KubX

KubX — Privacy

Privacy policy

Last updated: July 2026

Who we are

KubX is the trading name of Kuberax Ltd (company number 16267827), an accountancy practice registered in England and Wales. We are the data controller for the personal information described here. Contact: hello@kubx.co.uk.

What we collect and why

  • Quote and onboarding details — your name, email, phone, business details and the services you select in our fee calculator. We use these to prepare your quote, engagement letter and client record.
  • Identity verification data — as an HMRC-supervised firm we are legally required to verify your identity under the Money Laundering Regulations before acting for you. Records are kept for five years after our engagement ends, as the law requires.
  • Portal content — documents you upload and messages you send through the client portal, used solely to deliver our services to you.
  • Billing data — invoicing and payment status, processed through our accounting and payment providers.

Who processes it for us

We use a small number of service providers to run KubX: Supabase (secure database, login and file storage), Xero (invoicing and accounting), GoCardless (Direct Debit payments) and Resend (sending you emails on our behalf, such as document and message notifications). If you operate a limited company or partnership, we also look up your company’s public record at Companies House to keep statutory dates up to date. Each processes your data only on our instructions. We do not sell your data or use it for advertising.

How long we keep it

Client records are kept for the duration of our engagement and for six years afterwards, in line with professional and tax record-keeping requirements. Anti-money-laundering records are kept for five years after the engagement ends. Quote enquiries that do not become clients are deleted within twelve months.

Your rights

You can ask for a copy of your data, ask us to correct it, and — where the law does not require us to keep it — ask us to delete it. You can complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we handle your data.

Security

Portal access requires a password and a second factor (authenticator app). Documents and messages are stored encrypted at rest, and each client can only access their own records. Where we ask you to approve a document we have shared with you (for example, a set of accounts before filing), we record the date and the IP address your approval was made from as proof of sign-off.