1. Who we are
Valla CIS Limited (“Valla”, “we”, “us”) provides the Valla CIS platform (the “Platform”) — software that helps construction businesses and their advisers manage Construction Industry Scheme (CIS) compliance, subcontractor onboarding, invoicing and payments.
| Detail | Detail |
|---|---|
| Company | Valla CIS Limited, registered in England and Wales |
| Company number | 17216592 |
| Registered office | Neville House, 66 High Street, Henley-in-Arden, England, B95 5BX |
| ICO registration number | ZC231862 |
| Privacy contact | privacy@vallacis.co.uk |
| Postal | Data Protection, Valla CIS Limited, Neville House, 66 High Street, Henley-in-Arden, England, B95 5BX |
This policy is written under the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003.
2. Which parts of this policy apply to you
Valla is used by three kinds of business, and by people who are invited into it by someone else. Where you sit changes what applies:
- You signed up yourself — as a subcontractor (Solo), a contractor (Hub), or an accountant. All of this policy applies to you.
- A contractor added you — a contractor entered your details to onboard you before you had any account with us. Section 5 is written for you, and explains where your data came from and what to do about it.
- You only visited our website — sections 1, 12, 13, 15 and 17 apply.
Our role: when we are the controller, and when we are not
- We are the controller for account, sign-in, security, billing and Platform-operation data; for our website; and for the records a Solo user creates on their own, outside any connection with a contractor.
- We are a processor for the records a Hub customer creates about the subcontractors it engages — right-to-work evidence, signed contracts, employment-status determinations and CIS records. The contractor decides why and how those are used; we act on its instructions under our Data Processing Agreement. If you want to exercise rights over that data, section 5 explains who to ask.
Because CIS is inherently two-sided, some records — an invoice, a payment, a statement — are shared between a contractor and a subcontractor and we are controller of our own copy for the purposes of running the Platform. Section 8 explains what that means in practice.
3. What we collect
Account and sign-in. Your name, email address, a hashed password, and multi-factor authentication data. MFA secrets and backup codes are stored hashed or encrypted, never in the clear.
Business and tax identifiers. Unique Taxpayer Reference (UTR), National Insurance number, Companies House number, CIS/Accounts Office reference, PAYE reference, VAT registration number and date, trading name. National Insurance numbers are held as a one-way hash for matching, plus separately encrypted for lawful use, and are shown masked in the interface.
Right-to-work and identity data. Where a contractor onboards you: document type (passport, biometric residence permit or share code), the identity documents themselves, date of birth, immigration permission type and expiry, and the reference of the check performed by our identity provider. This is encrypted and held on an append-only basis so it cannot be silently altered.
Employment-status questionnaire. Your answers and the resulting determination. The questionnaire is input; the contractor makes the determination, not us and not you.
Financial and transactional. Invoices and invoice lines (gross, labour, materials, VAT, CIS deductions), payments and payment runs, ledger entries, statements, expenses, and CIS return records. Monetary values are held in whole pence.
Bank data. Where you connect a business bank account: the institution, an account reference, and statement lines — date, amount, narrative and counterparty reference. We use this only to match and evidence payments against invoices (see section 4). The connection is read-only: it cannot move money, and you approve it with your own bank, so we never receive your banking credentials.
Contract records. Signed agreements, signature audit trails, document hashes and timestamps.
Authentication tokens. Encrypted credentials for services you connect, such as HMRC. Raw tokens are never stored.
Usage, audit and security. An append-only audit trail of significant actions, product-analytics events, security logs, IP address and device/browser information.
HMRC fraud prevention data. When you use a feature that submits to HMRC, HMRC requires us by law to send technical details about the device making the submission. This includes your device’s local and public IP addresses, screen size and resolution, browser window size, timezone, installed browser plugins and user-agent string. We collect this only for HMRC submissions, we send it to HMRC, and we do not use it for anything else. HMRC’s own guidance on this is published on its developer hub.
Website. If you join our waitlist or contact us, your name, email and stated role.
4. Why we use it, and our lawful basis
| What we do | Why | Lawful basis |
|---|---|---|
| Run your account, authenticate you, provide invoicing, CIS calculation, statements and reporting | To deliver what you signed up for | Performance of a contract |
| Verify subcontractors with HMRC and obtain the correct deduction rate | Required to operate CIS correctly | Legal obligation; contract |
| Right-to-work checks | To help our customer meet its duty under immigration law | Legal obligation; and, for the identity documents themselves, the substantial public interest condition for preventing unlawful acts (DPA 2018 Sch. 1 Pt. 2) |
| Employment-status questionnaire | So the contractor can make and evidence a status determination | Contract; legitimate interests of the contractor in evidencing its position |
| Prepare and, where you instruct us, submit CIS and VAT information to HMRC | Required to meet your CIS and VAT obligations | Legal obligation; contract |
| Send HMRC fraud prevention headers | HMRC requires it as a condition of using its APIs | Legal obligation |
| Electronic signature of onboarding agreements | To form and evidence the contract between you and your counterparty | Contract |
| Match payments to invoices from your bank statement data | So invoices can be marked paid and evidenced without re-keying | Contract; plus your explicit consent to the bank connection itself, which you give at your bank and can withdraw at any time |
| Classify invoice lines for CIS and VAT treatment | To give you a correct starting point you then confirm | Legitimate interests — accurate tax records |
| Security, MFA, lockout, audit logging, fraud prevention | To keep accounts and financial data safe | Legitimate interests; legal obligation |
| Billing and subscription management | To take payment | Contract |
| Service emails — verification, invitations, operational notices | To operate the Platform | Contract; legitimate interests |
| Waitlist and product updates you ask for | Because you asked | Consent |
Where we rely on legitimate interests we have balanced our interest against your rights and you can object at any time (section 12). Where we rely on consent you can withdraw it at any time.
If you do not provide certain data. We would rather be blunt about this than have you find out later:
- Without a UTR and a successful HMRC verification, the law requires deduction at the higher 30% rate rather than 20%, or the contractor cannot pay you at all.
- Without a completed right-to-work check, a contractor cannot lawfully engage you and the Platform will not let the onboarding proceed.
- Without an employment-status questionnaire and a signed contract, you cannot invoice that contractor through the Platform.
These are consequences of the law and of your contractor’s process, not choices we make about you individually.
5. If a contractor added you to Valla
If you received an invitation to Valla, a contractor entered some of your details before you had an account. The law requires us to tell you where that came from.
Where we got your data. From the contractor or agency that is engaging you — the business named in your invitation. Typically your name, email address, phone number and sometimes your UTR or National Insurance number. Everything else comes from you, or from the checks you complete.
Who is responsible for it. For onboarding records — right-to-work evidence, your status determination, your signed contract and your CIS records — that contractor is the data controller and we act on its instructions. If you want to see, correct or object to that data, ask the contractor first. If you contact us instead we will help you reach the right party and will tell the contractor.
What we do with it. We use it to create your account, run the onboarding steps that contractor requires, and operate the Platform. We do not sell it, and we do not use it to market to you.
Your rights are the same as everyone else’s — see section 12. You can also complain to us (section 13) or to the ICO.
6. Automated decisions
The Platform automates parts of onboarding and classification. Some of these decisions have real consequences for you, so here is exactly how they work.
What is automated. Onboarding runs as a sequence of gates, in this order: HMRC verification, right to work, employment-status questionnaire, contract signature. Until all four are complete for a given contractor, the Platform will not let you invoice that contractor through it. The deduction rate applied to your invoices is the rate HMRC returns, or the statutory 30% default where no verification exists.
What is not automated. A person decides the things that require judgement. Your employment status is determined by the contractor, not by the questionnaire and not by us — the questionnaire is evidence the contractor considers. The VAT treatment of a site is set by the contractor. Whether to engage you at all is the contractor’s decision.
Your rights over automated decisions. Under Articles 22A–22D of the UK GDPR you are entitled, for any significant decision made about you by automated means, to:
- be told that the decision was made and on what basis;
- make representations about it;
- obtain human intervention from us or from the contractor, as appropriate; and
- contest the decision.
To use any of these, contact us at privacy@vallacis.co.uk or use the complaints route in section 13, and we will route it to the right decision-maker and respond. We do not make significant automated decisions using special category data.
7. Artificial intelligence
We use software, including AI, to read invoice documents and suggest how lines should be classified for CIS and VAT.
- The AI supplies facts; it does not make the decision. Its output is checked against a fixed schema, and a separate, inspectable rules engine produces the classification. That logic can be explained to you.
- Where a fact that would change the answer is missing, the item goes to a person. It is not guessed.
- The Platform works with AI switched off. It is an enhancement, not a dependency.
- At present no personal data is sent to any external AI provider. Extraction runs inside our own environment. If that changes we will update this policy and tell you before it takes effect, and personal identifiers will be removed or replaced with tokens before anything leaves our environment.
- We do not use your data to train AI models, and our agreements with any AI provider will prohibit them from doing so.
8. What your counterparty can see
CIS is two-sided, so a contractor and a subcontractor working together see the same invoice, statement, payment and ledger records. That is how the Platform works and you agree to it when you connect to a counterparty.
- A contractor sees the onboarding evidence it required, and the invoices and payments between you.
- A subcontractor sees the invoices, statements and payments between them and that contractor.
- Where you appoint an accountant, the people it authorises can see your data only after you grant access, and only until you revoke it. You control that, and can revoke it at any time.
- Correcting a shared record may be visible to your counterparty, because it is the same record.
- We do not show a contractor your data relating to any other contractor.
9. Who else your data goes to
We use the following organisations to run the Platform. We have data-processing agreements with each of our processors.
| Who | What for | What they get |
|---|---|---|
| Amazon Web Services | Hosting and storage, London region (eu-west-2) | All Platform data, at rest and encrypted |
| Finexer Ltd | Open banking — read-only retrieval of your bank statement data | The bank connection itself. Finexer is authorised by the Financial Conduct Authority as an authorised payment institution (firm reference 925695). Its hosting and storage are in Ireland (EEA) — see section 10 |
| TrustID | Digital identity and right-to-work checks | Identity document and check data |
| Stripe | Subscription billing on the web | Customer and subscription references. We never see or store your card number |
| Apple | Subscription billing for purchases made inside our iOS app | Apple handles the purchase under its own terms and tells us only that a subscription is active |
| Resend | Sending service emails | Recipient email address and message content |
| Vercel | Hosting our marketing website | Website traffic data |
| Supabase | Waitlist storage for the marketing website | Name, email, role |
We also send data to the following, who are not our processors — they decide their own purposes and have their own duties to you:
- HMRC — subcontractor verification, VAT number checks, and CIS or VAT information you instruct us to submit, together with the fraud prevention data described in section 3.
- Companies House — we look up public register data about limited-company subcontractors.
Our electronic signature software (DocuSeal) runs on our own infrastructure in London, not as a third-party service, so your signed documents do not leave our environment for signing.
How the bank connection works. Connecting an account is your choice, and you can use the Platform without it. When you connect, you are taken to your own bank to approve access — you never give us your banking credentials. Our open banking provider, Finexer Ltd, is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 (firm reference 925695), and Valla acts as its agent for this service; you can check both on the FCA register at register.fca.org.uk. Access is read-only, so it cannot move money or change anything at your bank. Your approval lasts 90 days and we will ask you to reconfirm it. You can withdraw it at any time, in the Platform or through your bank, and we will stop retrieving new data immediately.
We may also disclose data where the law requires it, to regulators, to our professional advisers, or in connection with a sale or reorganisation of our business, with appropriate safeguards.
10. Where your data is held
Your Platform data is hosted in the United Kingdom (AWS London, eu-west-2), and that is where it stays. Once your bank data reaches us, it is stored in that same UK environment.
The bank connection itself runs through Finexer Ltd, a UK company. Finexer’s own application hosting and customer data storage, including bank transaction data, are located in Microsoft Azure’s North Europe region in Ireland, within the EEA. Transfers to the EEA are covered by the UK adequacy regulations, so your data has the same legal protection on that leg as it does here.
A small number of the services above operate outside the UK. Where personal data is transferred abroad we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment applying the data protection test in the Data (Use and Access) Act 2025. You can ask us which mechanism applies to a particular recipient.
11. How long we keep it
| What | How long |
|---|---|
| CIS, VAT and other tax records | At least 6 years from the end of the tax year they relate to, as UK tax law requires |
| Right-to-work evidence | For the duration of the engagement and 2 years after it ends, as the Home Office requires for a statutory excuse |
| Signed contracts and signature audit trails | 6 years from the end of the contract |
| Audit trail of actions in the Platform | 7 years |
| Account and sign-in data | For as long as your account is open, then 12 months |
| Bank statement data used to evidence a payment | 6 years |
| Billing records | 6 years |
| Security logs | 12 months |
| Website waitlist and enquiries | 24 months, or until you ask us to remove you |
An important limit, stated honestly. Our ledger and audit records are append-only: they are built so that entries cannot be edited or deleted, and corrections are made by adding a new linked entry while the original remains visible. This is deliberate — it is what makes the records trustworthy to HMRC and to your counterparty. It means that for those records we cannot perform erasure, and we rely on the legal-obligation exemption in Article 17(3)(b) UK GDPR. Where we cannot erase, we will restrict processing instead. See section 12.
12. Your rights
You have the right to: be informed; get a copy of your data; have inaccurate data corrected; have data erased; restrict or object to processing; portability; and rights in relation to automated decisions (section 6). You can withdraw consent where we rely on it.
To exercise a right, email privacy@vallacis.co.uk. We will respond within one month. If your request is complex we may extend that by up to two further months and will tell you why.
Two honest caveats:
- Erasure is limited where we must keep records to meet a legal obligation, and where our ledger is append-only (section 11). In those cases we will restrict processing rather than delete, and we will tell you which parts we could not erase and why.
- If a contractor added you, for its onboarding records that contractor is the controller and the request belongs with it. We will help you get to the right party — see section 5.
13. How to complain
Complain to us first. You have the right to complain to us directly about how we have handled your personal data, and we have a duty to deal with it properly.
- Use the complaints form at vallacis.co.uk/privacy/complaint, or email privacy@vallacis.co.uk with “Data protection complaint” in the subject.
- We will acknowledge your complaint within 30 days.
- We will investigate without undue delay and tell you the outcome.
Complain to the regulator. You can also complain to the Information Commissioner’s Office at any time — ico.org.uk, or 0303 123 1113. We would appreciate the chance to put things right first, but you do not have to come to us before going to the ICO.
14. Security
We protect your data with, among other measures:
- encryption in transit (TLS 1.3) and at rest (AES-256);
- separate field-level encryption for the most sensitive identifiers — tax references, National Insurance numbers, bank details and identity documents;
- database row-level security so one customer’s data cannot be reached from another’s account;
- mandatory multi-factor authentication on every account;
- brute-force lockout, an append-only audit trail, and internal controls that keep personal identifiers out of our analytics logs.
No system is perfectly secure. If a personal data breach occurs we will notify the ICO and, where the law requires, you, within the statutory timeframes.
16. Age
The Platform is for business use. You must be 16 or over to hold an account, which reflects the minimum age at which a person can lawfully be engaged as a subcontractor in construction. Where a user is under 18 we do not treat them differently in the Platform, but contractors remain responsible for any additional duties they owe to young workers.
17. Changes to this policy
We may update this policy. We will post the new version here with a new date and version number. For changes that materially affect you we will tell you before they take effect.
Version 1.0 · Effective 7 September 2026 · Valla CIS Limited
Last updated 7 September 2026.