EOACC Limited – Privacy Policy
Who we are
EOACC Limited (“EOACC”, “we”, “us”) is a company registered in England and Wales, company number 06477880, with its registered office at 5 Approach Rd, Raynes Park, London SW20 8BA. We provide accountancy, tax and related services.
Our website address is: [EOACC website address]. We are the “data controller” of the personal data described in this policy and are registered with the Information Commissioner’s Office (ICO), for questions, contact info@eoacc.com This policy forms part of our Terms of Service.
What personal data we collect
Clients and platform users
- Identity and contact details (name, address, date of birth, email, telephone).
- Tax and financial information (National Insurance number, Unique Taxpayer Reference, income, expenses, bank details and documents you provide), and information we obtain from HMRC on your behalf.
- Identity documents and proof of address for anti-money laundering checks.
- Information about spouses, partners, businesses or others connected to your affairs.
- Account details, login activity, documents you upload to our online platform, and fee, payment and communication records.
Website visitors
- Technical data such as IP address, browser and device, collected through cookies (see “Website” below), and anything you submit through forms or comments.
You must make sure you can lawfully share any personal data about other people with us.
How we use your data and our lawful bases
- Providing our services (returns, bookkeeping, dealing with HMRC, managing your account and fees). Lawful basis: contract.
- Legal and regulatory duties, including anti-money laundering, tax and accounting law and AAT rules. Lawful basis: legal obligation.
- Running and protecting our business (security, fraud and spam prevention, quality control, getting paid, handling complaints). Lawful basis: legitimate interests.
- Marketing, where you have asked for it or the law allows. Lawful basis: consent or legitimate interests. You can opt out at any time.
We only use special category data where the law allows, and it is needed for your service. You can withdraw consent at any time. We do not make solely automated decisions with legal or similarly significant effects.
Who we share your data with
We do not sell your personal data. We share it only where needed, with:
- HMRC and other authorities, when acting for you.
- Our team and subcontractors, including team members in South Africa, who are bound by confidentiality.
- Service providers, such as cloud hosting, software and security, identity verification and anti-money laundering checks, payments, email tools and IT support. [List key providers or categories here.]
- AAT, our insurers, advisers and independent file reviewers.
- The National Crime Agency, where the law requires a report (we may not be able to tell you).
- A buyer, if we sell or restructure our business.
- Anyone you ask us to share it with.
If you request a password reset, your IP address is included in the reset email. We may also disclose data where a court, regulator or the law requires it.
Where we send your data
Some of our work is done by team members in South Africa, so your data may be accessed from or transferred to South Africa. We use appropriate safeguards, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so it stays protected to UK standards. Contact us for more information. Providers storing data outside the UK must protect it to the same standard.
Visitor comments may be checked through an automated spam detection service.
How long we retain your data
We keep personal data only as long as needed for the purposes above and to meet legal, tax and regulatory requirements.
- Client records: generally, [six] years after our engagement ends, or longer if the law requires or a claim is ongoing.
- Documents you upload to our online platform: as set out in our Terms of Service.
- Anti-money laundering records: at least five years after our relationship ends.
- Marketing preferences: until you opt out.
- Comments: retained indefinitely with their metadata, so we can approve follow-up comments automatically instead of holding them in a moderation queue.
- Registered website users (if any): profile information is stored. Users can see, edit or delete it at any time (except the username), and administrators can also see and edit it.
We delete or anonymise data securely when we no longer need it.
What rights you have over your data
You can request an exported file of the personal data we hold about you, or ask us to erase it, except for data we are obliged to keep for administrative, legal or security purposes. You can also ask us to correct, restrict or stop using your data, object to direct marketing, receive your data in a portable format where it applies, and withdraw consent.
To exercise these rights, contact [privacy email address]. We may need to verify your identity and will normally reply within one month. Some rights are limited where we must keep data by law, including anti-money laundering rules.
If you are unhappy, please contact us first. You can also complain to the ICO at ico.org.uk or on 0303 123 1113.
Website
This section applies to visitors to our websites and users of our online platform.
Comments
When visitors leave comments on the site, we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help with spam detection.
An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
If you leave a comment on our site, you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Security and changes to this policy
Security. We use appropriate technical and organisational measures to protect your personal data. Please keep your password safe and tell us at once if you think your account has been accessed without permission.