TradesOffice

Privacy Policy

Effective: 15 May 2026  ·  Last updated: 15 May 2026  ·  ICO: ZC133896

This Privacy Policy explains how TradesOffice collects, uses, stores and protects personal data when you use the TradesOffice platform, website, applications and related services (the "Service").

TradesOffice is committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable privacy laws.

Trades Office Limited is registered in England and Wales under company number 17181500. ICO Registration Number: ZC133896.

1. About TradesOffice

TradesOffice is an operational administration platform designed for UK trades businesses, including sole traders and small limited companies.

The Service helps users organise and manage operational business records and communications, including:

  • invoices;
  • quotes;
  • expenses;
  • mileage logs;
  • CIS records;
  • accountant exports;
  • customer communications;
  • and workflow administration;

TradesOffice is not:

  • an accountancy practice;
  • bookkeeping software;
  • payroll software;
  • or HMRC-recognised filing software;

2. Data Controller & Processor Roles

For most customer business data processed through the Service:

  • the customer business acts as the data controller;
  • and TradesOffice acts as the data processor.

TradesOffice acts as a data controller for:

  • account registration data;
  • billing information;
  • support communications;
  • operational analytics;
  • and platform security data;

This relationship is further governed by the TradesOffice Data Processing Agreement, which forms part of the contractual relationship between TradesOffice and its users.

3. Information We Collect

TradesOffice may collect and process the following categories of personal data.

Account Information

  • name;
  • business name;
  • email address;
  • phone number;
  • billing information;
  • UTR number (where voluntarily provided);
  • password credentials (stored as a bcrypt hash — we never see your plain-text password);
  • and account credentials;

Customer Business Records

  • invoices;
  • quotes;
  • expense records;
  • mileage records;
  • CIS records;
  • customer names;
  • customer contact details;
  • job information;
  • and operational notes;

Communications & Message Data

  • WhatsApp messages;
  • SMS messages;
  • uploaded images;
  • voice note audio;
  • transcriptions;
  • and support communications;

Technical & Usage Data

  • IP addresses;
  • browser information;
  • session information;
  • device information;
  • runtime logs;
  • audit logs;
  • page interactions;
  • and product analytics data;

4. How We Use Personal Data

TradesOffice uses personal data to:

  • provide and operate the Service;
  • process invoices and operational records;
  • provide AI-assisted drafting and classification;
  • authenticate users;
  • manage subscriptions and billing;
  • provide customer support;
  • monitor platform stability and security;
  • improve platform functionality;
  • generate accountant exports;
  • comply with legal obligations;
  • and prevent fraud or misuse;

5. AI Processing & Human Review

The Service uses artificial intelligence and automated processing tools to assist with the preparation, drafting, organisation and classification of operational business records and communications.

This may include processing:

  • message text;
  • uploaded receipt images;
  • invoice information;
  • operational records;
  • and voice note transcriptions;

Customer data submitted through the Service is not used by TradesOffice to train general-purpose AI models.

TradesOffice uses third-party AI providers including OpenAI and Anthropic to process operational data submitted through the Service.

All AI-generated outputs should be reviewed by the user before legal or commercial reliance.

6. Lawful Bases for Processing

TradesOffice processes personal data using the following lawful bases under UK GDPR.

PurposeLawful Basis
Providing the ServiceContract
Account managementContract
Subscription billingContract
Fraud preventionLegitimate interests
Security monitoringLegitimate interests
Audit loggingLegitimate interests
Legal complianceLegal obligation
Financial record retentionLegal obligation
Product improvementLegitimate interests
Support communicationsContract

7. Communications

TradesOffice currently sends operational and transactional communications only.

These may include:

  • login or security notifications;
  • invoices and receipts;
  • payment notifications;
  • operational reminders;
  • accountant exports;
  • daily operational briefings;
  • and support responses;

TradesOffice does not currently send:

  • promotional WhatsApp campaigns;
  • newsletter campaigns;
  • or bulk marketing communications;

If marketing communications are introduced in future, TradesOffice will comply with applicable UK GDPR and PECR requirements.

8. Data Retention

TradesOffice retains data only for as long as reasonably necessary for operational, legal and regulatory purposes.

Financial & Operational Records

Invoices, expense records, mileage records and related financial records may be retained for up to 7 years in accordance with HMRC, tax and legal record-keeping obligations.

Note: TradesOffice cannot delete financial records within 7 years of the relevant tax year end even if you request erasure, because HMRC regulations require retention. If you submit an erasure request, we will explain which records are subject to this legal hold.

Inactive Accounts

Inactive customer accounts may be deleted after 24 months of inactivity following reasonable notice to the account holder.

Following cancellation or termination, account data may remain accessible for 90 days to allow data export before deletion.

Audit Logs

Operational audit logs are retained for up to 12 months.

IP addresses processed for operational security and rate-limiting purposes may be retained for up to 1 hour.

Media Files

Uploaded photographs and raw voice recordings are not retained longer than operationally necessary and are typically deleted within 24 hours after processing or transcription.

Backups

Infrastructure backups are managed by Supabase and may include rolling 7-day point-in-time recovery retention.

9. Security Measures

TradesOffice uses technical and organisational measures designed to protect personal data.

These measures may include:

  • encryption at rest;
  • encrypted data transmission;
  • multi-factor authentication;
  • access controls;
  • audit logging;
  • infrastructure monitoring;
  • managed cloud infrastructure;
  • and restricted administrative access;

Access to customer data is restricted to authorised personnel on a need-to-know basis. At present, TradesOffice operates as a sole-founder business with restricted administrative access.

In the event of a personal data breach involving a risk to individuals' rights or freedoms, TradesOffice will comply with applicable UK GDPR breach notification obligations, including notifying the Information Commissioner's Office (ICO) where legally required within 72 hours of becoming aware of the breach.

10. Sub-Processors & Third-Party Providers

TradesOffice uses approved third-party providers to operate the Service. These providers may process personal data on behalf of TradesOffice.

Current providers may include:

  • Supabase;
  • Vercel;
  • Twilio;
  • OpenAI;
  • Anthropic;
  • Stripe;
  • Resend;
  • Upstash;
  • Google APIs;
  • PostHog;
  • and Sentry;

A current list of approved sub-processors is available at: tradesoffice.io/legal/sub-processors

11. International Transfers

Some third-party providers used by TradesOffice may process personal data outside the United Kingdom.

Where international transfers occur, TradesOffice uses appropriate safeguards including:

  • adequacy regulations;
  • UK International Data Transfer Agreements (IDTAs);
  • Standard Contractual Clauses (SCCs);
  • or equivalent lawful transfer mechanisms;

12. Your Rights

Depending on applicable law, you may have rights including:

  • access to your personal data;
  • correction of inaccurate data;
  • deletion of personal data;
  • restriction of processing;
  • objection to processing;
  • data portability;
  • and the right to lodge a complaint with the Information Commissioner's Office (ICO);

Requests relating to personal data may be sent to [email protected]. TradesOffice will respond to applicable data subject requests within the time periods required under UK GDPR, typically within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk  ·  ICO Helpline: 0303 123 1113

13. Cookies & Analytics

TradesOffice uses strictly necessary authentication cookies required for secure operation of the Service. Authentication sessions are managed using secure HttpOnly cookies.

TradesOffice also uses limited operational analytics tools to understand platform performance and usage patterns. PostHog is configured using memory-only session persistence and is not used for advertising or remarketing.

TradesOffice does not currently use:

  • advertising pixels;
  • cross-site tracking;
  • remarketing tools;
  • or behavioural advertising networks;

Further details are available in the TradesOffice Cookie Policy.

14. Children

The Service is intended for business users only and is not directed at children. TradesOffice does not knowingly collect personal data from children.

If you believe a child's personal data has been submitted to the Service, please contact [email protected] and TradesOffice will take reasonable steps to delete it promptly.

15. Changes to This Privacy Policy

TradesOffice may update this Privacy Policy from time to time. Where changes materially affect privacy rights or obligations, reasonable notice will be provided. Continued use of the Service following updates constitutes acceptance of the revised Privacy Policy.

16. Contact Information

Questions regarding this Privacy Policy or data protection matters may be directed to: [email protected]

Trades Office Limited
Company No. 17181500
Hexham, Northumberland, United Kingdom
ICO Registration Number: ZC133896

Privacy PolicyTerms of ServiceData Processing AgreementSub-processorsCookie Policy