Legal & compliance
Privacy Policy
This website (www.isaacs-co.com) is made available by Affinity Associates Isaacs & Co Limited (Company number 10038011), Unit 7, Atlas Business Park, Balby Carr Bank, Doncaster, DN4 5JT — referred to in this statement as "we", "us" or "our".
This Privacy Policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For the purposes of data protection legislation, the data controller is Affinity Associates Isaacs & Co Limited, Unit 7, Atlas Business Park, Balby Carr Bank, Doncaster, DN4 5JT.
1. Introduction
We are committed to safeguarding the privacy of our website visitors and clients. In this policy we explain how we will collect, use and protect your personal information.
We will ask you to consent to our use of cookies in accordance with the terms of this policy when you first visit our website.
As a firm supervised for Anti-Money Laundering (AML) purposes by the Association of Taxation Technicians (ATT), we are subject to legal obligations that may require us to collect, verify and retain certain personal information. This policy should be read alongside our AML obligations.
2. Collecting Personal Information
We may collect, store and use the following kinds of personal information:
- Information about your computer and about your visits to and use of this website (including your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths).
- Information that you provide to us when using our website contact form (including your name, email address, telephone number and the content of your enquiry).
- Information that you provide to us for the purpose of subscribing to our email notifications, newsletters or downloadable resources (including your name and email address).
- Information contained in or relating to any communication that you send to us or through our website (including the communication content and metadata associated with the communication).
- Client information collected in the course of providing our professional services, including tax planning and compliance, bookkeeping, VAT, payroll, year end accounts, business advisory, company secretarial and IT/digital accounting services.
- Identity and verification information required for AML compliance purposes, including proof of identity and proof of address.
- Any other personal information that you choose to provide to us.
3. Using Personal Information
Personal information submitted to us through our website or provided to us in the course of our professional engagement will be used for the purposes specified in this policy.
We may use your personal information to:
- Administer our website and business operations.
- Personalise our website experience for you.
- Enable your use of the services available on our website.
- Provide our professional services to you, including tax planning and compliance, bookkeeping, cloud accounting, VAT services, payroll and CIS, year end accounts, financial reporting, business advisory, company secretarial services, and IT and digital accounting solutions.
- Send you statements, invoices and payment reminders, and collect payments from you.
- Send you non-marketing commercial communications relevant to your engagement with us.
- Send you email notifications or newsletters that you have specifically requested (you may unsubscribe at any time).
- Deal with enquiries and complaints made by or about you.
- Keep our website secure and prevent fraud.
- Comply with our legal and regulatory obligations, including our AML obligations as a firm supervised by the ATT.
- Send you marketing communications relating to our business which we think may be of interest to you (you may opt out at any time).
We will not supply your personal information to any third party for the purpose of their or any other third party's direct marketing without your consent.
4. AML Compliance and Legal Obligations
As a firm supervised for AML purposes by the ATT, we are required by law to verify the identity of our clients and, in certain circumstances, to report information to the relevant authorities. The legal basis for this processing is compliance with a legal obligation (Article 6(1)(c) UK GDPR).
We may be required by law to retain records relating to client due diligence and transactions for a period of five years from the end of our business relationship with you or the date of a transaction (whichever is later). This obligation overrides any general right of erasure you may have.
We may be required to make disclosures to the National Crime Agency (NCA) or other relevant authorities where we have knowledge or suspicion of money laundering or terrorist financing. In such circumstances, we are prohibited by law from informing you ("tipping off") that such a disclosure has been made.
5. Disclosing Personal Information
We may disclose your personal information to our employees and contractors insofar as reasonably necessary for the purposes set out in this policy.
We may disclose your personal information:
- To the extent that we are required to do so by law or regulation, including our AML obligations.
- To HMRC, Companies House, the ATT or other regulatory bodies in the performance of our professional services on your behalf or in fulfilment of our regulatory obligations.
- To cloud accounting software providers (such as Xero or QuickBooks) and other third party software platforms used in the delivery of our services.
- In connection with any ongoing or prospective legal proceedings.
- In order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk).
- To any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information where, in our reasonable opinion, such court or authority would be reasonably likely to order such disclosure.
Except as provided in this policy, we will not provide your personal information to third parties.
6. International Data Transfers
All personal data is primarily hosted and processed within the United Kingdom, in accordance with UK GDPR and applicable data protection legislation.
Our servers are situated within the UK. Our support teams, including back office personnel based in India, may remotely access these UK based servers to perform necessary tasks. All data remains within the geographical boundaries of the UK at all times and is not transferred or replicated overseas.
Where any international access occurs, appropriate safeguards are in place to ensure that your personal data is handled securely and in accordance with applicable data protection law.
7. Retaining Personal Information
We will not keep personal information for longer than is necessary for the purpose for which it was collected, subject to our legal and regulatory obligations.
Client records and AML related documentation (including identity verification records and client due diligence) will be retained for a minimum of five years from the end of the business relationship or the date of the relevant transaction, in accordance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
Records required for tax purposes will be retained in accordance with HMRC guidelines, which typically require retention for a minimum of six years.
Website enquiry and general correspondence data will typically be retained for no longer than two years unless a professional engagement results from the contact.
Notwithstanding the above, we will retain documents containing personal data:
- To the extent that we are required to do so by law or regulation.
- If we believe the documents may be relevant to any ongoing or prospective legal proceedings.
- In order to establish, exercise or defend our legal rights.
8. Security of Personal Information
We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information.
We store personal information you provide on secure, password protected and firewall protected servers.
You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
You are responsible for keeping any access credentials you use in connection with our services confidential. We will not ask you for your password.
9. Cookies
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.
We will ask for your consent to our use of cookies when you first visit our website. You may withdraw your consent at any time by adjusting your browser settings or using our cookie preferences tool.
For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy [available on our website].
10. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- The right to access — you may request a copy of the personal data we hold about you.
- The right to rectification — you may request that we correct inaccurate or incomplete personal data.
- The right to erasure — you may request that we delete your personal data, subject to our legal retention obligations (including AML requirements).
- The right to restrict processing — you may request that we restrict the processing of your personal data in certain circumstances.
- The right to data portability — you may request that we provide your personal data to you in a structured, commonly used and machine readable format.
- The right to object — you may object to our processing of your personal data for marketing purposes at any time.
- Rights in relation to automated decision making and profiling — we do not currently make decisions about you based solely on automated processing.
To exercise any of your rights, please contact us at george@isaacs-co.com or in writing to our registered address.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by telephone on 0303 123 1113 if you believe we have not handled your personal data in accordance with data protection law.
11. Amendments
We may update this policy from time to time by publishing a new version on our website. You should check this page occasionally to ensure you are happy with any changes.
We may notify you of material changes to this policy by email or through a notice on our website.
12. Third Party Websites
Our website may include hyperlinks to third party websites. We have no control over, and are not responsible for, the privacy policies and practices of third party websites. We recommend that you review the privacy policy of any third party website you visit.
13. Our Details
This website is owned and operated by Affinity Associates Isaacs & Co Limited.
We are registered in England and Wales under company number 10038011. Our registered office is at Unit 7, Atlas Business Park, Balby Carr Bank, Doncaster, DN4 5JT.
We are supervised for AML purposes by the Association of Taxation Technicians (ATT).
14. Contact Us
You can contact us regarding any privacy related queries or concerns:
- By post: Unit 7, Atlas Business Park, Balby Carr Bank, Doncaster, DN4 5JT
- By email: george@isaacs-co.com
- Via our website contact form at: www.isaacs-co.com
- By telephone: as published on our website
We will endeavour to respond to all privacy related requests within one calendar month of receipt.
