Legal · Your data

Privacy Policy

FiscalGeek helps cross-border sellers run payments and VAT as one clean stack. That work touches sensitive numbers. This policy says, in plain terms, what we collect and how we guard it. No fine print. No surprises.

Last updated
25 June 2026
Applies to
fiscalgeek.com and every engagement
Standards
GDPR · PCI DSS aligned

What we collect

Only the data the work needs

We are advisors, not a data business. We gather a small set of details. Each one has a clear job and a clear legal basis.

Contact details

Your name, work email, and company when you book a call or send a message. We use it to reply and scope work.

Legal basis: your consent and our talks before a contract.

Engagement records

Notes, files, and figures you share during a payments or VAT project. We hold them only to do the agreed work.

Legal basis: the contract we sign with you.

Site analytics

Privacy-first, aggregate page metrics with no cross-site tracking. It shows which guides are read, never who read them.

Legal basis: our fair interest in a useful site.

Cookie choices

Your consent answer is stored so the banner stays quiet. We set no marketing or ad cookies on this site.

Legal basis: your consent, which you can change anytime.

Your rights

You stay in control

Under the GDPR you hold real rights over your data. We honour each one fast. To use any of them, email [email protected].

  • Access Ask for a copy of the data we hold on you.
  • Rectify Have us fix anything wrong or out of date.
  • Erase Request deletion once we no longer need it.
  • Object Tell us to stop a use you do not accept.
  • Portability Receive your data in a portable file.
  • Complain Raise a concern with your local regulator.

How we handle it

The life of your data, end to end

We treat your records the way we treat a VAT filing. Careful at every step. Here is the path your data takes with us.

  1. Collected with purpose

    We ask only for what a payments or VAT engagement needs. No idle data hoarding.

  2. Secured in transit and at rest

    Traffic is encrypted. Files sit in access-controlled stores. We hold PCI DSS and GDPR-aligned practices.

  3. Retained only as required

    Tax records are kept for the legal window. Everything else is cleared once the work is closed.

  4. Deleted on request

    Email us and we remove your data, unless a law makes us keep a record longer.

Questions?

Talk to a real person about your data

A request, a worry, or a data question? Our team answers, not a bot. We reply within two working days. You can also raise a concern with your national data regulator at any time.