1. Identity and Contact Details of the Data Controller
AccoDrop is a trading name operated by Meatwala Group Ltd (“we”, “us”, “our”, “AccoDrop”). Meatwala Group Ltd is a private limited company registered in England and Wales under company number 15260965, with its registered office at 6 Shelburne Court, High Wycombe, England, HP12 3NH.
For personal data we collect and use for our own purposes, including account administration, billing, security, service management and our website, Meatwala Group Ltd acts as the data controller. Where an Accountant uploads or otherwise processes Client personal data through AccoDrop on behalf of that Client or accounting practice, AccoDrop will generally act as a data processor on the Accountant’s documented instructions, as set out in our Data Processing Agreement. The precise roles may vary depending on the particular processing activity.
Website: www.accodrop.co.uk
General Enquiries: support@accodrop.co.uk
Where an Accountant or accounting practice uses AccoDrop to manage Client personal data, that Accountant will normally determine the purposes for which its Client data is processed and will therefore normally act as controller for that Client data. AccoDrop will generally process that data on the Accountant’s behalf as processor. Our Data Processing Agreement sets out the respective responsibilities of the parties.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
the AccoDrop website at www.accodrop.co.uk;
the AccoDrop web dashboard used by accountants and accounting practices;
the AccoDrop mobile application available to self-managing business owners;
all services, features, and functionality provided under the AccoDrop brand; and
all personal data submitted to us by users, their clients, or third parties in connection with the above.
This Policy does not apply to third-party websites or services that may be linked to from the AccoDrop platform. We are not responsible for the privacy practices of those third parties.
3. Personal Data We Collect
3.1 Data You Provide Directly
We collect personal data that you actively provide to us, including:
Identity data: full name, trading name, business name, and job title;
Contact data: email address, telephone number, and postal address;
Account credentials: username and encrypted password (we do not store passwords in plaintext);
Business and professional data: accountant firm name, professional body membership details, and practice information;
Financial data: bank account numbers and sort codes contained within bank statements and financial documents you upload;
Transaction data: details of financial transactions extracted from documents you submit, including payee names, amounts, dates, and transaction references;
Identity verification data: where required, copies of professional authorisation documents such as HMRC 64-8 authorisation forms;
Communications data: the content of messages you send to us via email or through the platform; and
Feedback and preferences: any information you choose to provide when completing surveys or providing product feedback.
3.2 Data We Collect Automatically
When you use AccoDrop, we automatically collect certain technical data, including:
Device and browser data: IP address, browser type and version, operating system, device type, and screen resolution;
Usage data: pages visited, features accessed, time spent on the platform, actions taken, and clickstream data;
Log data: server logs recording requests made to our infrastructure, including timestamps and error reports;
Cookie data: information collected through cookies and similar tracking technologies as described in our Cookie Policy; and
Fraud prevention data: where required for relevant HMRC API services, technical information and identifiers that must be included in fraud prevention headers, which may include IP address, connection information, device or browser information, and software-related identifiers.
3.3 Data We Receive from Third Parties
We may receive personal data about you from third parties in the following circumstances:
from accountants or accounting practices who add you as a client on our platform and who confirm they hold appropriate legal authorisation to act on your behalf;
from Stripe, our payment processor, in connection with subscription billing and payment verification;
from HMRC, via the Making Tax Digital API, when we retrieve or submit tax information on your behalf; and
in future phases of our service, from Open Banking providers where you have expressly authorised a direct bank data feed. We will update this Policy before introducing any material new provider or processing activity.
3.4 Special Category and Sensitive Data
We do not intentionally collect special category personal data as defined under Article 9 of the UK GDPR (such as data revealing racial or ethnic origin, religious beliefs, health data, or biometric data). Financial data, while sensitive in nature, does not constitute special category data. However, we recognise that financial information is commercially and personally sensitive, and we treat it accordingly with heightened technical and organisational safeguards.
If you believe you have inadvertently submitted special category data to us, please contact us immediately at privacy@accodrop.co.uk.
4. How We Use Your Personal Data
We use your personal data only where we have a lawful basis to do so under the UK GDPR and the Data Protection Act 2018. The lawful bases we rely upon are:
Performance of a contract: processing that is necessary to provide you with the AccoDrop service under our Terms of Service or Subscription Agreement;
Legal obligation: processing necessary to comply with applicable legal or regulatory requirements, including relevant HMRC Making Tax Digital requirements and data protection law;
Legitimate interests: processing for our legitimate business interests, provided those interests are not overridden by your rights and freedoms; and
Consent: where we have asked for and received your express consent, for example in relation to optional marketing communications.
The specific purposes for which we use your data are set out below:
4.1 Provision of the AccoDrop Service
Creating and maintaining your account;
Processing and categorising bank statements and financial documents using automated tools, including artificial intelligence;
Matching transactions with receipts and supporting documents;
Generating bookkeeping records, journal entries, VAT calculations and other accounting outputs where those features are available;
Enabling accountants to review, approve, and submit financial data on behalf of their clients;
Facilitating Making Tax Digital submissions to HMRC where the relevant functionality is available and authorised; and
Sending transaction review notifications, statement processing confirmations, and other service-related communications.
Lawful basis: Performance of a contract.
4.2 Compliance with Legal Obligations
Retaining records for periods required by applicable law or necessary for compliance, dispute resolution, security and audit purposes;
Submitting required fraud prevention information to HMRC where applicable to the relevant API service;
Responding to lawful requests from HMRC, law enforcement authorities, or regulatory bodies;
Maintaining appropriate audit and activity logs where required or reasonably necessary for compliance, security and accountability purposes; and
Complying with our obligations under the UK General Data Protection Regulation and the Data Protection Act 2018.
Lawful basis: Legal obligation.
4.3 Billing and Payments
Processing subscription payments via Stripe;
Sending invoices and payment confirmations;
Managing subscription upgrades, downgrades, and cancellations; and
Handling payment disputes or chargebacks.
Lawful basis: Performance of a contract and legitimate interests.
4.4 Improving and Developing our Services
Monitoring platform performance, identifying errors, and resolving technical issues;
Analysing aggregated, anonymised usage patterns to improve our features and user experience;
Testing and improving our document-processing and categorisation functionality using aggregated, anonymised or otherwise appropriately protected data where reasonably practicable; and
Conducting internal research and development.
Lawful basis: Legitimate interests. Where a different lawful basis is required for a particular processing activity, we will rely on that basis and provide any additional information required by law.
4.5 Security and Fraud Prevention
Detecting, investigating, and preventing unauthorised access, fraudulent transactions, or other illegal activity;
Maintaining security logs and audit trails; and
Verifying the identity of users where necessary.
Lawful basis: Legitimate interests and legal obligation.
4.6 Marketing and Communications
Sending you product updates, newsletters, or information about new features, where you have opted in to receive such communications.
Lawful basis: Consent. You may withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@accodrop.co.uk.
5. Automated Processing and Artificial Intelligence
AccoDrop uses artificial intelligence and automated processing as an integral part of its service. You should be aware of the following:
5.1 How AI is Used
Our platform processes bank statements and financial documents using a layered approach. We may process documents using text extraction, optical character recognition and automated classification tools. Where enhanced processing is required, selected document content may be processed using the Claude API supplied by Anthropic. We aim to minimise the amount of personal data sent to third-party AI services and use such services only where reasonably necessary to provide the relevant functionality.
AI is used to:
extract structured transaction data from bank statements and financial documents;
suggest VAT categorisation and merchant classifications for individual transactions;
assign confidence scores to automated categorisations; and
identify potential duplicate transactions.
5.2 Human Review
All AI-generated categorisations and classifications are presented to the relevant accountant or authorised user for review and approval before any data is submitted to HMRC. AccoDrop does not make fully automated decisions with legal or significant financial consequences without human oversight. Confidence scores are displayed to assist reviewers in prioritising their attention.
5.3 Your Right to Object
If third-party AI processing is optional for a particular feature, we will provide appropriate information or controls where required. You may also contact us at privacy@accodrop.co.uk with questions about how automated processing applies to your data. Some features may not be available without the processing necessary to provide them.
5.4 Third-Party AI Processor
Where we use the Anthropic Claude API to process personal data on our behalf, we use Anthropic as a service provider under appropriate contractual terms. Anthropic states that inputs and outputs from its commercial products, including its API, are not used to train its models by default unless the customer expressly opts in or submits qualifying feedback. For current information about Anthropic’s practices, please refer to its commercial privacy documentation at www.anthropic.com.
6. Disclosure and Sharing of Personal Data
We do not sell your personal data. We share personal data only in the limited circumstances described below.
6.1 Accountants and Accounting Practices
Where you are a Client whose Accountant manages your AccoDrop account, your financial data and account information may be accessible to that Accountant and their authorised staff. Accountants are responsible for ensuring that they have an appropriate lawful basis and any authority required to access and process their Clients’ data, including any HMRC authorisation required for the relevant service.
6.2 Service Providers (Data Processors)
We engage third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:
OVH SAS — cloud infrastructure, server hosting, and file storage (London, United Kingdom);
Anthropic, Inc. — AI document processing (limited circumstances only, as described in Section 5);
Stripe, Inc. — payment processing and subscription management;
Mailgun Technologies — email delivery and, where enabled, inbound email processing;
Google Firebase — push notification delivery;
HMRC — as required for Making Tax Digital submissions (controller to controller).
Where required by data protection law, we put appropriate contractual arrangements in place with processors and require suitable technical and organisational security measures.
6.3 Legal Disclosures
We may disclose personal data to competent authorities, courts, or regulatory bodies where required to do so by applicable law, court order, or regulatory requirement, including but not limited to disclosures to HMRC in connection with a tax investigation.
6.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant acquiring entity as part of that transaction, subject to that entity assuming our obligations under this Privacy Policy. We will provide you with prior notice where required by applicable law.
7. International Transfers of Personal Data
AccoDrop’s primary infrastructure is hosted on OVH servers located in London, United Kingdom. Where personal data is transferred outside the United Kingdom, we use an appropriate lawful transfer mechanism where required. The UK recognises certain countries and territories as providing an adequate level of protection for personal data.
Some of our service providers, including Anthropic and Stripe, are incorporated in the United States. Where personal data is transferred to countries outside the United Kingdom that do not benefit from an adequacy decision, we ensure that appropriate safeguards are in place in accordance with Chapter V of the UK GDPR. These safeguards may include:
the UK International Data Transfer Agreement or UK Addendum to approved Standard Contractual Clauses;
other lawful transfer mechanisms as permitted by applicable UK data protection law.
You may obtain a copy of the transfer safeguards we rely upon by contacting us at privacy@accodrop.co.uk.
8. Retention of Personal Data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, to comply with applicable legal obligations, to establish or defend legal claims, to maintain security and audit records, or, where we act as processor, in accordance with the relevant Accountant’s instructions and our Data Processing Agreement.
Our usual retention approach is as follows:
financial records, bank statements, transaction data, VAT information and HMRC submission records: for the period required by applicable tax or accounting rules, or for the period instructed by the relevant controller where AccoDrop acts as processor;
account and identity data: for the duration of the account and for a reasonable period after closure where needed for legal, accounting, fraud prevention or dispute-resolution purposes;
audit and security logs: for a period proportionate to security, compliance and evidential requirements;
payment and billing records: for the period required for accounting, tax and legal purposes;
marketing preferences and consent records: for as long as necessary to demonstrate and respect your communication choices; and
server and application logs: normally for a limited operational period unless they need to be retained for longer in connection with security, fraud, legal or regulatory matters.
Where we no longer need personal data, we will delete it securely or anonymise it so that it can no longer be linked to an identifiable individual. More detailed retention periods may be set out in our internal retention schedule or in the Data Processing Agreement applicable to an Accountant’s Client data.
9. Your Rights as a Data Subject
Under the UK General Data Protection Regulation and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are subject to certain conditions and exemptions, as set out in applicable legislation.
9.1 Right of Access
You have the right to request a copy of the personal data we hold about you and information about how we process it. This is known as a Subject Access Request. We will respond without undue delay and normally within one month, subject to any lawful extension or exemption. We do not normally charge a fee, although the law permits a reasonable fee or refusal in certain circumstances, including where a request is manifestly unfounded or excessive.
9.2 Right to Rectification
You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data, without undue delay.
9.3 Right to Erasure (‘Right to be Forgotten’)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected. This right is not absolute. Where we are required by law to retain financial records (for example, under HMRC data retention requirements), we will inform you of the applicable retention period and the reasons why erasure is not possible at that time.
9.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while the accuracy of data is being contested or where you have objected to processing.
9.5 Right to Data Portability
Where we process your personal data on the basis of your consent or in performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
9.6 Right to Object
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds for continuing, or the processing is required for the establishment, exercise, or defence of legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes. We will action such requests immediately.
9.7 Rights in Relation to Automated Decision-Making
Where we use solely automated processing to make a decision that has a legal or similarly significant effect on you, applicable UK data protection law provides safeguards, including information about the decision and an opportunity to make representations and obtain human intervention where required. AccoDrop is designed so that accounting categorisations and tax-related outputs are subject to review by an authorised user before final submission.
9.8 How to Exercise Your Rights
To exercise any of the rights described above, please contact our data protection contact at:
Email: privacy@accodrop.co.uk
Post: Data Protection, AccoDrop, 6 Shelburne Court, High Wycombe, England, HP12 3NH
We may need to verify your identity before processing your request. We will respond without undue delay and normally within one month. Where the law permits an extension, we will tell you and explain the reason.
9.9 Right to Lodge a Complaint
If you are dissatisfied with the way in which we have handled your personal data or responded to a rights request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:
ICO Website: www.ico.org.uk
Telephone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We would, however, appreciate the opportunity to address your concerns directly before you contact the ICO. Please contact us at privacy@accodrop.co.uk in the first instance.
10. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. Our security measures include:
encryption in transit using current transport security measures;
secure password hashing and authentication controls;
role-based access controls designed to limit access to authorised users and personnel;
logging and monitoring of relevant security and account activity;
infrastructure hosted in the United Kingdom for AccoDrop’s primary production environment; and
periodic review of technical and organisational security measures.
Specific technical controls may evolve as the Platform develops. We do not publish security-sensitive implementation details in this Privacy Policy.
Notwithstanding the above, no method of data transmission over the internet or method of electronic storage is entirely secure. We cannot guarantee absolute security, and you use the platform at your own risk in this regard. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO in accordance with our obligations under Articles 33 and 34 of the UK GDPR.
11. Cookies
AccoDrop uses cookies and similar tracking technologies on our website and web dashboard. Cookies are small text files placed on your device that enable us to recognise your device on return visits and provide you with a consistent experience.
We use the following categories of cookies:
Strictly necessary cookies: essential for the operation of the platform, including session management and security cookies. These cannot be disabled.
Functional cookies: enable enhanced features such as remembering your preferences and login state.
Analytical cookies: help us understand how the platform is used so that we can improve it. We use anonymised analytics data.
Non-essential cookies and similar technologies are used only where the applicable consent requirements are satisfied. You can manage or withdraw your choices through our cookie consent tool and, where applicable, your browser settings. Please note that disabling certain optional technologies may affect some non-essential features. For full details, please refer to our Cookie Policy, available at www.accodrop.co.uk/cookie-policy.
12. Children’s Privacy
AccoDrop is a business-to-business service intended solely for use by adults in a professional or commercial capacity. Our services are not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us at privacy@accodrop.co.uk and we will investigate and take appropriate steps, including deletion where required and lawful.
13. Links to Third-Party Websites
Our platform may contain links to third-party websites, including HMRC, your bank, or professional body portals. We have no control over and accept no responsibility for the content, privacy policies, or practices of those third-party websites. We encourage you to read the privacy notice of every website you visit.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The effective date at the top of this document will be updated accordingly.
Where changes are material, we will notify you by email to your registered email address or by displaying a prominent notice within the AccoDrop platform at least fourteen days before the changes take effect. We encourage you to review this Privacy Policy periodically. Previous versions are available upon request.
15. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any dispute arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.
We process personal data in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018, as amended from time to time, including relevant changes made by the Data (Use and Access) Act 2025.
16. Contact Us
If you have any questions, concerns, or requests in relation to this Privacy Policy or our data processing practices, please do not hesitate to contact us:
Email support@accodrop.co.uk
Website: www.accodrop.co.uk
Post:Please use the registered office address stated above.
AccoDrop – Version 1.0 | Effective Date: 24 August 2026
© 2026 AccoDrop. All rights reserved.