Privacy Policy

Last updated: 19 June 2026

This Privacy Policy explains how Slyck Flow (“we”, “us”, “our”) collects, uses, shares, and protects your personal data when you use our accounting application and website. We are committed to handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

Slyck Flow provides accounting software for UK sole traders and limited companies. For the purposes of UK data protection law, Slyck Flow is the data controller for the personal data described in this policy. You can contact us at dataprotection@slyck.app.

2. Data we collect

We collect the following categories of personal data:

  • Account details — your name, email address, and authentication information when you register (including via Google sign-in).
  • Business information — business name, type (sole trader, limited company, partnership), VAT registration status and scheme, and tax year settings.
  • Bank and transaction data — when you connect a bank account through Open Banking, we receive account names, balances, and transaction history (typically up to 90 days at connection, then ongoing). Access is read-only; we cannot initiate payments or move funds.
  • Content you add — manual transactions, categories, notes, and uploaded receipts or documents.
  • Technical data — IP address, device and browser information, and usage data collected to operate and secure the service.

3. Open Banking

We connect to your bank through a regulated Open Banking provider (Enable Banking) acting as an Account Information Service Provider. You authorise each bank connection directly with your bank, and you can revoke that consent at any time with your bank or by disconnecting the account in Slyck Flow. We never see or store your online banking login credentials, and our access is strictly read-only.

4. How we use your data and our legal bases

  • To provide the service — syncing transactions, categorising spending, and producing tax, VAT, and dividend calculations (legal basis: performance of a contract).
  • To secure and improve the service — fraud prevention, debugging, and analytics (legal basis: legitimate interests).
  • To meet legal obligations — for example, retaining certain records where required by law (legal basis: legal obligation).
  • To send service communications — important notices about your account (legal basis: legitimate interests). Marketing emails are sent only with your consent.

5. How we share your data

We do not sell your personal data. We share it only with service providers who help us run Slyck Flow, including:

  • Google Firebase — authentication, database, hosting, and storage infrastructure.
  • Enable Banking — our Open Banking provider for bank connections.
  • Other processors strictly necessary to operate, secure, or support the service.

These providers act as our processors under written agreements and may only use your data on our instructions. We may also disclose data where required by law or to protect our legal rights.

6. International transfers

Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement to ensure your data remains protected.

7. Data retention

We keep your personal data for as long as your account is active. If you close your account, we delete or anonymise your data within a reasonable period, except where we are required to retain certain records for legal, accounting, or tax purposes.

8. Your rights

Under UK data protection law you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data in certain circumstances
  • Restrict or object to certain processing
  • Request portability of data you provided to us
  • Withdraw consent at any time where we rely on it

To exercise any of these rights, contact dataprotection@slyck.app. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

9. Security

We protect your data with encryption in transit and at rest, strict access controls, and read-only banking access. No system is perfectly secure, but we take appropriate technical and organisational measures to safeguard your information.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “last updated” date. Significant changes will be communicated to you directly where appropriate.

11. Contact us

For any questions about this policy or your data, email dataprotection@slyck.app.

Template notice. This document is a starting point and not legal advice. Have it reviewed by a qualified solicitor and confirm your ICO registration before relying on it in production.