Privacy Policy

Last updated: December 2025

This Privacy Policy outlines how Sodium Software Ltd ("we", "us", or "our") processes personal data on behalf of our users in connection with our platforms:

  • SodiumHQ – a practice management platform for UK accountants, providing tools for client relationship management, proposals, tasks, workflows, and more
  • CIS Manager – a platform for managing Construction Industry Scheme (CIS) compliance, subcontractor verification with HMRC, and contractor-subcontractor invoicing

1. Who We Are

Sodium Software Ltd is a UK-based company acting as a data processor on behalf of users who are the data controllers.

  • Company Name: Sodium Software Ltd
  • Registered Address: Amelia House, Crescent Road, Worthing, West Sussex, United Kingdom, BN11 1RL
  • Email: hello@sodiumhq.com

2. Role in Data Processing

As a data processor, we do not determine the purpose or means of processing personal data. Users control the data and its use, with our company acting solely on their instructions.

3. Data We Process

We process the following types of personal data:

  • Names
  • Email addresses
  • Phone numbers
  • IP addresses
  • Billing details
  • Login credentials
  • Device and browser information

Data collection occurs through account registration, user-submitted entries, and cookies/analytics tools.

4. Legal Basis and Purpose for Processing

Processing occurs under UK GDPR with the following legal bases:

Contractual Necessity

Core platform functionality including account creation and management.

Consent

Sending marketing or promotional communications and non-essential cookies require user consent, which can be withdrawn at any time.

Legitimate Interests

Understanding service usage for product development, monitoring platform security and performance, and preventing fraudulent activity.

5. Data Sharing

Data sharing occurs only as instructed by users. No international data transfers occur.

6. Data Retention

We retain personal data for 7 years to comply with legal and contractual obligations. Following this period, data is securely deleted or anonymized unless otherwise instructed.

7. Data Subject Rights

Although acting as a processor, we support users in exercising their GDPR rights:

  • Access to personal data
  • Correction of inaccurate data
  • Deletion requests
  • Objection to processing
  • Data portability
  • Restriction of processing
  • Withdrawal of consent

8. Cookies and Tracking

Cookies are used for session management and analytics, with a consent banner obtaining informed user approval.

9. Security Measures

We implement protective measures including:

  • SSL encryption
  • Data encryption at rest and in transit
  • Access controls
  • Regular data backups

10. Children's Data

Our platform is not intended for or directed at children under the age of 13 or 16. We do not knowingly process children's data.

11. Contact

If you have any questions about this Privacy Policy or how we process data on behalf of our users, please contact us at:

  • Email: hello@sodiumhq.com
  • Address: Amelia House, Crescent Road, Worthing, West Sussex, United Kingdom, BN11 1RL