Legal

Privacy policy

Last updated: 30 September 2026

Accounts & Business Services Ltd ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This policy explains what we collect, why, how long we keep it, and the rights you have. It applies to this website and to enquiries and services provided by the practice.

1. Who we are

Accounts & Business Services Ltd is the data controller for personal data processed through this website and our practice. We are registered with the Information Commissioner's Office (ICO registration ZA123456).

Accounts & Business Services Ltd · 12 Sadler Gate, Cathedral Quarter
Derby DE1 3NB
United Kingdom
Email: contact@accountsandbusinessesservices.com · Phone: 01332 496 013

2. What data we collect

  • Enquiry data — name, email address, phone number (optional) and the content of your message when you use the contact form, email or call us.
  • Client data — where you become a client, the additional information needed to provide accounting services (identification, financial records, tax details) as set out in our engagement letter.
  • Technical data — standard server logs kept by our hosting provider (IP address, browser type, pages visited) for security and troubleshooting. We do not use this to profile you.

This website sets no advertising or tracking cookies. The only cookies used are strictly necessary session cookies that keep the contact form secure. See section 6 for details.

3. How and why we use your data

  • To reply to your enquiry — lawful basis: your consent (given via the consent box on the form) and/or steps towards a contract at your request.
  • To provide accounting services — lawful basis: performance of our contract with you, and compliance with legal obligations (tax, anti-money-laundering).
  • To keep the site secure — lawful basis: our legitimate interest in operating a safe website.

We never sell your data, and we do not use it for marketing unless you have explicitly asked us to.

4. Who we share it with

Only with processors and bodies necessary for the work, under data-processing agreements and, where relevant, UK adequacy arrangements:

  • Cloud accounting platforms you ask us to use (e.g. Xero, QuickBooks);
  • Our hosting and email providers, to operate this site and mailbox;
  • HMRC, Companies House and other authorities where the law requires or you authorise it;
  • Professional advisers (e.g. our professional indemnity insurers) in limited circumstances.

5. How long we keep it

  • Enquiries that don't become clients — deleted 24 months after our last contact.
  • Client records — kept for the periods required by HMRC and our professional body (typically five to seven years after the end of the engagement), then securely destroyed.
  • Server logs — kept by our host for up to 90 days.

6. Cookies

  • Essential — a session cookie (jsac_session) protects the contact form against cross-site request forgery. It contains no personal identifiers beyond a random ID and expires when you close your browser. This cookie is strictly necessary, so it does not require consent.
  • Analytics & advertising — none are loaded. If we ever add analytics, we will ask for your consent before loading them, and this policy will be updated first.

7. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you;
  • Have inaccurate data corrected;
  • Have your data erased ("right to be forgotten"), subject to legal retention duties;
  • Object to or restrict processing;
  • Data portability (a machine-readable copy);
  • Withdraw consent at any time, where consent is our lawful basis;
  • Complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint (opens in a new tab) or on 0303 123 1113.

To exercise any right, email contact@accountsandbusinessesservices.com or write to the address in section 1. We respond within 30 days, and usually within a week. You will never have to pay a fee, and we will never treat you differently for asking.

8. How we protect your data

  • TLS/HTTPS encryption for this website and all data in transit;
  • Access to client records restricted by role and protected by strong authentication;
  • Devices encrypted; annual information-security training for all staff;
  • Anti-money-laundering and professional-body obligations underpin our identity checks.

9. Changes to this policy

We review this policy at least annually. Material changes will be announced on this page with a new "last updated" date, and — where we hold your email — notified to clients directly.

Ready to hand over the paperwork?

Book a free, no-obligation chat about your accounts, tax or payroll — in person in Derby or online.

Book a free chat