NBM MTD Bridge ("the software") is in-house bridging software operated by
Paul Barclay, NBM Digital, to submit his own Making Tax Digital for Income Tax
quarterly updates to HM Revenue & Customs (HMRC). The software is not
offered to the public. The data controller is Paul Barclay
(paul.barclay@nbmdigital.com),
who is also the software's only user and the taxpayer whose data it processes.
What data the software processes
Business financial records — invoice, payment and expense
data held in the operator's own Invoice Ninja accounting system, used to
calculate quarterly income and expense summaries.
Tax identifiers — the operator's National Insurance number
and HMRC business identifiers, used to address submissions to the correct
taxpayer records.
HMRC authorisation tokens — OAuth 2.0 access and refresh
tokens granted by the operator through HMRC's authorisation flow. These are
stored encrypted at rest and are used solely to call HMRC APIs.
Fraud prevention data — HMRC legally requires all Making Tax
Digital software to send fraud prevention header data with every API call
(see HMRC's
transaction monitoring requirements). This includes device identifiers,
browser details, screen information, timezone, public IP address and
software identifiers of the person using the software. This data is
collected when the software is used and transmitted to HMRC.
How data is stored and shared
Data is stored on a server in a DigitalOcean (London, UK) data centre,
protected by a firewall, TLS encryption in transit, and authentication.
Authorisation tokens are encrypted at rest.
Data is shared with exactly one third party: HMRC, to meet
the operator's statutory Making Tax Digital obligations. No data is sold or
shared with anyone else.
A log of each submission (figures sent and HMRC's response) is retained as
part of the digital records HMRC requires taxpayers to keep.
Retention
Financial records and submission logs are retained for at least 6 years in line
with HMRC record-keeping requirements. Authorisation tokens are retained while
the HMRC connection is active and can be revoked at any time via the operator's
Government Gateway account or HMRC's
manage
authorised applications page.
Cookies
This software uses only strictly necessary cookies and similar storage, required
to provide the service you're using — it does not use analytics, advertising or
tracking cookies, and none are set by third parties. Because these are strictly
necessary, UK cookie law does not require consent for them, but they're listed
here for transparency:
Session cookie — keeps you signed in between requests.
CSRF token cookie — protects the software's forms against
cross-site request forgery.
Device identifier (browser local storage, not a cookie) — a
random ID generated on first use, sent with each HMRC API call as part of the
fraud prevention header data HMRC legally requires (see above).
Your rights
Under UK GDPR you have rights of access, rectification, erasure and objection.
As the software processes only its operator's own data, requests can be made to
the contact above. You also have the right to complain to the Information
Commissioner's Office (ico.org.uk).