Privacy Policy
At Yonda Tax, we help businesses expand globally, without the burden of managing sales tax compliance across multiple countries and states.
1. Who We Are and How to Contact Us
Yonda Tax Limited (“Yonda”, “we”, “us”, “our”) is a company registered in England and Wales (Company No. 13973098) with its registered office at 86-90 Paul Street, London, EC2A 4NE. We provide indirect tax compliance software and services, including VAT, GST, and US sales tax registration, filing, and advisory services, via our online platform (the “Platform”) and associated website at www.yondatax.com (the “Website”).
For all privacy-related queries, data subject requests, or concerns, please contact our designated privacy contact at:
2. Scope of This Policy
This Privacy Policy applies to Personal Data we collect and process in connection with:
- visitors to our Website (www.yondatax.com);
- individuals who contact us via our Website, email, telephone, or social media;
- prospective clients and their representatives;
- clients (“Clients”) who access and use our Platform and Services; and
- personnel and authorised users of Client organisations who access the Platform on their employer’s behalf.
This Policy does not cover Personal Data that Clients upload to the Platform in connection with their own customers or end-users (“Client-Controlled Data”). In respect of Client-Controlled Data, Yonda acts as a data processor on the Client’s instructions, and the Client is the data controller. Such processing is governed by the Data Processing Agreement (“DPA”) between Yonda and the Client.
3. Personal Data We Collect
3.1 Website visitors and marketing contacts
- Name, job title, company name and contact details (email, phone, LinkedIn).
- IP address, browser type and version, device information, and operating system.
- Pages visited, time spent on site, referral source, and clickstream data.
- Cookie identifiers and behavioural data (see Section 8).
- Any information you voluntarily provide via contact forms, demo requests, or webinar registrations.
3.2 Prospective and onboarding clients
- Business name, registration number, and registered address.
- Name, email, and contact details of authorised representatives and signatories.
- Information provided in scoping calls, proposals, and onboarding questionnaires.
3.3 Platform users
- Account credentials (username, hashed password).
- Name, job title, work email address, and telephone number.
- Tax identifying numbers (VAT, GST, EIN/TIN) for the Client entity.
- Banking details where provided in connection with tax registration or filing services.
- Transaction and filing data uploaded to or generated within the Platform.
- Audit logs of Platform activity (logins, actions taken, timestamps).
- Support tickets and correspondence with our team.
3.4 Data from your connected platforms.
- Where you authorise a connection to an e-commerce platform, marketplace or accounting system — including Amazon Seller Central, Shopify, eBay, Etsy, Walmart, Wix, Magento, BigCommerce, WooCommerce, Stripe, QuickBooks and Xero — we retrieve order, transaction and settlement records from that platform through its official API, using credentials you authorise and can revoke at any time. We retrieve only the records needed to determine and report your indirect tax obligations.
- From Amazon Seller Central we receive delivery location data only: country, city, postal code, region, municipality and county. We do not request or receive buyer names, street addresses, telephone numbers or email addresses. This data is used solely to determine the tax jurisdiction of each sale and to prepare and file your returns. It is not used for any other purpose, not combined with data from other clients, and not shared other than with the tax authorities and filing agents required to submit your returns.
3.5 AI-assisted mapping of files you upload.
- When you upload a transaction file to our platform, we suggest how the columns in your file correspond to the fields we need for your return. To produce that suggestion we send the column headings and a small sample of rows from your file to Amazon Bedrock, a machine-learning service operated by Amazon Web Services, which we use under our existing data processing agreement with AWS.
- What is sent. Only the column headings and a short extract of rows from the file you uploaded — enough for the model to recognise the shape of the data. We send nothing else.
- Where it is processed. Processing takes place within the European Economic Area. Your data is not transferred outside the EEA for this purpose, and no request is routed to the United States.
- What happens to it. The model returns a suggested mapping and the data is discarded. We do not store the content sent to the model or the suggestion it returns. Your data is not used to train, fine-tune or improve any model, whether ours, AWS's or the model provider's, and is not shared with any other customer.
- You remain in control. The suggestion is only ever a suggestion. It is shown to you for review, and no mapping is applied to your data until a person confirms it. We do not make decisions about you by automated means alone.
4. How and Why We Use Your Personal Data
We process your Personal Data on the following legal bases under UK GDPR:
5. Sharing Your Personal Data
We do not sell, rent, or trade your Personal Data. We may share your data with the following categories of third parties where necessary to deliver our Services:
- Cloud infrastructure and hosting providers (e.g. AWS or equivalent) who host the Platform and process data on our behalf;
- Tax authority portals and government systems to which we submit filings on behalf of Clients;
- Payment processors and banking partners where required to facilitate tax payments or fee collection;
- Customer relationship management (CRM), helpdesk, and analytics software providers;
- Professional advisers including lawyers, accountants, and auditors under obligations of confidentiality;
- Regulatory or law enforcement authorities where we are required to do so by law.
- Within our client and operations portals we use analytics and support tools to understand how features are used and to answer your questions. These record your name, email address, user identifier, organisation and the actions you take in the product, together with the content of any support conversation. They do not receive your transaction data.
All third-party processors are subject to written data processing agreements and are authorised to use your data only for the purpose of providing services to us. We publish a list of our current sub-processors, which is available on request at privacy@yondatax.com.
6. International Data Transfers
Yonda is headquartered in the United Kingdom. We serve clients globally, including in the United States, and some of our sub-processors are based outside the UK and European Economic Area (EEA).
Where we transfer Personal Data outside the UK or EEA, we ensure that appropriate safeguards are in place in accordance with UK GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO) or the European Commission;
- Adequacy decisions where applicable; or
- Other transfer mechanisms recognised under applicable data protection law.
Some of our sub-processors are located outside the UK and European Economic Area, including in the United States. Where they are, we rely on the UK Extension to the EU–US Data Privacy Framework where the recipient is certified under it, or on an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. A current list of our sub-processors, their location and the transfer mechanism relied on for each is available on request at privacy@yondatax.com.
7. Data Retention
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:
Following the end of the applicable retention period, Personal Data will be securely deleted or anonymised. Where deletion is not immediately possible (for example, where data is held in backup archives), we will ensure the data is isolated and protected from further processing.
8. Data Protection Accountability
We have assessed whether we are required to appoint a Data Protection Officer under Article 37 of the UK GDPR and concluded that we are not. We maintain a Data Protection Lead who is accountable for our privacy programme, including our record of processing activities, retention periods, data subject requests and international transfers. You can contact them at privacy@yondatax.com.
9. Cookies and Tracking Technologies
Our Website uses cookies and similar tracking technologies. We use the following categories of cookies:
- Strictly necessary cookies – essential for the Website to function. These cannot be disabled.
- Analytical / performance cookies – help us understand how visitors interact with our Website (e.g. Microsoft Clarity, Google Analytics).
- Functional cookies – remember your preferences to personalise your experience.
- Targeting / advertising cookies – used to deliver relevant advertising and track campaign performance (e.g. Microsoft Advertising, LinkedIn Insight Tag).
You can manage your cookie preferences via the cookie consent banner on our Website or by adjusting your browser settings. Please note that disabling certain cookies may affect Website functionality.
For information about how Microsoft Clarity and Microsoft Advertising collect and use your data, please refer to the Microsoft Privacy Statement at https://privacy.microsoft.com.
10. Security
We take data security seriously and implement appropriate technical and organisational measures to protect your Personal Data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encryption of data in transit (TLS/HTTPS) and at rest;
- Role-based access controls and authentication requirements for Platform access;
- Regular security assessments and penetration testing;
- Staff training on data protection and information security;
- Incident response and breach notification procedures.
In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and will notify affected individuals without undue delay where required by law.
11. Your Rights
Depending on your location and the applicable law, you may have the following rights in respect of your Personal Data:
- Right of access – to obtain a copy of the Personal Data we hold about you.
- Right to rectification – to correct inaccurate or incomplete Personal Data.
- Right to erasure – to request deletion of your Personal Data in certain circumstances.
- Right to restrict processing – to request that we limit how we use your data.
- Right to data portability – to receive your data in a structured, machine-readable format.
- Right to object – to object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
California residents may additionally exercise rights under the CCPA/CPRA, including the right to know, the right to delete, the right to correct, and the right to opt out of the “sale” or “sharing” of Personal Data. Yonda does not sell or share Personal Data as those terms are defined under California law.
To exercise any of your rights, please contact us at hello@yondatax.com. We will respond within one calendar month (or within 45 days for US residents where applicable). We will not charge a fee unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your Personal Data, you have the right to lodge a complaint with the relevant supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO) at www.ico.org.uk.
12. Children
Our Website and Platform are not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If you believe we have inadvertently collected such data, please contact us at privacy@yondatax.com and we will take steps to delete it promptly.
13. Links to Third-Party Websites
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. We will post the updated policy on our Website with a revised “Last updated” date. Where changes are material, we will notify active Platform users by email or in-platform notification with reasonable notice before the changes take effect.
15. Contact Us
If you have any questions about this Privacy Policy or how we handle your Personal Data, please contact us: