Skip to main content
Bastion Gateway

Display and language

Changes apply immediately on this device.

Your browser's zoom works too, and applies everywhere.

TrustSupportSign in
Menu
  • Trust
  • Support
  • Sign in

Privacy policy

Last updated 31 July 2026. This policy explains what Bastion Gateway does with personal data when an accountancy practice uses this software to manage their clients’ tax obligations.

Who is responsible for your data

When a practice uses this software, the practice is the data controller for their clients’ information and Bastion Gateway is the processor acting on their instructions. For the practice’s own account data — the people who log in — we are the controller.

Our lawful bases

For practice staff account data, we process what is necessary to provide the contracted service. We use legitimate interests for proportionate security, fraud-prevention and audit records. Where a law requires us to keep or disclose a record, we process it to meet that legal obligation.

For a practice’s client tax data, the practice is the controller and decides its lawful basis. We process that data only on the practice’s documented instructions.

What we hold

  • Practice staff accounts: name, email address, and a hashed password.
  • Client records the practice enters or imports: names, tax reference numbers, and the income and expense figures needed to meet an obligation.
  • Authorisations granted through HMRC, stored encrypted so that a copy of our database is not a set of usable credentials.
  • A record of everything sent to HMRC and its outcome, so a practice can prove what was filed and when.

Why we hold it

To do what the practice asked: keep digital records, work out what is due, and submit it to HMRC. Some of it we are required to keep — a filed tax return or quarterly update, and its receipt, are kept to meet tax record-keeping obligations, which is why they cannot simply be deleted on request.

Deleting your data

You can ask us to delete personal data and we will, except where the law requires us to keep it. A filed tax return or quarterly update, and its HMRC receipt, fall into that exception: we keep them, and we will tell you exactly what we kept and why rather than refusing without explanation.

Records of what was filed are stored in a tamper-evident form. When we delete content from them, the record that something existed and was removed remains, so the trail does not silently develop a hole. That is a deliberate design choice and it is what lets us honour a deletion request without destroying our ability to prove what was filed.

Who else sees it

HMRC receives data when we submit on your instruction. Hetzner Online GmbH hosts the application and its PostgreSQL database. Cloudflare provides the public reverse proxy and processes network identifiers such as IP addresses and request metadata.

We do not use third-party analytics on any page that handles tax data, and we do not sell or share personal data for advertising. Brevo is selected for transactional email and Stripe for hosted payment processing, but neither receives customer data until its production configuration and supplier approval are complete. No AI provider receives customer data from this service.

Where it is held

The application and its database run in Hetzner’s Nuremberg, Germany location. This is outside the UK. Cloudflare may process network metadata at its edge locations. The operator must maintain the applicable UK transfer safeguards and supplier agreements.

Automated decisions

Nothing in this software decides your tax position automatically. Figures are calculated from the records you provide, and nothing is sent to HMRC without a person confirming it. Where software suggests a category for a transaction, a person confirms it before it reaches HMRC.

Contact

Email [email protected] about anything in this policy, including a request to access or delete data. If you are not satisfied with our response you can complain to the Information Commissioner’s Office at ico.org.uk.

Bastion Gateway is files company tax returns and confirmation statements.

  • Trust centre
  • Support
  • Privacy
  • Terms
  • Report a security issue

© 2026 Bastion Gateway·Version 436259b