Privacy Policy
Last updated: 8th April, 2026
Taxscio (operated by Altascio) is committed to protecting your personal data. This policy explains what information we collect, why we collect it, how it is used, and the rights you hold over your data. Please read it carefully before using our platform.
Information We Collect
When you use Taxscio, we collect information to provide, improve, and personalise our service. The categories of data we may collect include:
| Category | Examples | How Collected |
|---|---|---|
| Account Information | Firm name, contact name, email address, hashed password | On registration |
| Firm & Practice Data | CPA firm size, client volume, software stack, workflow preferences | Provided by you during onboarding |
| Client File Data | Uploaded documents, extracted data fields, pre-filing metadata | Uploaded directly by your firm |
| Technical Data | IP address, browser type, device identifiers, time zone | Automatically via your browser |
| Usage Data | Pages visited, features used, session duration, workflow interactions | Automatically via analytics |
| Integration Signals | Data exchanged with connected tax software or document sources | Via authorised integrations (read/write as permissioned) |
| Communications | Support messages, survey responses, feedback submitted | Provided directly by you |
We do not collect sensitive personal data beyond what is necessary for tax pre-filing workflows. We never access client file content beyond what you explicitly upload and authorise, and all integration access is limited strictly to the permissions you grant.
How We Use Your Information
We use the data we collect for the following purposes, each grounded in a lawful legal basis under applicable data protection law:
- To deliver and operate the Taxscio service — processing uploaded documents, automating data extraction, managing pre-filing workflows, and surfacing accuracy checks for your team. (Basis: performance of a contract.)
- To personalise your experience — adapting workflow templates, surfacing relevant checks, and prioritising tasks based on your firm's practice patterns. (Basis: legitimate interests.)
- To improve our platform — analysing aggregated and anonymised usage patterns to fix issues, improve automation accuracy, and guide product decisions. (Basis: legitimate interests.)
- To communicate with you — sending transactional emails (verification, notifications, status updates), product announcements, and, where opted in, marketing communications. (Basis: consent or legitimate interests.)
- To support integrations — exchanging data with connected tax software and document systems as authorised by your firm, solely to enable the workflow automations you have configured. (Basis: performance of a contract.)
- To meet legal obligations — retaining records where required by applicable law and responding to lawful requests from authorities. (Basis: legal obligation.)
We will never use your data or your clients' data to make fully automated decisions that produce legal or similarly significant effects without human review from your team.
Data Storage & Security
Your data is stored on secure, SOC 2-aligned cloud infrastructure. We implement industry-standard security practices, including:
- Encryption in transit — all data transmitted between your browser and our servers uses TLS 1.2 or higher.
- Encryption at rest — stored data, including client documents and extracted fields, is encrypted using AES-256.
- Access controls — access to personal and client data within Altascio is restricted on a strict need-to-know basis. All internal access is logged and audited regularly.
- Password hashing — passwords are never stored in plain text. We use bcrypt hashing with a unique salt per user account.
- Regular security assessments — we conduct periodic vulnerability scans and responsibly address reported security issues.
We retain your personal and client data for as long as your account is active or as needed to provide services. If you delete your account, we will remove your data within 30 days, except where retention is required by law or a legitimate business need such as fraud prevention.
Sharing Your Information
We do not sell your personal data or your clients' data. We may share your information only in the following limited circumstances:
- Service providers — trusted third-party companies that help us operate Taxscio, such as cloud hosting providers, email delivery services, and analytics tools. These providers process data solely on our instructions and are bound by data processing agreements.
- Integration partners — only the data fields you explicitly authorise are exchanged with connected tax software or document platforms. You control these permissions entirely from your account settings.
- Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. You will be notified in advance with the opportunity to withdraw consent.
- Legal requirements — we may disclose your data when required by applicable law, court order, or to protect the rights, property, or safety of Taxscio, our users, or the general public.
When we engage third-party processors, we carry out due diligence to ensure they provide sufficient guarantees around data protection in line with applicable data protection law.
Your Rights
Depending on your jurisdiction, you hold the following rights regarding your personal data. You may exercise these rights at any time by contacting us:
- Right of access — request a copy of the personal data we hold about you or your firm.
- Right to rectification — ask us to correct inaccurate or incomplete data without undue delay.
- Right to erasure — request deletion of your personal data (the "right to be forgotten"), subject to certain legal exceptions.
- Right to restriction of processing — ask us to limit how we process your data in specific circumstances.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another service.
- Right to object — object to processing based on legitimate interests or to direct marketing at any time.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email legal@taxscio.com. We will respond within 30 calendar days. We may need to verify your identity before processing your request. You also have the right to lodge a complaint with your local supervisory authority or data protection regulator at any time.
Cookies & Tracking
We use cookies and similar tracking technologies to operate and improve the Taxscio platform. Cookies are small text files stored on your device when you visit our site or use our application.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication sessions, security tokens, CSRF protection. Required for the platform to function. | Session / up to 30 days |
| Functional | Remembering your preferences such as workflow settings and UI state. | Up to 1 year |
| Analytics | Understanding how users navigate the platform via anonymised data. Helps us identify and fix issues. | Up to 2 years |
| Marketing | Measuring the effectiveness of our communications and campaigns. Set only with your explicit consent. | Up to 90 days |
You can manage or disable non-essential cookies through your browser settings. Disabling essential cookies may affect the functionality of Taxscio. We do not use cookies to build advertising profiles or sell tracking data to third-party advertisers.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how Altascio processes your personal data, please get in touch with our legal team:
This Privacy Policy may be updated periodically to reflect changes in our practices or applicable legal requirements. When we make significant changes, we will notify you via email or a prominent notice on the platform. The "Last updated" date at the top of this page will always reflect the most recent revision.