01244 220 062
Client Data & Security

Privacy Policy & Data Commitment

Experience personalised accounting solutions tailored to your needs. Our family-run firm is here to simplify your financial journey with clear, jargon-free advice.

Official Regulatory Governance

Phillips & Co Privacy Policy

TPP Accountants Ltd t/a Phillips & Co Accountants is committed to protecting your personal data in full compliance with UK GDPR and the Data Protection Act 2018.

Data Controller TPP Accountants Ltd t/a Phillips & Co Accountants
ICO Registration Reference ZB260708 (UK GDPR & DPA 2018)
Effective Date June 2026

1. Introduction & Key Terms

At TPP Accountants Ltd t/a Phillips & Co Accountants, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share your personal information when you use our services or visit our website. This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

  • Personal Data: Any information that relates to an identified or identifiable living person.
  • Data Controller: The entity that determines the purposes and means of processing personal data (TPP Accountants Ltd t/a Phillips & Co Accountants).
  • Data Processor: An entity that processes personal data on behalf of the data controller.

2. Information We Collect

We collect the following types of personal data:

  • Identity Data: Full name, date of birth, residential and business addresses, email addresses, telephone numbers, National Insurance number, and passport/driving licence details where required for identity verification.
  • Financial Data: Bank account details, transaction records, invoices, payroll information, tax returns, financial statements, digital asset/cryptocurrency records, and statutory student loan obligations (Plan 1, 2, 4, 5, or Postgraduate Loans).
  • Special Category Data: Sensitive personal data (such as medical/health information) collected only when strictly necessary for service delivery and with your explicit consent.
  • Technical & Usage Data: IP addresses, browser types, and usage data collected via cookies when you interact with our website.
  • Third-Party & API Data: Automated syncing of tax, corporate, and financial data from third-party government gateways (e.g., HMRC, Companies House) via secure software APIs as authorized upon engaging our services.

3. How We Use Your Information & Legal Basis

We process personal data only when we have a valid legal basis under UK GDPR (Contractual Performance, Legal Obligation, Legitimate Interests, or Explicit Consent):

  • To provide accounting, tax, and advisory services as outlined in your Engagement Letter.
  • To comply with legal and regulatory obligations, including Anti-Money Laundering (AML) laws and HMRC reporting.
  • To manage business operations, client communications, billing, and record-keeping.
  • To send relevant tax updates and regulatory newsletters (such as Making Tax Digital announcements). You may opt out of marketing communications at any time.

4. Data Sharing, Software & Cookie Tracking

  • Data Sharing & Disclosure: We do not sell personal data. Data is shared with explicit consent, with required authorities (HMRC, Companies House), or with trusted third-party software partners essential to our service delivery (such as our secure document portal IRIS OpenSpace, and cloud accounting software like Xero).
  • Cookies & Tracking Pixels: Our website uses cookies to improve user experience, analyze traffic, and execute targeted cross-platform marketing (including social media and search engine pixels). You can configure your browser to refuse cookies, though some site features may become limited.

5. Data Security, Retention & Transfers

  • Data Security: We maintain robust technical and organizational safeguards against unauthorized processing, accidental loss, destruction, or damage.
  • Data Retention: Personal data is retained only for as long as necessary to fulfill legal, accounting, and reporting obligations—typically **seven years** following the end of our engagement.
  • International Transfers: Data is primarily processed within the UK. Any overseas transfers strictly adhere to approved UK GDPR data protection safeguards.

6. Your Data Protection Rights

Under UK data protection law, you hold the following rights:

  • Subject Access Request (SAR): Right to access your personal data. Data supplied under a SAR will be provided in a standardized digital export format (e.g., secure PDF or CSV) generated directly from our internal working papers.
  • Rectification & Erasure: The right to correct inaccurate data or request deletion ("right to be forgotten"), subject to statutory accounting retention rules.
  • Restriction, Portability & Consent: The right to restrict processing, request data portability, object to processing, or withdraw consent at any time.
  • ICO Complaint Right: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK's supervisory authority (www.ico.org.uk), if you are dissatisfied with our response.

7. Contact Our Data Protection Team

If you have any questions regarding this Privacy Policy or wish to exercise your UK GDPR rights, please reach out to us directly:

Telephone 01244 220 062
Trading Address (Correspondence) Obsidian Offices, Chantry Court, Chester, CH1 4QN
Registered Corporate Office 85 Great Portland Street, London, W1W 7LT