← Back to home

Privacy Policy

Last updated: 3 April 2026

1. Who We Are

OpenCT is operated by Lightweight Integration Ltd (company number 15043498), registered in England and Wales. We are the data controller for personal data processed through the OpenCT platform.

2. Data We Collect

Account data: Email address, display name, and encrypted password hash.

Company data: Company name, registration number, UTR, accounting period, financial data (trial balance, P&L, balance sheet), Government Gateway credentials (encrypted at rest with per-tenant Fernet keys).

Usage data: API request logs (anonymised after 90 days), audit trail entries.

3. How We Use Your Data

We process your data solely to provide the CT600 filing service: computing corporation tax, generating HMRC-compliant XML and iXBRL documents, and submitting returns via the Government Gateway on your behalf.

4. Legal Basis (GDPR Article 6)

Contract performance: Processing your financial data to provide the filing service you signed up for.

Legal obligation: Retaining submission records as required by HMRC and Companies House.

Legitimate interest: Security logging and fraud prevention.

5. Data Sharing

We share data only with HMRC (for CT600/VAT/SA100 submissions) and Companies House (for accounts filing). We do not sell or share your data with any third parties for marketing purposes.

6. Data Security

All data is encrypted in transit (TLS 1.3) and at rest. Government Gateway credentials use per-tenant Fernet encryption with HKDF key derivation. Workspaces are isolated per company. Multi-tenant data isolation is enforced at the application and database level.

7. Your Rights (GDPR Articles 15-20)

You have the right to access, rectify, erase, and export your data. Use the GDPR section in Settings or contact us at privacy@openli.ai.

8. Data Retention

Active account data is retained for the duration of your subscription. On deletion, all personal and financial data is permanently removed within 30 days (GDPR Article 17 compliance). HMRC submission records are retained for 7 years as required by law.

9. Contact

Data Protection Officer: Zhong Li, Director
Email: privacy@openli.ai
Address: Lightweight Integration Ltd, England, United Kingdom