Privacy
Privacy Policy
What is this policy for?
We take issues relating to your personal data really seriously. This policy explains how we handle your, or your employees’, personal data.
What do various terms mean?
“Personal data” means recorded information we hold about you (if you are an individual) or your staff (if you are an organisation) from which you or another person can be identified. It may include contact details, other personal information, photographs, expressions of opinion or indications as to our or your intentions towards a person.
“Processing” means doing anything with the data, such as accessing, disclosing, destroying or using the data in any way.
“Sensitive personal data” or “special categories of data” includes:
- information about a person’s physical or mental health or condition;
- racial or ethnic origin or religious or similar information;
- information about a person’s sexual life;
- information about a person’s criminal record or criminal proceedings;
- whether you are a trade union member or not;
- biometric information.
Generally, we do not need any such sensitive personal data to perform our services for you and we will not seek such information from you.
What purposes do you use personal data for?
We only process data for the purposes we have agreed with you or where it relates to:
- carrying out the terms of our retainer with you or the organisation you work for, where we need to consider the data when advising, in order to give the best advice;
- complying with legal requirements (such as our professional obligations to our regulator);
- pursuing our legitimate interests (such as being able to communicate with you and update you regarding our services);
- something necessary for the protection of a person’s vital interests (this is likely to be exceptional);
- something you have consented to, or where the data has been made public by you.
What safeguards are in place?
We will comply with the data protection principles, which say that personal data must be: processed fairly and lawfully; processed for limited purposes and in an appropriate way; adequate, relevant and not excessive for the purpose; accurate; not kept longer than necessary for the purpose; processed in line with individuals’ rights; secure; and not transferred to people or organisations situated in countries without adequate protection. We don’t transfer any client data outside of the UK.
Your personal data will only be processed to the extent that it is necessary for the specific purposes notified to you. We will keep the personal data we store about you accurate and up to date. Please notify us if your personal details change or if you become aware of any inaccuracies in the personal data we hold about you.
We will not keep your personal data for longer than is necessary for the purpose of carrying out our retainer. For regulatory purposes we are required to keep our files for a six year period, after which they are securely destroyed.
We have procedures and technologies in place to maintain the security of all personal data from the point of collection to the point of destruction. For example:
- Staff are trained in the importance of privacy and data security.
- Laptops and phones are encrypted.
- We don’t give advice via social media or text message.
- Electronic files can only be accessed via password logins.
- No visible labels on physical files or documents, for example when visiting your premises.
We will only pass your data to third parties where you have asked us to, for example if you ask us to refer your contact details to other professionals such as tax experts or lawyers. We only make referrals of this kind when consent has been expressly given by you. We do not sell any data or pass any data to other organisations.
What rights do I have?
- Request access to any personal data we hold about you. To make a subject access request, tell us in writing, specifying as far as possible which data you are interested in.
- Ask to have inaccurate data held about you amended or deleted.
- Prevent processing that is likely to cause unwarranted substantial damage or distress to you or anyone else.
- Raise a complaint with us under our Complaints Policy if you have any concerns about the handling of your data, or ask the Information Commissioner’s Office for support in relation to a data protection issue.
- Be notified of high risk breaches of the law.
What about third parties?
We will not disclose your personal data to a third party without your consent unless we are satisfied that they are legally entitled to the data. Where we do disclose your personal data to a third party, we will have regard to the data protection principles.
What if we process data for you (organisations)?
From time to time we are asked to process data on your behalf. In engaging us you agree that you are a Controller and that we are a Processor of the protected data, and that you will comply with all data protection laws in connection with that processing. We will process protected data only in accordance with this policy and your documented instructions, keep it secure, not use sub-processors without your written authorisation, not transfer it outside the UK without your prior written consent, assist you (at your cost) with your obligations under Articles 32 to 36 of the GDPR and with data subject requests, notify you without undue delay of any personal data breach, make available the information necessary to demonstrate compliance (including one audit request in any 12 month period), and at the end of our services return or securely dispose of the protected data unless the law requires us to keep it.
This website
Messages sent through the contact form on this website are emailed to us and used only to respond to your enquiry. The form is protected by Google reCAPTCHA to prevent spam; Google’s Privacy Policy and Terms of Service apply to that service.
