Artema Ltd and Avencia — Privacy Policy
Introduction
Artema and Avencia are strongly committed to protecting personal data. References in this policy to ‘we’, ‘us’, or ‘our’ mean Artema Ltd and Avencia Tax and Accountancy Ltd, which operate one shared process for handling personal data. This privacy statement describes why and how we collect and use personal data, and provides information about individuals' rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to personal data provided to us, whether by individuals themselves or by others. We may use personal data provided to us for any of the purposes described in this privacy statement, or as otherwise stated at the point of collection.
Each company acts as the data controller for the personal data relating to its own clients and engagements. The company named in your engagement letter will normally be your data controller. The companies share staff, systems and administrative processes and may share personal data within the group where necessary.
Personal data we collect
Personal data is any information relating to an identified or identifiable living person. Depending on the services we provide, we may collect and process:
- Contact details, including full name, any previous names, current and previous home addresses, telephone number, and email address.
- Date of birth, National Insurance number, and tax reference number (UTR).
- Bank details, where applicable.
- Financial records, including income, expenditure, assets and liabilities.
- Tax information and correspondence with HMRC.
- Identity documents, obtained for anti-money laundering verification purposes.
- Company and beneficial ownership information.
- Payroll and employment information, including pension information.
- Family and dependant information, where relevant to your affairs.
- Correspondence between us relating to your instructions.
If you provide personal information about another person, such as a spouse, dependant, or employee, you must be authorised to provide it and, where appropriate, make them aware of this privacy policy.
Some information is required so that we can comply with the law or provide the services set out in our engagement. If you do not provide the information requested, we may be unable to act for you or continue providing particular services.
Special category and criminal offence information
Some of the information we hold may include special category data, such as health information relating to sickness absence, maternity, or trade union membership within payroll records, or information relating to criminal offences, which can arise in the course of anti-money laundering or fraud-related work. We only process this information where both a lawful basis under Article 6 UK GDPR and an appropriate condition under the Data Protection Act 2018 apply.
Where we obtain your information from
In addition to information you provide to us directly, we may also obtain personal data from your employer or company, other family members, your previous accountant, HMRC, Companies House, banks, bookkeeping and accounting software, and other publicly available sources.
How we use your personal information, and our lawful basis for doing so
We need your personal information in order to carry out our work properly. The table below sets out the main purposes for which we process personal data and the lawful basis we rely on for each. More than one basis may apply to a given activity.
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and providing accountancy and tax services | Contract, or steps taken at your request before entering into a contract |
| Acting for a company client and dealing with its directors, employees and contacts | Legitimate interests, as the contract is with the company rather than the individual |
| Anti-money laundering, fraud prevention, sanctions, tax and other regulatory compliance | Legal obligation and, where applicable, recognised legitimate interests in preventing or detecting crime |
| Managing the practice, security, debt recovery and legal claims | Legitimate interests and legal obligation |
| Newsletters and marketing | Legitimate interests under UK GDPR, together with consent or the soft opt-in where required by PECR |
| Referrals to independent financial advisers, lenders or other professionals | Consent or your specific instruction |
The law also requires us to comply with a number of regulations. Where necessary, we use your personal data to allow us to fulfil these legal and regulatory requirements.
Who we share your information with
We will only share personal information with others when we are legally permitted to do so. Where we share data with others, we put contractual arrangements and security measures in place to protect that data and to comply with our data protection, confidentiality, and security standards. Depending on the service provided, we may share personal data with:
- HMRC, by telephone or through a secure link via the Government Gateway. HMRC will only rarely accept email correspondence, and only with our client's prior consent.
- Companies House. Please note that information submitted to Companies House, such as details of company officers, becomes part of the public register as a result of that submission.
- Identity verification and anti-money laundering check providers.
- Payment and direct debit collection providers, which are regulated and hold recognised information security certification.
- Cloud accounting, tax preparation, payroll, document management, and practice management software providers that we use to deliver our services.
- Other cloud-based bookkeeping platforms chosen and owned by the client directly. Although the subscription belongs to the client, we remain responsible for our own access to and use of information within these systems.
- Our professional body, AML supervisor, insurers, and legal advisers, where necessary for regulatory compliance, risk management, or to obtain professional advice.
- Pension providers, banks, other regulators, and law enforcement bodies, where relevant to the services we provide or where we are legally required to do so.
We do not share your information with, or introduce you to, any other third party, such as an independent financial adviser, bank, mortgage broker, or lender, without your consent or specific instruction, unless the disclosure is otherwise permitted or required by law.
We do not record telephone calls. We may keep a note of the date and time we spoke with you if something of importance was discussed.
International data transfers
Where your personal data is processed by a supplier outside the United Kingdom, we ensure it remains protected by an appropriate safeguard recognised under UK data protection law. Depending on the supplier and location involved, this may include reliance on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or another legally permitted safeguard.
Data security
- All of our PCs and portable devices are encrypted.
- We do not send sensitive information by email without encrypting the content and any attachments. Ordinary email is not a completely secure method of communication. Where information is sensitive, we ask that our Client Portal is used instead.
- We use our Client Portal to send confidential information to clients, such as statutory accounts, financial reports, and other sensitive material.
How long we keep your information
We normally retain client and engagement records for seven years from the end of the relevant financial year or the end of our relationship, whichever is later. Enquiry, marketing and other information is retained only for as long as reasonably necessary for the purpose for which it was collected. Different retention periods may apply where required by tax, anti-money laundering, employment, professional, legal claim, or other regulatory obligations.
Where you apply for a role with us and are not successful, we retain your application information for six months, after which it is deleted, unless you agree to remain on file for longer for future opportunities.
Your rights
Under UK data protection law, you have the following rights:
- The right to be informed about the collection and use of your personal data. This privacy policy exists to explain that to you.
- The right of access. You may ask us to confirm what personal data of yours we hold, and to provide you with a copy of it and other supplementary information. We do not normally charge a fee for dealing with such a request. A fee may only be charged, or a request declined, where it is manifestly unfounded or excessive, particularly if repetitive, or where you request further copies of information already provided.
- The right to rectification. You may ask us to correct inaccurate personal data or complete incomplete data.
- The right to erasure. You may ask us to delete your personal data in certain circumstances, for example where it is no longer necessary for the purpose it was collected, where we relied on consent and you withdraw it, or where we have processed it unlawfully. This right does not apply where we are required to retain records to meet a legal or professional obligation. In these cases, we will retain the relevant records until that obligation is fulfilled.
- The right to restrict processing. You may ask us to limit the way we use your personal data in certain circumstances.
- The right to object. You may object to our processing of your personal data where we rely on legitimate interests, including direct marketing.
- The right to withdraw consent. Where we rely on your consent, you may withdraw it at any time.
- The right to data portability. Where the information was provided by you, is processed by automated means, and our lawful basis is consent or contract, you may ask us to provide that data to you, or to another organisation, in a structured, commonly used, machine-readable format.
- The right to complain to the Information Commissioner's Office (ICO). You may complain to the UK's data protection regulator if you believe we have not handled your personal data in accordance with the law. Details are set out below.
We do not carry out any decision-making based solely on automated processing, including profiling, which produces legal or similarly significant effects on you.
Before we act on any request, we will take reasonable steps to verify the identity of the person making it.
How to raise a concern or complaint
If you have any concerns about how we handle your personal data, please contact us at [email protected]. We will acknowledge your complaint within 30 days and will respond without undue delay.
If you remain dissatisfied, you have the right to complain to the Information Commissioner's Office at ico.org.uk, or by telephone on 0303 123 1113.
Marketing
We only send marketing communications, such as newsletters, where permitted under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), relying on legitimate interests together with the soft opt-in where applicable. An opt-out is offered when your details are first collected, and in every marketing communication we send.
We do not send marketing materials to individuals or organisations who are not our clients, unless they have given consent to receive them.
Our website and cookies
Our website uses Google Analytics, which sets non-essential cookies to help us understand how visitors use our site, so that we can improve it. These cookies are not strictly necessary for the website to function. Where you have a choice over non-essential cookies, this is set out in the cookie banner shown when you first visit our website.
Our website may contain links to other websites of interest. Once you use these links to leave our site, we have no control over that other website, and we cannot be responsible for the protection or privacy of any information you provide while visiting it. Such sites are not governed by this privacy policy, and you should refer to the privacy statement applicable to the website in question.
Communication
Sensitive personal information, including tax returns and payslips, is sent to you using a secure channel of communication, such as our Client Portal, or another method agreed with you. Where we have provided, or you have chosen, a password to access parts of our website or Client Portal, you are responsible for keeping this password confidential and should not share it with anyone. Ordinary email is not a completely secure method of communication, and we recommend the Client Portal is used for anything sensitive.
Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or in the law.