Privacy notice
1. Purpose of this notice
Digicounts Ltd (‘the Firm’, ‘we’, ‘us’, ‘our’ and ‘ours’) respects your privacy and is committed to protecting it. This notice sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purposes of the GDPR, the data controller is Digicounts Ltd, registered in England and Wales as a Limited Company – Registration Number 13483480 – with their registered office at 153 Banstead Road South, Sutton, SM25LL. In some cases, we may also act as a data processor eg - where we undertake payroll services .
The person responsible for Data Protection is the Director.
2. Definitions
“Personal data” is any information that relates to a living individual who can be identified from that information. Processing is any use that is made of data, including collecting, storing, amending, disclosing or destroying it.
“Special categories of personal data” means information about an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation and genetic and biometric data.
3. Why have a privacy statement
Digicounts is committed to privacy for everyone who get to contact with us or use our services – we appreciate that you do not want the personal information you provide to us to be distributed indiscriminately. We will only use your personal information to help deliver the services you have requested from us, and to meet our legal responsibilities.
In accordance with the General Data Protection Regulation, we are required to comply with certain rules and regulations which are designed to ensure that any data you provide to us is processed with due care and attention.
4. How we collect information from you
We obtain information about you when you contact us or engage us to deliver our services and when you use our website. You may give us information about you by corresponding with us in person, by telephone, email, our secure portal (if applicable) , post, social media, online forms and questionnaires or otherwise.
We collect most of this information from you. However, we may also collect information:
We may also obtain information about your employees in the course of our work with you.
5. The data that we collect
The personal data we collect from you will vary depending on which services you are interested in or engage us to deliver. We will only collect personal data from you that we consider to be necessary in the context and purpose in which it is collected.
The data we collect might include your name, nationality, address, date of birth, e-mail address, phone number(s), your Unique Tax Reference (UTR) number, your National Insurance number, passport details, bank details, details of personal assets and income including your employment status, salary and benefits, pension arrangements, your IP address, information to enable us to check and verify your identity and any additional information we may require to provide our services to you.
You are under no obligation to provide any such information; however, this will affect the quality of the services we are able to provide you with if you choose not to.
Through your use of our services we may also collect personal data from you about a third party. If you provide us with their personal data , you must ensure that you are authorised to disclose that data and that, without us taking any further steps required by applicable data protection or privacy laws, we may collect, use and disclose such personal data for the purposes described in this Policy. You must, therefore, ensure that the third party concerned is aware of and agrees to the contents of this Policy, including: the fact that their personal data is being collected; the purposes for which it is being collected; the intended recipients of that data; and the third party's right to obtain access to the data (including details of how to request access). Where requested to , you must assist us with any requests by the third party to access or update the personal data you have collected from them and provided in connection with our Services.
6. How we use personal data we hold about you
We may process your personal data for purposes necessary for the performance of our engagement with you, and to comply with our legal obligations.
In general terms, and depending on which services you engage us to deliver, as part of providing our agreed services we may use your information to:
We are required by legislation, other regulatory requirements and our insurers to retain your data where we have ceased to act for you. In deciding how long to retain personal data we will make a decision based on statutory retention periods, limitation periods for claims, individual business needs and the data quality principles. The period of retention required varies with the applicable legislation, however, to ensure compliance with all such requirements it is the policy of the Firm to retain data for no more than 10 years from the end of the period of last engagement.
7. Why we collect and process sensitive personal data
We collect and process Sensitive Personal Data only so far as is necessary and in compliance with all applicable legislation. By providing your details to us, you consent to us collecting and processing the Personal Data supplied by you and disclosing this information, as necessary, in connection with the delivery of our services.
8. Access to your information
Your information will be shared internally where necessary. Any Directors, employees, staff, contractors or IT support services staff with access to your information have a duty of confidentiality under the ethical standards that the Firm is required to follow. While we will strive to uphold these standards, we shall not be held responsible if there is a breach of this inherent confidentiality and if this breach is unknown to us.
9. Who we share your personal data with
In order to deliver our services, the Firm needs to enter into agreement with third party software and IT service providers. Where the Firm engages such third parties to process personal data on its behalf, they do so in good faith and on the basis of written instructions or a contractual obligation. They are under a duty of confidentiality and are obliged to implement appropriate technical and organisational measures to ensure the security of data and ensure compliance under the GDPR regulations. Measuring the steps taken towards GDPR compliance by these third parties are beyond the scope of our scrutiny . Activities carried out by third-party services providers may include,among others, IT service providers, Cloud Accounting service providers, Document Management Services providers on the Cloud, professional advisory services, and administration services.
We will not transfer personal data outside of the European Economic Area (EEA) without complying with the relevant provisions of GDPR. You shall be solely responsible for compliance with Data Protection regulations if you access our services and tranfer personal data from outside the EEA.
10. How you can access and update your information
Keeping your information up to date and accurate is important to us. We commit to regularly review and correct where necessary, the information that we hold about you. If any of your information changes, please email or write to us, or call us using the ‘Contact information’ noted below.
You have the right to ask for a copy of the information the Firm holds about you.
11. Data Security
The Firm takes the security of your data seriously. The Firm has internal policies and controls in place to try to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by its Directors, employees and staff, in the performance of their duties. All our systems have appropriate security in place that complies with all applicable legislative and regulatory requirements.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
12. Your choices
We may occasionally contact you by post / email / telephone with details of any changes in legal and regulatory requirements or other developments that may be relevant to your affairs and, where applicable, how we may assist you further. If you do not wish to receive such information from us, please let us know by contacting us as indicated under ‘Contact information’ below.
13. Right to withdraw consent
In circumstances where you may have provided your consent to the collection, processing and transfer of your personal data for a specific purpose (for example, in relation to direct marketing that you have indicated you would like to receive from us), you have the right to withdraw your consent for that specific processing at any time
Once we have received notification that you have withdrawn your consent, we will no longer process your personal information (personal data) for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
14. Your rights
You have the following rights, which you can exercise free of charge (see (15) below) :
Please contact us in any of the ways set out in ‘Contact information’ below if you wish to exercise any of these rights.
15. No fee usually payable
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
16. How do we let you know if our policy changes?
Any policy changes, either due to business reasons or future changes in legislation, will be published on our website and, if substantial, may be promoted on the website or through other communication methods.
This privacy notice was last updated in September 2021.
Contact information
If you have a query or wish to make a compliant about this statement or any procedures that are set out in it, please contact us at admin@digicounts.co.uk . Alternatively, you may write to:
Digicounts Ltd
153 Banstead Road South
Sutton
Surrey
SM5LL
Complaints
We seek to resolve directly all complaints about how we handle your personal information, but you also have the right to lodge a complaint with the Information Commissioner’s Office at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk