SECURITY & DATA HANDLING

Protecting customer data with UK-based storage, encryption, access controls, monitoring, and GDPR-aligned practices.

GAIN Tax Uses Advanced Security Controls, Strict Access Governance, Encryption, Monitoring, Incident Response Procedures, And GDPR-Aligned Data Handling Practices To Protect Customer Data Across The Platform.

Where data is stored?

Customer data is stored in the UK only, within secure, access-controlled infrastructure.

Encryption at rest / in transit

Data is encrypted both at rest and in transit using secure encryption and transport protocols.

Who can access client files?

Access to client files is restricted to authorized customer users and, where necessary, a limited number of authorized GAIN Tax personnel for support, maintenance, or security purposes.

Role-based permissions

GAIN Tax uses role-based access controls to ensure users can access only the data and functions required for their role.

Logging / audit trail

GAIN Tax maintains logging and audit trails for key system activity, access events, and security-relevant operations to support monitoring, investigation incidents, and accountability.

Retention & deletion policy

Customer data is retained only for as long as necessary to provide the service, comply with legal obligations, and meet operational requirements. Data is deleted or securely removed in accordance with defined retention and deletion procedures.

GDPR rights / deletion requests

GAIN Tax supports GDPR-aligned handling of customer data, including processes for access, correction, export, and deletion requests, subject to applicable legal and regulatory requirements.

Subprocessor list

GAIN Tax maintains a subprocessor list, available on request.

DPA availability

A Data Processing Addendum is available on request.

Whether customer data is used for model training?

Customer data is not used to train public or shared AI models.

Incident response

GAIN Tax maintains incident response procedures for the timely identification, containment, investigation, remediation, and notification of security incidents where required.

Backup / disaster recovery

GAIN Tax maintains backup and disaster recovery measures to support resilience, business continuity, and restoration of critical data and services.