DRAFT — PENDING COUNSEL REVIEW

Privacy & Data Practices

Last updated: July 2026 · Version 0.1 (draft)

This notice explains what data Taxly handles, why, and how we protect it. Taxly is practice software for accounting firms, so most of the personal data we process belongs to our customers’ clients — and our customers, the firms, control it. This draft describes the practices the product is built to; it is pending review by legal counsel and does not yet constitute a binding legal agreement.

1Who this covers

Taxly serves two audiences, and this notice addresses both:

  • Firms— the CPA and bookkeeping practices that subscribe to Taxly and are the controllers of their clients’ data.
  • Firm clients — the businesses and individuals a firm serves, who use the client portal to exchange documents, answer questionnaires, and sign engagement letters.

For data a firm uploads or its clients submit, the firm is the data controller and Taxly is a processor acting on the firm’s instructions. If you are a firm’s client and have a question about your data, contact your firm first; we will support their response.

2What we collect

Account and firm data

Names, work email addresses, roles, and authentication data for the people at a firm who use Taxly. We use AWS Cognito for identity; passwords are never stored in plaintext.

Client records

Entity details, contacts, services, and tax-relevant identifiers a firm enters or imports — including sensitive identifiers such as SSNs and EINs. These fields receive field-level encryption on top of encryption at rest (see Section 4).

Documents and messages

Files that firms and their clients upload (statements, organizers, engagement letters) and the messages exchanged inside a client record.

Bank and bookkeeping data

Bank-statement PDFs a firm uploads, and — for firms in the early-access bank-feed program — transaction data retrieved through Plaid. See Section 6 for how Plaid data is handled.

Usage and audit data

We record an audit trail of actions taken in the product: actor, IP address, user agent, and timestamp, across document activity, sign-offs, and bookkeeping. This log exists to make the product audit-ready and to protect firms and their clients.

3How we use data

We use data only to operate the service and do the work a firm asks us to do:

  • To provide onboarding, the client portal, document collection, bookkeeping review, work-item tracking, and e-signature.
  • To parse and categorize bank statements a firm uploads, so staff can review rather than re-key.
  • To secure the service, prevent abuse, and maintain the audit trail.
  • To provide support and communicate about the service.

We do not sell personal data, and we do not use client data for advertising.

4How we protect data

  • Field-level encryption. Sensitive identifiers (SSNs, EINs) are encrypted as individual fields, in addition to encryption at rest and TLS in transit.
  • Tenant isolation.Every firm’s data is partitioned, and every request is re-verified against the firm it claims to belong to. Cross-firm access is not a permission that can be granted — it is not a path that exists in the system.
  • Complete audit trail. Views, uploads, edits, and signatures are logged with actor, IP, and timestamp, and firms can read their own log.
  • Signed, sealed evidence. E-signature completions are hash-sealed with an asymmetric key and stored write-once (WORM) for the retention period — tamper-evident and independently verifiable.
  • SOC 2-aligned controls.We build to SOC 2-aligned controls throughout. We say “aligned,” not “certified,” until an audit is complete.

5AI and your data

Some features use AI — most notably bank-statement parsing and document pre-fill. Statement parsing runs on AWS Bedrock under our own account.

We do not train models on your clients’ data — ours or anyone else’s. Data submitted to an AI feature is used to do your work and to return a result, not to improve a foundation model. Our AI processing runs under enterprise terms that prohibit provider-side training on inputs and outputs.

6Plaid and bank data

Firms in the early-access bank-feed program may connect a client’s bank account through Plaid, a third-party financial-data network. When a bank connection is established:

  • Bank credentials are entered with Plaid, not with Taxly — we never see or store them.
  • We receive transaction and account data needed to do bookkeeping, scoped to the connected accounts.
  • Plaid’s handling of data is governed by Plaid’s own privacy policy in addition to this notice.
  • Disconnecting a bank connection stops future data retrieval; previously imported transactions remain in the firm’s books as accounting records.

7Sharing and subprocessors

We share data only with infrastructure and service providers that help us run Taxly, under contract and only as needed. Core subprocessors include Amazon Web Services (hosting, storage, identity, email, and AI inference) and Plaid (bank data, for connected accounts). We do not share client data with third parties for their own purposes.

8Retention

We retain data for as long as a firm maintains its account, and as needed to provide the service and meet legal and professional record-keeping obligations. Signed documents are held in write-once storage for their retention period. On account closure, firms can export their data; we then delete or de-identify it on a defined schedule, except where retention is legally required.

9Your choices and rights

Firm clients: your firm controls your data — contact your firm to access, correct, or delete it, and we will support them. Firm users: manage your profile and account data in-product. Depending on your jurisdiction, you may have additional rights over your personal data; we honor applicable requests routed through the controlling firm.

10Contact

Questions about this notice or our data practices: hello@taxly.com. This is a pre-launch draft and will be finalized with counsel before general availability.

← RETURN TO TAXLY.COM