Privacy Policy

Last updated: January 2025

1. Introduction

Welcome to WiMi. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our payroll compliance and management platform.

Important: Data Controller vs Data Processor

For your business data: You (the subscriber) are the Data Controller. We act as a Data Processor, processing data on your behalf according to your instructions through the platform.

For account data: We are the Data Controller for information needed to provide and secure the platform (login credentials, billing information, usage data).

2. Data We Control (WiMi as Data Controller)

As the SaaS platform provider, we are the Data Controller for the following data:

Account & Authentication Data

  • Email address and full name
  • Encrypted password
  • Account creation date
  • User role (employer, employee, accountant)

Billing & Subscription Data

  • Subscription plan and status
  • Payment information (processed by Stripe - we don't store card details)
  • Billing history and invoices

Platform Usage Data

  • IP address and browser information
  • Pages visited and features used
  • Login timestamps and session data
  • Analytics (Google Tag Manager)

3. Data You Control (You as Data Controller)

As a subscriber, YOU are the Data Controller for all business data you enter into the platform. WiMi acts as a Data Processor, processing this data on your behalf:

Your Company Data

  • Company registration details
  • Tax references (UTR, PAYE, VAT)
  • HMRC Gateway credentials (encrypted)
  • Business addresses and contact information

Your Employee Data

  • Employee personal information
  • National Insurance Numbers
  • Bank account details (encrypted)
  • Salary and payment information
  • Employment records and contracts

Your Business Operations Data

  • Payroll records and calculations
  • Compliance tasks and deadlines
  • Documents and files you upload
  • Reports and analytics you generate

Your Responsibilities: As Data Controller of your business data, you are responsible for:

  • Ensuring you have lawful basis to process your employees' data
  • Obtaining necessary consents from your employees
  • Responding to data subject requests from your employees
  • Maintaining accurate and up-to-date information

5. Who We Share Data With

We do not sell your data. We only share it with:

HMRC (On Your Behalf)

When YOU use the platform to submit RTI (Real Time Information) payroll returns, we submit them to HMRC on your behalf as your Data Processor. You remain the Data Controller.

Payment Processing

We use trusted third-party service providers to deliver our platform:

  • Stripe: Payment processing - We do not store your card details. Stripe handles all payment information securely.
  • Google Tag Manager: Analytics only - Helps us understand how you use the platform to improve our services.

All service providers are GDPR-compliant and bound by data protection agreements.

Accountants (When YOU Grant Access)

When you invite an accountant to access your data, YOU control what they can see and for how long. You can revoke access anytime. We facilitate this access as your Data Processor.

6. How We Protect Your Data

As WiMi, we implement enterprise-grade security for the sensitive payroll and compliance data we process:

Encryption

  • • SSL/TLS for all data in transit
  • • AES-256 encryption for sensitive fields
  • • Password hashing (bcrypt)
  • • HMRC credentials fully encrypted

Access Controls

  • • Role-based access permissions
  • • Multi-factor authentication
  • • Regular security audits
  • • Principle of least privilege

Infrastructure

  • • UK/EU data centers only
  • • Automated daily backups
  • • Regular security updates
  • • ISO 27001 compliant hosting

Monitoring

  • • Activity logging and audit trails
  • • Incident response procedures
  • • 24/7 security monitoring
  • • Breach notification protocols

7. Data Retention

Subscription-Based Retention:

Your business data is retained for as long as you maintain an active subscription. When your subscription ends, you control what happens to your data through our data export and deletion options.

During Active Subscription

All your business data is retained and accessible while you have an active subscription

Subscription Cancellation

30 days grace period to export your data or reactivate subscription

After Grace Period

Your business data is permanently deleted from our systems (except where legally required to retain)

Legal Requirements

We may retain certain records as required by law (e.g., accounting records for 6 years)

Platform Account Data:

  • Account data: Retained for 30 days after subscription ends, then deleted
  • Billing records: Retained for 6 years for accounting and tax compliance
  • Usage logs: Retained for 90 days for security and troubleshooting

8. Your Privacy Rights

Under UK GDPR, you have the following rights:

Access Your Data

Request a copy of your account and platform data

Correct Your Data

Update inaccurate account information

Delete Your Data

Request deletion of your account and data

Export Your Data

Download all your business data in machine-readable format

Restrict Processing

Limit how we process your data

Data Portability

Transfer your data to another service provider

For Your Business Data (Employee Data):

Since YOU are the Data Controller for your employee data, your employees should direct their data subject requests to YOU, not to us. You can use the platform to manage these requests. We can assist you as your Data Processor if needed.

To Exercise Your Rights (For Your Account Data):

Use the privacy and data export tools in your Profile settings, or submit a request through our contact form.

We will respond within 30 days as required by UK GDPR.

Lodge a Complaint:

If you're not satisfied with our response, contact the Information Commissioner's Office (ICO) at ico.org.uk

9. Cookies & Tracking

Essential Cookies (Always Active)

Required for the platform to work:

  • • Login session tokens
  • • Security tokens (CSRF protection)
  • • User preferences (selected company)

Analytics Cookies (Optional)

Help us improve the platform:

  • Google Tag Manager: Page views, feature usage
  • • We do NOT track you across other websites
  • • Data is anonymized after 26 months

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.

10. Contact Us

If you have questions or comments about this Privacy Policy, please contact us at:

WiMi Support

Email: service@projah.com

Address: Belfast, Northern Ireland

Submit an Inquiry

We respond within 24-48 hours