About This Policy
This Privacy Policy describes how GDS ACCOUNTANTS LTD collects, uses, stores, shares and otherwise processes personal information when you visit our website, contact the practice, or engage us to provide accounting, tax, bookkeeping, payroll or company secretarial services. It applies to clients, prospective clients, website visitors, suppliers, contractors and any other individual whose information reaches the practice. The developer named in the introduction to this policy is GDS Accountants, which is the trading identity used by the registered company. We are committed to handling personal information lawfully, fairly and transparently, and to keeping it accurate and secure for as long as we need it. Please read this policy carefully, and if anything is unclear, contact us using the details at the end before you provide any information to the practice.
Who We Are
The data controller responsible for your personal information is GDS ACCOUNTANTS LTD, a company registered in the United Kingdom. Our registered office and principal place of business is 71-75 Shelton Street, Covent Garden, LONDON - WC2H 9JQ, United Kingdom (GB). We provide computer integrated systems design and related accounting, tax preparation, bookkeeping and payroll services. When this policy refers to the Company, to we, to us or to our, it means GDS ACCOUNTANTS LTD. When it refers to you, it means the individual whose personal information we process, including a client contact, a director, a shareholder, an employee on a payroll we administer, a sole trader, a landlord, or a visitor to this website.
Because we are established in the United Kingdom, we process personal information in line with the data protection legislation that applies there, together with the wider framework of rules that govern the confidentiality of accounting and tax work. Where we act as an agent for a client, we may process personal information on that client behalf, and in those circumstances the client remains responsible for the lawfulness of the processing while we apply the safeguards described in this policy and in our engagement terms.
Information We Collect
The categories of personal information we may collect and process include the following. Identity information such as your full name, title, date of birth, national insurance number, unique taxpayer reference, company registration number, passport or identity document details where verification is required, and signature. Contact information such as your postal address, email address, telephone number, and the details of any authorised representative. Financial information such as bank account details, payment card details where a transaction is processed, invoice and payment records, income and expenditure figures, asset and liability details, loan and mortgage information, and tax payment history. Employment information such as your job title, employer, salary, benefits, pension arrangements, tax code, student loan plan and statutory leave records. Technical information such as your internet protocol address, browser type, device type, and the pages you viewed on this website.
We may also process special category information where it is necessary and lawful to do so, for example health information that supports a statutory sick pay claim, or information about trade union membership where a payroll deduction requires it. We collect only the information that is relevant to the service being provided, and we do not seek special category information unless a legal obligation or the service itself requires it.
How We Collect Information
We collect personal information directly from you when you complete a form on this website, send us an email, telephone the practice, or provide documents and records in the course of an engagement. We collect information automatically when you browse this website, through the ordinary technical records that a web server and browser exchange. We collect information from third parties in certain circumstances, for example from your bank where you authorise us to access statements, from your previous accountant where you instruct a transfer of records, from payroll bureaux, pension providers and software platforms you use, and from public registers such as the register held at Companies House.
Where you provide information about another person, for example a fellow director, a shareholder, an employee or a family member, you confirm that you have the authority to share it with us and that the individual understands how the practice will use it. We will handle that information in the same way as information provided directly by the individual concerned.
Why We Use Information
We use personal information to prepare and submit annual accounts, self assessment returns, VAT returns, payroll submissions, pension filings and company secretarial documents. We use it to maintain bookkeeping and ledger records, to reconcile bank transactions, to raise invoices and collect payment for our services, and to respond to enquiries. We use it to comply with legal and regulatory obligations that apply to the practice, including record keeping, anti money laundering checks, and the requirements of professional and statutory bodies. We use it to protect the practice against fraud, to resolve disputes, and to establish or defend legal claims. We use it to improve our website and services, and, where you have agreed, to send you information about the practice that may be relevant to you.
We do not use personal information for purposes that are incompatible with those described in this policy. If we wish to use information for a new purpose, we will notify you and, where the law requires it, seek your consent before doing so.
Lawful Bases for Processing
We rely on several lawful bases depending on the activity. Performance of a contract applies where processing is necessary to provide the services you have engaged us to deliver, or to take steps at your request before entering an engagement. Legal obligation applies where processing is necessary to comply with the law, including tax law, company law, pension law and anti money laundering rules. Legitimate interests applies where processing is necessary for the proper running of the practice, such as protecting our systems, defending legal claims, or corresponding with you about work in progress, provided your rights and interests do not override those interests. Consent applies where you have given us a clear indication that we may process information for a particular purpose, for example receiving a newsletter, and you may withdraw consent at any time.
Where we process special category information, we rely on an additional condition, such as the establishment, exercise or defence of legal claims, the provision of the service where it is required by law, or, in limited cases, your explicit consent. We record the basis on which each processing activity relies, and we review it when the service changes.
Bookkeeping and Accounting Records
Our bookkeeping service involves processing transaction data that may contain personal information, such as the names of customers and suppliers, the details of invoices and receipts, the identity of payees, and the amounts and dates attached to them. This information is entered into a ledger, categorised, reconciled to bank statements and used to produce periodic reports. It may be shared with the software platform that hosts the ledger, and with the client on whose behalf the work is done. We keep the working papers that support the ledger so that every entry can be traced and explained.
Where we manage a sales ledger, we may process information about the debtors of a client, and where we manage a purchase ledger we may process information about the creditors of a client. In each case the information is used for the accounting purpose only, is restricted to the people who need it, and is retained under the schedule described later in this policy.
Payroll and Employee Data
When we administer payroll on behalf of a client, we process employee information that includes names, addresses, dates of birth, national insurance numbers, tax codes, bank account details, salary and wage amounts, hours, absence records, statutory payments, and pension contributions. This information is used to calculate pay, produce payslips, make statutory submissions to the tax authority, and enrol eligible employees into a workplace pension. Payroll information is among the most sensitive categories we handle, and it is subject to additional access controls, confidentiality obligations and retention rules.
We process payroll information on the instruction of the employer client, and we act as a processor for much of this work. Employees who wish to exercise a right in relation to their payroll information should in the first instance contact their employer, although we will assist with any request we receive and will direct it to the employer where that is appropriate.
Tax Preparation and Filings
Tax preparation requires us to process income, gains, expenses, allowances, reliefs and payment history, together with the identifiers that the tax authority uses to recognise a taxpayer. We use this information to prepare returns, compute liabilities, submit filings and correspond with the tax authority on your behalf. We may also process the information needed to claim reliefs and to support a position taken in a return. Where an enquiry or a compliance check arises, we may process additional information to respond to it, and we may share it with professional advisers acting for the same client where that is necessary and authorised.
Tax information is retained for the statutory period required by tax law and by the record keeping rules that apply to the practice, so that we can answer questions about a filing long after it has been submitted. The retention schedule later in this policy explains how that period is determined.
How We Share Information
We share personal information only where it is necessary and lawful to do so. Recipients may include the software providers that host our accounting, payroll and client management systems, professional advisers such as legal advisers and auditors where they are engaged, pension providers and payroll intermediaries, banks and payment processors, and the public authorities to which filings must be submitted. We may share information within the practice where it is needed to deliver a service. Where we use a service provider, we put a written contract in place that requires confidentiality and appropriate security, and limits the provider to processing the information on our instructions.
We may disclose information where we are required to do so by law, by a court, by a regulator, or by a professional body, and where we believe disclosure is necessary to protect the rights, property or safety of the practice, our clients, or others. We do not sell personal information, and we do not share it for the independent marketing purposes of third parties.
International Transfers
Some of the service providers we use may store or process information outside the United Kingdom. Where that happens, we take steps to ensure the information continues to receive an adequate level of protection, either because the destination is covered by an adequacy finding, or because a transfer mechanism such as standard contractual clauses is in place, together with an assessment of the risks involved. We review the location of our providers and the safeguards they offer, and we will provide further information about a specific transfer on request.
Where a client instructs us to use a particular platform or provider that operates outside the United Kingdom, we will explain the implications and, where required, obtain the necessary authorisations before the transfer takes place.
How Long We Keep Information
We keep personal information for as long as it is needed for the purpose for which it was collected, and for the period required by law or by the record keeping rules that apply to accounting and tax work. In practice this means that accounting, tax and payroll records are ordinarily retained for a minimum of six years from the end of the relevant tax or accounting period, and often longer where a matter remains open, where a claim may arise, or where a longer period is required by law. Website enquiry records are kept for a shorter period, and marketing preferences are kept until you ask us to change them.
When information is no longer needed we delete it or anonymise it in a way that means it can no longer be linked to an individual. Where deletion is not immediately possible because information is held in a backup, we isolate it and delete it when the backup cycle completes.
How We Protect Information
We use technical and organisational measures to protect personal information against unauthorised access, loss, alteration and disclosure. These measures include access controls that limit information to staff and contractors who need it, encrypted storage and transmission where appropriate, secure configuration of the software we use, and written confidentiality obligations for everyone who handles information on our behalf. We keep our systems updated, we use authentication that reduces the risk of unauthorised account access, and we review our arrangements as the services we use evolve.
No method of storage or transmission is entirely free of risk, so we also maintain procedures to detect and respond to an incident. Where a personal data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority and, where required, the individuals affected, in line with the law. If you believe you have identified a security issue, please contact us immediately using the details at the end of this policy.
Your Rights
Subject to the conditions in the law, you have the right to be informed about how your information is used, which this policy provides. You have the right of access to the personal information we hold about you, and the right to receive a copy. You have the right to have inaccurate information corrected, and to have incomplete information completed. You have the right to have information erased where there is no continuing reason for us to hold it. You have the right to restrict processing while a question about accuracy or lawfulness is resolved. You have the right to object to processing that relies on legitimate interests, and to object to direct marketing at any time. You have the right to data portability for information you provided to us where processing is based on consent or contract and is carried out by automated means. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise a right, contact us using the details at the end of this policy. We will respond within the period allowed by law, and we may need to confirm your identity before we act. There is no charge for a reasonable request, although we may charge a proportionate fee where a request is manifestly unfounded or excessive. Where a request concerns information we hold on behalf of a client, we may direct it to that client, or handle it in consultation with them.
Cookies and Similar Technology
This website is designed to work without tracking cookies. Any cookie or similar technology used is limited to what is necessary for the site to function correctly, such as remembering a display preference for the duration of a visit. We do not use cookies to build advertising profiles, and we do not sell information gathered through cookies. Where a cookie that is not strictly necessary is introduced, we will ask for your consent before it is set, and we will explain what it does.
You can control cookies through your browser settings, including blocking them or deleting those already stored. Blocking strictly necessary cookies may affect how parts of the website behave, but the informational content of the site remains available without them.
Privacy for Children
Our services are provided to businesses and to adults acting in a professional or personal capacity, and this website is not directed at children. We do not knowingly collect personal information from a child, and we do not market to children. Where a payroll or tax matter genuinely involves information about a minor, for example a child named in a trust or a benefit arrangement, we process that information only as far as the service requires and with the involvement of the responsible adult or the client instructing us.
If you believe that a child has provided personal information to us without appropriate involvement of a responsible adult, please contact us and we will take steps to remove the information unless we are required to keep it by law.
Direct Marketing
We may send you information about the practice, its services and developments that may affect your business, where you have asked to receive it or where we have a legitimate interest in doing so and you have not objected. Every marketing message includes a way to opt out, and we honour opt out requests promptly. Opting out of marketing does not affect the service messages we send in connection with an engagement, such as a filing reminder or an invoice, because those are part of the service itself.
We do not sell or rent contact details to third parties for their own marketing, and we do not permit third parties to market their products to our clients using information we hold.
Automated Decisions and Profiling
We do not make decisions about you using solely automated means where those decisions would produce legal effects or similarly significant effects. Software helps us categorise transactions, reconcile accounts and calculate figures, but the judgements that affect a client position, such as the treatment of an item in a return, are made and reviewed by a person. Where a service provider offers an automated feature, we assess whether it is suitable before relying on it and we retain the ability to review its output.
If in future we introduce a process that involves solely automated decision making of a significant kind, we will update this policy and put in place the safeguards the law requires, including a route to request human intervention.
Third Party Links
This website may contain links to websites operated by others, including software platforms and public registers. Those websites are not controlled by the practice and are governed by their own privacy notices. We provide links for convenience only, and a link does not mean that we endorse the practices of the site concerned. Before providing personal information to a third party website, you should read the privacy notice published there.
If you reach our website from a third party site, we are not responsible for the information practices of that site, and this policy applies only to the information we handle ourselves.
Changes to This Policy
We review this policy regularly and may update it to reflect changes in the law, in regulation, in the services we provide, or in the systems we use. When we make a material change we will update the effective date at the top of the policy and, where the change is significant, we will bring it to the attention of clients by a suitable means. The version published on this website is the current version and replaces any earlier version.
We encourage you to check this page from time to time so that you are aware of the basis on which we handle personal information. Continued use of the website or of our services after an update indicates that you have had the opportunity to read the revised policy.
Complaints
If you are unhappy with how we have handled your personal information, please contact us first so that we have the opportunity to put it right. We take complaints seriously and will investigate promptly and explain the outcome. If you remain dissatisfied, you have the right to complain to the supervisory authority for data protection in the United Kingdom, which is the Information Commissioner Office. You may also have the right to complain to the supervisory authority in the country where you live or work, or where the alleged infringement took place.
We will not treat you differently because you have raised a concern, exercised a right, or made a complaint, and we will cooperate fully with any regulatory process.
How to Contact Us
If you have a question about this policy, wish to exercise a right, or want to raise a concern, please contact GDS ACCOUNTANTS LTD using any of the following. By post, write to 71-75 Shelton Street, Covent Garden, LONDON - WC2H 9JQ, United Kingdom (GB). By email, write to billing@gdsaccountants.buzz. By telephone, call +15628701574. Please include enough detail for us to identify you and understand the request, and we will respond within the period allowed by law.
This policy is published by the developer named in the introduction, GDS Accountants, on behalf of GDS ACCOUNTANTS LTD. Thank you for reading it.