | To open and run your account: to sign you in, confirm your email address, and write to you about your account, payments and renewal. Contract. | While the account exists. Deleted within 30 days of a request to delete the account. |
| Your sign-in: a code your device works out from your password, which we hash again before storing it — never the password itself; one-way hashes of the six-digit email code and of any reset code, with when they expire | To check that it is you, and to confirm your address or reset your sign-in. Contract. | The sign-in hash while the account exists; a code until it is used or replaced |
| Your plan: the plan, the date it runs to, and when the account was switched on | To know what you have paid for, and to switch the software on or off. Contract. | While the account exists |
| Sessions: a random sign-in token (we keep only its hash), when it started and when it ends, the IP address, the browser, and the device identifier | To keep you signed in, to end a session when another computer takes its place, and for security. Contract, and legitimate interests for the security part. | Deleted when you sign out or the session ends, and in any case after 30 days |
| Devices: a random device identifier your browser makes and keeps, and sends to us when you sign in; a label such as “Chrome on Windows”; when it was first and last seen; and, for a practice, a one-way hash of the practice name in the folder it opened (the name itself is never sent) | To count how many devices a subscription is used on, and to notice one subscription being shared by different firms. Legitimate interests. | A device unused for 60 days is removed the next time the account signs in; all of them go with the account |
| Your last visit: when you last opened the application, the IP address it came from, and which version of the application it was | Support and security. Legitimate interests. | Replaced at each visit; deleted with the account |
| Sign-in attempts: each attempt, recorded against the email address and against the IP address; and each time an account looks up an accountant to share books with | To slow down anyone guessing passwords or trying addresses one after another. Legitimate interests. | Deleted after 24 hours |
| Payments: the date, the amount, the plan, the invoice, your VAT number if you give it, and the email address the payment was made under. Payment is by bank transfer or another way arranged by email; we see what our bank statement shows and what you write to us, and never a card number | To switch the plan on and to keep accounts of the money we receive. Contract, and legal obligation for the record. | The payment record for 8 years, which is the record-keeping period the law in India sets for our own accounts |
| A record of what was agreed and done: when you ticked the box at registration to agree to the Terms of Service and this policy, and which version of the notice was on screen; and what we have done to the account by hand, such as switching it on, extending it, suspending it, sending a reset code or deleting it, with the plan and dates it changed and any reason written with it. Each record names the account by its email address | To show what was agreed and what was done. Legitimate interests, and legal obligation where the record is one we must keep. | 8 years, kept with the payment records, including after the account is deleted |
| Books in cloud storage (a business that turns it on): the books, as ciphertext encrypted on your device; for each stored copy, which set of books and period it is, the business’s name as a readable label, its size, a checksum, which device sent it and when; and the locked copy of your encryption key — locked by your password and separately by your recovery code — so a second device can open the books | To open the same books on a phone or a second computer by signing in. Contract. For the personal data inside the books — your customers, suppliers and staff — you are the controller and we are your processor, holding ciphertext we cannot read. | While the account exists, whether or not the plan has lapsed; deleted with the account |
| Sharing keys (every account): a key pair for sharing books — the public half readable, the private half as ciphertext locked by your own sign-in | So that a business can share its books with its accountant without our being able to read them. Contract. | While the account exists |
| Books shared with an accountant: which business and which accountant’s account; the books’ key, locked for the accountant (ciphertext); when the share was given, renewed or withdrawn; and which of the two is working on the books, from which device, and since when | To let the accountant open the books, and to keep one of the two working on them at a time. Contract. | While both accounts exist; a withdrawn share is kept, marked withdrawn, and goes when either account is deleted |
| A demo enquiry: your name and email address, a one-way hash of the code we email you, whether it is for a business or a practice, and when you ticked the consent box, with the notice on screen | To arrange your demonstration and follow up about Mini Accounts. The enquiry is emailed to our own support address so a person can reply. Consent. | Deleted after 30 days if the email address is never confirmed, after 18 months if it is, and sooner if you ask |
We do not hold ledgers, trial balances, bank statements, invoices, payslips, customer, client or employee names, employees’ bank details and email addresses, subcontractors’ tax references, or any other figure from your books in a form we can read, apart from the business’s name on each stored copy, above. Where the application reads a photograph or a scanned PDF, it does so on your own device; the picture is not sent to us. We make no decision about you by automated means, and we do no profiling.
| Name | Purpose | Expires | Type |
|---|---|---|---|
ma_session |
Keeps you signed in after you enter your password. It holds a random token and nothing else. | 30 days, or at once when you sign out | Strictly necessary |
The cookie is marked HttpOnly (scripts cannot read it), Secure (sent only over HTTPS) and
SameSite=Lax (not sent from other websites). Under the Privacy and Electronic Communications Regulations
a cookie that is strictly necessary to provide a service you have asked for needs no consent, and a sign-in cookie
is the standard example, so it is set whatever you answer on the cookie notice below: refusing it would simply mean
being unable to sign in. We set no other cookie, and we would ask you before adding one that is not necessary.
The cookie notice at the foot of each page asks one thing: whether the website’s pages may have your browser
keep a copy of the application (a service worker), so that it opens quickly and works when your connection is
poor, and so that a phone can install it. Accept all allows it. With Essential only, or before you
answer, the pages do not ask your browser to keep it. Your answer is kept in your browser’s own storage under
miniaccounts.cookieChoice, with the day you gave it; it is not a cookie and it is not sent to us. To
change it, use Cookie choices at the foot of any other page of this website. Three things ask for the application itself and keep
its copy whatever you answered: signing in, the app installed on a phone, and the home page’s button that
puts Mini Accounts on your phone.
The application also keeps working copies in your browser’s own storage: your workbook and client register, the lock that opens encrypted books, the folders you connected, where cloud storage last synchronised, when you last backed up, the name shown on the sign-in screen, the device identifier, and your answer on the cookie notice. A service worker keeps a copy of the application itself so that it opens when the connection is poor. These stay on your device, apart from the device identifier, which is sent when you sign in, and the books a business stores in the cloud, which are encrypted before they leave. Clearing this website’s data in your browser removes them; signing out clears the application’s own copy. A practice’s books stay in its folder, and a business with cloud storage keeps its stored copy; anything kept only in the browser goes with it, which is why the Data screen offers a backup.
The app installed on a phone from this website is the same application in the phone’s browser engine, and keeps its data in the same way.
We do not sell your details, share them with advertisers, or pass them to anyone for their own purposes. We send no marketing email; every email we send is about your account, your payment or the demonstration you asked for.
If a breach affects your personal data and is likely to result in a risk to you, we will tell the Information Commissioner’s Office within 72 hours of learning of it, and tell you without undue delay where the risk is high, as UK GDPR requires. A breach of books held as ciphertext exposes ciphertext.
Under UK GDPR you may ask us:
How. Email support@miniaccounts.uk from the address your account is registered with — that address is how we know the request is yours — or write to the address above. We answer within one month, as the law requires, and usually within 7 days. There is no charge.
Withdrawing consent is as easy as giving it: one email. Your account details are what the account runs on, so asking us to delete them means closing the account. What was done before you asked stays lawful, and the records we must keep, such as payment records, are kept for the period given above.
Where we rely on your consent — a demonstration request is the clearest example — we ask for it separately, say what it is for before you give it, and record when it was given. We do not make consent to one thing a condition of getting another.
Write to Kulwinder Singh, Proprietor, at support@miniaccounts.uk, or by post to VPO Gurney Kalan, Budhlada, District Mansa, Punjab 151502, India. A complaint about your personal data is acknowledged within 5 working days — the Data Protection Act 2018 allows 30 — and answered without undue delay; any other complaint is acknowledged within 24 hours and answered within 7 days. More on Complaints.
If you are not satisfied with our answer, you may complain to the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You may go to the ICO at any time, but it usually expects you to have raised the matter with us first.
Children. Mini Accounts is for people aged 18 or over, and we do not knowingly hold personal data of anyone younger.
Indian law. Because we are established in India, the Digital Personal Data Protection Act, 2023 also applies to us. Nothing in it reduces the rights this page gives you.
What we never do. We run no analytics and no tracking. We do not use your data, or your clients’ data, to train anything. There is no profiling, and no automated decision that has a legal or similarly significant effect on you.
Changes. This is version 2026-09-24 of this policy. When it changes, the date below changes, and a change to what we collect or why is shown on this page before it applies.