Last updated: 29 July 2026
This Privacy Policy explains how MOJITAX LIMITED ("MojiTax", "we", "us", "our") collects, uses, shares and protects personal data when you use our website at mojitax.co.uk, our learning platform at lms.mojitax.co.uk, the MojiTax mobile app for iOS and Android (the "App"), and any related services (together, the "Services"). It applies to all visitors, learners, and prospective customers.
MojiTax is a UK-registered company. Our registered office is 11 Bishops Close, Erdington, Birmingham B23 7AY, United Kingdom. We are the data controller for personal data processed through the Services.
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored as a secure hash), country | You, when you sign up |
| Payment data | Transaction amount, currency, payment status | Stripe (we do not store full card numbers) |
| Course data | Courses enrolled in, progress, assessment results, downloads, study plans, and the study preferences you give us (such as your qualification goal, the papers you are taking, and when you plan to sit them) | You, through use of the Services |
| Communication data | Messages to our support team, questions to your Consultant, email engagement | You |
| Assistant chat data | Messages you send to @moji, our AI assistant, the replies it gives you, and — if you chat without signing in — the name and email address you give us before chatting | You, through the chat window |
| Technical data | IP address, browser type, device, pages visited, timestamps | Automatically, via your browser |
| Marketing data | Preferences, consent status, advertising engagement | You, and Google Ads / Google Analytics |
| Mobile app data | Push notification token and device platform (iOS or Android), where you have allowed notifications | Your device, through the App |
When you chat with @moji, our AI assistant, we keep the conversation — your messages and the assistant's replies — as part of your support history, linked to your account or, if you chat as a guest, to the name and email address you give us first. A conversation can be passed to our support team as an enquiry (for example when you ask for a human, or when the assistant cannot answer). The assistant's replies are generated for us by Anthropic — section 4 explains exactly what Anthropic receives. Chat conversations are kept on the same schedule as our other support communications (section 8) and are deleted or anonymised if you delete your account (section 10).
Under the UK GDPR and the Data Protection Act 2018, we rely on: contract — to deliver the Services you have purchased; consent — for marketing communications and non-essential cookies (withdrawable at any time); legitimate interests — to operate, secure and improve our Services, prevent fraud, and measure advertising effectiveness (balanced against your rights); and legal obligation — to keep financial records and respond to lawful requests from authorities.
All third-party processors are contractually bound to process personal data only in accordance with our instructions and applicable data-protection law.
The App is a reader for courses you already have access to. It uses the same account and the same learning platform as our website, so everything set out in this Policy applies to it. This section explains what is specific to the App.
Signing in. When you sign in — with your email and password, a one-time email sign-in link, or a supported social sign-in — the App stores your session token in the secure store your device's operating system provides (Keychain on iOS, Keystore on Android). It is sent to us only to identify you on each request, and it is removed from the device when you sign out.
Push notifications. If you allow notifications, your device is issued a push notification token, which the App sends to us and we store against your account so that we can send you course announcements and platform notices. We do not receive a token unless you grant that permission, and you can withdraw it at any time in your device's notification settings.
Offline downloads. Chapters and library PDFs you download for offline study are encrypted and stored on your device, together with a local record of how long your offline access lasts. That content stays on your device: it is never uploaded to us and we cannot read it. You can remove individual downloads, or every download for a course, on the App's Downloads screen. Signing out does not remove downloads — they remain encrypted on the device, stop being readable when your offline access lapses or your access to the course ends, and are deleted by the App after that. If you delete your account, the App removes every download from the device you used to make the request.
What the App does not do. The App contains no advertising, no advertising identifiers, and no third-party analytics or crash-reporting software. It does not access your location, contacts, camera, microphone, photos or health data, and it does not take payments. No data collected in the App is used to track you across other companies' apps or websites.
See our Cookie Policy for the cookies used on the learning platform. Analytics and advertising cookies are set only with your consent.
Some of our processors (e.g. Google, Stripe, Cloudflare, Anthropic) operate globally. Where personal data is transferred outside the United Kingdom or the European Economic Area, we rely on appropriate safeguards including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or adequacy decisions.
These are the periods that apply if you leave your account in place. If you ask us to delete your account, we do not wait for them: we delete or anonymise the personal data described above within 30 days, and keep only the records the law requires us to keep, together with the fraud-prevention records described above, which expire on their own 12-month schedule. Section 10 explains what that means in practice.
Under the UK GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data ("right to be forgotten"), subject to legal exceptions; object to or restrict certain processing, including direct marketing; request data portability; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, contact us using the details below — we respond within one month, as required by law. You may also lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.
You can delete your MojiTax account at any time. In the App, open the Profile tab, tap Delete account, then confirm twice. If you cannot sign in, or you no longer have the App, email compliance@mojitax.com from the address on your account and we will action the request for you. There is no charge, and you do not need an active subscription to ask.
Deleting your account takes effect straight away. Your account is deactivated, you are signed out on every device, your access to all courses ends, push notifications stop, and any active subscription is cancelled immediately — we do not refund the remainder of a period you have already paid for. The personal data we hold about you is then deleted or anonymised within 30 days. Records we are required by law to keep are retained, in particular payment records, which we hold for six years because UK tax and accounting law requires it. Our Delete your account page sets out the whole process in full.
Three details of how that deletion works. First, when we erase your data we place the removed records in a locked quarantine store for up to 30 days, so that an account deleted by mistake — or by someone who was not you — can be put back exactly as it was; at the end of that window the quarantined copy is deleted automatically and the erasure becomes final. Second, our log of the emails we have sent you is redacted rather than deleted: the message content, subject and email address are removed, and we keep only which template was sent to your account, when, and whether it was delivered — the record that proves what we sent, with nothing personal left in it. Third, the fraud-prevention records described in section 8 are kept for up to 12 months from when they were recorded, because they exist to stop the abuse they detect from being repeated through a new account; they are deleted automatically when that period ends.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS) and at rest where appropriate, access controls, multi-factor authentication for staff accounts, continuous off-site backups, and regular security review. No system is completely secure; if a personal data breach occurs, we will notify you and the ICO where required by law.
The Services are intended for tax professionals and adult learners. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, contact us and we will delete it.
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be notified by email to active account holders.
Data Controller: MOJITAX LIMITED
Registered office: 11 Bishops Close, Erdington, Birmingham B23 7AY, United Kingdom
Email for privacy matters: compliance@mojitax.com
General contact: support@mojitax.com
MOJITAX LIMITED (trading as "MojiTax") is a company registered in England and Wales, company number 13857853. Registered office: 11 Bishops Close, Erdington, Birmingham B23 7AY, United Kingdom. Contact: support@mojitax.com.
Terms of Service · Privacy Policy · Refund Policy · Cookie Policy