OpusBUSINESS EXPERT

Legal

Opus Clients Privacy Policy

What Opus Clients collects, why, where it goes, and the rights you have over it. This policy covers the app only.

Effective date: 1 August 2026

Our legal documents are published in English only, and the English text is the authoritative version. If you would like help understanding any part of it, email [email protected].

1. Who we are

Opus Clients is published by Opus Accountancy Limited, a limited company registered in England and Wales, company number 03956240, with its registered office at Bretton House, Bell Meadow Business Park, Park Lane, Pulford, Chester, CH4 9EP.

Opus Accountancy Limited is the data controller for the personal data described in this policy. That means it decides what is collected and why. This policy covers the Opus Clients app only. It does not cover any website, and it does not cover any other app.

App
Opus Clients (iOS, Android)
Published by
Opus Accountancy Limited
Company number
03956240
Registered office
Bretton House, Bell Meadow Business Park, Park Lane, Pulford, Chester, CH4 9EP
Data protection contact
[email protected]

2. What this app collects

Opus Clients collects the following, and nothing else. Each entry says what it is for and where it goes.

contact information, such as your name, email address or phone number
your email address and your name, as they are held on your Opus ID and on your portal record. To sign you in and to show you the documents that belong to you. Sent to us or to a service provider.
your location
your precise location — latitude and longitude, and on Android the accuracy of the fix — read once at the moment you sign a document, and kept as part of the record of that signature. To record where a document was signed, as part of the audit record that shows the signature is genuine. Sent to us or to a service provider.
content you create, such as photos, messages or files
the signature you draw, sent as an image; any file you upload; and the reason you type if you decline to sign. To complete and record the signing of a document, and to pass the files you send to your accountant. Sent to us or to a service provider.
identifiers that could be used to recognise you or your device
your portal user identifier, the customer and contact identifiers that link you to the companies you act for, and a push notification token for the device — from Apple on iPhone, and from Google’s Firebase Cloud Messaging on Android. To know which portal account you are, which companies you are entitled to see, and where to send a notification when a document needs your signature. Sent to us or to a service provider.
any other personal data
on Android only, a short description of the device you signed on — its maker, model and Android version — and a record that the device’s own fingerprint, face or screen lock check passed before the signature was submitted. To show what device a signature was made on, as part of its audit record. Sent to us or to a service provider.

3. What this app does not collect

Apple groups the data an app might collect into categories, and asks a developer to declare which apply. For Opus Clients, these do not:

  • health or fitness data
  • financial information, such as payment card details
  • sensitive information, such as racial or ethnic origin, health or sexual orientation
  • your address book or contacts
  • your browsing history
  • your search history
  • your purchase history
  • data about how you use the app
  • diagnostic data, such as crash logs or performance measurements

The app does not track you. It does not link what you do in it to data from other companies’ apps or websites, and it shares nothing with data brokers.

4. Why, and the lawful basis

The UK GDPR requires a lawful basis for processing personal data. These are the bases we rely on, for the data that reaches us:

contact information, such as your name, email address or phone number
Contract. To sign you in and to show you the documents that belong to you.
your location
Legitimate interests. To record where a document was signed, as part of the audit record that shows the signature is genuine.
content you create, such as photos, messages or files
Contract. To complete and record the signing of a document, and to pass the files you send to your accountant.
identifiers that could be used to recognise you or your device
Contract. To know which portal account you are, which companies you are entitled to see, and where to send a notification when a document needs your signature.
any other personal data
Legitimate interests. To show what device a signature was made on, as part of its audit record.

Things that stay on your device

Documents you open are downloaded to your own device so you can read them, and they are held in the app’s private storage rather than anywhere you or another app can browse to. On iPhone they are protected by the device’s own encryption and cannot be read while the phone is locked. Signing out deletes every one of them, and you can clear them yourself at any time — from Settings on Android, and from the documents list on iPhone.

The signature you draw is turned into an image on your device before it is sent. The individual strokes never leave it.

Your fingerprint or face never leaves your device either, and the app never sees it. When the app asks you to confirm with Face ID, Touch ID or your Android screen lock, the check is done by the phone itself and the app is told only whether it passed.

One thing on this page is not about you. When you upload a file, we cannot see what is in it, and it may contain other people’s personal information — payroll for your own employees, for instance. For your own account, your signature and your messages to us, Opus Accountancy Limited decides how that data is used and is answerable for it under this policy. For other people’s information inside a file you upload, we are handling your data on your behalf under our engagement with you, and it is that engagement — not this policy — that governs it. If you are not a portal user but your details appear in something a client sent us, this app policy is not the document that describes how they are handled.

Location

To record where a document was signed, as part of the audit record that shows the signature is genuine.

Your location is sent from your device so that the app can answer with information about where you are.

The app asks your permission before using location, and you can withdraw that permission at any time in your device’s Settings. The app continues to work without it, with the features that depend on location unavailable.

This is not a passing request parameter. The coordinate is written into the permanent audit record of your signature and can be read back afterwards, so it is kept for as long as that record is — which follows the engagement letter between us and the business you are linked to, and the periods the law requires a signed document to be kept for, rather than anything set in the app. No location history is kept: the app reads your position only at the moment you sign, never in the background and never continuously.

Who we share data with

We share personal data only where it is necessary for the purposes described above. The parties involved are:

Apple
Push notifications on iPhone, and the map on the iPhone signed-confirmation screen. On iPhone, the device’s notification token and the contents of every notification we send you, because Apple’s push service carries them. Separately, when the app shows the map on a signed document, the area around the recorded coordinate is requested from Apple’s map service. Both are handled under Apple’s own privacy policy. Processed in countries outside the United Kingdom, not yet confirmed.
Google
Push notifications on Android (Firebase Cloud Messaging). On Android only, the device’s Firebase registration token and the contents of every notification we send you, because Google’s messaging service carries them. Firebase also holds an installation identifier for the app on that device. The iPhone app uses Apple’s push service instead and involves Google in nothing. Processed in countries outside the United Kingdom, not yet confirmed.
Opus ID
The sign-in service, which the practice operates on its own domain. Your Opus ID password, which you type into the sign-in page in a browser rather than into the app, and which the app never sees. It issues the token that carries your email address and name to the portal. Because the sign-in happens in your browser, a session cookie for it stays in that browser afterwards, which is why signing out asks the sign-in service to end the session rather than only clearing the app. Processed in the United Kingdom (a self-hosted server in Manchester).
Microsoft
Cloud storage behind the portal, holding the documents your accountant shares. The documents your accountant makes available to you, and the files you upload to a cloud folder. The app never contacts this service: every request goes to the portal, which fetches the document and sends it on. Processed in not yet confirmed.

We do not sell personal data, and we do not share it for anyone else’s marketing. We will disclose personal data where we are legally required to, and to the extent necessary to establish, exercise or defend legal claims.

Transfers outside the United Kingdom

Some of the parties above are based outside the United Kingdom, or process data on infrastructure that is. Where personal data is transferred outside the UK, we rely on the UK’s adequacy regulations for the destination country where they apply, and otherwise on the International Data Transfer Agreement, or the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with any additional safeguards the transfer requires.

Children

This app is not directed at children, and it does not knowingly collect personal data from anyone under 13. If you believe a child has provided personal data through this app, contact us using the details below and we will delete it.

How long data is kept

contact information, such as your name, email address or phone number
Your portal account is set up and closed by the practice rather than in the app, so how long the account itself lasts is not something the app decides. On the device, your name and email are held only for the length of the session and are dropped when you sign out.
your location
This is not a passing request parameter. The coordinate is written into the permanent audit record of your signature and can be read back afterwards, so it is kept for as long as that record is — which follows the engagement letter between us and the business you are linked to, and the periods the law requires a signed document to be kept for, rather than anything set in the app. No location history is kept: the app reads your position only at the moment you sign, never in the background and never continuously.
content you create, such as photos, messages or files
Your signature image, your uploaded files and any reason you give for declining are stored by the portal. How long they are kept is set by the practice’s retention schedule rather than by the app, and is not stated here until it has been confirmed. Documents you only VIEW are cached on your device while you read them and are deleted when you sign out.
identifiers that could be used to recognise you or your device
When you sign out, the app asks our server to stop sending notifications to that device. Your portal user and customer identifiers last as long as your portal account does, and how long that is follows the engagement letter between us and the business you are linked to rather than anything set in the app.
any other personal data
Kept with the audit record of the signature it belongs to, for as long as that record is kept. The iPhone app sends neither of these.

Your rights over your personal data

You have rights over the personal data we process as controller. We aim to respond promptly; how long a response takes depends on the nature and extent of the request. You have the right to:

  • request access to your personal data under Article 15 of the UK GDPR, so that you receive a copy of what we hold;
  • request rectification under Article 16 of any errors or inaccuracies in it;
  • request erasure under Article 17 where there is no good reason for us to continue processing it;
  • object to processing under Article 21 where we rely on legitimate interests and you believe your own interests or rights override them;
  • request restriction of processing under Article 18, for example while its accuracy is established;
  • withdraw consent under Article 7 where we process on the basis of your consent;
  • request the transfer of your personal data to you or to another controller under Article 20.

To exercise any of these rights, email [email protected]. There is no charge.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile individuals.

Getting help with the app

Questions about how Opus Clients works, rather than about your personal data, are answered on the support page at opus.expert/opus-clients/support, which also explains how to ask for your data to be deleted.

Contact and complaints

If you have any question about this policy, or would like to discuss how we process personal data, email [email protected]. You can also write to us at Bretton House, Bell Meadow Business Park, Park Lane, Pulford, Chester, CH4 9EP.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. We would ask you to raise the matter with us first so that we have the chance to put it right.

Information Commissioner’s Office
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113. ico.org.uk/concerns

Changes to this policy

We may update this policy from time to time. The current version is always the one published on this page, and its effective date is shown at the top. Where a change materially affects what the app collects, it is accompanied by an update to the app’s App Store privacy details.

We would like to use analytics cookies to understand how this site is used, and to load our office map from Google. Both are off unless you accept, and nothing is loaded until you choose. Read our cookie policy