1. About this policy

This privacy policy explains how DIGI Accountancy Ltd collects, uses, shares, and protects personal data.
It applies to:

•   visitors to our website www.wearedigi.co.uk;
•   clients and prospective clients who engage us to provide accountancy, tax, payroll, and related services, including individual clients, sole traders, and partners;
•   individuals connected with our clients, including directors, shareholders, beneficial owners, and employees whose personal data we process in the course of providing services;
•   business contacts at organisations we work with, market to, or partner with;
•   suppliers and contractors;
•   individuals whose personal data we process on behalf of our clients in the course of delivering services, for example employees included in a payroll we run for a client.

This policy does not cover the processing of personal data relating to our own employees and workers, which is dealt with in the Employee Privacy Notice issued under our Employee Handbook.

We use the terms “UK GDPR” to mean the United Kingdom General Data Protection Regulation, “DPA 2018” to mean the Data Protection Act 2018, “PECR” to mean the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended, and “MLR 2017” to mean the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. References to “we”, “us”, and “our” are to DIGI Accountancy Ltd

2. Who we are and how to contact us

DIGI Accountancy Ltd is the data controller for the personal data described in this policy, except where this policy states that we act as a data processor on behalf of a client.

Our details
•   Registered name: DIGI Accountancy Ltd
•   Company number: 12593143
•   Registered office: Sun House, 2-4 Little Peter Street, Manchester, M15 4PS
•   ICO registration number: A8817650

Data protection contact

Questions about this policy, requests to exercise your data protection rights, and any other data protection matters should be directed to:
•   Email: hello@wearedigi.co.uk
•   Post: Adam Rawling, DIGI Accountancy Ltd, Sun House, 2-4 Little Peter Street, Manchester, M15 4PS.

We are not required under Article 37 of the UK GDPR to appoint a Data Protection Officer. We have nominated a senior member of the management team to act as our data protection contact and to oversee compliance with data protection law across the firm.

3. Personal data we collect, and why

We collect different categories of personal data depending on your relationship with us. This section describes each category, the data we collect, where we get it from, what we use it for, and our lawful basis for doing so.

3.1 Website visitors
When you visit our website we may collect:
•   technical information from your device and browser (including IP address, device type, browser type, operating system, and pages visited);
•   information about how you interact with the website (pages viewed, time spent, referral source, broad geographic region);•   any information you choose to provide through online forms, enquiries, or newsletter sign-ups.We use this data to operate, secure, and improve our website, to respond to enquiries, and, where you have consented, to send you our newsletter and other communications. Further information on cookies and analytics is set out in section 9.

Lawful basis: legitimate interests (operating, securing and improving our website, and responding to enquiries); consent for non-essential cookies and electronic marketing under PECR.

3.2 Clients and prospective clients
When you engage us to provide services, or speak to us about doing so, we collect:
•   name, contact details, and (for business clients) job title, organisation, business address, business email address, and business telephone number;
•   financial and tax information needed to deliver the services you have engaged us for, which may include accounting records, bank statements, income and expenditure details, tax references (such as UTR and National Insurance number), VAT and PAYE registration details, and information about assets, liabilities, and investments;
•   information about your business, its ownership, and its officers, including details of directors, shareholders, and persons with significant control;
•   contractual and financial information needed to administer the engagement, including engagement letters, invoices, and payment details;
•   correspondence and notes of meetings, calls, and other interactions.We use this data to deliver the services we have agreed with you (including preparing accounts and tax returns, providing tax and business advice, running payroll, and dealing with HMRC and Companies House as your agent), to manage our relationship with you, to comply with our legal, regulatory, and professional obligations, and, where appropriate, to keep you informed about other services we offer.

Lawful basis: performance of a contract (or to take steps prior to entering into a contract); legal obligation (tax, accounting, anti-money laundering, and other statutory and regulatory requirements); legitimate interests (managing client relationships and informing clients about related services).

3.3 Identity verification and anti-money laundering checks
As an accountancy practice, we are subject to the MLR 2017 and are required to carry out customer due diligence before acting for a client and to keep that due diligence under review. For these purposes we collect:
•   identity documents (such as a passport or driving licence) and proof of address;
•   information about the ownership and control of client entities, including the identity of beneficial owners;
•   the results of electronic identity verification, sanctions, and politically exposed person (PEP) screening checks, which we may obtain from third-party verification providers and other publicly available sources;
•   records of the checks we have carried out and the conclusions we have reached.

Lawful basis: legal obligation (compliance with the MLR 2017 and related legislation).
Where our checks involve criminal offence data (for example, information arising from sanctions or adverse media screening), we process it in accordance with Article 10 UK GDPR and the conditions in Schedule 1 of the DPA 2018 relating to the prevention and detection of unlawful acts and compliance with regulatory requirements.

3.4 Individuals connected with our clients
In the course of providing services to a client we often process personal data about individuals connected with that client, for example directors, company secretaries, shareholders, beneficial owners, partners, and employees. This may include names, contact details, dates of birth, remuneration and benefits information, National Insurance numbers, pension details, and bank details.Where we run a payroll or provide similar services for a client, we generally act as a data processor, processing the personal data of the client’s employees only on the documented instructions of our client and under a written processing agreement that meets the requirements of Article 28 UK GDPR. If you are an employee of one of our clients, your data protection rights are exercised in the first instance against your employer. We will, however, assist our client to respond to any request you make. You can also contact us using the details in section 2.

Lawful basis (where we act as controller): legal obligation (for example, filing statutory returns that identify officers and shareholders); legitimate interests (delivering the services our client has engaged us to provide); performance of a contract where the individual is themselves our client.

3.5 Business contacts and prospects
We identify and contact organisations that may be interested in our services. The data we hold typically includes business contact details (name, job title, organisation, business email, business telephone) and notes of our interactions. This data is generally obtained from publicly available business sources, business directories, networking events, referrals, or directly from the individual concerned.Lawful basis: legitimate interests (developing our business and informing organisations about services that are likely to be relevant to them). We carry out a documented legitimate interests assessment for our business development activity.

Direct marketing (PECR):
we send electronic marketing communications to corporate subscribers (companies, limited liability partnerships, public bodies) on the basis of legitimate interests, with a clear and free opt-out in every communication. To individual subscribers (including sole traders and non-LLP partnerships in most cases), and to personal email addresses, we send electronic marketing only with prior consent or where the soft opt-in conditions under PECR are met.

3.6 Suppliers and contractors
We process contact and contractual information about our suppliers and contractors, including the names, business contact details, and (where applicable) bank details of individuals through whom we deal with supplier organisations. We use this data to manage our supply chain, place and receive deliveries of goods and services, pay invoices, and meet our legal obligations.

Lawful basis: performance of a contract (or steps prior to a contract); legitimate interests (operating our supply chain); legal obligation (tax, accounting, anti-money laundering, and other statutory obligations).

4. Special category and criminal offence data

Some of the personal data we process may be “special category data” under Article 9 of the UK GDPR, such as data concerning health. This arises most often where health information is relevant to a service we are providing, for example statutory sick pay or other health-related payments processed through a payroll, or where a client or contact chooses to tell us about a health condition or accessibility requirement so that we can support them appropriately. We process special category data only where we have both a lawful basis under Article 6 and a separate condition under Article 9, most commonly:

•   Article 9(2)(b) – employment, social security and social protection law,
where the processing is necessary to meet obligations arising under employment or social security law (for example, payroll processing involving statutory payments);

•   Article 9(2)(a) – explicit consent, where you choose to share information with us voluntarily, and you can withdraw that consent at any time.We also process criminal offence data in the limited circumstances described in section 3.3 (anti-money laundering screening). We maintain an Appropriate Policy Document, as required by Schedule 1 Part 4 of the DPA 2018, setting out our procedures for compliance with the data protection principles when we process special category data and criminal offence data.

5. How we share personal data

We share personal data only where it is necessary to do so for the purposes set out in this policy, and only with recipients who are appropriate and (where they are processors acting on our behalf) bound by a written processing agreement.

The recipients we share personal data with include:
•   HM Revenue & Customs, Companies House, and other government bodies, where we make filings or handle correspondence on your behalf as your agent, or where we are otherwise required to share data with them by law;
•   providers of the cloud accounting, payroll, tax, and practice management software we use to deliver our services, and other approved suppliers including IT and cloud service providers;
•   third-party identity verification and screening providers, for the purposes described in section 3.3;
•   professional advisers (including lawyers and insurers) and our professional body, including in connection with practice assurance and quality review visits and with our anti-money laundering supervision;
•   banks, lenders, and other third parties (such as mortgage brokers or grant bodies), where you ask us to provide references or financial information to them;
•   law enforcement, regulators, and other public authorities, where we are legally required to share data (including making reports under the Proceeds of Crime Act 2002 where required) or where we consider sharing is necessary to protect a vital interest, prevent serious harm, or protect the integrity of our firm;
•   third parties involved in any actual or proposed reorganisation, merger, sale, or transfer of assets affecting our firm, subject to appropriate confidentiality safeguards.We do not sell personal data and we do not share personal data with third parties for their own independent marketing purposes.

6. International transfers

Most personal data that we process is stored on systems located in the United Kingdom or the European Economic Area. Some of the third-party service providers we use (for example, providers of website analytics, email, cloud accounting, and cloud storage services) operate platforms that involve transfers of personal data to countries outside the UK, including the United States.

Where we transfer personal data outside the UK to a country that is not the subject of UK adequacy regulations, we put in place one of the safeguards permitted by the UK GDPR. These include the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or, where applicable, our supplier’s certification under the UK extension to the EU-US Data Privacy Framework. We carry out a transfer risk assessment before relying on these mechanisms.

You can request further information about the safeguards we apply to a particular transfer by contacting us using the details in section 2.

7. How long we keep personal data

We keep personal data only for as long as we need it for the purposes for which it was collected, plus any further period that is necessary to meet our legal, regulatory, or accounting obligations or to manage potential disputes. The table below summarises our standard retention periods. Where a specific engagement, legal obligation, or regulatory requirement requires a different period, that period takes precedence.

Category of data Retention period Notes
Client engagement files, accounts, and tax records 7 years from the end of the engagement or the relevant accounting period, whichever is later Limitation Act / HMRC and Companies Act record-keeping
Customer due diligence and AML records 5 years from the end of the business relationship (or the date of the relevant transaction), unless a longer period is required by law Regulation 40 MLR 2017
Payroll records processed on behalf of clients For the duration of the engagement and as instructed by the client, subject to statutory minimums Processed under client instructions
Business development and prospect contact data 3 years from last meaningful engagement, subject to refresh Reviewed annually
Marketing consent and opt-out records Retained for as long as needed to evidence compliance with PECR and the UK GDPR; opt-out records retained indefinitely as a suppression record PECR evidence
Supplier records 7 years from end of supplier relationship Accounting
Website analytics data As set out in section 9 and in our cookie notice See cookie table
Records relating to the exercise of data subject rights 3 years from completion of the response Accountability
Personal data breach records 6 years from the date the breach is closed Article 33(5) UK GDPR

8. Your rights

You have a number of rights under the UK GDPR in relation to personal data we hold about you. We will respond to a valid request to exercise these rights within one month of receipt. We may extend this period by up to a further two months where a request is complex or where we receive a number of requests from you, and will tell you within the first month if we need to do so.

•   Right to be informed. You have the right to be told what personal data we hold about you, how we use it, and who we share it with. This policy is part of how we meet that duty.

•   Right of access. You have the right to request a copy of the personal data we hold about you and information about how we are using it. There is no charge unless your request is manifestly unfounded or excessive, or you ask for additional copies of the same information.

•   Right to rectification. You can ask us to correct personal data that is inaccurate or incomplete.

•   Right to erasure. In certain circumstances you can ask us to delete personal data we hold about you. This right is not absolute and does not apply where we are required or permitted by law to keep the data (for example, records we must retain under tax or anti-money laundering legislation).

•   Right to restriction of processing. In certain circumstances you can ask us to limit how we use your personal data, for example while we investigate a complaint about its accuracy.

•   Right to data portability. Where we process your personal data by automated means on the basis of your consent or a contract with you, you can ask us to provide it to you (or to a third party you nominate) in a structured, commonly used, machine-readable format.

•   Right to object. You have the right to object to our processing of your personal data where we are relying on legitimate interests. You have an absolute right to object to processing for direct marketing purposes.

•   Rights relating to automated decision-making and profiling. You have the right not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects on you. We do not make decisions of this kind (see section 11).

•   Right to withdraw consent. Where we rely on your consent to process your personal data, you can withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.

To exercise any of these rights, please contact us using the details in section 2. We may ask you for information to verify your identity before responding. Please note that some rights are limited where the law requires us to keep or continue processing data, for example records we hold under the MLR 2017.

9. Cookies and analytics

Cookies are small text files that are placed on your device when you visit a website. We use cookies on our website to make it work, to remember your preferences, and to understand how visitors use the site. The table below describes the cookies we use and their purpose.

We do not place non-essential cookies on your device unless you have given consent through our cookie banner. You can change or withdraw your consent at any time using the cookie settings on the website. You can also control cookies through your browser settings.

Google Analytics collects information that may include IP addresses (which are truncated before storage), device and browser information, and aggregated information about how visitors use the website. We do not use this information to identify individual visitors. Google’s privacy information is available at policies.google.com/privacy.

10. Direct marketing

We send marketing communications about our work and services to clients, prospects, partners, and people who have asked to hear from us. We always make it easy to opt out, and we keep a record of opt-outs so that we do not contact you again by that channel

.You can opt out of marketing communications at any time by:

•   clicking the unsubscribe link in any marketing email;
•   emailing hello@wearedigi.co.uk;
•   writing to us at the address in section 2.

Opting out of marketing does not stop us from sending you communications that we are required to send in order to deliver a service to you (for example, reminders about filing deadlines for an engagement we are handling on your behalf, or information about work we are carrying out for you).

11. Automated decision-making and profiling

We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you. We use website analytics to understand aggregate patterns of website use, and automated tools may be used as part of identity verification checks, but in each case any decision that significantly affects you involves human review.

12. How we protect personal data

We have appropriate technical and organisational measures in place to protect personal data against unauthorised access, accidental loss, alteration, and disclosure. These include access controls, encryption in transit and at rest where appropriate, secure premises and storage, staff training on data protection and confidentiality, and contractual safeguards with the suppliers and processors we use.

The nature of our work means we routinely handle sensitive financial information. Where we share or store particularly sensitive material (for example, payroll data or identity documents), we apply additional controls including password protection, encrypted storage and transfer, restricted access, and secure destruction at the end of the applicable retention period. We document these controls and can provide a summary to clients on request.

13. Personal data breaches

We take any actual or suspected personal data breach seriously. Where we become aware of a breach that is likely to result in a risk to the rights and freedoms of individuals, we will report it to the Information Commissioner’s Office within 72 hours, in line with Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify those individuals without undue delay, unless one of the exceptions in Article 34(3) applies. Where we act as a processor for a client, we will notify the client without undue delay after becoming aware of a breach affecting their data.

If you believe that a personal data breach affecting you has occurred and we have not contacted you about it, please get in touch using the details in section 2.

14. Complaints

If you are unhappy with how we have handled your personal data, please contact us first using the details in section 2 so that we have the opportunity to put things right.

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):

•   Website: ico.org.uk
•   Helpline: 0303 123 1113
•   Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

15. Changes to this policy

We review this policy regularly and may update it from time to time to reflect changes in our processing activities, in the law, or in regulatory guidance. The current version is identified in the footer of this document. Where changes are significant, we will publish notice of them on our website and (where appropriate) contact you directly.This policy supersedes any previous version of the DIGI Accountancy privacy policy.

Newsletter

Subscribe to our newsletter and stay up to date on our latest news and promotions!