Your information
Privacy & cookies
This notice explains how Novo Delta Limited handles information through the Kanabar Financial website, its calculators and the Kanabar MTD Bridge software.
Who is responsible for your information
Novo Delta Limited is the data controller for the information described in this notice. Kanabar Financial and Kanabar MTD Bridge are trading and product names used by Novo Delta Limited.
Novo Delta Limited is registered in England and Wales under company number 13485883. Its current registered-office details are available on the Companies House register. Privacy enquiries can be sent to info@kanabarfinancial.com.
Calculator information
The figures you enter into the PAYE, Stamp Duty and Self Assessment calculators are processed in your browser. They are not sent to Novo Delta Limited, saved to an account or stored in a website database.
If you choose to copy or print a result, that action is handled by your browser and device.
MTD Bridge account and tax information
The public MTD Bridge workflow remains a preview. A private, allowlisted subscriber test area can connect to HMRC's official sandbox using a dummy taxpayer, store dummy digital-record rows and retain accepted dummy-summary receipts. It cannot connect to HMRC production or submit real taxpayer information. Do not enter real taxpayer records in the sandbox test area. The service may process:
- your name, email address and account identifier;
- subscription status, Stripe customer references, invoices and payment status, but not your full card or bank details;
- your tax identifiers, business details, accounting periods, obligations, income, expenses, adjustments, losses, calculations, declarations and HMRC submission receipts;
- HMRC OAuth access and refresh tokens used to act only after you authorise the software; and
- device, connection and user-audit information required in HMRC fraud-prevention headers.
Novo Delta Limited will not ask for or store your Government Gateway password. You authorise access on HMRC's own sign-in page and can withdraw that authority.
Why information is used
Account, subscription and tax information is used to provide the software you request, keep your digital records, retrieve obligations and calculations, show information for your review and send submissions to HMRC only when you approve them. This processing is necessary to perform the software contract with you.
Information may also be used to secure the service, prevent duplicate subscriptions, investigate errors, prevent fraud and maintain audit records. Novo Delta Limited relies on legitimate interests for proportionate service security and support, and on legal obligations where records or HMRC fraud-prevention information must be retained or supplied.
Consent is used for non-essential advertising cookies and any optional marketing. You can withdraw that consent without affecting the core service.
Who receives information
Information is shared only where needed with:
- HMRC, when you connect your account, retrieve information or approve a submission;
- Stripe, which provides checkout, subscription billing, invoices and the billing portal;
- secure hosting, database, authentication, email and support suppliers acting under contract; and
- professional advisers, regulators, law-enforcement bodies or courts where disclosure is legally required.
Novo Delta Limited does not sell customer tax information. Read HMRC's privacy notice and Stripe's privacy policy for their own processing.
HMRC fraud-prevention information
Software using the Income Tax Self Assessment APIs is legally required to send specified fraud-prevention header information to HMRC. This may include IP-address, device, operating-system, browser, screen, time-zone and connection information, plus identifiers for the software and user session. HMRC uses this information to prevent and detect tax fraud.
More detail is available in HMRC's official fraud-prevention guidance.
Retention and account closure
Customer tax records are kept while an account is active so the service can operate. Before closing an account, customers should export the records they need. Subject to legal, fraud, dispute and security requirements, customer-entered tax records and HMRC tokens will be deleted or irreversibly anonymised within 90 days after account closure; HMRC authority will be revoked or allowed to expire.
Contract, subscription, invoice and accounting records may be retained for up to six years after the relevant transaction or the end of the relationship. Security and technical logs are normally retained for no more than 12 months. Enquiry records are normally retained for up to 24 months unless they become part of a client or contractual record.
Security and international processing
HMRC access and refresh tokens are encrypted before storage, and connected information is encrypted in transit. Production HMRC connectivity remains disabled. Access is restricted to people and service providers that need it. No internet service can be guaranteed completely secure, so customers should also protect their email, HMRC and device credentials.
Some contracted technology providers may process information outside the United Kingdom. Where that happens, Novo Delta Limited will use an approved transfer mechanism and appropriate safeguards required by UK data-protection law.
Report a security problem
If you discover a possible security weakness or believe information has been exposed, email info@kanabarfinancial.com with Security issue in the subject. Do not email passwords, Government Gateway details, OAuth tokens, full National Insurance numbers or bank files. We will record, investigate and escalate the report through the applicable HMRC and data-protection process.
When you contact us
If you email or telephone Kanabar Financial, the contact details and information you provide are used to respond to your enquiry, discuss services and keep appropriate business records. Please do not include unnecessary sensitive information in an initial enquiry.
Advertising and cookies
This website may display advertising supplied by Google AdSense. When advertising is enabled, Google and its advertising partners may use cookies, IP addresses, web beacons or similar technologies to deliver, measure and protect ads.
Visitors in the UK, EEA and Switzerland will be offered the consent choices required for Google advertising through a Google-certified consent management platform. You can change or withdraw your choices through the privacy controls shown on the site.
Learn more about how Google uses information from sites that use its services and read Google's privacy policy.
Your data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing of your information, and to receive information you provided in a portable format. Where processing relies on consent, you can withdraw it. There is no solely automated decision-making that produces legal or similarly significant effects.
Signed-in MTD Bridge customers can download a JSON copy of the customer-facing information held in their workspace and can record an account-deletion request from the account page. The export deliberately excludes passwords, OAuth tokens, encryption material, raw HMRC identifiers and internal security information. Deletion is reviewed before action because some tax, payment, fraud-prevention or security records may need to be retained.
To exercise another right, or if you cannot use the account controls, email info@kanabarfinancial.com or write to the registered office shown on the Companies House register. You also have the right to complain to the Information Commissioner's Office.
External links and changes
The website links to official guidance and other external sites. Their operators are responsible for their own privacy practices and content. This notice will be updated when the MTD Bridge's processing or suppliers materially change.
Last updated: 22 August 2026