Last updated: January 2025
Welcome to WiMi. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payroll compliance and management platform.
Important: Data Controller vs Data Processor
For your business data: You (the subscriber) are the Data Controller. We act as a Data Processor, processing data on your behalf according to your instructions through the platform.
For account data: We are the Data Controller for information needed to provide and secure the platform (login credentials, billing information, usage data).
As the SaaS platform provider, we are the Data Controller for the following data:
As a subscriber, YOU are the Data Controller for all business data you enter into the platform. WiMi acts as a Data Processor, processing this data on your behalf:
Your Responsibilities: As Data Controller of your business data, you are responsible for:
Under UK GDPR, we process data based on:
Contract Performance
To provide the SaaS platform service you subscribed to
Legal Obligation
To comply with tax, accounting, and legal requirements
Legitimate Interests
Platform security, fraud prevention, service improvement
We process your business data strictly according to your instructions through the platform. The legal basis for processing this data is determined by YOU, not us. We act only as your Data Processor to facilitate your payroll, compliance, and administrative operations.
We do not sell your data. We only share it with:
When YOU use the platform to submit RTI (Real Time Information) payroll returns, we submit them to HMRC on your behalf as your Data Processor. You remain the Data Controller.
We use trusted third-party service providers to deliver our platform:
All service providers are GDPR-compliant and bound by data protection agreements.
When you invite an accountant to access your data, YOU control what they can see and for how long. You can revoke access anytime. We facilitate this access as your Data Processor.
As WiMi, we implement enterprise-grade security for the sensitive payroll and compliance data we process:
Subscription-Based Retention:
Your business data is retained for as long as you maintain an active subscription. When your subscription ends, you control what happens to your data through our data export and deletion options.
During Active Subscription
All your business data is retained and accessible while you have an active subscription
Subscription Cancellation
30 days grace period to export your data or reactivate subscription
After Grace Period
Your business data is permanently deleted from our systems (except where legally required to retain)
Legal Requirements
We may retain certain records as required by law (e.g., accounting records for 6 years)
Under UK GDPR, you have the following rights:
Access Your Data
Request a copy of your account and platform data
Correct Your Data
Update inaccurate account information
Delete Your Data
Request deletion of your account and data
Export Your Data
Download all your business data in machine-readable format
Restrict Processing
Limit how we process your data
Data Portability
Transfer your data to another service provider
Since YOU are the Data Controller for your employee data, your employees should direct their data subject requests to YOU, not to us. You can use the platform to manage these requests. We can assist you as your Data Processor if needed.
Use the privacy and data export tools in your Profile settings, or submit a request through our contact form.
We will respond within 30 days as required by UK GDPR.
Lodge a Complaint:
If you're not satisfied with our response, contact the Information Commissioner's Office (ICO) at ico.org.uk
If you have questions or comments about this Privacy Policy, please contact us at:
WiMi Support
Email: service@projah.com
Address: Belfast, Northern Ireland
Submit an Inquiry
We respond within 24-48 hours