This policy outlines how we manage your personal data as it relates to the My Biz website and application.
This is Version 1.1, and this policy was issued in April 2021. We may update this policy again in the future and will publish any subsequent versions of it here. If you have any questions about this policy, just get in touch –e-mail us at help@mybizmanager.co.uk.
Personal data is highly valuable, and as we handle your personal and financial data, we have responsibility to keep your data safe and we take this responsibility very seriously.
1. Who are we?
My Biz (“we”, “us”, “our”) is an online business management software application which is best suited to small businesses and freelancers (sole traders, limited companies and partnerships).
As a data controller, we collect, store and process personal data when you browse our site go.mybizmanager.co.uk (the “My Biz website”), use the My Biz service/application (“My Biz”) or provide personal data to us by other means (e.g. email). Our Privacy Policy explains how we treat your data, including personal data, and it should be read in conjunction with our . These documents apply both to your use of the My Biz website and My Biz service.
2. What data do we collect, receive and keep?
Personal data
“Personal data” is data that relates to, and identifies, a living person. Personal data is included in the information that you provide to us or that is provided during your interactions with us or our service, or in the information that you authorise a third party to give to us on your behalf (e.g. if you are a Secondary User or Free User).
The personal data referenced here does not include the financial data that you enter into My Biz, or that is provided to My Biz from your bank, unless it identifies a person. Please see the section below on ‘Financial data’ for more information on the privacy of your financial data.
With regards to personal data, My Biz is fully compliant with our obligations under the General Data Protection Regulation (GDPR) and other applicable data protection legislation. My Biz does not sell, rent, release, make available, disseminate, transfer, disclose, or otherwise communicate personal information to another business or a third party for monetary or other valuable consideration.
My Biz does not collect or process any special categories of personal data, as defined under GDPR and the Data Protection Act 2018. We do not knowingly collect or solicit any personal data from anyone under the age of 16 or knowingly allow such persons to register for My Biz. As outlined in our Terms and Conditions, My Biz is not directed at children under the age of 16. In the event that we learn that we have collected personal data from a child under age 16 without verification of parental consent, we will delete that information as quickly as possible.
Your personal data includes the information you provide to us or that you authorise someone else to provide when you:
- apply for a My Biz account (trial period and subscription);
- elect to have a My Biz account provided to you;
- sign up to receive our emails or communications;
- participate in customer research or activities e.g. or answer questionnaires or surveys;
- provide information in your My Biz account profile;
- provide information about you and/or your business during a support enquiry, by telephone or email;
- provide information when you complete any forms which you submit to us, e.g. when you authorise us to receive transaction information from your bank; or
- provide information to your My Biz Account via an upload or data transfer.
Examples of this personal data include name, email address, contact number, as well as any correspondence sent by you to us. It may also include your bank account and bank transaction details (if that information identifies a person). In addition, personal data may also include details in any invoices or receipts that you upload (if they identify a person). We maintain the integrity of your personal data to Secondary and Free Users to your account – Secondary Users only have access to your calendar and scheduling functions, and you are responsible for what personal data you include there. Free Users have read-only access to financial data only, if that information identifies a person.
Financial data
In addition to your personal data, we may also hold financial data that you enter into My Biz in order to make use of our services, for example, your organisation’s invoices, expenses, receipts and bank transactions. You are in control of the financial data subject to our Terms and Conditions, and in control of who has access to it. You can authorise your account to have access to your data by setting up a Free User associated account (e.g. for your accountant), on their behalf. You can remove Secondary and Free User accounts at any time, and you can stop a feed of data from your bank at any time. We maintain the integrity of your financial data to Secondary and Free Users to your account – Secondary Users do not have access to this data, and Free Users have read-only access.
The security of access to your account is your responsibility – you must safeguard your login information and manage third party account access. You are also responsible for making suitable disclosures and, where applicable, for obtaining any relevant consents and/or permissions required for you to upload personal and financial data of others, for example, your contacts, to My Biz and for that data to be managed and used as set out in this policy. If you want to prevent third party access to your account, you can delete any associated Secondary or Free User accounts in your Account settings, or by contacting us directly at help@mybizmanager.co.uk.
If, at any time, you want to stop any transfer of data between your bank, you can disable the bank feed directly in your My Biz, or by contacting us at help@mybizmanager.co.uk.
Information that we collect
We collect information about how you use our website and application, in order to continually improve our service, understand trends of use, and to enhance and customise our content and communications. Some of this data may be “personal data”, where it relates to an identifiable person. Below we summarise the information that we collect and how we use it:
- Patterns of usage (e.g. your Internal Protocol (IP) address) to understand how people are using My Biz, to support our security measures, to inform our communications with you, and to continually improve our products and service.
- we monitor traffic information to our website and emails, including page visits, email clicks, purchases, referring sites, and video viewings. This helps us to improve our products and service. We use cookies to do this; please see our policy on cookies.
Information provided to us by third parties
We may receive information from third parties (e.g. your bank) when you have authorised that third party to provide information to us. This could, in certain circumstances, include the initial information to enable us to create your account (e.g. your full name, your email address and your business type), as well as your bank transaction data.
3. What do we use your personal data for?
We collect and use your personal data for a variety of business reasons. Some of the data that you provide allows us to enter into and perform our contract with you, maintain the security of our systems and provide you with access to My Biz e.g. information requested for registration with My Biz. If you do not provide this data, either by failing or refusing to do so, we may be unable to provide our service to you.
We process all of the data that we use and collect in line with a set of processing conditions, which are the legal bases under which we have the authority to collect, use and store your personal information. We summarise these below:
Contractual Necessity
We process data where it is required to enter into a contract with you, for the provision of the My Biz service or to perform our obligations under that contract. Please note that if you do not agree to provide us with certain requested information you may not be able to operate the service, either as intended or at all. Examples of this include:
- processing and reviewing applications for the My Biz service or additional services;
- executing your instructions, processing transactions, providing support or advice, resolving any queries or discrepancies and administering any changes;
- receiving calls or emails to our support team;
- managing and maintaining our relationships with you and for ongoing customer service;
- communicating with you about the service and products you receive from us or via the My Biz service; and
- handling any complaints, queries or requests which relate to the My Biz service.
Please note – you will retain complete discretion to terminate your account with My Biz where we/you consider that it does not meet your needs or expectations.
Legal Obligation
When you elect to use the My Biz service, we are required to collect and process certain personal information about you, by law. If you fail or refuse to provide us with certain mandatory information, it may not be possible for you to access the service. Examples include:
- confirming your identity (e.g. by confirming your email) and protecting against fraud;
- performing checks on the service and monitoring transactions and location data for the purpose of preventing and detecting crime and to comply with laws relating to money laundering, fraud, terrorist financing, bribery and corruption;
- sharing information with police, law enforcement, tax authorities or other government and fraud prevention agencies where we have a legal obligation to do so, including reporting suspicious activity and complying with production and court orders;
- delivering mandatory communications to users of the service, providing service messages, publishing revised disclosures, policies, or terms and conditions;
- investigating and resolving complaints where we may need to exercise or defend our legal rights;
- conducting investigations into suspected criminal acts, breaches of conduct and corporate policies;
- processing applications for products and services available from or through My Biz, including making decisions about whether to agree to approve any application;
- performing assessments and analysing customer information for the purposes of managing, improving and fixing data quality; and
- providing assurance that we have effective processes to identify, manage, monitor and report on the risks My Biz might be exposed to (e.g. security, fraud and client confidentiality).
Legitimate Interests
Where it is in our legitimate interests to do so, we will process your personal data within My Biz, without prejudicing your interests or fundamental rights and freedoms. Examples include:
- delivering service insights to you which help to maximise your use of My Biz;
- providing you with updates about the My Biz service and its functionality;
- analysing your personal data and financial data so that we can administer, support, improve and develop our business, customer service and features of the My Biz service. We may use third parties to assist us in performing these activities and, in those cases, we may pass on your personal and/or financial data to them. We will only share your data with third parties once we are confident that they will protect your data robustly and in full compliance with the law;
- improving your experience of the My Biz service by:
- evaluating your use of our service;
- gathering feedback from you on your use of and interactions within our service;
- monitoring your interactions with our service to tailor the content; and
- recording and monitoring communications to our support team; and
- conducting research and/or trend analysis.
- taking action if we need to defend our legal rights under our Terms of Service if you misuse the service or act in a way which contravenes laws, regulations or our Terms of Service;
- utilising any available support functions for the management of the service;
- tracking and analysing your use of our service to understand its performance;
- sharing anonymous or aggregate data with trusted third parties, e.g. for research purposes;
- monitoring anonymous, aggregated information about accounting and financial data so that we can develop and publish insights about small business finance;
- developing and enhancing our data models to improve the accuracy of the service and your insights;
- better engaging our users by:
- gathering your feedback on the service;
- providing you with detailed information on your account activity;
- providing you with detailed information on your account activity;
- reporting at an aggregate level on the user experience and/or service performance; and
- engaging and communicating with our users on social media and via email.
- using your personal information, in an anonymised and aggregated form, to create content to include in:
- videos on the My Biz service;
- posts from social media accounts owned and operated by My Biz; and
- infographics, industry reports and media campaigns.
4. Who do we share your information with?
Elective third-party access to My Biz data
If you elect to activate the My Biz functions that permit the sharing of your personal and/or financial data with third parties (for example, if you choose to give your accountant or your bank access to your data), then that will constitute your authorisation for this data to be shared and your personal and/or financial data will be shared in that way. Such personal or financial data may include, for example, general, financial and transactional data and information from your account such as bank transactions and invoices, bills, and expenses. These third parties will use that data in accordance with their Privacy Policies and Terms and Conditions, and you are responsible for ensuring that you are happy for your data to be managed by them in this way.
Supplier and third-party arrangements
As part of the service, we may need to share your personal information outside My Biz. There are limited circumstances in which we would do this and we will always have a compelling business reason to do so. Examples of when we will share your information include:
- when you have given us your permission to do so;
- when you ask us to share your information, e.g. with your bank and to add accounts from other providers to the My Biz service;
- when part of the service, or a product you are interested in, is supported or provided by a third party outside My Biz;
- when we are under a duty to disclose or share your personal or financial data in order to comply with any legal or regulatory obligation;
- to cooperate with law enforcement officials, judicial bodies, government entities, tax authorities or regulatory bodies in the investigation of unlawful activities of My Biz users or relating to My Biz users; or in order to enforce or apply any contract with you; or to protect our rights, property, or the safety of our employees, customers or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction;
- sharing with third parties and other financial services companies to help prevent, detect and prosecute unlawful acts and fraudulent behaviour;
- sharing with suppliers, sub-contractors and advisors who support the operation of the service, provide information for an insight, or manage connected products;
- sharing with third parties in the event that we, our business, or substantially all of its assets are acquired by a third party (in which case, personal information about customers will be one of the transferred assets);
- we may pass aggregate information on the usage of the My Biz service, where relevant, to maintain, improve and manage the My Biz service or for the purposes of research, but this will not include your personal data.
5. How long do we store your data for?
We aim to store your data for the minimum amount of time that provides benefit to you, and for as long as is necessary for the purposes of processing that are set out in this policy.
For active accounts (those with a valid subscription) to My Biz, we regularly take secure, encrypted back-ups of your data to ensure the integrity of our service and of your data.
When you cancel your account with My Biz, you can either delete your data immediately via the Delete Account function in your Account Settings, or if you do not do this, we will automatically delete your data after one year. If your Free Trial expires and you do not commence subscription payments, you will retain the option to delete your account, by logging in to the My Biz application. Please see the table below detailing our retention periods for all types of non-active accounts.
Account Type | Retention Period | Notes |
Cancelled | 1 year | Either by selecting ‘Delete Account’ in your Account Settings, or by contacting us directly at help@mybizmanager.co.uk |
Expired Free Trial | 1 year | Either by selecting ‘Delete Account’ option presented after entering log in details to My Biz, or by contacting us directly at help@mybizmanager.co.uk |
Suspended | 1 year | After non-payment |
Non-activated | 1 year | Sign ups that have been
suspended/are incomplete |
If you are signed up to marketing communications, cancelling your My Biz account will not automatically cancel your marketing preferences. If you would like to unsubscribe, please email help@mybizmanager.co.uk, otherwise we will delete your email address from our system after one year of inactivity.
All data, including deleted data, remains archived within these backups for a period of one year, after which they are deleted.
6. Can I export my data at any time?
You can export a copy of your data whenever you like, e.g. your personal data and that of your contacts, your financial transactions, invoices, and receipts and expenses.
While we regularly back-up your data, we are unable to restore back-ups on an individual basis and therefore recommend that you regularly export your data. (You can learn more about exporting your My Biz data by contacting us at help@mybizmanager.co.uk). You can also ask us for a copy of your personal data that we hold.
7. Can I delete my data at any time?
You have the option to delete all of your data at any time, using the “Delete Account” option in the Manage my Account area of My Biz if you are a Primary User whose payments are up to date. If you cease to make payments, or do not commence making payments, you will retain the option to Delete your Account and all of your data upon log in to the My Biz application. If you select this option, your My Biz account and all associated data will be deleted. This means that it will be removed from our active servers right away; however, your data will be retained in our backups as for a period of one year before they are permanently deleted, as per our retention policy (see section 5 of this document).
As many countries, including the United Kingdom, require you to retain business records for a number of years, even after you have ceased trading, we highly recommend that you export your data before cancelling. My Biz is under no obligation to retain data on your behalf, if you are no longer subscribed to the My Biz service.
Your data will be automatically deleted after one year of inactivity following the expiration of your free trial, or suspension of your account due to non-payment.
We retain historical details about your payments to My Biz for accounting purposes because we are required by law to do so.
8. Do you store my payment details?
Once your 30-day free trial is over, you will need to provide payment details to start your subscription and continue using My Biz. Where this information is provided, it is passed directly to our payment service provider, Stripe, via an encrypted mechanism. We do not store any payment details on our system. We handle ongoing billing by passing a token to Stripe that identifies your account (Find out more about Stripe’s privacy policy).
9. Our use of cookies
A cookie is a small amount of data generated by a website and saved by your web browser. We use cookies to track, save and store information about your interactions and usage of our website and service. We use cookies to enable us to provide a smooth, efficient and personalised experience for our users, for example through remembering your preferences, and securely storing your password (if requested) to facilitate your login.
Your browser should allow you to manage or disable cookies for the My Biz website (or any other site), by changing your browser settings. Please note that disabling functional cookies may impair the availability and/or functionality of the My Biz service.
Please see our Cookie Policy for more information about the cookies that we use, and why.
10. Security and data storage
Security and privacy are at the core of the service we provide to you, and as such we strive to take all reasonable steps to keep your personal and financial data secure once it has been transferred to our systems. We implement appropriate, industry-standard data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction.
Where we utilise third parties to help provide our services, we will always ensure that, as a minimum, the security policies and confidentiality arrangements of those third parties adhere to the same requirements that we impose and expect.
You will select a password to restrict access to your My Biz account and to keep your data secure. You are responsible for keeping this password confidential, and therefore we encourage you not to share your password with anyone. If you do so, this is at your own risk. If you become aware that your account login details have become compromised, you must create a new password (which will be validated by email) at the earliest opportunity.
If you would like to update the personal data that we hold about you, please log in to your My Biz account and update your Settings, or contact us at help@mybizmanager.co.uk.
We advise that, despite our best efforts, the internet is not a secure medium and therefore we cannot guarantee the security of any data transmitted to My Biz. Any such transmission is at your own risk.
11. What are my rights under GDPR and how do you meet them?
The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union, which came into effect on 25th May 2018. Below we summarise your individual rights, provided by GDPR and how we meet them:
- Access to your personal data: You may ask us to confirm if we are processing your personal data, and you may request a copy of your personal data by contacting our team at using the details in section 13 of this document.
- Right to change or withdraw your consent: Where you have given us consent to make use of your personal data for any of the purposes outlined in this policy, you may withdraw that consent by contacting us using the details located in section 13 of this policy. If you wish to change your contact preferences or you no longer wish to be contacted for marketing purposes, get in touch.
- Right to rectification: If you need to update out-of-date or inaccurate information that we hold about you, please log on to your My Biz account and update your information or get in touch.
- Right to erasure: You are free to delete your data at any point, using the “Delete Account” functionality in your Settings.
- Right to data portability: In certain circumstances you may ask us to provide you with the personal data that we hold about you in a structured, commonly used, machine-readable form, or ask for us to send such personal data to another data controller. You can use the “Export All Data” functionality at any time to export your data in this manner.
- Right to object: In certain circumstances you may object to our processing of your personal data, e.g. for direct marketing purposes. If this is the case, please get in touch.
- Right to restrict processing: You can ask us to restrict the processing of personal data we hold about you in certain circumstances. If you wish to do so, please get in touch.
- Make a complaint: You may make a complaint about our data processing activities to a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO). Further details can be found on their website.
- Getting in touch: To make enquiries and/or to exercise any of your rights as outlined in this privacy policy please contact our team at help@mybizmanager.co.uk.
12. Updates to our Privacy Policy
We may modify or update this Privacy Policy from time to time to reflect the changes in our business and practices, so we advise that you should review this page periodically.
We will alert you to updates in our policy by updating the ‘last updated’ header at the top of the page. If we make material changes to the policy, we will alert you upon your next log in to your account, subsequent to the update.
13. Getting in touch
If you have any queries relating to this Privacy Policy or My Biz’s use of your personal or financial data, please contact us at help@mybizmanager.co.uk.