1. Who we are
This Privacy Policy explains how personal data is processed in connection with Neysan Group (neysangroup.com) and the Excel Solutions Portal (portal.excelsolutions.uk).
Neysan Group develops and maintains the software. Excel Financial Solutions Limited (“Excel Solutions”) operates the portal for accountancy practice work.
Contact — Neysan Group:
contato@neysangroup.com
Contact — Excel Solutions portal privacy:
contact@excelsolutions.uk
2. Scope
This policy covers personal data processed when:
- you browse or contact us via neysangroup.com;
- staff use the Excel Solutions Portal;
- clients or contacts use public forms, payment links, or customer access we host;
- the portal connects to third-party services (for example HMRC Making Tax Digital for VAT, Intuit QuickBooks Online / QuickBooks Online Accountant, Companies House, GoCardless, Stripe, and email delivery).
3. Data we process
Depending on how our sites and products are used, we may process:
- Website / enquiry data — contact details you send us (email, WhatsApp, forms) and basic technical logs;
- Staff account data — name, email, role, login and security events;
- Client / company records — contact details, company identifiers, engagement and filing-related information entered into the portal;
- HMRC VAT (MTD) data — when a company connects Government Gateway / HMRC OAuth, we may retrieve and store VAT obligations, returns, liabilities, payments, penalties, and related registration/customer information needed to operate VAT workflows in the portal;
- Payment data — payment statuses, mandate/schedule references, and related metadata from payment providers (card numbers and bank account secrets are handled by those providers, not stored as full PANs/IBANs in the portal);
- Accounting data from QuickBooks — when an owner/admin connects the practice and links a company, we may retrieve bookkeeping summaries such as account balances, profit and loss totals, and transaction lines for staff use inside the portal;
- Companies House data — company profile and filing-related information retrieved to keep practice records up to date;
- Technical / fraud-prevention data — IP address, browser type, timestamps, device/connection signals required by HMRC fraud-prevention guidance, and basic diagnostics needed to secure and operate the Service.
4. Why we process it (lawful bases)
- Contract / legitimate interests — to run the practice portal, respond to enquiries, deliver accountancy operations support, and keep systems secure;
- Legal obligation — where records must be retained for accounting, tax, or regulatory reasons;
- Consent — where a specific optional feature requires it (we will say so at the point of collection), including where a company authorises HMRC or QuickBooks access via OAuth.
5. HMRC Making Tax Digital for VAT
Where HMRC VAT is connected for a company, HMRC authenticates the company’s Government Gateway user and issues OAuth tokens stored only on our servers. Staff of the practice can then sync and view mirrored VAT information inside the portal. Disconnecting HMRC in the portal stops new API access; historical mirrored records may remain according to our retention rules.
We do not store Government Gateway usernames or passwords. Access uses OAuth 2.0; only tokens are retained server-side.
Each company remains responsible for its own VAT obligations to HMRC. The portal is an operational tool; it does not replace the company’s duty to file and pay correctly.
HMRC also processes data under its own privacy notices when Government Gateway / HMRC services are used.
6. QuickBooks / Intuit
If QuickBooks is connected, Intuit authenticates the practice and issues tokens stored only on our servers. Staff of the practice can then view linked company information through the portal without each person logging into QuickBooks separately. Disconnecting QuickBooks in the portal stops new API access; historical portal records may remain according to our retention rules.
Intuit also processes data under its own privacy terms when you use QuickBooks products.
7. Who we share data with
We use processors/providers needed to operate our sites and products, which may include:
- hosting and database providers;
- authentication and email delivery;
- HMRC (when VAT MTD is connected for a company);
- Companies House;
- payment processors (GoCardless, Stripe);
- Intuit (QuickBooks) when that integration is enabled;
- Neysan Group as software developer / processor supporting the platform;
- professional advisers or authorities where required by law.
We do not sell personal data.
8. International transfers
Some providers may process data outside the UK. Where that happens, we use appropriate safeguards required by UK data-protection law (such as standard contractual clauses or equivalent mechanisms offered by the provider).
9. Retention
We keep personal data only as long as needed for the purposes above, including practice retention needs and legal requirements, then delete or anonymise it where practicable.
10. Security
We use access controls, server-side secrets for integrations, HTTPS, and role-based permissions. OAuth tokens for HMRC and QuickBooks are not exposed to the browser. No method of transmission or storage is perfectly secure; please protect your login and tell us promptly if you suspect unauthorised access.
11. Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. To exercise these rights, email contact@excelsolutions.uk (portal) or contato@neysangroup.com (Neysan Group website / developer enquiries). You may also complain to the UK Information Commissioner’s Office (ICO).
12. Children
Our products and website are not directed at children and are intended for business use.
13. Changes
We may update this policy from time to time. The “Last updated” date shows the current version.