Privacy, data protection and security

Version 1.1 · 27 July 2026

Privacy, data protection
& security.

How M46 LTD, trading as SMRC, handles information connected with its computer-based Windows desktop payroll software, supporting website and online services.

In short: SMRC uses personal information only where there is a clear business or legal reason, applies appropriate safeguards, does not sell personal information and retains it only as long as needed. SMRC Pay is primarily Windows desktop payroll software. Payroll files and local backups remain on the customer’s device or chosen location unless the customer deliberately shares information through a supported online feature or for support.

1. Who we are

M46 LTD (company number 16881593), trading as SMRC, provides SMRC Pay payroll software (“SMRC”, “we”, “us” or “our”) through smrc-pay.com. Its registered office is 468 Tyldesley Road, Atherton, Manchester, England, M46 9AT. This policy covers the desktop software, website, licensing, updates, customer support and supported online services.

SMRC will normally be the data controller for website, licensing and support information. The employer, bureau or agent will normally be controller for payroll data entered into the software. Where SMRC accesses payroll information only on documented support instructions, SMRC will normally act as a data processor.

2. Scope

This policy applies to software customers and users, website visitors, licensees, agents, business contacts, support users and supported online-feature users. It does not replace the employee privacy notice that an employer, payroll bureau or agent must provide.

3. Information we may process

Website, software, licensing and customer information

Payroll information controlled by customers

Payroll information may reveal health, family leave, bereavement, trade-union or other sensitive circumstances. Customers must identify a lawful basis and any required UK GDPR Article 9 condition.

HMRC fraud-prevention metadata for applicable API requests

Where HMRC requires fraud-prevention headers, SMRC is designed to collect and transmit limited audit metadata about the originating Windows device, network interfaces, local IP addresses, collection time, screens, active window size, timezone, operating system, user identifiers, product version and a one-way hashed licence reference. It does not include passwords, OAuth tokens or the raw activation key. The complete intended register and current validation status are published on the HMRC Fraud Prevention Data page.

4. How we obtain information

Information is received when someone visits the website, downloads or updates software, buys or activates a licence, uses a supported online feature, contacts support or corresponds with SMRC. Installing the desktop software does not itself upload the local payroll database. Information reaches SMRC only when deliberately entered, uploaded, synchronised, filed or shared.

5. Purposes and lawful bases

PurposeInformationLawful basis
Provide downloads, licences, activation, updates and supportCustomer, account, licence, device and support informationContract; legitimate interests
Manage payments, tax and business recordsCustomer, invoice and transaction informationContract; legal obligation; legitimate interests
Protect systems and prevent misuseDevice, log, licence, diagnostic and security informationLegitimate interests; legal obligation
Submit mandatory HMRC fraud-prevention metadata with applicable API requestsRequired device, network, software, user and hashed-licence audit metadataLegal obligation where the relevant HMRC requirement applies; legitimate interests in preventing fraud and securing tax services
Respond to enquiries and improve serviceContact details, messages and feedbackSteps toward a contract; legitimate interests
Send optional product newsName, email and preference recordsConsent where required; legitimate interests where lawful
Support customer-controlled payroll processingOnly information necessary for the selected support or online featureContract; documented processor instructions

6. Local storage, credentials and HMRC services

Local-first design: SMRC payroll records and backups are stored on the customer’s Windows device or in folders selected by the customer.

The website supports downloads, licensing, activation, updates, documentation and support. Where desktop filing credentials are stored, the design protects the password locally using Windows encryption tied to the Windows user. Customers must never send credentials in ordinary email or support messages.

Draft RTI or year-end XML is not proof of submission. Genuine HMRC filing will be offered only after required onboarding, testing and production integration. SMRC will not ask for GOV.UK One Login or Government Gateway sign-in credentials; agent access must use HMRC’s authorised process.

Fraud-prevention headers: the production-onboarding answer is recorded as “Yes”, meaning that every applicable request must include the real header values required for the selected connection method. The supplied desktop code has not yet completed that implementation or HMRC Test API validation, so live filing remains locked. If a required value cannot be collected because of a genuine technical restriction, SMRC must discuss the exception with HMRC rather than inserting a placeholder.

7. Sharing

SMRC does not sell personal information. Information may be shared where necessary and lawful with providers supporting website, email, payment, licensing, security or customer support; HMRC or authorities when authorised or required; professional advisers; courts, regulators or law enforcement; and a genuine business successor with safeguards.

8. International transfers

If a provider processes information outside the UK, SMRC will require a lawful transfer mechanism and safeguards such as UK adequacy regulations, an International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses.

9. Retention

RecordNormal retention
Contracts, invoices and accounting recordsSix years after the relevant financial year or relationship, unless longer is legally required
Licence and activation recordsDuring the licence relationship and up to six years afterwards
General support ticketsNormally 24 months after closure
Payroll file deliberately supplied for supportOnly while needed, then deleted within 30 days after closure unless agreed or legally required
Website and security logsNormally up to 12 months unless needed for investigation
Marketing recordsUntil consent is withdrawn or an objection is made; a suppression record may remain

Locally stored payroll information is controlled by the customer, who must apply appropriate payroll, tax, employment and legal retention periods.

10. Security

SMRC uses proportionate safeguards including access control, least privilege, local Windows credential protection, encryption in transit for approved online services, secure development, backups, audit records, vulnerability management, confidentiality and incident response. Customers must protect devices, accounts, exports and backups, use supported systems and install trusted updates.

11. Personal data breaches

Suspected breaches are assessed, contained, investigated and documented. When acting as processor, SMRC notifies the affected controller without undue delay. When controller, SMRC notifies the ICO within 72 hours of awareness where legally required and informs affected individuals where required.

12. Your rights

Depending on the circumstances, individuals may request access, correction, erasure, restriction, objection or portability; withdraw consent; and challenge qualifying solely automated decisions. Where data is held in an employer’s or agent’s payroll file, contact that organisation first because it is normally controller. SMRC normally responds within one month, subject to lawful extensions.

13. Automated calculations

SMRC Pay performs payroll calculations using information and rules selected or entered by the customer. Customers must review and finalise results. The public website does not make solely automated decisions producing legal or similarly significant effects.

14. Cookies

The website may use strictly necessary cookies for security and essential functions. Analytics, advertising or other non-essential cookies will not be placed before legally required consent, and rejecting them will be as easy as accepting them.

15. Customer responsibilities

16. Complaints

Contact SMRC first so the concern can be investigated. Individuals may also complain to the UK Information Commissioner’s Office through its data protection complaints service.

17. Changes

This policy may change for legal, regulatory, technical or business reasons. The current version and date will remain on this page, and material changes will receive a prominent notice where appropriate.

18. Contact

M46 LTD trading as SMRC and SMRC Pay

Privacy contact: Mohammed Amin
Email: admin@smrc-pay.com
Website: smrc-pay.com
Registered office: 468 Tyldesley Road, Atherton, Manchester, England, M46 9AT
Company number: 16881593
Registered in: England and Wales

ICO status: no registration number has been supplied or published. M46 LTD should use the ICO’s official data protection fee self-assessment to determine whether it must register and pay the fee.

Regulatory references

This policy is designed with reference to the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations, current ICO guidance and the HMRC Standard for Agents.

Original supplied Visual Studio privacy project

The exact ZIP provided for this policy is preserved unchanged.

Download ZIP →