1. Introduction
Warm Crest Accounting Services ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website warm-crest.com or use our accounting services.
We are registered in England and Wales and operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
- Contact information (name, email address, phone number, postal address)
- Business information (company name, VAT number, Companies House number)
- Financial information (bank details, transaction records, tax information)
- Employment information (payroll details, pension information)
- Website usage data (IP address, browser type, pages visited)
2.2 How We Collect Information
We collect information through:
- Direct communication (emails, phone calls, contact forms)
- Service provision (accounting software, document uploads)
- Website interactions (cookies, analytics)
- Third-party sources (HMRC, Companies House, banks)
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing accounting and financial services
- Complying with legal and regulatory requirements
- Communicating with you about our services
- Processing payments and managing invoices
- Improving our website and services
- Sending marketing communications (with your consent)
- Preventing fraud and ensuring security
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: To perform our accounting services
- Legal obligation: To comply with tax and regulatory requirements
- Legitimate interests: To operate our business and improve our services
- Consent: For marketing communications and non-essential cookies
5. Data Sharing and Disclosure
We may share your information with:
- HMRC and other tax authorities: As required by law
- Companies House: For company formation and filing requirements
- Banks and financial institutions: For payment processing
- Professional advisors: Lawyers, auditors, and other professionals
- Software providers: Cloud accounting and payroll systems
- Service providers: IT support, hosting, and other business services
We do not sell your personal information to third parties.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Secure access controls and authentication
- Regular security assessments and updates
- Staff training on data protection
- Secure disposal of confidential documents
7. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal and regulatory requirements
- Resolve disputes and enforce agreements
Generally, we retain client records for 6 years after the end of our professional relationship, in line with professional accounting standards and HMRC requirements.
8. Your Rights
Under UK GDPR, you have the following rights:
- Access: Request copies of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data
- Restriction: Request limitation of processing
- Portability: Request transfer of your data
- Objection: Object to processing based on legitimate interests
- Withdraw consent: For processing based on consent
To exercise these rights, please contact us using the details below.
9. Cookies and Website Analytics
Our website uses cookies to:
- Ensure the website functions properly
- Remember your preferences and settings
- Analyse website usage and performance
- Provide personalised content and advertising
You can manage your cookie preferences through our cookie consent banner or your browser settings. For more information, see our Cookie Policy.
10. International Transfers
Some of our service providers may be located outside the UK. When we transfer your personal data internationally, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government
- Standard contractual clauses
- Binding corporate rules
- Certification schemes
11. Children's Privacy
Our services are not directed at children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending you an email notification
- Providing notice through our services
Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.
13. Contact Information
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated. Visit ico.org.uk for more information.