Skip to content

Legal

Privacy Policy

Valla CIS Limited · Version 1.0 · Effective 7 September 2026

This policy explains what we do with personal data when you use Valla CIS, and what your rights are. We have tried to write it in plain English. Where the law makes us do something you might not expect, we say so rather than burying it.

1. Who we are

Valla CIS Limited (“Valla”, “we”, “us”) provides the Valla CIS platform (the “Platform”) — software that helps construction businesses and their advisers manage Construction Industry Scheme (CIS) compliance, subcontractor onboarding, invoicing and payments.

DetailDetail
CompanyValla CIS Limited, registered in England and Wales
Company number17216592
Registered officeNeville House, 66 High Street, Henley-in-Arden, England, B95 5BX
ICO registration numberZC231862
Privacy contactprivacy@vallacis.co.uk
PostalData Protection, Valla CIS Limited, Neville House, 66 High Street, Henley-in-Arden, England, B95 5BX

This policy is written under the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003.

2. Which parts of this policy apply to you

Valla is used by three kinds of business, and by people who are invited into it by someone else. Where you sit changes what applies:

  • You signed up yourself — as a subcontractor (Solo), a contractor (Hub), or an accountant. All of this policy applies to you.
  • A contractor added you — a contractor entered your details to onboard you before you had any account with us. Section 5 is written for you, and explains where your data came from and what to do about it.
  • You only visited our website — sections 1, 12, 13, 15 and 17 apply.

Our role: when we are the controller, and when we are not

  • We are the controller for account, sign-in, security, billing and Platform-operation data; for our website; and for the records a Solo user creates on their own, outside any connection with a contractor.
  • We are a processor for the records a Hub customer creates about the subcontractors it engages — right-to-work evidence, signed contracts, employment-status determinations and CIS records. The contractor decides why and how those are used; we act on its instructions under our Data Processing Agreement. If you want to exercise rights over that data, section 5 explains who to ask.

Because CIS is inherently two-sided, some records — an invoice, a payment, a statement — are shared between a contractor and a subcontractor and we are controller of our own copy for the purposes of running the Platform. Section 8 explains what that means in practice.

3. What we collect

Account and sign-in. Your name, email address, a hashed password, and multi-factor authentication data. MFA secrets and backup codes are stored hashed or encrypted, never in the clear.

Business and tax identifiers. Unique Taxpayer Reference (UTR), National Insurance number, Companies House number, CIS/Accounts Office reference, PAYE reference, VAT registration number and date, trading name. National Insurance numbers are held as a one-way hash for matching, plus separately encrypted for lawful use, and are shown masked in the interface.

Right-to-work and identity data. Where a contractor onboards you: document type (passport, biometric residence permit or share code), the identity documents themselves, date of birth, immigration permission type and expiry, and the reference of the check performed by our identity provider. This is encrypted and held on an append-only basis so it cannot be silently altered.

Employment-status questionnaire. Your answers and the resulting determination. The questionnaire is input; the contractor makes the determination, not us and not you.

Financial and transactional. Invoices and invoice lines (gross, labour, materials, VAT, CIS deductions), payments and payment runs, ledger entries, statements, expenses, and CIS return records. Monetary values are held in whole pence.

Bank data. Where you connect a business bank account: the institution, an account reference, and statement lines — date, amount, narrative and counterparty reference. We use this only to match and evidence payments against invoices (see section 4). The connection is read-only: it cannot move money, and you approve it with your own bank, so we never receive your banking credentials.

Contract records. Signed agreements, signature audit trails, document hashes and timestamps.

Authentication tokens. Encrypted credentials for services you connect, such as HMRC. Raw tokens are never stored.

Usage, audit and security. An append-only audit trail of significant actions, product-analytics events, security logs, IP address and device/browser information.

HMRC fraud prevention data. When you use a feature that submits to HMRC, HMRC requires us by law to send technical details about the device making the submission. This includes your device’s local and public IP addresses, screen size and resolution, browser window size, timezone, installed browser plugins and user-agent string. We collect this only for HMRC submissions, we send it to HMRC, and we do not use it for anything else. HMRC’s own guidance on this is published on its developer hub.

Website. If you join our waitlist or contact us, your name, email and stated role.

4. Why we use it, and our lawful basis

What we doWhyLawful basis
Run your account, authenticate you, provide invoicing, CIS calculation, statements and reportingTo deliver what you signed up forPerformance of a contract
Verify subcontractors with HMRC and obtain the correct deduction rateRequired to operate CIS correctlyLegal obligation; contract
Right-to-work checksTo help our customer meet its duty under immigration lawLegal obligation; and, for the identity documents themselves, the substantial public interest condition for preventing unlawful acts (DPA 2018 Sch. 1 Pt. 2)
Employment-status questionnaireSo the contractor can make and evidence a status determinationContract; legitimate interests of the contractor in evidencing its position
Prepare and, where you instruct us, submit CIS and VAT information to HMRCRequired to meet your CIS and VAT obligationsLegal obligation; contract
Send HMRC fraud prevention headersHMRC requires it as a condition of using its APIsLegal obligation
Electronic signature of onboarding agreementsTo form and evidence the contract between you and your counterpartyContract
Match payments to invoices from your bank statement dataSo invoices can be marked paid and evidenced without re-keyingContract; plus your explicit consent to the bank connection itself, which you give at your bank and can withdraw at any time
Classify invoice lines for CIS and VAT treatmentTo give you a correct starting point you then confirmLegitimate interests — accurate tax records
Security, MFA, lockout, audit logging, fraud preventionTo keep accounts and financial data safeLegitimate interests; legal obligation
Billing and subscription managementTo take paymentContract
Service emails — verification, invitations, operational noticesTo operate the PlatformContract; legitimate interests
Waitlist and product updates you ask forBecause you askedConsent

Where we rely on legitimate interests we have balanced our interest against your rights and you can object at any time (section 12). Where we rely on consent you can withdraw it at any time.

If you do not provide certain data. We would rather be blunt about this than have you find out later:

  • Without a UTR and a successful HMRC verification, the law requires deduction at the higher 30% rate rather than 20%, or the contractor cannot pay you at all.
  • Without a completed right-to-work check, a contractor cannot lawfully engage you and the Platform will not let the onboarding proceed.
  • Without an employment-status questionnaire and a signed contract, you cannot invoice that contractor through the Platform.

These are consequences of the law and of your contractor’s process, not choices we make about you individually.

5. If a contractor added you to Valla

If you received an invitation to Valla, a contractor entered some of your details before you had an account. The law requires us to tell you where that came from.

Where we got your data. From the contractor or agency that is engaging you — the business named in your invitation. Typically your name, email address, phone number and sometimes your UTR or National Insurance number. Everything else comes from you, or from the checks you complete.

Who is responsible for it. For onboarding records — right-to-work evidence, your status determination, your signed contract and your CIS records — that contractor is the data controller and we act on its instructions. If you want to see, correct or object to that data, ask the contractor first. If you contact us instead we will help you reach the right party and will tell the contractor.

What we do with it. We use it to create your account, run the onboarding steps that contractor requires, and operate the Platform. We do not sell it, and we do not use it to market to you.

Your rights are the same as everyone else’s — see section 12. You can also complain to us (section 13) or to the ICO.

6. Automated decisions

The Platform automates parts of onboarding and classification. Some of these decisions have real consequences for you, so here is exactly how they work.

What is automated. Onboarding runs as a sequence of gates, in this order: HMRC verification, right to work, employment-status questionnaire, contract signature. Until all four are complete for a given contractor, the Platform will not let you invoice that contractor through it. The deduction rate applied to your invoices is the rate HMRC returns, or the statutory 30% default where no verification exists.

What is not automated. A person decides the things that require judgement. Your employment status is determined by the contractor, not by the questionnaire and not by us — the questionnaire is evidence the contractor considers. The VAT treatment of a site is set by the contractor. Whether to engage you at all is the contractor’s decision.

Your rights over automated decisions. Under Articles 22A–22D of the UK GDPR you are entitled, for any significant decision made about you by automated means, to:

  • be told that the decision was made and on what basis;
  • make representations about it;
  • obtain human intervention from us or from the contractor, as appropriate; and
  • contest the decision.

To use any of these, contact us at privacy@vallacis.co.uk or use the complaints route in section 13, and we will route it to the right decision-maker and respond. We do not make significant automated decisions using special category data.

7. Artificial intelligence

We use software, including AI, to read invoice documents and suggest how lines should be classified for CIS and VAT.

  • The AI supplies facts; it does not make the decision. Its output is checked against a fixed schema, and a separate, inspectable rules engine produces the classification. That logic can be explained to you.
  • Where a fact that would change the answer is missing, the item goes to a person. It is not guessed.
  • The Platform works with AI switched off. It is an enhancement, not a dependency.
  • At present no personal data is sent to any external AI provider. Extraction runs inside our own environment. If that changes we will update this policy and tell you before it takes effect, and personal identifiers will be removed or replaced with tokens before anything leaves our environment.
  • We do not use your data to train AI models, and our agreements with any AI provider will prohibit them from doing so.

8. What your counterparty can see

CIS is two-sided, so a contractor and a subcontractor working together see the same invoice, statement, payment and ledger records. That is how the Platform works and you agree to it when you connect to a counterparty.

  • A contractor sees the onboarding evidence it required, and the invoices and payments between you.
  • A subcontractor sees the invoices, statements and payments between them and that contractor.
  • Where you appoint an accountant, the people it authorises can see your data only after you grant access, and only until you revoke it. You control that, and can revoke it at any time.
  • Correcting a shared record may be visible to your counterparty, because it is the same record.
  • We do not show a contractor your data relating to any other contractor.

9. Who else your data goes to

We use the following organisations to run the Platform. We have data-processing agreements with each of our processors.

WhoWhat forWhat they get
Amazon Web ServicesHosting and storage, London region (eu-west-2)All Platform data, at rest and encrypted
Finexer LtdOpen banking — read-only retrieval of your bank statement dataThe bank connection itself. Finexer is authorised by the Financial Conduct Authority as an authorised payment institution (firm reference 925695). Its hosting and storage are in Ireland (EEA) — see section 10
TrustIDDigital identity and right-to-work checksIdentity document and check data
StripeSubscription billing on the webCustomer and subscription references. We never see or store your card number
AppleSubscription billing for purchases made inside our iOS appApple handles the purchase under its own terms and tells us only that a subscription is active
ResendSending service emailsRecipient email address and message content
VercelHosting our marketing websiteWebsite traffic data
SupabaseWaitlist storage for the marketing websiteName, email, role

We also send data to the following, who are not our processors — they decide their own purposes and have their own duties to you:

  • HMRC — subcontractor verification, VAT number checks, and CIS or VAT information you instruct us to submit, together with the fraud prevention data described in section 3.
  • Companies House — we look up public register data about limited-company subcontractors.

Our electronic signature software (DocuSeal) runs on our own infrastructure in London, not as a third-party service, so your signed documents do not leave our environment for signing.

How the bank connection works. Connecting an account is your choice, and you can use the Platform without it. When you connect, you are taken to your own bank to approve access — you never give us your banking credentials. Our open banking provider, Finexer Ltd, is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 (firm reference 925695), and Valla acts as its agent for this service; you can check both on the FCA register at register.fca.org.uk. Access is read-only, so it cannot move money or change anything at your bank. Your approval lasts 90 days and we will ask you to reconfirm it. You can withdraw it at any time, in the Platform or through your bank, and we will stop retrieving new data immediately.

We may also disclose data where the law requires it, to regulators, to our professional advisers, or in connection with a sale or reorganisation of our business, with appropriate safeguards.

10. Where your data is held

Your Platform data is hosted in the United Kingdom (AWS London, eu-west-2), and that is where it stays. Once your bank data reaches us, it is stored in that same UK environment.

The bank connection itself runs through Finexer Ltd, a UK company. Finexer’s own application hosting and customer data storage, including bank transaction data, are located in Microsoft Azure’s North Europe region in Ireland, within the EEA. Transfers to the EEA are covered by the UK adequacy regulations, so your data has the same legal protection on that leg as it does here.

A small number of the services above operate outside the UK. Where personal data is transferred abroad we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment applying the data protection test in the Data (Use and Access) Act 2025. You can ask us which mechanism applies to a particular recipient.

11. How long we keep it

WhatHow long
CIS, VAT and other tax recordsAt least 6 years from the end of the tax year they relate to, as UK tax law requires
Right-to-work evidenceFor the duration of the engagement and 2 years after it ends, as the Home Office requires for a statutory excuse
Signed contracts and signature audit trails6 years from the end of the contract
Audit trail of actions in the Platform7 years
Account and sign-in dataFor as long as your account is open, then 12 months
Bank statement data used to evidence a payment6 years
Billing records6 years
Security logs12 months
Website waitlist and enquiries24 months, or until you ask us to remove you

An important limit, stated honestly. Our ledger and audit records are append-only: they are built so that entries cannot be edited or deleted, and corrections are made by adding a new linked entry while the original remains visible. This is deliberate — it is what makes the records trustworthy to HMRC and to your counterparty. It means that for those records we cannot perform erasure, and we rely on the legal-obligation exemption in Article 17(3)(b) UK GDPR. Where we cannot erase, we will restrict processing instead. See section 12.

12. Your rights

You have the right to: be informed; get a copy of your data; have inaccurate data corrected; have data erased; restrict or object to processing; portability; and rights in relation to automated decisions (section 6). You can withdraw consent where we rely on it.

To exercise a right, email privacy@vallacis.co.uk. We will respond within one month. If your request is complex we may extend that by up to two further months and will tell you why.

Two honest caveats:

  • Erasure is limited where we must keep records to meet a legal obligation, and where our ledger is append-only (section 11). In those cases we will restrict processing rather than delete, and we will tell you which parts we could not erase and why.
  • If a contractor added you, for its onboarding records that contractor is the controller and the request belongs with it. We will help you get to the right party — see section 5.

13. How to complain

Complain to us first. You have the right to complain to us directly about how we have handled your personal data, and we have a duty to deal with it properly.

Complain to the regulator. You can also complain to the Information Commissioner’s Office at any time — ico.org.uk, or 0303 123 1113. We would appreciate the chance to put things right first, but you do not have to come to us before going to the ICO.

14. Security

We protect your data with, among other measures:

  • encryption in transit (TLS 1.3) and at rest (AES-256);
  • separate field-level encryption for the most sensitive identifiers — tax references, National Insurance numbers, bank details and identity documents;
  • database row-level security so one customer’s data cannot be reached from another’s account;
  • mandatory multi-factor authentication on every account;
  • brute-force lockout, an append-only audit trail, and internal controls that keep personal identifiers out of our analytics logs.

No system is perfectly secure. If a personal data breach occurs we will notify the ICO and, where the law requires, you, within the statutory timeframes.

15. Cookies

We use a small number of cookies that are strictly necessary or functional. We do not use advertising or third-party tracking cookies in the Platform.

CookieWhat it doesTypeKept for
cis_sessionKeeps you signed inStrictly necessaryYour session
cis_mfa_challengeCompletes multi-factor sign-inStrictly necessaryAbout 10 minutes
cis_active_entityRemembers which business you are viewingFunctional7 days
cis_capabilityRemembers your active roleFunctional7 days

The first two are marked httpOnly, meaning page scripts cannot read them.

Strictly necessary cookies do not require your consent. We do not currently use analytics cookies on our marketing website. If we introduce them, we would rely on the statistical exception introduced by the Data (Use and Access) Act 2025: the data would be used only to understand how the site is used so we can improve it, it would not be shared for any other purpose and it would never be used for advertising. We would update this policy and provide a way to opt out before any such cookie was set.

16. Age

The Platform is for business use. You must be 16 or over to hold an account, which reflects the minimum age at which a person can lawfully be engaged as a subcontractor in construction. Where a user is under 18 we do not treat them differently in the Platform, but contractors remain responsible for any additional duties they owe to young workers.

17. Changes to this policy

We may update this policy. We will post the new version here with a new date and version number. For changes that materially affect you we will tell you before they take effect.

Version 1.0 · Effective 7 September 2026 · Valla CIS Limited

Last updated 7 September 2026.