1. Who we are
This Privacy Policy explains how personal data is processed in connection with Neysan Group Ltd (Companies House 16887422, neysangroup.com), its websites, software products, applications, portals, shared identity services and related digital services (together, the “Neysan Services”).
Neysan Group Ltd develops, operates and maintains software and technology services used by businesses, their staff, contractors, clients and other authorised users. Some products may be operated by, provided for, or used in partnership with another organisation. Where this applies, that organisation may also act as a controller of personal data processed through the relevant product.
Products and services currently covered by this policy include, where applicable:
- Neysan Identity — the shared identity and authentication infrastructure used across Neysan products;
- MyClean (myclean.neysangroup.com);
- the Excel Solutions Portal (portal.excelsolutions.uk);
- the Alcohol Licensing Portal (irb.neysangroup.com);
- other Neysan Group products, applications, portals and services that refer or link to this Privacy Policy.
This structure allows a single privacy framework to apply across Neysan products while individual products use only the categories of data and functionality that are relevant to them.
Neysan Group Ltd develops and maintains the software. Excel Financial Solutions Limited (“Excel Solutions”) operates the Excel Solutions Portal for accountancy practice work.
Contact — Neysan Group:
contact@neysangroup.com
Contact — Excel Solutions portal privacy:
contact@excelsolutions.uk
2. Scope
This policy covers personal data processed when:
- you browse or contact us via neysangroup.com;
- you access or use a Neysan product, application, portal or service;
- an organisation creates or manages an account for you within a Neysan product;
- staff, workers, contractors, administrators or operators use Neysan products for business operations;
- businesses enter or manage information about their staff, customers, suppliers, service locations, jobs, transactions or other business activities;
- clients or contacts use public forms, payment links, customer access or other functionality that we host;
- a Neysan product connects to third-party services, including where applicable HMRC Making Tax Digital for VAT, Intuit QuickBooks Online / QuickBooks Online Accountant, Companies House, payment providers, mapping services, authentication providers and email or notification delivery services.
Not every Neysan product uses every type of data or integration described in this policy. The data processed depends on the product, the features enabled by the organisation using it and the actions performed by the user.
3. Neysan Identity and accounts
Neysan products may use a shared identity system (“Neysan Identity”). A single identity may provide authorised access to one or more Neysan products, organisations or workspaces.
Identity information may include your name, email address, internal user or profile identifiers, organisation memberships, access roles and authentication information. Depending on the product and organisation, additional business contact information such as a telephone number may also be associated with your profile.
Passwords are handled through our authentication infrastructure and are not stored by Neysan products as readable passwords. Authentication sessions and security identifiers may be processed as necessary to keep users signed in and protect access to the Services.
Accounts may be created or provisioned by an authorised organisation administrator rather than through public self-registration.
4. Data we process
Depending on the Neysan Service used and the functionality enabled, we may process the following categories of information:
- Website / enquiry data — contact details you send us by email, forms, messaging services or other communication channels, together with basic technical information needed to operate and secure our websites;
- Identity and account data — name, email address, telephone number where applicable, user/profile identifiers, organisation memberships, access roles, authentication status and security-related account information;
- Staff and workforce data — information entered by an employer or authorised administrator about workers, staff or contractors, which may include names, business contact details, roles, assignments, rates, working records and other information required for workforce management;
- Client / company records — names, contact details, addresses, company identifiers, notes, engagement information, filing-related information and other records entered by authorised business users;
- Operational data — jobs, services, assignments, schedules, service locations, work instructions, attendance records, clock-in and clock-out records, time entries, approvals, checklists and other information required to operate the relevant business workflow;
- Location data — some Neysan products may process precise location information when a location-dependent feature is enabled. For example, location may be used to verify attendance or presence at a service location, support a geofence, or allow an authorised user to set or confirm a business location. Location access is requested by the relevant feature and is not intended for continuous background tracking unless a product expressly states otherwise;
- Photos, images, documents and files — some products may allow or require users to capture or upload photographs, receipts, evidence of work, company logos, documents or other business files. Camera or file access is requested only where the relevant functionality requires it;
- Financial and operational records — amounts payable or receivable, payment status, rates, transaction references, ledger information, subscription status and related business records;
- Payment data — payment statuses, payment-method references, mandate or schedule references and related metadata received from payment providers. Full card numbers and online banking credentials are handled by the relevant payment provider rather than stored by Neysan products;
- Notification data — notification preferences, push subscription information, browser or device notification endpoints and notification content needed to provide alerts requested or enabled through a product;
- HMRC VAT (MTD) data — when a company connects Government Gateway / HMRC OAuth, we may retrieve and store VAT obligations, returns, liabilities, payments, penalties and related registration/customer information needed to operate VAT workflows in the portal;
- Accounting data from QuickBooks — when an owner/admin connects the practice and links a company, we may retrieve bookkeeping summaries such as account balances, profit and loss totals and transaction lines for authorised staff use inside the portal;
- Companies House data — company profile and filing-related information retrieved where a product uses Companies House functionality;
- Technical and security data — browser type, user agent, timestamps, session information, security events, connection information and technical logs that may be generated by our infrastructure or service providers to operate, diagnose, protect and secure the Services;
- Local application data — some products may store preferences, interface settings, cached application resources or session information locally on your device or browser to provide functionality and improve usability.
5. Why we process it (lawful bases)
Depending on the circumstances, we process personal data on one or more of the following bases:
- Contract — where processing is necessary to provide a product, service or functionality requested under an agreement;
- Legitimate interests — to operate our products, manage business workflows, provide support, improve reliability, maintain records, prevent misuse and keep our systems secure, where those interests are not overridden by the rights of individuals;
- Legal obligation — where information must be processed or retained for accounting, tax, employment, regulatory, legal or other statutory requirements;
- Consent — where a specific optional feature requires consent, including certain device permissions, notifications or third-party connections. Where consent is the applicable basis, it may be withdrawn subject to applicable law and technical requirements.
Where a business customer uses a Neysan product to manage information about its own staff, contractors, customers or other individuals, that business may be the data controller for that information and Neysan Group may process it on the business's behalf as a processor or service provider.
6. Location, camera and device permissions
Some Neysan Services contain optional or organisation-configurable functionality that requires access to device capabilities.
Where precise location is required, the product may request your current location for a specific action such as recording attendance, clocking in or out, verifying presence at a work location, or setting a location on a map. Location collected for such an action may be stored as part of the relevant operational record.
Where photographic evidence or image upload is enabled, the product may request access to the camera or allow an image to be selected from the device. Images may then be stored securely with the relevant business record.
Notification permission may be requested where a product offers browser or device notifications. Users may control notification permission through the product or their browser/device settings where supported.
Individual Neysan products may not use all of these permissions. Permissions are requested only where relevant to the functionality being used.
7. HMRC Making Tax Digital for VAT
Where HMRC VAT is connected for a company, HMRC authenticates the company’s Government Gateway user and issues OAuth tokens stored only on our servers. Staff of the practice can then sync and view mirrored VAT information inside the portal. Disconnecting HMRC in the portal stops new API access; historical mirrored records may remain according to our retention rules.
We do not store Government Gateway usernames or passwords. Access uses OAuth 2.0; only tokens are retained server-side.
Each company remains responsible for its own VAT obligations to HMRC. The portal is an operational tool; it does not replace the company’s duty to file and pay correctly.
HMRC also processes data under its own privacy notices when Government Gateway / HMRC services are used.
8. QuickBooks / Intuit
If QuickBooks is connected, Intuit authenticates the practice and issues tokens stored only on our servers. Staff of the practice can then view linked company information through the portal without each person logging into QuickBooks separately. Disconnecting QuickBooks in the portal stops new API access; historical portal records may remain according to our retention rules.
Intuit also processes data under its own privacy terms when you use QuickBooks products.
9. Payments and subscriptions
Some Neysan products or services may require a paid subscription or may provide payment-related functionality. Where a third-party payment processor is used, payment credentials such as full card details or online banking credentials are submitted directly to that provider.
Neysan Services may receive and retain information such as customer identifiers, payment-method references, subscription status, transaction references, payment status and other information needed to administer the relevant service.
10. Who we share data with
We use processors, infrastructure providers and third-party services where needed to operate our websites and products. Depending on the product and features used, these may include:
- hosting, database, storage and backend infrastructure providers;
- authentication and identity services;
- email and notification delivery services;
- HMRC, where HMRC functionality is connected for a company;
- Companies House, where relevant functionality is used;
- payment processors, including Stripe and, where enabled, GoCardless;
- Intuit / QuickBooks, where that integration is enabled;
- mapping and geocoding services, including OpenStreetMap-related services where map or address functionality is used;
- browser or device push-notification services where notifications are enabled;
- an organisation using a Neysan product where information belongs to or is managed by that organisation;
- professional advisers, regulators, law-enforcement bodies, courts or other authorities where disclosure is required or permitted by law.
Neysan Group does not sell personal data.
Neysan Group does not use personal data from Neysan business products for third-party behavioural advertising unless a product expressly states otherwise and provides any notices or choices required by law.
11. International transfers
Some providers may process data outside the United Kingdom. Where personal data is transferred internationally, we use or rely on appropriate safeguards required by UK data-protection law, such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or equivalent lawful safeguards provided by the relevant service provider.
12. Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, subject to contractual, operational, accounting, tax, employment, regulatory, security and legal requirements.
Different categories of information may therefore have different retention periods. Business records may need to remain available after a user's access to a product has ended or after the user's Neysan Identity has been deleted.
Where information no longer needs to identify an individual, we may delete, anonymise or otherwise minimise that information where practicable.
13. Account and data deletion
A Neysan Identity may be linked to more than one Neysan product, organisation or workspace. A request to delete an account therefore relates to the underlying Neysan Identity and may affect access to multiple Neysan Services.
Users may request deletion of their Neysan Identity and associated personal data through deletion functionality made available within supported Neysan products or through an external deletion-request method provided by Neysan Group.
Before completing a deletion request, we may identify the products, organisations and workspaces associated with the identity so that the effect of deletion can be properly processed. We may contact the account email address where necessary to confirm or communicate the status of the request.
Account deletion requests are normally processed as soon as reasonably practicable. Where manual review is required, we aim to complete the process within 7 days and, in exceptional circumstances, within 30 days.
Deleting a Neysan Identity does not necessarily mean that every record in which the individual previously appeared will be immediately deleted. Certain business, employment, financial, transactional, security, audit, tax, regulatory or operational records may need to be retained where required by law, required to establish or defend legal claims, necessary for fraud or security purposes, or otherwise supported by a lawful basis.
Where continued identification is not required, personal information associated with retained records may be deleted, minimised, anonymised or otherwise separated from the deleted account where reasonably practicable.
Further information about requesting deletion is available by contacting contact@neysangroup.com.
14. Security
We use technical and organisational measures appropriate to the Services we provide. These may include HTTPS encryption in transit, authentication controls, role-based permissions, database access controls, server-side secrets, restricted storage and other measures designed to protect information against unauthorised access, alteration, disclosure or loss.
OAuth tokens for integrations such as HMRC and QuickBooks are not intentionally exposed to the browser. Passwords are handled through our authentication infrastructure rather than stored as readable passwords in Neysan product databases.
No method of transmission or storage is perfectly secure. Users are responsible for protecting their login credentials and should tell us promptly if they suspect unauthorised access.
15. Your rights
Under UK GDPR, depending on the circumstances, you may have rights to access, rectify, erase or restrict your personal data, object to certain processing, receive certain data in a portable format, and withdraw consent where processing is based on consent.
Where your information is controlled by the business or organisation that provided your Neysan account or entered your information into a Neysan product, some requests may need to be handled by that organisation as the relevant data controller.
To exercise rights relating to Neysan Group, contact contact@neysangroup.com. For matters specifically concerning data controlled by Excel Solutions through the Excel Solutions Portal, contact contact@excelsolutions.uk.
You may also complain to the UK Information Commissioner’s Office (ICO) if you believe your personal data has been processed in breach of applicable data protection law.
16. Children
Neysan products and services are designed primarily for business and professional use and are not directed at children. We do not intentionally design our business products for use by children.
17. Security reports
If you need to report a security risk, vulnerability or suspected incident relating to a Neysan product or service, email contact@neysangroup.com.
For matters specifically relating to the Excel Solutions Portal, you may also contact contact@excelsolutions.uk.
18. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our products, services, technology, legal requirements or business operations.
New Neysan products and services may be brought within the scope of this policy by referring or linking to it. Where a new product introduces materially different processing that is not adequately described by this policy, we will update this policy or provide an additional product-specific privacy notice as appropriate.
The “Last updated” date at the top of this page identifies the current version.