Privacy Policy
Last Updated: 8 August 2026
This Privacy Policy sets out how Mikilyuto ("we", "us", "our") collects, uses, stores, and protects personal data in connection with the operation of our bookkeeping automation platform and website at Mikilyuto.com. We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018. The Information Commissioner's Office (ICO) is the supervisory authority for data protection matters in the United Kingdom.
1. Data Controller
The data controller responsible for your personal data is Mikilyuto, registered in England and Wales, with its registered office at 101 Whitehouse Ln, South Yorkshire, Sheffield S6 2UY. If you have any questions about how we handle your personal data or wish to exercise any of your rights under applicable data protection law, please contact us by email at [email protected] or by post to the registered office address above. We will endeavour to respond to all enquiries within the timeframes required by UK GDPR.
2. Categories of Personal Data We Collect
We collect and process different categories of personal data depending on how you interact with us. When you visit our website, we may collect technical data such as your IP address, browser type and version, operating system, referral source, pages viewed, and the duration of your visit. This data is collected automatically through cookies and similar technologies, details of which are set out in our Cookie Policy. When you submit an enquiry via our contact form, we collect your name, email address, and the content of your message. If you use the Mikilyuto platform, we may additionally collect business name, contact details of authorised users, and financial transaction data that you connect to the platform. We do not knowingly collect personal data from individuals under the age of 18.
3. Lawful Basis for Processing
We process personal data only where we have a lawful basis for doing so, as required by Article 6 of the UK GDPR. The lawful bases we rely on are as follows. For enquiries submitted via the contact form, processing is carried out on the basis of your consent, which you provide by submitting the form after confirming that you have read this Privacy Policy. For the operation of the platform and fulfilment of any contractual relationship with users, we process personal data on the basis of contract performance under Article 6(1)(b). Where we have a legal obligation to retain or disclose certain records, we process personal data on the basis of legal obligation under Article 6(1)(c). Where we have a legitimate business interest in understanding how our website is used in order to improve it, we may process technical and analytical data on the basis of legitimate interests under Article 6(1)(f), having balanced those interests against your rights and freedoms.
4. How We Use Your Personal Data
Personal data collected through our website is used to respond to your enquiries, to operate and improve our website, and to understand how visitors interact with our content. Personal data collected in connection with the platform is used to deliver the bookkeeping automation services you have requested, to maintain your account, to provide technical support, and to communicate with you regarding your use of the platform. We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review. We do not sell your personal data to third parties. We do not use your personal data for unsolicited commercial marketing unless you have separately consented to receive such communications.
5. Data Sharing and Third Parties
We do not share your personal data with third parties except in the following circumstances. We may share data with trusted service providers who assist us in operating our website and platform, such as hosting providers, email delivery services, and analytics providers. These providers act as data processors under written agreements that require them to process data only on our instructions and in compliance with UK GDPR. We may share data where we are required to do so by law, regulation, court order, or at the request of a competent authority. We may share data in connection with a corporate transaction such as a merger, acquisition, or transfer of business assets, in which case we will notify affected individuals in advance where practicable. All third-party service providers we engage are selected with regard to their data protection practices, and where applicable, we ensure that adequate safeguards are in place for any international transfers of personal data.
6. International Data Transfers
Our primary data processing activities take place within the United Kingdom. Where we engage third-party service providers who may process personal data outside the UK, we ensure that appropriate safeguards are in place as required by Chapter V of the UK GDPR. This may include reliance on adequacy decisions made by the Secretary of State, the use of International Data Transfer Agreements (IDTAs) approved by the ICO, or other lawful transfer mechanisms. If you would like more information about the specific safeguards applicable to any particular transfer, please contact us using the details in section 1.
7. Data Retention
We retain personal data for no longer than is necessary for the purposes for which it was collected, taking into account our legal and regulatory obligations. Enquiry data submitted via the contact form is retained for a period of 24 months, after which it is securely deleted unless a contractual relationship has been established. Platform user data is retained for the duration of the account relationship and for a period of up to six years following the termination of that relationship, to comply with legal and financial record-keeping obligations. Technical and analytical data collected via cookies is retained in accordance with the retention periods described in our Cookie Policy. Where retention is required by law, we will retain data for the minimum period necessary to fulfil that obligation.
8. Security of Personal Data
We take the security of personal data seriously and implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include encryption of data in transit using TLS and encryption of data at rest, access controls limiting data access to authorised personnel on a need-to-know basis, regular review of our security practices, and staff training on data protection responsibilities. Notwithstanding these measures, no method of data transmission or storage is entirely secure. We cannot guarantee absolute security, and any transmission of personal data is at your own risk. If you believe your personal data has been compromised, please contact us immediately at [email protected].
9. Your Rights Under UK GDPR
You have the following rights in relation to your personal data under UK GDPR. The right of access: you may request a copy of the personal data we hold about you. The right to rectification: you may request that we correct inaccurate or incomplete personal data. The right to erasure: in certain circumstances, you may request that we delete your personal data. The right to restriction of processing: you may request that we restrict processing of your data in certain circumstances. The right to data portability: where processing is based on consent or contract and carried out by automated means, you may request that we provide your data in a structured, commonly used, and machine-readable format. The right to object: you may object to processing based on legitimate interests or for direct marketing purposes. The right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal. To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month. You also have the right to lodge a complaint with the ICO at ico.org.uk if you believe we have not handled your personal data in accordance with applicable law.
10. Cookies
Our website uses cookies and similar tracking technologies. Full details of the cookies we use, their purposes, and how to manage your preferences are set out in our Cookie Policy, which is available at Mikilyuto.com/cookies.html. By continuing to use our website after being presented with the cookie consent notice, you acknowledge that you have been given the opportunity to manage your cookie preferences.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or our services. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our website or platform after any changes to this policy constitutes your acknowledgement of the updated terms. If changes are significant, we will take additional steps to notify platform users directly where we hold contact information for them.
12. Contact and Complaints
All enquiries, requests to exercise your data protection rights, and complaints relating to this Privacy Policy should be addressed in writing to Mikilyuto, 101 Whitehouse Ln, South Yorkshire, Sheffield S6 2UY, or by email to [email protected]. If you are not satisfied with our handling of your complaint, you have the right to escalate the matter to the Information Commissioner's Office. The ICO can be contacted at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.