1. Who we are
M46 LTD (company number 16881593), trading as SMRC, provides SMRC Pay payroll software (“SMRC”, “we”, “us” or “our”) through smrc-pay.com. Its registered office is 468 Tyldesley Road, Atherton, Manchester, England, M46 9AT. This policy covers the desktop software, website, licensing, updates, customer support and supported online services.
SMRC will normally be the data controller for website, licensing and support information. The employer, bureau or agent will normally be controller for payroll data entered into the software. Where SMRC accesses payroll information only on documented support instructions, SMRC will normally act as a data processor.
2. Scope
This policy applies to software customers and users, website visitors, licensees, agents, business contacts, support users and supported online-feature users. It does not replace the employee privacy notice that an employer, payroll bureau or agent must provide.
3. Information we may process
Website, software, licensing and customer information
- Names, business names, job titles and contact details.
- Account, licence, activation, subscription, invoice and payment-status information.
- Enquiries, correspondence, support tickets and feedback.
- IP address, browser, device, access-time and security logs.
- Marketing preferences and consent records.
Payroll information controlled by customers
- Identity, address, date-of-birth, employment and payroll details.
- National Insurance numbers, tax codes, PAYE references and tax references.
- Earnings, deductions, benefits, expenses, pensions, loans and statutory payments.
- Bank or payment details where recorded by the customer.
- CIS contractor and subcontractor records.
- Payslips, P45s, P60s, reports, draft RTI files, audit records and backups.
Payroll information may reveal health, family leave, bereavement, trade-union or other sensitive circumstances. Customers must identify a lawful basis and any required UK GDPR Article 9 condition.
HMRC fraud-prevention metadata for applicable API requests
Where HMRC requires fraud-prevention headers, SMRC is designed to collect and transmit limited audit metadata about the originating Windows device, network interfaces, local IP addresses, collection time, screens, active window size, timezone, operating system, user identifiers, product version and a one-way hashed licence reference. It does not include passwords, OAuth tokens or the raw activation key. The complete intended register and current validation status are published on the HMRC Fraud Prevention Data page.
4. How we obtain information
Information is received when someone visits the website, downloads or updates software, buys or activates a licence, uses a supported online feature, contacts support or corresponds with SMRC. Installing the desktop software does not itself upload the local payroll database. Information reaches SMRC only when deliberately entered, uploaded, synchronised, filed or shared.
5. Purposes and lawful bases
| Purpose | Information | Lawful basis |
|---|---|---|
| Provide downloads, licences, activation, updates and support | Customer, account, licence, device and support information | Contract; legitimate interests |
| Manage payments, tax and business records | Customer, invoice and transaction information | Contract; legal obligation; legitimate interests |
| Protect systems and prevent misuse | Device, log, licence, diagnostic and security information | Legitimate interests; legal obligation |
| Submit mandatory HMRC fraud-prevention metadata with applicable API requests | Required device, network, software, user and hashed-licence audit metadata | Legal obligation where the relevant HMRC requirement applies; legitimate interests in preventing fraud and securing tax services |
| Respond to enquiries and improve service | Contact details, messages and feedback | Steps toward a contract; legitimate interests |
| Send optional product news | Name, email and preference records | Consent where required; legitimate interests where lawful |
| Support customer-controlled payroll processing | Only information necessary for the selected support or online feature | Contract; documented processor instructions |
6. Local storage, credentials and HMRC services
The website supports downloads, licensing, activation, updates, documentation and support. Where desktop filing credentials are stored, the design protects the password locally using Windows encryption tied to the Windows user. Customers must never send credentials in ordinary email or support messages.
Draft RTI or year-end XML is not proof of submission. Genuine HMRC filing will be offered only after required onboarding, testing and production integration. SMRC will not ask for GOV.UK One Login or Government Gateway sign-in credentials; agent access must use HMRC’s authorised process.
Fraud-prevention headers: the production-onboarding answer is recorded as “Yes”, meaning that every applicable request must include the real header values required for the selected connection method. The supplied desktop code has not yet completed that implementation or HMRC Test API validation, so live filing remains locked. If a required value cannot be collected because of a genuine technical restriction, SMRC must discuss the exception with HMRC rather than inserting a placeholder.
7. Sharing
SMRC does not sell personal information. Information may be shared where necessary and lawful with providers supporting website, email, payment, licensing, security or customer support; HMRC or authorities when authorised or required; professional advisers; courts, regulators or law enforcement; and a genuine business successor with safeguards.
8. International transfers
If a provider processes information outside the UK, SMRC will require a lawful transfer mechanism and safeguards such as UK adequacy regulations, an International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses.
9. Retention
| Record | Normal retention |
|---|---|
| Contracts, invoices and accounting records | Six years after the relevant financial year or relationship, unless longer is legally required |
| Licence and activation records | During the licence relationship and up to six years afterwards |
| General support tickets | Normally 24 months after closure |
| Payroll file deliberately supplied for support | Only while needed, then deleted within 30 days after closure unless agreed or legally required |
| Website and security logs | Normally up to 12 months unless needed for investigation |
| Marketing records | Until consent is withdrawn or an objection is made; a suppression record may remain |
Locally stored payroll information is controlled by the customer, who must apply appropriate payroll, tax, employment and legal retention periods.
10. Security
SMRC uses proportionate safeguards including access control, least privilege, local Windows credential protection, encryption in transit for approved online services, secure development, backups, audit records, vulnerability management, confidentiality and incident response. Customers must protect devices, accounts, exports and backups, use supported systems and install trusted updates.
11. Personal data breaches
Suspected breaches are assessed, contained, investigated and documented. When acting as processor, SMRC notifies the affected controller without undue delay. When controller, SMRC notifies the ICO within 72 hours of awareness where legally required and informs affected individuals where required.
12. Your rights
Depending on the circumstances, individuals may request access, correction, erasure, restriction, objection or portability; withdraw consent; and challenge qualifying solely automated decisions. Where data is held in an employer’s or agent’s payroll file, contact that organisation first because it is normally controller. SMRC normally responds within one month, subject to lawful extensions.
13. Automated calculations
SMRC Pay performs payroll calculations using information and rules selected or entered by the customer. Customers must review and finalise results. The public website does not make solely automated decisions producing legal or similarly significant effects.
14. Cookies
The website may use strictly necessary cookies for security and essential functions. Analytics, advertising or other non-essential cookies will not be placed before legally required consent, and rejecting them will be as easy as accepting them.
15. Customer responsibilities
- Use a lawful basis and provide appropriate privacy notices.
- Keep information accurate, relevant and limited.
- Control access to SMRC, devices, accounts, exports and backups.
- Use HMRC services only with proper authority and protect credentials.
- Review calculations, reports and submissions before finalising.
- Meet retention and deletion duties and report security concerns promptly.
16. Complaints
Contact SMRC first so the concern can be investigated. Individuals may also complain to the UK Information Commissioner’s Office through its data protection complaints service.
17. Changes
This policy may change for legal, regulatory, technical or business reasons. The current version and date will remain on this page, and material changes will receive a prominent notice where appropriate.
18. Contact
M46 LTD trading as SMRC and SMRC Pay
Privacy contact: Mohammed Amin
Email: admin@smrc-pay.com
Website: smrc-pay.com
Registered office: 468 Tyldesley Road, Atherton, Manchester, England, M46 9AT
Company number: 16881593
Registered in: England and Wales
ICO status: no registration number has been supplied or published. M46 LTD should use the ICO’s official data protection fee self-assessment to determine whether it must register and pay the fee.
Regulatory references
This policy is designed with reference to the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations, current ICO guidance and the HMRC Standard for Agents.
The exact ZIP provided for this policy is preserved unchanged.