CUNNTAS
Data Protection & Your Data
CUNNTAS processes information at the centre of an Organisation's financial affairs. Accounting records, bank transactions, payroll information, customer and Supplier details and statutory records can contain significant amounts of personal and commercially sensitive information.
We therefore believe Organisations should understand not only how CUNNTAS protects personal information, but also whose data it is, why we process it, who can access it and what happens to it when an Organisation uses or leaves the platform.
CUNNTAS is operated by Mayside Partners Limited, a company registered in Scotland under company number SC642690, trading as CUNNTAS.
Mayside Partners Limited, trading as CUNNTAS, is registered with the Information Commissioner's Office (ICO) for data protection purposes.
This page provides an overview of our approach to data protection and Organisation data. It should be read together with the CUNNTAS Privacy Policy, Cookie Policy and Terms of Service.
1. Your Organisation's Data Remains Your Organisation's Data
Using CUNNTAS does not transfer ownership of an Organisation's accounting records, business information or other data to Mayside Partners Limited.
Information entered, imported or connected by an Organisation remains the information of that Organisation or the relevant owner of the information.
CUNNTAS processes and stores that information so that we can provide the bookkeeping, accounting, payroll, banking, reporting and financial administration services requested by the Organisation.
We do not claim ownership of an Organisation's financial records merely because those records are maintained using CUNNTAS.
2. Mayside Partners Limited and Data Protection
Mayside Partners Limited, trading as CUNNTAS, is registered with the Information Commissioner's Office for data protection purposes.
Depending upon the information and the circumstances in which it is processed, Mayside Partners Limited may act as a Data Controller or as a Data Processor.
Where we determine why and how personal information is processed for our own legitimate business purposes — for example, information required to administer CUNNTAS User Accounts, subscriptions, billing, security and regulatory obligations — Mayside Partners Limited will ordinarily act as controller.
Where an Organisation uses CUNNTAS to process personal information contained within its own accounting, payroll, customer, Supplier or other business records, the Organisation will ordinarily determine the purpose for which that information is processed and Mayside Partners Limited will process the information through CUNNTAS in providing the service.
3. The Organisation's Responsibilities
An Organisation using CUNNTAS remains responsible for the information it places within the platform.
This includes ensuring that personal information has been obtained lawfully, that there is an appropriate basis for processing it, that information is used for legitimate purposes and that appropriate information is provided to individuals where required.
CUNNTAS provides the technology and services through which information can be processed. Use of the platform does not transfer an Organisation's own data-protection responsibilities to Mayside Partners Limited.
4. What Information May Be Held in CUNNTAS?
The information held for an Organisation depends upon the functions it uses.
It may include:
- Accounting and bookkeeping records
- Bank-account and transaction information
- Customer information
- Supplier information
- Sales and Purchase Invoices and Credit Notes
- Employee and payroll information
- PAYE and National Insurance information
- Pension information
- VAT records
- Corporation Tax information
- Financial reports
- User and Organisation permissions
- Documents associated with financial transactions
- Audit and system activity records
Some of this information may identify individuals even where the principal purpose of the record is financial or accounting administration.
5. Payroll Data
Payroll can contain particularly important personal information.
Depending upon the Organisation and employee, this may include names, addresses, dates of birth, National Insurance information, employment information, pay, deductions, tax information, pension information and payment details.
Access to payroll information should therefore be limited to Users who legitimately require it.
CUNNTAS is designed so that User access can be associated with the Organisation and the permissions appropriate to that User.
6. Banking Data
Where an Organisation connects an eligible bank account, CUNNTAS may receive account and transaction information through supported banking and Open Banking services.
CUNNTAS uses this information for the banking, reconciliation, bookkeeping and accounting functions selected by the Organisation.
Users do not provide their online banking passwords directly to CUNNTAS for this purpose. Authentication and authorisation take place through the relevant banking or Open Banking process.
7. We Do Not Sell Your Data
CUNNTAS does not sell an Organisation's accounting, payroll, banking or personal information.
Information entrusted to CUNNTAS is processed for the operation and provision of the platform, fulfilment of our legal and regulatory responsibilities, security, support and other legitimate purposes described in our Privacy Policy and contractual arrangements.
An Organisation's financial information is not a commodity to be sold to advertisers or unrelated third parties.
8. We Do Not Use Your Accounting Data for Unrelated Advertising
The fact that CUNNTAS processes financial information does not give us permission to use an Organisation's accounting records to construct unrelated advertising profiles.
Customer purchases, Supplier payments, payroll information, bank transactions and similar financial records are processed because they are required for the functions the Organisation has chosen to use.
They are not provided to unrelated advertisers for their independent marketing purposes.
9. Who Can Access an Organisation's Data?
Access is based upon authorised User relationships with the Organisation.
A CUNNTAS User does not obtain access to another Organisation merely because they have a CUNNTAS account.
Users may be authorised for one Organisation or several Organisations, but the underlying Organisation records remain separate.
This separation allows individuals who legitimately manage several companies or entities to use one secure identity without combining the financial records of those Organisations.
10. Individual User Accounts
CUNNTAS is designed around individual User Accounts rather than shared login credentials.
This improves data protection because access can be granted or withdrawn for a particular individual and important activity can be associated with the User responsible for it.
Organisations should not circumvent these protections by unnecessarily sharing User credentials.
11. Controlled Support Access
Providing technical support does not require CUNNTAS personnel to have unrestricted permanent access to every Organisation.
CUNNTAS includes a Protected Support Access system through which temporary access can be authorised when investigation genuinely requires access to an Organisation's workspace.
The process is designed around positive User consent, controlled access and recorded activity.
This provides support while preserving accountability for access to customer information.
12. Security of Your Data
CUNNTAS uses technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure or loss.
These measures include mandatory Two-Factor Authentication, secure authenticated sessions, trusted-browser controls, User and Organisation permissions, audit records, encrypted HTTPS communications and protected system configuration.
Security is part of the standard CUNNTAS service rather than an optional premium feature.
13. Auditability
Access control is only one aspect of protecting information.
It is also important that significant activity can be reviewed.
CUNNTAS maintains audit and event information relating to important User and system actions. These records can assist with identifying what occurred, when it occurred and the User or process responsible.
Auditability supports both data protection and accounting integrity.
14. Financial Record Integrity
An Organisation's data is not protected merely by preventing somebody from stealing it. Financial information must also retain its integrity.
CUNNTAS is therefore designed to preserve important relationships between transactions and their accounting consequences.
Permanent financial documents, audit records and connected banking information should not be silently rewritten merely to remove evidence of an earlier transaction.
Where financial information requires correction, appropriate accounting processes can preserve the original history and the subsequent correction.
15. Service Providers
Operating CUNNTAS requires certain specialist service providers.
These may include infrastructure and hosting providers, payment providers, communications services, banking and Open Banking providers and other technical services required to deliver the platform.
Where a provider processes personal information on our behalf, access should be limited to what is necessary for the relevant service and subject to appropriate contractual and security arrangements.
Use of a service provider does not transfer ownership of an Organisation's information to that provider.
16. International Processing
Some service providers may process information outside the United Kingdom.
Where personal information is transferred internationally, Mayside Partners Limited takes appropriate measures intended to ensure that the transfer complies with applicable UK data-protection requirements.
The location of a technical service does not remove our responsibility to consider the protections applicable to personal information entrusted to CUNNTAS.
17. Retention of Information
Different information must be retained for different periods.
An Organisation may want information removed when it no longer uses CUNNTAS, but accounting, tax, payroll, billing, regulatory, security and audit requirements may require certain records to be retained.
CUNNTAS therefore does not promise that every piece of information will be immediately destroyed when a subscription ends.
Information will be retained for as long as reasonably necessary for the purpose for which it is held and to satisfy applicable legal, accounting, tax, regulatory, security and contractual requirements.
18. Leaving CUNNTAS
An Organisation should not be trapped within CUNNTAS merely because its financial records are held through the platform.
Where applicable, CUNNTAS is intended to provide appropriate means of obtaining or exporting Organisation information so that records required by the Organisation can be retained independently.
The exact information available for export may depend upon the type of record and the functions used.
Termination of a subscription does not require CUNNTAS to delete information that Mayside Partners Limited is legally or legitimately required to retain.
19. Moving to CUNNTAS
The same principle applies when an Organisation joins CUNNTAS.
CUNNTAS is being designed to support the import and mapping of information from established accounting systems, including information originating from platforms such as Xero, Sage and QuickBooks.
An Organisation should be able to move its accounting information without having to treat a change of software provider as the beginning of its financial history.
Imported information remains subject to the same Organisation access, security and integrity principles as information created directly within CUNNTAS.
20. Data Subject Rights
Individuals have rights concerning their personal information under applicable UK data-protection law.
Depending upon the circumstances, these may include rights of access, correction, deletion, restriction, objection and portability.
Where information is held within the business records of an Organisation using CUNNTAS, the Organisation may be the appropriate party to receive and determine a request because it controls the purpose for which that information is processed.
Where Mayside Partners Limited is responsible as controller, requests can be directed to us through the contact facilities provided by CUNNTAS.
21. Data Protection Requests Involving an Organisation
If an individual contacts CUNNTAS about information held within an Organisation's accounting, payroll or other business records, we may need to refer the request to the relevant Organisation.
This does not mean the request is being disregarded.
It reflects the distinction between the Organisation that determines why the information is being processed and CUNNTAS providing the platform through which that processing takes place.
Where appropriate, we can assist an Organisation in responding to legitimate data-protection requests relating to information processed through CUNNTAS.
22. Data Breaches and Security Incidents
Mayside Partners Limited maintains responsibility for responding appropriately to security incidents affecting CUNNTAS.
Where a personal-data breach occurs, the circumstances will be assessed in accordance with applicable data-protection requirements.
Where notification to an Organisation, affected individual, the Information Commissioner's Office or another authority is legally required, the appropriate notification process will be followed.
Organisations also have responsibilities to report suspected incidents promptly where those incidents involve their Users, devices, credentials or information.
23. The Information Commissioner's Office
The Information Commissioner's Office (ICO) is the United Kingdom's independent regulator for data protection and information rights.
Mayside Partners Limited, trading as CUNNTAS, is registered with the ICO for data protection purposes.
Individuals who have concerns about the handling of their personal information may contact us so that the matter can be investigated.
Applicable data-protection law also provides individuals with the right to raise concerns with the Information Commissioner's Office.
24. Privacy by Design
CUNNTAS is being developed on the principle that data protection should influence how the platform operates rather than simply appear in a Privacy Policy.
Examples include:
- Individual User identities rather than shared accounts
- Mandatory Two-Factor Authentication
- Controlled Organisation permissions
- Protected Support Access
- Audit and event records
- Secure banking authorisation
- Restricted handling of authentication secrets
- Separation of Organisation records
- Controlled trusted-browser credentials
- Financial-record integrity controls
As CUNNTAS develops, new functionality should continue to be assessed against the same principles.
25. Transparency
An Organisation entrusting its accounts, payroll and banking information to a platform should be able to understand how that information is treated.
Our objective is therefore straightforward:
- Your Organisation's data remains your Organisation's data.
- We process it to provide and protect the CUNNTAS service.
- We do not sell it.
- We restrict access to authorised purposes.
- We preserve financial and audit integrity where records must be retained.
- And we remain accountable for the data-protection responsibilities that apply to Mayside Partners Limited as the operator of CUNNTAS.
26. Contact
Questions concerning data protection or the handling of information through CUNNTAS may be directed to: Mayside Partners Limited. Registered with the Information Commissioner's Office for data protection purposes
Data-protection enquiries may be submitted using the contact details provided through the CUNNTAS platform.
The name CUNNTAS is pronounced “KOON-tas”. It comes from the Scottish Gaelic word cunntas, meaning “account”, “accounts”, “accounting” or “reckoning” — a name that reflects both the purpose of the platform and its Scottish identity.
Last Updated: 10 August 2026