Skip to main content

Privacy Policy

Last updated: 24 August 2026

1. Introduction

DormantFile ("we", "us", "our") is committed to protecting the personal data of everyone who uses our website and service. This privacy policy explains what information we collect, why we collect it, how we share it, and how we keep it safe. It applies to all users of DormantFile, whether you have a free account, a paid subscription, or are simply browsing the site.

2. Data controller

If you have any questions about how we handle your data, contact us at privacy@dormantfile.co.uk.

3. What data we collect

We collect the following categories of personal data:

  • Account information — your email address, name, and a securely hashed password.
  • Company details — company name, Companies House registration number, Unique Taxpayer Reference (UTR), and accounting period dates. For an LLP filing an SA800, also the partnership UTR and each member's name and personal UTR (stored encrypted).
  • Filing records — submission timestamps, correlation IDs, response payloads, and filing type (accounts, CT600 or SA800).
  • Payment information — your Stripe customer ID and email address. We never store your card details; all card data is held by Stripe as an independent controller.
  • HMRC Gateway credentials — your Government Gateway user ID and password are used only at the moment of filing. They are transmitted to HMRC over TLS, never written to our database, and discarded from server memory immediately after the submission completes.
  • Companies House authentication code — entered at the point of filing and transmitted directly to Companies House over TLS. For one-off filings it is used transiently and not retained. It is stored — encrypted at rest (AES-256-GCM) — only if you choose to save it, for example for annual autopilot, and you can remove it at any time from the company's settings.

We also record help-centre searches — the words typed into the search box, the number of results returned, and which result was opened. These records are deliberately not personal data: they contain no account, session or IP identifier, and are automatically stripped of company registration numbers, Unique Taxpayer References and email addresses before they are stored. We use them for one purpose, which is to find out what our guides fail to answer so we can write the missing ones. They are never sent to any third party.

We process your personal data under UK GDPR on the lawful bases set out below.

Processing activityData usedLawful basis
Create and manage your accountEmail, password, nameContract performance
Submit filings to HMRC and Companies HouseCompany details, Gateway credentials, CH auth codeContract performance
Filing confirmationsEmail, filing recordsContract performance
Process paymentsEmail, Stripe customer IDContract performance
Deadline remindersEmail, company details, deadline datesLegitimate interests
Register and strike-off alertsEmail, company details, Companies House filingsLegitimate interests
Offers and upsellsEmail, account and company detailsLegitimate interests (soft opt-in — refuse at sign-up or any time)
Product newsEmailLegitimate interests (soft opt-in — refuse at sign-up or any time)
Analytics (if consented)Anonymised usage dataLegitimate interests (cookie placement requires PECR consent)
Filing progress diagnosticsFiling records, wizard step timestampsLegitimate interests

Deadline reminders, register and strike-off alerts, offers and upsells, and product news can each be switched on or off individually at any time, from the Emails section of Settings, or from the "Manage all emails" link in the footer of any of these emails — that footer link works without logging in. Turning a category off only stops the emails in that category. These are the only four categories that can be turned off: account, billing, plan-change, autopilot and filing-outcome emails always send while you have an account, whatever your settings above.

Offers and upsells, and product news go only to our own customers, about our own service — the "soft opt-in" under the Privacy and Electronic Communications Regulations (PECR), processed on the lawful basis of our legitimate interests. You can refuse them at the moment you create your account (the sign-up form has a checkbox for exactly this), and you have an absolute right to object to direct marketing at any time afterwards — turning either category off in the controls above does exactly that, immediately. Deadline reminders and register and strike-off alerts are sent on the basis of our legitimate interest in keeping you informed about your company's compliance position — you can still turn these off at any time, but doing so means we will not chase you if a deadline is missed or your company's record changes unexpectedly.

5. Third-party services

We share data with the following third parties, only as necessary to provide the service:

  • HMRC — your company details and Gateway credentials are transmitted to HMRC to file your CT600 return (or, for an LLP, your SA800 partnership return). HMRC is an independent controller for data it receives.
  • Companies House — your company details and authentication code are transmitted to Companies House to file your annual accounts (dormant, or FRS 105 micro-entity). Companies House is an independent controller for data it receives.
  • Stripe — your email address and payment data are shared with Stripe to process subscription payments. Stripe acts as an independent data controller for payment data. See Stripe's privacy policy.
  • Resend — your email address is shared with Resend to deliver every email we send you, including account and filing emails and any of the deadline reminder, register alert, offers or product news categories you have not turned off. Resend acts as a data processor on our behalf.
  • AI model provider — questions you ask our assistant (and, on paid plans, the company and filing data needed to answer them) are processed by our AI model provider to generate responses. Your data is not used to train their models. The provider acts as a data processor on our behalf.
  • Google Analytics — anonymised usage data is shared with Google Analytics if you have consented to analytics cookies. Google acts as a data processor on our behalf.

6. International transfers

Stripe and Resend are US-based companies. Transfers of personal data to these providers are covered by UK adequacy regulations and standard contractual clauses, as applicable. Google Analytics data may also be processed internationally under equivalent safeguards.

We do not transfer personal data outside the UK except through the services listed above.

7. Data storage and security

Your data is stored in a PostgreSQL database. All data is encrypted in transit using TLS. Passwords are hashed using bcrypt before storage — we never store your password in plain text.

HMRC Gateway credentials are never persisted. They are held in server memory only for the duration of the submission request and discarded immediately after HMRC responds. Companies House authentication codes are used transiently for one-off filings and not retained. If you choose to save yours — for example for annual autopilot — it is stored encrypted at rest (AES-256-GCM), never logged, and you can remove it at any time from the company's settings.

8. Data retention

  • Account data — retained while your account is active, plus 12 months after cancellation to allow you to reactivate.
  • Filing records — retained for 6 years from the filing date, in line with HMRC record-keeping requirements.
  • Due-diligence records — customer identity and due-diligence records are retained for 5 years after our business relationship ends, as required by the Money Laundering Regulations 2017. See our anti-money laundering policy.
  • Help-centre search records — retained for 12 months, then deleted automatically. Filing demand is seasonal, so a full year is the shortest window in which a rising search can be told apart from a recurring one.
  • After the applicable retention period, or upon your written request (subject to legal retention obligations), we delete all personal data associated with your account.

9. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate personal data.
  • Erase your personal data (subject to legal retention obligations — for example, filing records must be kept for 6 years).
  • Restrict processing of your data in certain circumstances.
  • Data portability — receive your data in a machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent for analytics cookies at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.
  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, email us at privacy@dormantfile.co.uk.

10. Children's data

DormantFile is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from someone under 18, please contact us and we will delete it promptly.

11. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

12. Cookies

We use a small number of cookies to operate the service and, with your consent, to understand how it is used. For full details, see our cookie policy.

13. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by placing a prominent notice on the website. Your continued use of the service after any changes constitutes acceptance of the updated policy.