Terms of Service

Effective 6 August 2026 · Last updated 6 August 2026

1. What BankScan AI is

BankScan AI (the "Service") parses UK bank statements and receipts, can import read-only account information through GoCardless Bank Account Data, categorises the resulting transactions against HMRC's MTD ITSA taxonomy, and — once HMRC recognition is granted — submits quarterly updates to HMRC on behalf of the user (the "Customer").

The Customer is the subscribing practice or individual subscriber. An "Authorised User" is a staff member the Customer permits to use its workspace. "Client Data" is information supplied about the Customer's clients and their contacts.

The Service is operated by BankScan AI (trading name; the underlying legal entity is Mitoba Consulting Ltd, registered in England & Wales). Contact: mitchellagoma@gmail.com.

2. Who can use the Service

BankScan AI is not authorised by the Financial Conduct Authority. When a Customer enables a bank feed, GoCardless provides the regulated bank-facing Account Information Service under its own terms and permissions. That does not make BankScan AI FCA-authorised. We do not provide regulated financial, accounting, investment, or legal advice.

3. Customer responsibilities

3a. Read-only bank feeds

A Customer may ask the Service to create a connection through GoCardless Bank Account Data. GoCardless handles bank selection, authentication and the account holder’s authorisation. BankScan AI does not receive the bank username or password and the integration does not give BankScan authority to make payments or move money. Use of that connection is also subject to the applicable GoCardless Bank Account Data terms.

After a successful connection, the Service periodically retrieves available account information and imports newly booked transactions into the selected client’s Ledger. Pending transactions are not added until the bank reports them as booked. Bank coverage, history, update frequency and consent duration vary by institution and provider; the Customer may need to reconnect when consent expires.

The feed is a collection aid, not a guarantee of real-time data, completeness or accounting reconciliation. Customers must compare the Ledger with the bank’s own records and review any duplicate, changed, missing or delayed item before relying on it.

Disconnecting stops future imports and asks GoCardless to revoke the connection. Transactions already imported remain in the Ledger to preserve the Customer’s accounting record and provenance unless the controller later deletes them under its retention policy.

4. MTD ITSA filing

The Service offers a one-click submission flow for quarterly updates once the Customer has signed up for MTD Income Tax, connected the correct National Insurance number and businesses, and given the Service explicit OAuth consent.

Filed submissions become the Customer's legal record with HMRC. BankScan AI provides an audit trail (the "Submission history") and lets the Customer correct their digital records and send an amended cumulative update where HMRC's current rules permit it. Earlier accepted submissions remain part of the HMRC audit trail.

BankScan AI's current HMRC build stage is an in-year product. Quarterly updates are not tax returns. The Service does not currently submit the annual tax return or support every possible source of income, gain, loss, relief or adjustment. The Customer must use HMRC-recognised compatible end-of-year software for that separate return by the applicable 31 January deadline.

For an account that remains connected to HMRC, the Service may send transactional reminders for quarterly-update deadlines reported by HMRC. Reminders are a best-effort convenience, not a substitute for checking the Customer's HMRC account or meeting legal deadlines. Disconnecting HMRC stops and invalidates unsent reminders.

A practice owner or admin may separately enable transactional client deadline reminders. The Service schedules these 14 days and 1 day before an eligible stored return deadline. Practice-level activation and a fresh authorisation bound to the contact's current address are both required; a legacy preference alone never triggers email.

The practice acts as controller for the contact data and instructs BankScan AI as processor. Each reminder identifies the practice, provides a way to contact it and includes a direct opt-out. An opt-out, address change, filing/payment, archive or practice disable cancels affected future reminders.

Until BankScan AI appears on the GOV.UK list of MTD ITSA-recognised software, no Customer may use the Service to submit a return to live HMRC services. Sandbox / test-API submissions are unrestricted.

5. Subscription & payment

Plans, prices, and trial terms are shown at the point of purchase. Billing is handled by Stripe; BankScan AI does not store full card details. Cancellation takes effect at the end of the current billing period.

Refunds are at our discretion. We will not unreasonably withhold a refund for unused time within the first 14 days of a paid plan.

6. Data, accuracy & limitations

The Customer acts as controller for Client Data and instructs BankScan AI to process it only as needed to provide the Service. Authorised Users must access only clients they are permitted to serve.

7. Acceptable use

Customers must not:

8. Intellectual property

The Service software, designs, and trade marks belong to BankScan AI. The Customer retains ownership of their uploaded data, Client Data, imported bank records and any submissions filed via the Service, subject to the connected bank’s and provider’s applicable rights and terms.

9. Liability

To the maximum extent permitted by law, BankScan AI's aggregate liability arising out of or in connection with the Service is capped at the fees the Customer paid in the 12 months preceding the claim. We exclude liability for indirect, special, or consequential loss.

Nothing in these Terms limits liability for death, personal injury caused by negligence, or fraudulent misrepresentation.

10. Termination

Either party may terminate the agreement at any time. The Customer can delete their account from the dashboard; we will erase personal data per the Privacy Policy except where retained for legal or tax-evidence purposes.

Closing an account or client workspace stops BankScan’s active polling. The Customer should use Disconnect first when it wants the Service to send GoCardless a provider-revocation request. Removing one staff user does not disconnect a practice-owned feed unless the workspace owner also closes that client or connection.

Removing one Authorised User removes that user's access but does not close the practice workspace or erase shared Client Data. A final owner must transfer ownership or explicitly close the workspace. Archived records and HMRC audit evidence follow the retention rules in the Privacy Policy.

We may suspend or terminate accounts that breach these Terms or that we reasonably suspect are being used for fraud or other unlawful activity.

11. Changes to these Terms

We may update these Terms. Material changes will be announced via email or in-app notice at least 14 days in advance. Continued use after the effective date constitutes acceptance.

12. Governing law

These Terms are governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.