Introduction

We are committed to protecting personal data and to complying with the Data Protection Act 2018 (DPA) and the United Kingdom General Data Protection Regulation (UK GDPR). Figio Group Limited is registered with the Information Commissioner's Office as a data controller, with registration number ZB900160.

"Ecommerce Accountants" is a trading name of Figio Group Limited (company number 16216397, registered office: 66 Paul Street, London, EC2A 4NA), and references to "we," "us," or "our" in this policy refer to Figio Group Limited.

This privacy statement explains how, as a data controller, we collect and use the personal data of individuals ("data subjects"). Data subjects may be our clients or others whose data we collect during the course of our business interactions. This includes, for example, individuals who visit our website, apply for a role with us, act as a supplier or subcontractor to us, or sign up to receive marketing communications from us, as well as our clients. We shall only use personal data for the purposes described in this privacy statement, or for purposes explained to the data subject at the point of collecting their personal data.

How we might receive personal data

We may obtain personal data directly from a data subject if and when they:

  • request a proposal from us in respect of the services we provide
  • engage us to provide our services, and also during the provision of those services
  • contact us, for whatever reason, by email, telephone, post, or via our website or social media

We may also obtain personal data indirectly:

  • from an employer
  • from third parties (for example, from the data subject's bank or from HMRC)
  • from publicly available sources (for example, from Companies House)

This list is not exhaustive. If and when it becomes necessary (or in the data subject's interests) to obtain personal data from third parties, the data subject will usually have been made aware that we intend to do so.

The lawful bases on which we process personal data

The lawful bases on which we process personal data are as follows:

  • Consent - where a data subject has given consent to the processing of their personal data for one or more specific purposes
  • Contract - where processing is necessary to meet our obligations under a contract to which the data subject is party (or to take steps at their request prior to entering into a contract)
  • Legal obligations - where processing is necessary for compliance with a legal obligation to which we are subject
  • Public interest - where processing is necessary for the performance of a task carried out in the public interest
  • Legitimate interests - where processing is necessary for the purposes of pursuing our legitimate interests, or the legitimate interests of another party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data

Why we process personal data

We process personal data to be able to:

  • meet our responsibilities to a client under our engagement letter and the provision of services agreements that exist between us
  • meet a client's wider expectations of our professional relationship, including providing information ancillary to the services agreed under the engagement letter and provision of services agreements
  • contact a client about other services we provide which may be of interest to them, if the client has consented to us doing so
  • comply with legal and regulatory requirements, including anti-money laundering and health and safety compliance
  • send marketing communications and event or webinar invitations to individuals who have opted in to receive them
  • manage our recruitment process and any resulting employment or contractor relationship
  • operate our website and respond to general enquiries
  • further our legitimate interests

The following sections relate the lawful bases on which we process personal data to the various reasons for which we expect to process personal data:

  • Under the engagement letter and provision of services agreements: Contract
  • Meeting clients' wider expectations of our professional relationship: Consent
  • Contacting a client about other services that may be of interest: Consent
  • Sending marketing communications, event and webinar invitations: Consent
  • Complying with legal and regulatory requirements: Legal obligations, Public interest
  • Furthering our legitimate interests: Legitimate interests

Our legitimate interests in processing personal data include the requirement that we comply with our legal and regulatory obligations, and are seen to do so. We may also process personal data for the purposes of our practice management and development, including statistical analysis.

Data security

We have put in place appropriate and proportionate security measures to address the risk of personal data being lost, used, altered, or accessed in an unauthorised way. We limit access to personal data to those who have a business need to access it, and who will only process the personal data on our instructions.

Nevertheless, no data transmission over the internet, or any other network, can ever be regarded as wholly secure, and we have in place measures to deal with any suspected breach of data security. Those measures include clear policies and procedures, which are periodically reviewed to ensure they are effective and fit for purpose. Procedures include the training of employees and subcontractors in the areas of data privacy, confidentiality, and information security.

Data breaches

In the event of a personal data breach, we have a documented internal process for identifying, containing, and responding to it. Where a breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, in line with our obligations under UK GDPR. Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly, without undue delay.

Where our staff are located

Ecommerce accountants may contract with a variety of third-party suppliers/providers/vendors/social networks from time to time, to provide for our hosting, authentication, serving, storage and telecommunication needs, etc., including without limitation storage of our users’ Personally Identifiable Information. Ecommerce Accountants shall not be responsible or liable, and hereby disclaims all responsibility and liability, for culpable (including without limitation negligent) acts or omissions by its third party suppliers/vendors.

Data sharing

We share personal data with third parties when absolutely necessary for the purposes for which we process it. We may also share personal data, with the consent of the data subject, where it is necessary to administer the relationship between us, or where we have another legitimate interest in doing so.

From time to time, and only with your specific consent, we may share information with third parties on your behalf - for example, providing a reference or financial information to a mortgage lender, letting agent, or other party you have asked us to assist with. We will only do this where you have given us clear instruction or consent to do so.

We are also required by law to submit certain personal data to regulatory and government bodies in the course of providing our services - for example, filing tax returns and related information with HM Revenue & Customs, and filing statutory information (such as company officer details) with Companies House. This sharing is necessary to comply with our legal obligations and to fulfil the services you have engaged us to provide.

We also use a number of third-party service providers to help us deliver our services, including but not limited to Microsoft Azure, Anthropic, Xero, Karbon, and Firmcheck, HubSpot, Socket, Slack, and Ecommerce Fusion. This list is not exhaustive. We only permit third-party service providers to process personal data for specified purposes and in accordance with our instructions, where appropriate contractual arrangements and security mechanisms are in place.

International transfers

Some of our third-party service providers may store or process personal data outside the United Kingdom, including within the European Economic Area and, in some cases, the United States. Where this occurs, we have satisfied ourselves that appropriate safeguards are in place - for example, the destination country's recognised adequacy status, or the provider's use of Standard Contractual Clauses, an International Data Transfer Agreement, or their certification under the UK Extension to the EU-US Data Privacy Framework.

We shall share personal data to the extent necessary in order to:

  • meet our responsibilities under our provision of services agreements with clients
  • fulfil our obligations to a regulator
  • enable effective quality control over our technical work
  • comply with our legal obligations

Cookies

Our website uses cookies and similar technologies. Some are strictly necessary for the site to function, including remembering your cookie preferences. Others - including Google Analytics, Google Ads, and HubSpot - are only used with your consent, and will not be set unless you actively accept them.

You can choose which cookies to allow using the cookie settings tool shown when you first visit our site, and you can change your preferences at any time via the cookie icon on our website. Your consent choice is stored securely and is not shared with third parties beyond what is necessary to remember your preference.

Data retention

When determining the appropriate period of retention for personal data, we shall consider the requirements of our business, the services provided, any legal and regulatory obligations, and the purposes for which we originally collected the data.

We shall only retain personal data for as long as there is a legal basis for doing so.

In accordance with recognised good practice within the accountancy profession, we usually retain records, including personal data, as follows:

  • Tax return information and accounting records are retained for seven years from the end of the tax year to which that information relates.
  • Information and records relating to advisory work are retained for seven years from the date the business relationship ceased.
  • Where we have an ongoing client relationship, information that is of ongoing relevance to our engagement is retained throughout the period of the engagement, and deleted seven years after the end of the business relationship.

Individuals' rights regarding their data

It is important that the data we hold is accurate and current. Should a data subject's personal information change, they should ensure that we are notified of those changes of which we need to be made aware.

Data subjects have certain rights over their personal data that we process as data controller. If a data subject exercises any of those rights, we shall aim to respond promptly. However, please note that the length of time it will take us to respond will be dependent on the nature and extent of the request.

A data subject has a right to:

  • request access to their personal data under Article 15 of UK GDPR - enabling them to receive a copy of their personal data that we hold
  • request rectification under Article 16 - of any errors or inaccuracies in their personal data that we hold
  • request erasure of their personal data under Article 17 - where there is no good reason for us continuing to process it, or where they have exercised their right to object to processing (see below)
  • object to processing of their personal data under Article 21 - where we have been relying on a legitimate interest as the basis for processing their data, which they believe is overridden by their own interests or rights
  • request the restriction of processing of their personal data under Article 18 - asking us to suspend processing their personal data if, for example, they wish to establish its accuracy or the reason for processing it
  • withdraw consent under Article 7 - where we have been processing their personal data based on their consent
  • request the transfer of their personal data to them or to another data controller under Article 20

If you wish to exercise any of your rights as a data subject, please email us at privacy@ecommerceaccountants.co.uk.

Contact details

If you have any questions regarding this notice, or if you would like to speak to us about the manner in which we process personal data, please email us at privacy@ecommerceaccountants.co.uk, or telephone the office on 020 7520 2676.

A data subject also has the right to make a complaint to the Information Commissioner's Office, whose address is:

Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

Telephone: 0303 123 1113 Website: www.ico.org.uk/concerns

Need an accountant? Get in touch today. See how we can support you.

flare20let's talk img