Privacy Policy
Last updated: 4 August 2026
1. Who we are
Cosavio is company secretarial software for UK accountancy firms. It tracks Companies House deadlines, prepares statutory filings, and manages identity verification (IDV) of company directors and people with significant control (PSCs) under the Economic Crime and Corporate Transparency Act 2023 (ECCTA).
The data controller for this website and for account data is:
- WOWL LIMITED, trading as Cosavio (company number SC770389, registered in Scotland)
- Registered office: 5 South Charlotte Street, Edinburgh, EH2 4AN
- Privacy contact: privacy@cosavio.com
You can contact us about anything in this policy at that address, and you can complain to the Information Commissioner's Office at any time — see section 6.
2. Our role: controller and processor
This distinction matters and is stated plainly because it changes your rights and who you contact.
- We are the controller for: accounts of people who work at a subscribing firm (name, work email, role), website visitors, and people who contact us.
- We are a processor acting on a firm's instructions for: the company, officer, PSC and identity-verification records that a firm manages in Cosavio. The firm — your accountant — is the controller of that data. If you are a director being verified, the firm that instructed the check is the first place to direct a request, though you may contact us and we will help.
Where we act as your processor, UK GDPR Article 28 requires a written data processing agreement between us. We will provide one and enter into it on request. Until we have, our Terms of Service record the same commitments: we process only on your documented instructions, keep the data confidential, apply the security measures in section 8, use only the subprocessors listed in section 4, help you answer data-subject requests, and return or delete the data when our agreement ends.
3. What we collect, why, and our lawful basis
3.1 Firm users (people who log in)
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, work email, password (stored only as a hash by our authentication provider), role, firm membership | Create and secure your account; apply permissions; show who did what | Performance of a contract (UK GDPR Art. 6(1)(b)) |
| An append-only audit record of actions you take (preparing, approving, filing) | Maintain the maker–checker audit trail the product exists to provide; support the firm's own regulatory record-keeping | Legitimate interests (Art. 6(1)(f)) — providing a trustworthy compliance record |
| Sign-in metadata and bot-protection signals | Protect accounts against automated abuse | Legitimate interests — security |
3.2 Company, officer and PSC records
Cosavio mirrors public Companies House register data for the companies a firm manages: company details, officers, PSCs, filing history and deadlines. This is public register information published by Companies House.
One deliberate limitation, stated because it is unusual and in your favour: we do not import full dates of birth. Companies House restricts the full day of birth of officers, and our data bridge is built so that only the month and year of birth can ever cross into Cosavio. The full date is structurally absent from our systems.
Lawful basis: legitimate interests (Art. 6(1)(f)) — enabling an accountancy firm to meet its clients' statutory filing obligations — and, for the firm, compliance with a legal obligation.
3.3 Directors and PSCs being identity-verified
If a firm asks us to run identity verification for you, we process:
| Data | Purpose |
|---|---|
| Your name, role and the company you are connected to | Identify whose verification is outstanding |
| Your email address and/or mobile number | Send you the verification link and reminders |
| Verification status, timestamps, and the outcome returned by our verification provider | Show the firm whether verification is complete |
| A reference to any Companies House personal code held for you | Record that a code exists |
We never store your personal code in readable form. Only a vault reference is held. Where a code is revealed to a firm user, that reveal is written to an append-only access log recording who looked and when.
We do not receive or store your identity documents or biometric data. The verification journey itself is hosted by our verification provider (see §4); your document and any facial-similarity check happen there, not here. We receive the outcome, not the underlying special-category data.
Lawful basis: the firm's legal obligation and ours in supporting it (Art. 6(1)(c)), and legitimate interests in preventing economic crime, which is the express purpose of the ECCTA regime. Because the identity documents and any facial-similarity check stay with our verification provider and never reach us, we do not process special-category data for this purpose. Our provider is responsible for that part of the journey and publishes its own notice.
3.4 Messages we send you
Firms use Cosavio to send service messages about a specific statutory obligation — for example, a reminder that your identity verification is outstanding. These are not marketing. Every message identifies the firm on whose behalf it is sent and how to stop receiving them.
WhatsApp messages are sent only using message templates approved in advance by Meta, as WhatsApp's rules require.
3.5 Website visitors and enquiries
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, firm, email and message you type into our contact form | Reply to you | Legitimate interests — responding to an enquiry you initiated |
| Bot-protection signals from Cloudflare Turnstile on our sign-up, sign-in and contact forms | Stop automated abuse and spam | Legitimate interests — security |
| Aggregate, cookieless usage statistics (page views, referrer, country, device type) | Understand which pages are useful | Legitimate interests — improving the site |
Our analytics do not use cookies, do not track you across websites, and do not build a profile of you. See our Cookie Policy.
4. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing. We use the following service providers ("subprocessors"):
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication for the product | EU (London and Ireland regions) |
| Vercel | Hosts and serves the website and application | US-headquartered, served via a global edge network |
| Resend | Sends product and reminder email | Sending region EU (eu-west-1); US-headquartered provider |
| yCloud | Sends WhatsApp reminder messages | Outside the UK and EEA |
| Certivus | Identity verification, including the hosted verification journey you are taken to | EU-resident infrastructure; its own subprocessors, including the provider of its verification journey, are listed in Certivus's privacy notice |
| Cloudflare | Bot and spam protection (Turnstile) | Global edge network |
| Plausible Analytics | Cookieless website statistics | EU |
| Railway | Runs our overnight Companies House data synchronisation | EU region |
| Stripe | Takes subscription payments. We never see or store your card details | US-headquartered, UK and EU entities |
Your product data is held in the EU (London and Ireland). Where a provider above processes personal data outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on adequacy where it applies.
We keep a data processing agreement with each provider. If you want to know which providers touch a particular piece of data, ask us at privacy@cosavio.com and we will tell you.
We may also disclose personal data where we are legally required to, or to establish or defend legal claims.
5. How long we keep it
We keep data only as long as we need it, and the periods below are the ones we work to.
| What | How long | Why |
|---|---|---|
| Identity-verification records and their evidence | 5 years after the firm's relationship with that client ends | Supports the firm's own record-keeping under the Money Laundering Regulations 2017. Deleting sooner would undercut a duty that sits on them. |
| Filing records and the audit trail | 6 years from the end of the relevant financial year | These are the record that something was done, and when. They are append-only by design. |
| Company, officer and PSC records | While the firm manages that company, then 12 months | So a firm that removes a company by mistake can get it back. |
| Firm user accounts | 12 months after the subscription ends | Lets you come back without losing your workspace. |
| Contact-form enquiries | 24 months | Long enough to pick up a conversation again. |
| Cookieless website statistics | Aggregate only, no personal data retained | Nothing to delete. |
Where we act as a processor, a firm can ask us to delete their data sooner and we will, unless we are legally required to keep it. Where the law requires us to keep something longer than the periods above, we keep it and no longer.
6. Your rights
Under UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; object to processing based on legitimate interests; data portability; and to withdraw consent where we rely on it (withdrawal is as easy as giving it).
To exercise any right, contact privacy@cosavio.com. We respond within one month, extendable by a further two months for complex requests, and we will tell you if we need the extension. There is no charge.
Where we act as a processor for a firm, we will pass your request to that firm and support them in answering it.
You can complain to the Information Commissioner's Office. The ICO is the UK supervisory authority for data protection: ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to resolve your concern first, but you do not have to come to us before going to the ICO.
7. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. An identity-verification result is returned by our provider and is acted on by a person at your firm. If that ever changes, we will update this section before it does, not after.
8. Security
Data is held in EU-region infrastructure. Access is restricted to the firm that manages the record, enforced both in our application and by database-level row-level security. Personal codes are never stored in readable form. Access to sensitive records is logged to an append-only trail.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, tell affected people directly. We keep a written breach-response procedure with a named owner.
9. Changes
We will update this page when our processing changes and revise the "last updated" date. Material changes will be notified to firm administrators.