1. Purpose
This policy protects our users, our systems, HMRC API integrations, third-party services and the integrity of the application. It forms part of our Terms and Conditions.
2. Permitted use
You may use the application for lawful business purposes, including:
- creating and managing invoices;
- creating credit notes;
- recording payments;
- maintaining customer and supplier records;
- sending invoice emails and reminders;
- preparing VAT records;
- connecting to HMRC where authorised;
- retrieving VAT obligations;
- submitting VAT returns where properly authorised.
3. Prohibited use
You must not use the application to:
- break any law or regulation;
- submit false, misleading or fraudulent VAT information;
- impersonate another person, company or organisation;
- access data belonging to another tenant or customer without permission;
- upload malware, viruses, ransomware or harmful code;
- probe, scan, attack or test the vulnerability of our systems without written permission;
- attempt to bypass authentication, authorisation or tenant separation controls;
- interfere with HMRC fraud prevention header collection or transmission;
- send spam or unlawful marketing communications;
- store data you have no right to process;
- use the application for unlawful tax evasion, fraud or deception;
- reverse engineer, scrape, copy or resell the application except where permitted by law;
- overload or disrupt the service or third-party systems.
4. Email and messaging use
Where the application allows you to send emails, you must ensure that messages are lawful, accurate and appropriate.
You must not use the email features to send:
- spam;
- phishing emails;
- malicious attachments or links;
- misleading invoices;
- unlawful marketing;
- abusive, threatening or discriminatory content.
5. HMRC and MTD VAT use
When using HMRC MTD VAT features, you must:
- only connect accounts you are authorised to manage;
- check VAT return values before submission;
- keep HMRC authorisation secure;
- not submit false or manipulated information;
- not interfere with fraud prevention header data;
- notify us promptly of suspected unauthorised access.
6. Security responsibilities
You must:
Keep login details confidential
Remove users who no longer require access
Use appropriate permission levels
Report suspected security issues promptly
Use secure devices and networks
7. Monitoring and enforcement
We may monitor use of the application to protect security, prevent abuse, investigate incidents, comply with law and maintain service integrity.
If we reasonably believe this policy has been breached, we may suspend or terminate access, remove content, notify affected parties, preserve evidence, or report matters to HMRC, regulators or law enforcement where appropriate.