Got a quick tax question? Get an answer from a certified accountant in under 5 minutes.

    Skip to main content
    Liberate Accountants - Professional accounting services

    Close Engine Privacy Policy

    How our internal Close Engine application processes data when a client's Xero organisation is connected to it.

    Liberate Accountants Ltd (“we”, “us”) is an ACCA-regulated accounting practice incorporated in England and Wales (company number 14008043), with its registered office at 60 St Martin's Lane, Covent Garden, London, WC2N 4JS. We are the data controller for the processing described in this policy and are registered with the Information Commissioner's Office under registration number ZB395768.

    This policy supplements the privacy notice provided with our engagement letter, which governs our client relationships generally; this document describes the specific processing carried out by the Close Engine application. Where we act as a data processor on a client's behalf for particular services (for example payroll), the processing schedule agreed for that service applies in addition to this policy.

    1. What this policy covers

    The Close Engine is an internal application operated by Liberate Accountants Ltd and used solely by our own staff to prepare and review monthly management accounts for clients of the practice. It is not offered to, or usable by, any third party. This policy explains what data the application processes when a client's Xero organisation is connected to it, and who else is involved in that processing.

    2. What data we access, and why

    With each client's authorisation, the application connects to their Xero organisation using OAuth 2.0 and accesses accounting records: the chart of accounts, contacts, invoices, bank transactions, journals, reports and organisation settings. This data can include personal data — for example the names of a client's customers, suppliers and employees, and transaction descriptions.

    We process this data to perform the accounting services the client has engaged us for: reconciling reported figures to the underlying ledger, verifying accruals and prepayments, checking for duplicates and omissions, reviewing tax positions, and producing month-end working papers.

    Access is currently read-only. A limited write capability — posting month-end journals prepared and approved by our qualified staff — is planned; this policy will be updated when it is introduced.

    Lawful basis

    Where the individual is our client (for example a sole trader or partner), processing is necessary for the performance of our engagement with them (Article 6(1)(b) UK GDPR). Where the data relates to other individuals — a client's customers, suppliers or employees — we rely on our legitimate interests in delivering accurate and efficient accounting services to our clients (Article 6(1)(f)), and on compliance with our legal and professional obligations (Article 6(1)(c)), including record-keeping and anti-money-laundering requirements. The application does not make automated decisions producing legal or similarly significant effects about any individual; all of its output is reviewed and acted on by our staff.

    3. Who else processes this data

    We use a small number of service providers, each acting as our data processor under contractual terms meeting the requirements of Article 28 UK GDPR:

    ProviderPurposeWhat they process
    ClerkStaff authentication and access controlStaff names, email addresses and team membership. No accounting data.
    OpenAIAI-assisted classification and drafting within the review engineAccount names, counterparty names, transaction descriptions and amounts, sent per request for inference only.
    AnthropicAI-assisted classification and drafting within the review engine (one or both AI providers may be used)Account names, counterparty names, transaction descriptions and amounts, sent per request for inference only.
    RailwayApplication and database hostingAll application data at rest, encrypted.
    VercelWeb interface hostingNo direct access to accounting data; the interface passes authenticated requests to our backend.

    On AI processing

    No data obtained from Xero is used to train, fine-tune or adapt any AI or machine-learning model. Training on API data is disabled in our OpenAI account's data controls, and Anthropic's commercial terms provide that it may not train models on customer content submitted through its services. We do not create or retain embeddings or derived datasets of Xero data for model development. Where AI providers process data outside the UK, this takes place under data processing agreements incorporating appropriate international transfer safeguards. AI output is used only to assist our own staff in their review work and is checked by them.

    4. Where data is hosted

    Our production database and application are hosted in the European Union (Amsterdam, Netherlands). Our web interface is hosted in the United Kingdom (London). Transfers between the UK and the EU take place under the existing UK–EU adequacy arrangements. Copies of the key transfer safeguards that apply to our service providers are available on request.

    5. Security

    Data is encrypted in transit and at rest. Access is restricted to authorised Liberate staff on a role basis. Connection credentials are stored encrypted and are revoked when a client's organisation is disconnected. All access to client data and all changes made through the application are recorded in a tamper-evident audit log.

    6. How long we keep data

    Accounting records and working papers processed by the application are retained in line with our engagement terms and recognised good practice in the tax and accountancy sector: six years from the end of the tax year to which the information relates, after which they are destroyed. Audit logs are retained on the same basis. Encrypted database backups are kept for one month. When a client relationship ends, data can also be deleted earlier on request, subject to those professional and legal obligations.

    7. Your rights

    If your personal data is processed through this application — whether you are a client, or a customer, supplier or employee of a client — you have rights under UK data protection law, including rights of access, rectification, erasure, restriction of processing, objection and, where applicable, data portability.

    To exercise them, or to ask any question about this policy, contact us at admin@liberateac.co.uk (marked for the attention of Data Protection), or by post to Liberate Accountants, 60 St Martin's Lane, Covent Garden, London, WC2N 4JS. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

    8. Changes

    We will update this policy when the application or our processing changes, and the current version will always be available at this address.

    Last updated: 4 September 2026