We are committed to protecting personal data and to complying with the Data Protection Act 2018 (DPA) and the United Kingdom General Data Protection Regulation (UK GDPR). Opus Accountancy Limited is registered with the Information Commissioner's Office as a data controller, with the registration number Z9143784.
This privacy statement explains how, as a data controller, we collect and use the personal data of individuals ('data subjects'). Data subjects may be our clients or others whose data we collect during the course of our business interactions. We shall only use personal data for the purposes described in this privacy statement or for the purposes explained to the data subject at the point of collecting their personal data.
We may obtain personal data directly from a data subject if and when they:
We may also obtain personal data indirectly:
This list is not exhaustive. If and when it becomes necessary (or in the data subject's interests) to obtain personal data from third parties, the data subject will usually have been made aware that we intend to do so.
The lawful bases on which we process personal data are as follows:
We process personal data to be able to:
The following sections relate the lawful bases on which we process personal data to the various reasons for which we expect to process personal data:
Our legitimate interests in processing personal data include the requirement that we comply with our legal and regulatory obligations and are seen to do so. We may also process personal data for the purposes of our practice management and development, including statistical analysis.
We have put in place appropriate and proportionate security measures to address the risk of personal data being lost, used, altered or accessed in an unauthorised way. We limit access to personal data to those who have a business need to access it, and who will only process the personal data on our instructions.
Nevertheless, no data transmission over the internet, or any other network, can ever be regarded as wholly secure, and we have in place measures to deal with any suspected breach of data security. Those measures include clear policies and procedures, which are periodically reviewed to ensure they are effective and fit for purpose. Procedures include the training of employees and subcontractors in the areas of data privacy, confidentiality and information security.
We share personal data with third parties when absolutely necessary for the purposes for which we process it. We may also share personal data, with the consent of the data subject, where it is necessary to administer the relationship between us, or where we have another legitimate interest in doing so.
'Third parties' includes third-party service providers, for example, providers of:
This list is not exhaustive. We only permit third-party service providers to process personal data for specified purposes and in accordance with our instructions, where appropriate contractual arrangements and security mechanisms are in place.
We shall not transfer personal data to any country outside the United Kingdom, unless we have advised the data subject accordingly in advance. A transfer of personal data outside the United Kingdom will only occur if we are satisfied that the country to which the data is to be transferred provides a level of personal data protection comparable to that provided by UK GDPR.
We shall share personal data to the extent necessary in order to:
When determining the appropriate period of retention for personal data, we shall consider the requirements of our business, the services provided, any legal and regulatory obligations, and the purposes for which we originally collected the data.
We shall only retain personal data for as long as there is a legal basis for doing so.
In accordance with recognised good practice within the accountancy profession, we usually retain records, including personal data, as follows:
It is important that the data we hold is accurate and current. Should a data subject's personal information change, they should ensure that we are notified of those changes of which we need to be made aware.
Data subjects have certain rights over their personal data that we process as data controller. If a data subject exercises any of those rights we shall aim to respond promptly. However, please note that the length of time it will take us to respond will be dependent on the nature and extent of the request.
A data subject has a right to:
If you wish to exercise any of your rights as data subject, please email at .
If you have any questions regarding this notice or if you would like to speak to us about the manner in which we process personal data, please email at , or telephone .
A data subject also has the right to make a complaint to the Information Commissioner's Office, whose address is:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website - www.ico.org.uk/concerns