Privacy policy
What is collected, why, and what happens to it when you leave.
Not reviewed by counsel. Not in force.
This document has been drafted to describe what the product actually does, and it has not been reviewed by a qualified lawyer. It is published here so that it can be read, checked against the system, and corrected — not so that anybody can rely on it.
Nothing in it takes effect, nothing in it is an agreement, and no date has been set for either. Where it describes a practice, that description is accurate today; where it states a term, that term has not been settled.
If you need any of these in force before contracting — a data processing agreement, usually — say so and you will be told where the review has got to. Write to privacy@taxorch.com.
What this covers
This describes what happens to data in the TaxOrch product and on this website. Everything below is a description of behaviour that is implemented, not of behaviour that is planned. Where something is not yet decided, it says so.
What is processed
On this website
Nothing that observes you runs before you agree to it. Until you make a choice, the only things stored in your browser are the ones the site cannot work without:
- Your consent decision, so you are not asked on every page. It records which version of this policy you were shown.
- Your theme and motion preferences, so the site does not change appearance or start animating between pages.
- A dismissal record, if you close a prompt, so it is not shown again during the same visit. It is cleared when you close the tab.
None of these leaves your browser and none identifies you.
If you consent to analytics, the site reports which pages and sections were read, which actions were pressed, and how forms progressed — as event names and categories. Form field contents are never included, and there is no property in the event model capable of carrying one.
If you write to us through a form, we process what you typed in order to reply to it: your name, your address, and whatever you wrote.
In the product
- Tax documents and the figures extracted from them, in order to compute and cite an answer.
- Entity, filing and jurisdiction data, in order to select the right calculator and the right law.
- Questions asked and answers produced, with the corpus release, model version and calculator version behind each one, so an answer can be reproduced later.
- An audit trail of who did what, including access to sensitive documents and every deletion.
What is never done with it
Tenant data is never used for training without an explicit opt-in, and the opt-out is on by default. The safe setting is the one you get without asking for it.
Where a dataset is built for training, deterministic redaction runs on every piece of text entering it, ordered most-specific-first, and rows that are unknown, restricted, licence-missing or PII-heavy are blocked outright.
Raw document contents, sensitive figures and conversation content are never written to logs. Taxpayer identifiers are redacted from prompts and from support surfaces before anyone or anything sees them, and bookkeeper message content is not visible in the administrative interface either.
How it is protected
- Encryption at rest for sensitive extracts. Full national identifiers and bookkeeper conversation content are encrypted; stored display fields keep only masked values.
- Structural tenant isolation. Every tenant-owned record inherits a workspace- and site-scoped base, and queries always filter by tenant. It is a property of the data model rather than a rule the application remembers.
- Hash-chained audit entries, per tenant, with a command that validates the whole chain — so tampering with the record is detectable rather than merely discouraged.
- Role-based access, including a read-only auditor role, so somebody can verify the record without being able to change it.
How long it is kept
Retention is configurable, with a seven-year default for tax documents, which reflects the period a tax record is typically required to be retained rather than a period chosen for convenience.
A retention-eligibility report lists what is due for removal, so deletion is something that happens on a schedule rather than when somebody remembers.
A legal hold flag blocks deletion for records under dispute or audit, overriding the retention schedule. A record under hold is not deleted by the retention process and cannot be deleted by a request.
Your data, on the way out
- Export. A per-tenant privacy export produces all of your tax data. Privacy requests are modelled and tracked to completion rather than handled ad hoc.
- Deletion. An explicit, audit-logged deletion path — not a support ticket and not a flag that hides a record while keeping it.
- Self-hosting. If you run TaxOrch on your own infrastructure, your tax data never leaves it. There is no third-party model in the request path, so there is nothing for it to be sent to.
Sub-processors
Not published yet. Where the product is self-hosted there are none by construction; for a managed deployment the list depends on infrastructure decisions that have not been finalised, and naming a provider before that is settled would be inventing one.
The data processing agreement is where that list will live, and it will be published there before any managed deployment carries customer data.
Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or delete the personal data held about you, and to object to certain processing. The export and deletion paths above exist to make those rights operable rather than theoretical.
To exercise any of them, write to privacy@taxorch.com.
Contacting us about this
privacy@taxorch.com for anything about data. security@taxorch.com for a vulnerability, where the disclosure terms and the response commitments are published in full on the security page.
How changes will be communicated
- Every version carries the date it took effect, and every earlier version stays reachable at the same address.
- A change is summarised in the terms a reader would care about. “Updated our terms” tells nobody anything and is why change notices go unread.
- A material change is notified to account holders in advance, not announced by a banner after the fact.
- Continuing to use the product is not treated as agreement to a change that was never sent.