Back to main site
Legal & Privacy Documentation

Legal Notice
& Privacy Policy

Company
Finexis Accountants Ltd
Company Number
15878065
Jurisdiction
England & Wales
Last Reviewed
January 2026
This policy was last reviewed in  January 2026 . We recommend you revisit it periodically.
01

Company Information

This Legal Notice and Privacy Policy is issued by Finexis Accountants Ltd, a company registered in England and Wales.

Registered Details
Registered Address
8 Vespers Close, Luton
England, LU4 0NW
Company Number
15878065
Telephone

Finexis Accountants Ltd operates as a fully remote practice with no public-facing office, serving clients across the United Kingdom by phone, email, video call and in-person meetings as required.

02

Professional Regulation

Finexis Accountants Ltd is a practice registered with the Association of Accounting Technicians (AAT). Our principal adviser holds the ACCA (Association of Chartered Certified Accountants) qualification.

AAT Licensed Accountant: As an AAT-licensed member in practice, we are bound by the AAT's Code of Professional Ethics, which requires us to act with integrity, objectivity, professional competence, confidentiality, and professional behaviour at all times.

We carry professional indemnity insurance as required by our professional body. Details are available on request.

03

Data Controller

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Finexis Accountants Ltd is the data controller in respect of personal data held about clients, prospective clients, and website visitors.

As data controller, we are responsible for deciding how and why personal data is processed. We are committed to processing personal data lawfully, fairly, and transparently.

ICO Registration: Finexis Accountants Ltd is registered with the Information Commissioner's Office (ICO) as required under UK data protection law. Our registration reference is available on request by contacting [email protected].
04

Data We Collect

We collect and process personal data necessary to provide our accountancy services. The categories of data we may hold include:

  • Identity data — full name, date of birth, National Insurance number, UTR number, and copies of identity documents where required
  • Contact data — home or business address, email address, telephone number
  • Financial data — income details, bank account information, payroll records, invoices, expenses, and tax records
  • Business data — company registration details, director information, VAT registration number, Companies House filings
  • Correspondence data — emails, notes from meetings or calls, and other communications relating to the engagement
  • Technical data — IP address, browser type, and pages visited on our website, collected via cookies where consent is given

We collect this data directly from you when you engage our services, through forms on our website, or in the course of carrying out work on your behalf.

05

Legal Basis for Processing

We rely on the following lawful bases under UK GDPR Article 6 to process your personal data:

  • Contract — processing is necessary to perform the services set out in our engagement letter with you
  • Legal obligation — we are required by law to retain certain records, including those required by HMRC, Companies House, and anti-money laundering legislation
  • Legitimate interests — for purposes such as improving our services, communicating relevant updates, and maintaining business records, where these interests do not override your rights
  • Consent — for marketing communications and certain uses of cookies, where you have given explicit consent
Special Category Data: We do not routinely collect special category data (as defined under UK GDPR Article 9). If any such data is provided, it will only be processed with your explicit consent and where strictly necessary.
06

How We Use Your Data

Your personal and financial data is used solely to deliver the services you have engaged us to provide. Specifically, we use your data to:

  • Prepare and file tax returns, VAT returns, and statutory accounts on your behalf
  • Manage your payroll and pension auto-enrolment obligations
  • Correspond with HMRC, Companies House, and other statutory bodies on your behalf
  • Provide bookkeeping, management accounts, and financial reporting
  • Meet our anti-money laundering (AML) and know-your-client (KYC) obligations
  • Send you relevant service updates, regulatory reminders, and deadline notifications
  • Respond to your queries and maintain records of our communications

We will never sell your data to any third party. We do not use your data for profiling or automated decision-making that produces legal or significant effects.

07

Data Sharing

Your data is treated as strictly confidential. We will only share it in the following circumstances:

  • HMRC — when submitting tax returns, VAT returns, PAYE filings, or other statutory submissions on your behalf
  • Companies House — when filing confirmation statements, annual accounts, or other company filings
  • Professional software providers — accounting and practice management platforms used to deliver our services, all of which are UK GDPR compliant and bound by data processing agreements
  • Professional advisers — such as solicitors, where necessary and with your prior agreement
  • Legal obligation — where required by law, a court order, or a regulatory authority with jurisdiction

All third parties with whom we share data are required to handle it securely and in accordance with data protection law. We do not transfer personal data outside the United Kingdom without appropriate safeguards in place.

08

Retention Policy

We retain personal and financial data only for as long as necessary to fulfil the purposes for which it was collected, and to comply with our legal and regulatory obligations.

Standard retention period: Client records are retained for a minimum of six years from the end of the relevant tax year or the end of our engagement, whichever is later. This aligns with HMRC requirements and the statutory limitation period under the Limitation Act 1980.

Certain records may be kept for longer where required by law. For example:

  • Anti-money laundering records are retained for five years from the end of the business relationship
  • Company secretarial and statutory records may be retained for the life of the company
  • Payroll records must be kept for at least three years after the relevant tax year

On expiry of the applicable retention period, data is securely and permanently deleted or destroyed. Physical documents are shredded; electronic files are overwritten or securely erased in accordance with recognised standards.

09

Your Rights

Under UK GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month.

Right of Access
You may request a copy of the personal data we hold about you (a Subject Access Request).
Right to Rectification
You may ask us to correct inaccurate or incomplete personal data without undue delay.
Right to Erasure
You may request deletion of your personal data where there is no lawful reason for us to continue holding it.
Right to Restriction
You may ask us to restrict processing of your data in certain circumstances, for example while a dispute is resolved.
Right to Portability
Where processing is based on consent or contract, you may request your data in a structured, machine-readable format.
Right to Object
You may object to processing based on legitimate interests, including direct marketing at any time.

Please note that some rights are subject to exemptions. For example, we cannot erase data that we are legally required to retain. We will always explain the reasons if we are unable to fulfil a request.

10

Cookies

Our website uses a small number of cookies to ensure it functions correctly and to understand how visitors use the site. Cookies are small text files stored on your device.

  • Strictly necessary cookies — required for the website to operate. These cannot be disabled.
  • Analytics cookies — help us understand visitor behaviour in aggregate, so we can improve the site. These are only set with your consent.

We do not use advertising or tracking cookies. You can manage your cookie preferences through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of the site.

11

Security

We take the security of your data seriously and maintain appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or disclosure.

Our security measures include:

  • Encrypted file transfer and storage for all client financial documents
  • Password-protected, access-controlled practice management systems
  • Multi-factor authentication on all systems handling client data
  • Regular software updates and security patching
  • Secure deletion of data at the end of the retention period

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours as required by UK GDPR, and will inform affected individuals without undue delay.

12

Complaints

If you have a concern about how we have handled your personal data, we encourage you to contact us in the first instance so we can try to resolve the matter directly.

Contact for Data Queries
Response time
Within 5 working days

If you remain dissatisfied after raising a concern with us, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters.

Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13

Changes to This Policy

We review this policy at least annually and whenever there are material changes to how we process data or to applicable law. When we make significant changes, we will notify existing clients by email and update the "Last Reviewed" date at the top of this document.

We encourage you to check this page periodically. Continued use of our services following any update constitutes acceptance of the revised policy.

This policy was last reviewed in January 2026.