Privacy Policy - TunedBooks

Effective: 1 January 2026 | Last Updated: June 2026

We are committed to protecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Nigeria Data Protection Act (NDPA) 2023, and all applicable global data protection regulations.

1. Introduction & Who We Are

Welcome to TunedBooks. We are committed to protecting your privacy and the security of your personal and business information. This Privacy Policy applies to all users globally and complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Nigeria Data Protection Act (NDPA) 2023, and applicable international data protection laws.

Company: Tuned Digital Solutions Limited (RC 9022196) | UK Entity: Tuned Digital Solutions UK Limited | DPO: Abdullahi Afolarin | Email: privacy@tunedbooks.online | Address: Plot 14, Katampe Extension, Abuja, Nigeria

2. Information We Collect

Information You Provide: full name, email, phone, business name, address, type, tax IDs (VRN, NINO, TIN), transactions, sales, purchases, expenses, customer data, inventory, financial records, payment details (processed by Apple/Google/Paystack/Stripe — not stored), support messages.

Automatically Collected: usage stats, device info, IP, HMRC OAuth tokens, fraud prevention data (device ID, OS, screen, timezone, IP — required by UK Finance Act 2020).

3. How We Use Your Information

Lawful bases: Contract, Legal Obligation, Legitimate Interest, Consent. Purposes: account management, service delivery, tax submissions (HMRC/FIRS), payments, notifications, analytics, fraud prevention, compliance.

4. HMRC Making Tax Digital (MTD) — UK Users

We submit VAT/Income Tax returns via OAuth, store secure tokens, send required fraud headers. Never store HMRC login details. You remain responsible for accuracy. Disconnect anytime in Settings.

5. How We Share Your Information

We do NOT sell data. Shared only with: HMRC, FIRS, Google/Firebase, Apple/Google, Paystack, Stripe, legal authorities (when required).

6. How We Protect Your Information

TLS 1.3, AES-256 encryption, secure database, Firebase rules, role-based access, secure token storage, 2FA/biometrics.

7. Data Retention

Active data: while account open. Financial records: 7 years (tax law). Audit logs: 7 years. Deleted accounts: profile removed in 30 days, records retained 7 years.

8. Your Rights

UK (UK GDPR): Access, Rectify, Erase, Data Portability, Object, Restrict, Withdraw Consent, Complain to ICO (ico.org.uk).

Nigeria (NDPA 2023): Access, Correct, Delete, Portability, Object, Complain to NDPC (ndpc.gov.ng).

9. International Data Transfers

Data processed in USA (Google Cloud — UK-US Adequacy Agreement) and Nigeria. Protected via SCCs and DPA.

10. Children's Privacy

For users 18+. No data collected from minors.

11. Cookies and Tracking

Essential, Performance, Functional cookies only. No advertising tracking.

12. Security Breach Notification

Notify ICO/NDPC within 72 hours, notify users if high risk. Report vulnerabilities: security@tunedbooks.online.

13. Changes to This Policy

Updates notified 30 days in advance. Continued use means acceptance.

14. Contact Us

Data Protection Officer: Abdullahi Afolarin | privacy@tunedbooks.online | security@tunedbooks.online

Privacy Policy

Effective: 1 January 2026 | Last Updated: June 2026

We are committed to protecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Nigeria Data Protection Act (NDPA) 2023, and all applicable global data protection regulations.

1
Introduction & Who We Are

Welcome to TunedBooks. We are committed to protecting your privacy and the security of your personal and business information. This Privacy Policy applies to all users globally and complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Nigeria Data Protection Act (NDPA) 2023, and applicable international data protection laws.

Who We Are
  • Company: Tuned Digital Solutions Limited (RC 9022196)
  • UK Entity: Tuned Digital Solutions UK Limited (Companies House)
  • Data Protection Officer: Abdullahi Afolarin
  • Privacy contact: privacy@tunedbooks.online
  • Security contact: security@tunedbooks.online
  • Address: Plot 14, Katampe Extension, Abuja, Nigeria
2
Information We Collect

Information You Provide

  • Account information: full name, email address, phone number
  • Business details: business name, address, business type and sector
  • Tax identifiers: VAT Registration Number (VRN), National Insurance Number (NINO), Tax Identification Number (TIN)
  • Business records: transactions, sales, purchases, expenses, customer data, inventory, financial summaries
  • Payment information: processed by Apple, Google, Paystack, or Stripe — we do NOT store full card details
  • Communications: messages sent through customer support, feedback, and survey responses

Information Automatically Collected

  • Usage data: log-in times, features used, pages visited, time spent in app
  • Device information: device type, operating system, unique device identifiers, IP address
  • HMRC OAuth tokens: secure access tokens allowing us to submit to HMRC on your behalf (never your HMRC password)
  • Fraud prevention data: device ID, OS version, screen size, timezone, local IP address — required by UK law (Finance Act 2020) to be submitted to HMRC with every API call
3
How We Use Your Information

We process your personal data under the following lawful bases:

Lawful Basis for Processing
  • Contract — to provide the TunedBooks service you subscribed to
  • Legal obligation — to comply with HMRC Making Tax Digital requirements and UK fraud prevention law
  • Legal obligation — to comply with FIRS requirements (Nigerian users)
  • Legitimate interests — fraud prevention, security, service improvement
  • Consent — for marketing communications (you may withdraw at any time)

Specifically We Use Your Data To

  • Create and manage your account
  • Provide business management, invoicing, and record-keeping features
  • Submit Making Tax Digital VAT returns and income tax summaries to HMRC on your behalf (UK users)
  • Generate FIRS-compliant e-invoices (Nigerian users)
  • Process your subscription payments
  • Send important service updates, security alerts, and notifications
  • Analyse app usage to improve features and fix technical issues
  • Detect and prevent fraud and security threats
  • Comply with legal obligations in applicable jurisdictions
4
HMRC Making Tax Digital (MTD) — UK Users

When you connect TunedBooks to HMRC for Making Tax Digital compliance, the following applies in addition to the rest of this policy:

What We Do

  • Submit VAT returns and Income Tax quarterly summaries to HMRC on your behalf via OAuth 2.0
  • Store a secure OAuth 2.0 access token so you stay connected to HMRC between sessions
  • Send fraud prevention headers to HMRC as required by the Finance Act 2020
  • Maintain a secure audit log of all HMRC submissions in your account

What We Never Do

  • Store your HMRC username or password — ever
  • Access more HMRC data than you explicitly authorise via the OAuth consent screen
  • Submit returns to HMRC without your explicit confirmation in the app
Fraud Prevention Headers
  • UK law requires us to send device and connection information to HMRC with every API call
  • This includes: device ID, operating system, screen size, timezone, and IP address
  • This data is sent directly to HMRC under their fraud prevention specification v3.3
  • Disconnect at any time: Settings → HMRC Connection → Disconnect
Your Responsibility
  • You confirm that data submitted to HMRC is accurate and complete to the best of your knowledge
  • TunedBooks acts as your software agent — you remain the taxpayer responsible for the accuracy of returns
  • Tax penalties arising from inaccurate data you provided are your responsibility
  • MTD quarterly submissions do not replace a Self Assessment return — consult a qualified UK tax advisor
5
How We Share Your Information

We do NOT sell, rent, or share your personal data with third parties for marketing purposes.

We Share Data Only With

  • HMRC — tax submissions made on your behalf with your explicit authorisation (UK users)
  • FIRS — via official e-invoicing systems where applicable (Nigerian users)
  • Google/Firebase — cloud infrastructure provider under a Data Processing Agreement (DPA)
  • Apple/Google — subscription payment processing under their own privacy policies
  • Paystack — payment processing for Nigerian users under a DPA
  • Stripe — payment processing for web/global users under a DPA
  • Legal authorities — only when required by UK, Nigerian, or other applicable law, with notice to you where permitted
6
How We Protect Your Information

Your business data is highly sensitive. We implement industry-leading security measures:

Security Measures
  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest (both cloud and on-device storage)
  • Encrypted on-device SQLite database (sqflite_sqlcipher)
  • Firebase security rules preventing unauthorised access — users can only access their own data
  • Role-based access control within businesses (owner vs member permissions)
  • HMRC OAuth tokens stored with server-only access — never exposed to the client app
  • HMRC client credentials stored in secure server-side secrets, never in app code
  • 2FA and biometric authentication available for account access
7
Data Retention

Retention Periods

  • Active account data: retained while your account is active
  • Financial and transaction records: 7 years after account closure (UK and Nigerian tax law requirement)
  • HMRC submission audit logs: 7 years (HMRC requirement)
  • HMRC OAuth tokens: until you disconnect or your account is deleted
  • Support communications: 3 years
  • Marketing consent records: until withdrawn or 2 years of inactivity
  • Deleted accounts: personal profile data deleted within 30 days; financial records retained 7 years for legal compliance
8
Your Rights

Depending on your location, you have the following rights over your personal data:

UK Users — Rights Under UK GDPR

  • Right to access — request a copy of your personal data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion (Settings → Delete Account)
  • Right to data portability — export your data in machine-readable format (Settings → Export Data)
  • Right to object — object to processing for direct marketing
  • Right to restrict processing — limit how we use your data in certain circumstances
  • Right to withdraw consent — disconnect HMRC at any time (Settings → HMRC Connection → Disconnect)
  • Right to lodge a complaint with the ICO: ico.org.uk | 0303 123 1113

Nigerian Users — Rights Under NDPA 2023

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to deletion of your data (Settings → Delete Account)
  • Right to data portability (Settings → Export Data)
  • Right to object to processing
  • Right to lodge a complaint with the NDPC: ndpc.gov.ng

To exercise any right, contact us at privacy@tunedbooks.online. We will respond within 30 days.

9
International Data Transfers

TunedBooks uses Google Cloud Platform (Firebase) infrastructure. Your data may be processed in the following locations:

Data Processing Locations

  • United States — Google Cloud us-central1 (primary server location)
  • Nigeria — NDPC-compliant processing for Nigerian users
UK Users — Adequacy Protection
  • The USA has an adequacy agreement with the UK: the UK-US Data Bridge (in force October 2023)
  • Your data processed on US servers receives equivalent protection to UK GDPR
  • Google Cloud operates under Standard Contractual Clauses (SCCs) for additional protection
  • Full details: cloud.google.com/privacy/gdpr
Nigerian Users — Cross-Border Transfers
  • Data transfers outside Nigeria comply with NDPA 2023 requirements
  • Google Cloud operates under a Data Processing Agreement ensuring NDPA-equivalent protection
10
Children's Privacy

TunedBooks is designed for business owners and professionals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, contact us immediately at privacy@tunedbooks.online.

11
Cookies and Tracking

Types of Cookies We Use

  • Essential cookies: required for login, security, and core functionality
  • Performance cookies: track feature usage and app performance to improve the service
  • Functional cookies: remember your preferences such as dark mode and language

We do not use advertising or third-party tracking cookies. You can manage cookies in Settings → Privacy or in your device/browser settings.

12
Security Breach Notification

In the event of a personal data breach, we will:

For UK Users

  • Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware
  • Notify HMRC within 72 hours via the HMRC developer support portal
  • Notify affected users without undue delay where the breach poses a high risk to your rights

For Nigerian Users

  • Notify the Nigeria Data Protection Commission (NDPC) within 72 hours as required by NDPA 2023
  • Notify affected users as required by law
Report a Security Vulnerability
  • Email: security@tunedbooks.online
  • We aim to respond to all security reports within 24 hours
  • Please provide as much detail as possible about the potential vulnerability
13
Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes via email and in-app notification at least 30 days in advance. Minor changes will be reflected in the "Last Updated" date above. Continued use of TunedBooks after the effective date constitutes acceptance.

14
Contact Us

Data Protection Officer

Abdullahi Afolarin
Tuned Digital Solutions Limited · RC 9022196
Plot 14, Katampe Extension, Abuja, Nigeria
privacy@tunedbooks.online
security@tunedbooks.online (security issues)
UK ICO Registration Number: [To be added after registration]
UK complaints: ico.org.uk | 0303 123 1113
Nigerian complaints: ndpc.gov.ng