Privacy Policy
Last updated: December 2025
This Privacy Policy outlines how Sodium Software Ltd ("we", "us", or "our") processes personal data on behalf of our users in connection with our platforms:
- SodiumHQ – a practice management platform for UK accountants, providing tools for client relationship management, proposals, tasks, workflows, and more
- CIS Manager – a platform for managing Construction Industry Scheme (CIS) compliance, subcontractor verification with HMRC, and contractor-subcontractor invoicing
1. Who We Are
Sodium Software Ltd is a UK-based company acting as a data processor on behalf of users who are the data controllers.
- Company Name: Sodium Software Ltd
- Registered Address: Amelia House, Crescent Road, Worthing, West Sussex, United Kingdom, BN11 1RL
- Email: hello@sodiumhq.com
2. Role in Data Processing
As a data processor, we do not determine the purpose or means of processing personal data. Users control the data and its use, with our company acting solely on their instructions.
3. Data We Process
We process the following types of personal data:
- Names
- Email addresses
- Phone numbers
- IP addresses
- Billing details
- Login credentials
- Device and browser information
Data collection occurs through account registration, user-submitted entries, and cookies/analytics tools.
4. Legal Basis and Purpose for Processing
Processing occurs under UK GDPR with the following legal bases:
Contractual Necessity
Core platform functionality including account creation and management.
Consent
Sending marketing or promotional communications and non-essential cookies require user consent, which can be withdrawn at any time.
Legitimate Interests
Understanding service usage for product development, monitoring platform security and performance, and preventing fraudulent activity.
5. Data Sharing
Data sharing occurs only as instructed by users. No international data transfers occur.
6. Data Retention
We retain personal data for 7 years to comply with legal and contractual obligations. Following this period, data is securely deleted or anonymized unless otherwise instructed.
7. Data Subject Rights
Although acting as a processor, we support users in exercising their GDPR rights:
- Access to personal data
- Correction of inaccurate data
- Deletion requests
- Objection to processing
- Data portability
- Restriction of processing
- Withdrawal of consent
8. Cookies and Tracking
Cookies are used for session management and analytics, with a consent banner obtaining informed user approval.
9. Security Measures
We implement protective measures including:
- SSL encryption
- Data encryption at rest and in transit
- Access controls
- Regular data backups
10. Children's Data
Our platform is not intended for or directed at children under the age of 13 or 16. We do not knowingly process children's data.
11. Contact
If you have any questions about this Privacy Policy or how we process data on behalf of our users, please contact us at:
- Email: hello@sodiumhq.com
- Address: Amelia House, Crescent Road, Worthing, West Sussex, United Kingdom, BN11 1RL