Privacy Policy
1. Who we are
AkamindTax is operated by Akamind Inc., a U.S. corporation (111 NE 1st St, 8th Floor #88269, Miami, FL 33132). We provide a self-service compliance filing platform for foreign-owned U.S. disregarded entities to complete and submit Form 5472 and Pro Forma Form 1120 to the Internal Revenue Service.
2. What we collect and why
We collect the minimum information necessary to complete your filing:
- Account data — your email address and password. The email is stored encrypted; we retain a one-way hash solely to verify uniqueness at registration.
- Entity data — your LLC's legal name, EIN, U.S. address, formation date, NAICS code, and total assets. Required by the IRS Form 1120 instructions.
- Owner data — the foreign owner's full name, country of citizenship, foreign address, and tax identification numbers (if any). Required by Form 5472 Part II.
- Transaction data — monetary transactions between your LLC and the foreign owner (Parts IV and V of Form 5472). You enter these; we do not independently source them.
- Signature — a digital representation of your handwritten or typed signature, stored to authenticate the filing you submit.
- Payment data — processed by Stripe. We store only the Stripe session ID and payment status. We never see or store your card number.
- Audit log — IP address, timestamp, and action type for every significant event (login, form save, payment, PDF access). Used for fraud prevention and security monitoring.
3. How we protect your data
Security is built into the infrastructure, not bolted on afterward:
- Encryption at rest (AES-256-GCM) — all personally identifiable fields (email, EIN, full name, tax IDs, legal name) are encrypted in the database using AES-256-GCM via libsodium before writing. Each value uses a unique 96-bit random nonce. The encryption key is stored separately from the database.
- Deterministic email hashing — email addresses are additionally stored as HMAC-SHA256 hashes, allowing login lookups without ever decrypting the stored ciphertext unnecessarily.
- Encrypted session storage — sessions use HMAC-signed cookies with server-side state.
- CSRF protection — every state-changing request requires a cryptographic CSRF token tied to your session.
- Rate limiting — login, registration, and payment endpoints enforce per-IP request limits to prevent brute-force and credential-stuffing attacks.
- Two-factor authentication — TOTP-based 2FA (RFC 6238, compatible with Google Authenticator and Authy) is available and enforced for administrative access. TOTP secrets are stored encrypted.
- TLS in transit — all traffic is served over HTTPS/TLS 1.2+. HTTP requests are redirected.
- Auditable access logs — every read of personally identifiable data by any system process is logged to a tamper-evident audit table with timestamp, action, and IP address.
4. Data retention
We retain your filing data for 7 years from the tax year reported. This mirrors the IRS general statute of limitations and allows you to retrieve your historical filings if audited. You may request earlier deletion; we will honor requests except where retention is legally required.
5. Who we share data with
We share your data only to complete your filing:
- IRS — we transmit your completed Form 5472 and Pro Forma 1120 by fax to the IRS Ogden, UT processing center. This is the entire point of the service.
- Stripe — payment processing. Subject to Stripe's privacy policy.
- Sinch — fax transmission. Your PDF is sent to Sinch's fax API to deliver to the IRS. Sinch does not retain fax content after transmission.
We do not use advertising networks. We do not sell, rent, or broker your personal data to any third party.
6. Cookies
We use a single session cookie, set only after login. No tracking pixels, no third-party analytics cookies, no fingerprinting. Cloudflare Turnstile (used on the registration form for bot detection) may set its own cookies subject to Cloudflare's privacy policy.
7. Your rights
Regardless of where you are located, you can:
- Request a copy of the data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data (subject to legal retention requirements)
- Withdraw consent for processing not legally required
To exercise any of these rights, email [email protected] from the address associated with your account. We respond within 30 days.
8. Changes to this policy
We will notify registered users by email at least 14 days before any material change takes effect. The "last updated" date at the top of this page reflects the most recent revision.
9. Contact
Questions or complaints: [email protected]