SelfSubmit is designed to help you stay compliant with HMRC Making Tax Digital requirements. You remain responsible for ensuring the information you submit is accurate.

Data processing agreement (DPA)

This page summarises how we process personal data on behalf of customers and the subprocessors we use. It supplements our Privacy policy and GDPR overview.

Last updated: 20 July 2026

1. When a DPA applies

A formal DPA is relevant when:

  • An accountant, bookkeeper, or agency uses SelfSubmit to handle client personal data on their instructions
  • You need a signed Article 28 contract for your own compliance programme
  • A corporate customer requires processor terms before rollout

Individual self-employed subscribers using SelfSubmit for their own records generally rely on our Privacy policy rather than a separate DPA.

2. Our processor commitments

Where we act as processor, we will:

  • Process personal data only on documented instructions from the controller
  • Ensure personnel with access are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Assist with data subject requests and security incidents as required by law
  • Delete or return data at the end of the service, subject to legal retention
  • Make available information needed to demonstrate compliance

3. Subprocessors

We use trusted providers under contract to run SelfSubmit. Categories of processing support include:

  • Cloud hosting & file storage — application hosting, CDN, serverless compute, and uploaded receipt/document storage
  • Managed database — account, business, and submission records
  • Authentication — Clerk
  • Payments — Stripe
  • Email — Resend
  • Optional SMS — where you enable SMS reminders
  • UK address lookup — Ideal Postcodes
  • Technical monitoring — error and reliability diagnostics

We require subprocessors to protect data under contract. Controllers who need a named subprocessor schedule for due diligence may request it by email. We will notify controllers of material subprocessor changes where our DPA requires it.

4. International transfers

Some subprocessors may process data outside the UK. We use appropriate safeguards (such as UK International Data Transfer Agreements or adequacy regulations) where required. See our GDPR & data protection page.

5. Request a signed DPA

Email support@selfsubmit.co.uk with your organisation name, role (controller/processor), and expected data volumes. We will provide our standard UK GDPR Article 28 terms or discuss bespoke arrangements for enterprise partners.