CGS ERP collects, uses, protects and shares information when you use our UK VAT management mobile and web services.
CGS ERP is designed for UK businesses and authorised users managing accounting records, VAT transactions, VAT returns and related communications with HM Revenue & Customs ("HMRC").
This policy applies to the CGS ERP mobile application, website and associated services.
The organisation that provides your account normally decides why and how business and employee information is used and is therefore the data controller for that information.
The operator of CGS ERP generally acts as its data processor and follows the organisation's documented instructions.
We do not intentionally request special-category personal information. Users should not enter such information unless it is necessary, lawful and authorised by their organisation.
We do not sell personal information. We do not use business VAT records for third-party advertising.
When an authorised user connects CGS ERP to HMRC, the user is redirected to HMRC to sign in and grant permission.
CGS ERP does not receive the user's HMRC password.
HMRC may provide access and refresh tokens, VAT obligations, return information, liabilities, payments and submission responses required to provide the requested functionality.
Tokens are used only to perform authorised HMRC operations and are stored with appropriate security controls.
Users or account administrators can disconnect the HMRC integration.
Depending on the circumstances, processing is based on performance of a contract, compliance with legal obligations, legitimate interests in operating and securing the service, or consent where legally required.
Organisations using CGS ERP are responsible for establishing their own lawful basis for information they enter into the service.
Information may be shared with:
Service providers receive only the information reasonably necessary for their function and may not use it for unrelated purposes.
Information is retained for as long as the account is active and as needed to provide the service.
Business, VAT, accounting, security and audit records may be retained longer where required by UK tax law, regulatory obligations, dispute resolution, fraud prevention, backups or contractual commitments.
Account deletion requests should normally be made through the organisation that controls the account.
We use proportionate technical and organisational safeguards, including access controls, authentication, encrypted network transport, permission separation, logging and operational monitoring.
No internet service can guarantee absolute security. Users must protect their credentials, use secure devices and promptly report suspected unauthorised access.
Subject to applicable law, you may have rights to access, correct, erase or restrict personal information; object to certain processing; receive portable information; and complain to the UK Information Commissioner's Office.
Where your organisation controls the information, submit your request to that organisation first.
The mobile app uses network access to communicate with CGS ERP and HMRC-connected services.
Depending on enabled features, the application may request access to files, images or the camera only when needed to upload business documents or capture permitted content.
Permission can be denied or withdrawn in device settings, although the related feature may then be unavailable.
The app does not use precise location, contacts, microphone or advertising identifiers unless a future feature clearly requests them and this policy is updated before use.
Where a service provider processes information outside the United Kingdom, appropriate safeguards will be used as required by UK data protection law.
CGS ERP is a business service and is not directed to children. Users must be authorised by their organisation and legally capable of using the service.
We may update this policy to reflect legal, technical or service changes. The revised version will be published here with a new "Last updated" date.
Material changes may also be communicated through the service or the account contact.
For privacy questions or requests, contact your organisation's account administrator or use the support contact supplied with your CGS ERP account or service agreement.
Please do not send passwords, authentication tokens or unnecessary financial records in a support request.