Privacy Policy
Last updated: 20 March 2026
1. About Filed Quarterly
Filed Quarterly Ltd provides cloud-based landlord reporting and Making Tax Digital (MTD) compliance software for UK letting agents. Inquiries can be sent to hello@filedquarterly.co.uk.
2. Data Collected
Filed Quarterly collects and processes the following personal data:
- Account information: name, email address, agency name, role
- Financial data: bank transaction descriptions, amounts, dates (via CSV upload)
- Landlord data: name, email, phone, tax reference (UTR) and National Insurance number (NINO) - both securely encrypted where they are stored
- Property data: addresses, tenancy details, rent amounts
- HMRC data: secure access keys (encrypted where stored), submission responses
- Usage data: pages visited, features used, IP address
3. Purposes and Legal Basis for Processing
- Contract performance: to provide the Filed Quarterly service you signed up for
- Legal obligation: to comply with HMRC Making Tax Digital requirements and tax reporting obligations
- Legitimate interest: to improve the service, send service-related emails, and prevent fraud
4. How Data is Used
- Generating landlord financial statements and reports
- Submitting quarterly income and expense data to HMRC on your behalf
- Matching bank transactions to properties and tenancies
- Sending service emails (MTD deadline reminders, password resets, invitations)
- Providing customer support
5. Data Sharing and Recipients
- HMRC: quarterly income and expense submissions via the MTD API, as authorised by you
- Brevo: for sending transactional emails
- Stripe: for payment processing (card details are not stored by Filed Quarterly)
- Microsoft Azure: cloud hosting (data stored in UK South region)
Filed Quarterly does not sell your data to third parties. Filed Quarterly does not share your data with anyone not listed above.
6. Data security
- All data is sent over a secure, encrypted connection (HTTPS)
- Sensitive personal data (National Insurance numbers, tax references) is strongly encrypted where it is stored, so it cannot be read even by someone with direct access to the database
- The access keys that allow submissions to HMRC on your behalf are encrypted and stored securely
- The database is hosted in the UK on Microsoft Azure, with stored data encrypted
- Internal admin access is restricted, with sensitive fields hidden and access keys never shown
- Role-based access with configurable team permissions (Professional plan)
- Secure sign-in sessions, protected against unauthorised requests
- Passwords are stored using strong one-way encryption, so they can never be read as plain text
7. Data retention & portability
Filed Quarterly retains your data for as long as your account is active. Financial transaction data and reports are kept for 6 years after creation to comply with HMRC record-keeping requirements. If you delete your account, Filed Quarterly removes personal data within 30 days, except where retention is required by law.
If you downgrade or cancel your subscription, you retain full read-only access to all existing data. Filed Quarterly never locks you out of your own data. You can export all your agency data at any time from Settings > Account > Data & Privacy as a ZIP file containing CSV files. Sensitive fields (NINOs, tax references) are masked in exports for security.
8. Your rights (UK GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Export your data in a portable format (available via Settings > Account > Export Data)
- Object to processing based on legitimate interest
- Withdraw consent at any time
To exercise any of these rights, email hello@filedquarterly.co.uk. A response will be provided within 30 days.
9. Cookies
Filed Quarterly uses essential cookies only: a cookie to keep you signed in and a security token that helps prevent unauthorised requests. Filed Quarterly does not use tracking cookies, analytics cookies, or advertising cookies.
10. Changes to this policy
This policy may be updated from time to time. Users will be notified of significant changes by email or via the application. The “last updated” date at the top reflects the most recent revision.
11. Security
To report a security vulnerability or incident, email hello@filedquarterly.co.uk immediately with the subject line “Security”. Filed Quarterly will acknowledge receipt within 24 hours and investigate promptly.
12. Contact
If you have questions about this privacy policy or want to make a complaint, contact hello@filedquarterly.co.uk. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.