Legal

Privacy Policy

Last updated: 4 August 2026

1. Who we are

Cosavio is company secretarial software for UK accountancy firms. It tracks Companies House deadlines, prepares statutory filings, and manages identity verification (IDV) of company directors and people with significant control (PSCs) under the Economic Crime and Corporate Transparency Act 2023 (ECCTA).

The data controller for this website and for account data is:

  • WOWL LIMITED, trading as Cosavio (company number SC770389, registered in Scotland)
  • Registered office: 5 South Charlotte Street, Edinburgh, EH2 4AN
  • Privacy contact: privacy@cosavio.com

You can contact us about anything in this policy at that address, and you can complain to the Information Commissioner's Office at any time — see section 6.

2. Our role: controller and processor

This distinction matters and is stated plainly because it changes your rights and who you contact.

  • We are the controller for: accounts of people who work at a subscribing firm (name, work email, role), website visitors, and people who contact us.
  • We are a processor acting on a firm's instructions for: the company, officer, PSC and identity-verification records that a firm manages in Cosavio. The firm — your accountant — is the controller of that data. If you are a director being verified, the firm that instructed the check is the first place to direct a request, though you may contact us and we will help.

Where we act as your processor, UK GDPR Article 28 requires a written data processing agreement between us. We will provide one and enter into it on request. Until we have, our Terms of Service record the same commitments: we process only on your documented instructions, keep the data confidential, apply the security measures in section 8, use only the subprocessors listed in section 4, help you answer data-subject requests, and return or delete the data when our agreement ends.

3. What we collect, why, and our lawful basis

3.1 Firm users (people who log in)

DataPurposeLawful basis
Name, work email, password (stored only as a hash by our authentication provider), role, firm membershipCreate and secure your account; apply permissions; show who did whatPerformance of a contract (UK GDPR Art. 6(1)(b))
An append-only audit record of actions you take (preparing, approving, filing)Maintain the maker–checker audit trail the product exists to provide; support the firm's own regulatory record-keepingLegitimate interests (Art. 6(1)(f)) — providing a trustworthy compliance record
Sign-in metadata and bot-protection signalsProtect accounts against automated abuseLegitimate interests — security

3.2 Company, officer and PSC records

Cosavio mirrors public Companies House register data for the companies a firm manages: company details, officers, PSCs, filing history and deadlines. This is public register information published by Companies House.

One deliberate limitation, stated because it is unusual and in your favour: we do not import full dates of birth. Companies House restricts the full day of birth of officers, and our data bridge is built so that only the month and year of birth can ever cross into Cosavio. The full date is structurally absent from our systems.

Lawful basis: legitimate interests (Art. 6(1)(f)) — enabling an accountancy firm to meet its clients' statutory filing obligations — and, for the firm, compliance with a legal obligation.

3.3 Directors and PSCs being identity-verified

If a firm asks us to run identity verification for you, we process:

DataPurpose
Your name, role and the company you are connected toIdentify whose verification is outstanding
Your email address and/or mobile numberSend you the verification link and reminders
Verification status, timestamps, and the outcome returned by our verification providerShow the firm whether verification is complete
A reference to any Companies House personal code held for youRecord that a code exists

We never store your personal code in readable form. Only a vault reference is held. Where a code is revealed to a firm user, that reveal is written to an append-only access log recording who looked and when.

We do not receive or store your identity documents or biometric data. The verification journey itself is hosted by our verification provider (see §4); your document and any facial-similarity check happen there, not here. We receive the outcome, not the underlying special-category data.

Lawful basis: the firm's legal obligation and ours in supporting it (Art. 6(1)(c)), and legitimate interests in preventing economic crime, which is the express purpose of the ECCTA regime. Because the identity documents and any facial-similarity check stay with our verification provider and never reach us, we do not process special-category data for this purpose. Our provider is responsible for that part of the journey and publishes its own notice.

3.4 Messages we send you

Firms use Cosavio to send service messages about a specific statutory obligation — for example, a reminder that your identity verification is outstanding. These are not marketing. Every message identifies the firm on whose behalf it is sent and how to stop receiving them.

WhatsApp messages are sent only using message templates approved in advance by Meta, as WhatsApp's rules require.

3.5 Website visitors and enquiries

DataPurposeLawful basis
Name, firm, email and message you type into our contact formReply to youLegitimate interests — responding to an enquiry you initiated
Bot-protection signals from Cloudflare Turnstile on our sign-up, sign-in and contact formsStop automated abuse and spamLegitimate interests — security
Aggregate, cookieless usage statistics (page views, referrer, country, device type)Understand which pages are usefulLegitimate interests — improving the site

Our analytics do not use cookies, do not track you across websites, and do not build a profile of you. See our Cookie Policy.

4. Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing. We use the following service providers ("subprocessors"):

ProviderWhat it doesWhere
SupabaseDatabase and authentication for the productEU (London and Ireland regions)
VercelHosts and serves the website and applicationUS-headquartered, served via a global edge network
ResendSends product and reminder emailSending region EU (eu-west-1); US-headquartered provider
yCloudSends WhatsApp reminder messagesOutside the UK and EEA
CertivusIdentity verification, including the hosted verification journey you are taken toEU-resident infrastructure; its own subprocessors, including the provider of its verification journey, are listed in Certivus's privacy notice
CloudflareBot and spam protection (Turnstile)Global edge network
Plausible AnalyticsCookieless website statisticsEU
RailwayRuns our overnight Companies House data synchronisationEU region
StripeTakes subscription payments. We never see or store your card detailsUS-headquartered, UK and EU entities

Your product data is held in the EU (London and Ireland). Where a provider above processes personal data outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on adequacy where it applies.

We keep a data processing agreement with each provider. If you want to know which providers touch a particular piece of data, ask us at privacy@cosavio.com and we will tell you.

We may also disclose personal data where we are legally required to, or to establish or defend legal claims.

5. How long we keep it

We keep data only as long as we need it, and the periods below are the ones we work to.

WhatHow longWhy
Identity-verification records and their evidence5 years after the firm's relationship with that client endsSupports the firm's own record-keeping under the Money Laundering Regulations 2017. Deleting sooner would undercut a duty that sits on them.
Filing records and the audit trail6 years from the end of the relevant financial yearThese are the record that something was done, and when. They are append-only by design.
Company, officer and PSC recordsWhile the firm manages that company, then 12 monthsSo a firm that removes a company by mistake can get it back.
Firm user accounts12 months after the subscription endsLets you come back without losing your workspace.
Contact-form enquiries24 monthsLong enough to pick up a conversation again.
Cookieless website statisticsAggregate only, no personal data retainedNothing to delete.

Where we act as a processor, a firm can ask us to delete their data sooner and we will, unless we are legally required to keep it. Where the law requires us to keep something longer than the periods above, we keep it and no longer.

6. Your rights

Under UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; object to processing based on legitimate interests; data portability; and to withdraw consent where we rely on it (withdrawal is as easy as giving it).

To exercise any right, contact privacy@cosavio.com. We respond within one month, extendable by a further two months for complex requests, and we will tell you if we need the extension. There is no charge.

Where we act as a processor for a firm, we will pass your request to that firm and support them in answering it.

You can complain to the Information Commissioner's Office. The ICO is the UK supervisory authority for data protection: ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to resolve your concern first, but you do not have to come to us before going to the ICO.

7. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means alone. An identity-verification result is returned by our provider and is acted on by a person at your firm. If that ever changes, we will update this section before it does, not after.

8. Security

Data is held in EU-region infrastructure. Access is restricted to the firm that manages the record, enforced both in our application and by database-level row-level security. Personal codes are never stored in readable form. Access to sensitive records is logged to an append-only trail.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, tell affected people directly. We keep a written breach-response procedure with a named owner.

9. Changes

We will update this page when our processing changes and revise the "last updated" date. Material changes will be notified to firm administrators.