C
CENTRIXACCOUNTANTS

Legal & Compliance

Privacy Policy

How CENTRIX ACCOUNTANTS collects, uses, stores and protects personal and client data, in accordance with UK GDPR and the Data Protection Act 2018.

Effective

1 April 2026

Last reviewed

20 August 2026

Version

3.1

01

Who we are

This Privacy Policy is issued by CENTRIX ACCOUNTANTS (“Centrix”, “we”, “us”, “our”), a UK corporate financial advisory and tax practice. We are the data controller for personal data processed in connection with our website, client engagements, enquiries and practice operations.

Our principal place of business is 1 Canada Square, Canary Wharf, London E14 5AB, United Kingdom. You may contact our privacy function at enquiries@centrix-accountants.co.uk or +44 (0) 20 7100 8800.

We are registered with the Information Commissioner’s Office (ICO) as a data controller. As a professional accountancy practice we are also subject to the confidentiality and data-handling standards of the ICAEW and ACCA, in addition to UK data protection law.

02

Scope of this policy

This policy applies to personal data we process about clients, prospective clients, beneficial owners and officers of client entities, suppliers, professional intermediaries, website visitors, and individuals who contact us.

It covers data collected through our website (including consultation and contact forms), the client workspace, email and telephone, letters of engagement, Customer Due Diligence / KYC procedures, and information received from HMRC, Companies House, professional advisers and other authorised third parties.

Where we act as a processor on a client’s instructions (for example, processing payroll data for a client’s employees), a data processing addendum or letter of engagement will set out those arrangements. This policy primarily describes our role as controller.

03

Personal data we collect

The categories of personal data we process depend on your relationship with us. We collect only what is necessary for the relevant purpose and, in the case of client work, for the proper performance of a professional engagement.

  • Identity data — name, title, date of birth, nationality, photographic identification, and Companies House identity-verification information.
  • Contact data — business and personal email, telephone numbers, postal address, and preferred correspondence channels.
  • Corporate and role data — job title, company name, Companies House numbers, PSC / beneficial-ownership details, and signing authority.
  • Financial and tax data — bank details for fee settlement, Unique Taxpayer References, National Insurance numbers, payroll identifiers, tax computations, accounts, and HMRC correspondence.
  • Engagement data — letters of engagement, service selections, meeting notes, working papers, and communications with you and your advisers.
  • AML / KYC data — source-of-funds and source-of-wealth information, PEP and sanctions screening results, and risk-assessment records (see our AML Policy).
  • Technical data — IP address, browser type, device identifiers, and limited analytics relating to website and portal use.

We do not seek special-category data (for example, health or biometric data) as a matter of course. If such data is provided to us incidentally in the course of an engagement, it is handled under the additional safeguards required by UK GDPR Article 9 and deleted or minimised as soon as it is no longer required.

04

How we collect data

We collect personal data directly from you when you complete a contact or consultation form, open a client workspace account, provide onboarding documents, or correspond with us. We also collect data from the corporate entity that engages us, from authorised officers and professional intermediaries acting on its behalf, and from publicly available registers.

  • Direct collection via website forms, email, telephone, video conference and in-person meetings.
  • Client onboarding packs, identity documents and proof-of-address supplied for CDD.
  • Companies House, HMRC, credit-reference and sanctions-screening services used for verification and compliance.
  • Other professional advisers (solicitors, bankers, auditors) where you have authorised us to receive information.
  • Cookies and similar technologies on our website, as described in the Cookies section below.
06

How we use personal data

We use personal data to deliver corporate financial advisory, tax, accounting and compliance services; to onboard and identify clients; to communicate about engagements; to operate the client workspace; to meet our regulatory and statutory duties; and to administer our practice.

  • Providing the services described in your letter of engagement, including tax filings, accounts, payroll, R&D claims and advisory work.
  • Customer Due Diligence, ongoing monitoring and suspicious-activity assessment as required by AML law.
  • Identity verification for Companies House and similar statutory processes.
  • Fee billing, credit control and practice management.
  • Responding to contact and consultation requests and arranging senior-advisor meetings.
  • Securing our systems, detecting misuse, and maintaining audit trails.
  • Complying with requests from HMRC, the ICO, professional bodies, the National Crime Agency and other competent authorities where we are legally required to do so.
07

Client data handling

Client files are treated as confidential professional records. Access is limited to the senior specialists assigned to the engagement and to a small number of practice-operations staff who require access for quality, AML, billing or IT-security purposes. We do not outsource client advisory work to junior or offshore production teams.

Working papers, tax computations, statutory accounts and correspondence are stored in access-controlled systems. Paper documents received during onboarding are digitised promptly and originals returned or securely destroyed in accordance with the engagement and AML record-keeping rules.

Where we hold data relating to a corporate client’s employees, directors, shareholders or beneficial owners, that data is used solely for the engagement (for example payroll, PSC verification or tax filings) and is not used for unrelated marketing.

Professional confidentiality is subject to mandatory legal exceptions, including our duties under the Proceeds of Crime Act 2002, the Terrorism Act 2000, and court or regulatory production orders. Those exceptions are described further in our AML Policy.

08

Sharing and processors

We do not sell personal data. We share it only where necessary to perform the engagement, to comply with the law, or to operate the practice through carefully selected processors bound by written contracts.

  • HMRC, Companies House, the Charity Commission and other statutory bodies in connection with filings and enquiries you have instructed us to handle.
  • Professional bodies (ICAEW, ACCA) and our AML supervisory authority in the course of monitoring, quality review or investigation.
  • IT, document-management, e-signature, identity-verification, sanctions-screening and secure-hosting providers acting as processors under UK GDPR Article 28 terms.
  • Professional indemnity insurers, legal advisers and auditors, where necessary to obtain advice or to meet insurance conditions.
  • Successor practices or professional referees, only with your instruction or as required on cessation of practice.

All processors are required to implement appropriate technical and organisational measures, to process data only on our documented instructions, and not to use client data for their own purposes.

09

International transfers

Our primary systems and client files are hosted in the United Kingdom. Where a processor stores or accesses data outside the UK, we ensure a lawful transfer mechanism is in place — typically the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

We do not routinely transfer client files to jurisdictions without an adequacy decision. If an engagement specifically requires such a transfer (for example, a group with overseas companies), we will discuss the safeguards with you before proceeding.

10

Retention

We retain personal data only for as long as necessary for the purpose collected, including legal, accounting, AML and professional-indemnity requirements.

  • Client engagement files — typically six years after the end of the tax year or engagement to which they relate, or longer where HMRC enquiry windows, group relief or capital-gains history so require.
  • AML / CDD records — at least five years after the end of the business relationship, as required by the Money Laundering Regulations, and not used for other purposes after that point except where a longer legal duty applies.
  • Enquiry and contact-form records — up to two years if no engagement follows, unless you ask us to delete them sooner and no legal hold applies.
  • Website analytics — in aggregated or short-retention form, generally no longer than thirteen months.

When retention expires, data is securely deleted or irreversibly anonymised. Backup copies fall out of rotation according to our disaster-recovery schedule.

11

Security measures

We implement technical and organisational measures appropriate to the sensitivity of tax, financial and identity data we hold. Security is reviewed as part of our practice governance and is not treated as an IT afterthought.

  • Encryption in transit (TLS) for the website, client workspace and email gateways, and encryption at rest for primary document stores.
  • Role-based access control, unique user credentials, and multi-factor authentication for the client workspace and internal systems.
  • Least-privilege access to client files, with senior-advisor ownership of each engagement.
  • Device hardening, endpoint protection, and prompt patching of production systems.
  • Staff confidentiality undertakings and mandatory data-protection and AML training.
  • Vendor due diligence on processors, including review of security certifications where available.
  • Incident-response procedures, including assessment of ICO notification duties within the 72-hour statutory window where a personal-data breach is likely to result in a risk to individuals.

No method of transmission or storage is perfectly secure. We maintain professional indemnity insurance and will notify affected clients and the ICO where the law requires it. You should also protect credentials issued for the client workspace and notify us immediately of suspected unauthorised access.

12

Your GDPR rights

Under the UK GDPR you have the following rights, subject to the exemptions that apply to professional advisers, legal obligation processing and AML record-keeping.

  • Access — to obtain confirmation of processing and a copy of your personal data.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to request deletion where there is no overriding legal or professional duty to retain the data.
  • Restriction — to request that we limit processing in certain circumstances.
  • Portability — to receive data you provided to us on the basis of contract, in a structured, commonly used format, where technically feasible.
  • Objection — to processing based on legitimate interests, including profiling of that kind.
  • Withdraw consent — where processing is based on consent.

We may refuse or limit a request where disclosure would breach our confidentiality duties to another client, prejudice a confidential SAR, or conflict with a legal obligation to retain records. We will explain the basis for any refusal. To exercise your rights, write to enquiries@centrix-accountants.co.uk with sufficient information for us to verify your identity. We will respond within one month, or explain if an extension is required.

13

Cookies and similar technologies

Our public website uses strictly necessary cookies to operate the session, remember essential preferences, and protect forms from abuse. We do not use advertising cookies or sell browsing data to third parties.

Limited first-party analytics may be used to understand aggregate traffic and improve the site. Where non-essential cookies are used, we will request your consent. You can control cookies through your browser settings; blocking strictly necessary cookies may affect site functionality, including the client workspace login.

14

Complaints and the ICO

If you are concerned about how we handle your personal data, please contact us first so that we can investigate. We take privacy complaints seriously and will respond promptly.

You also have the right to lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority for data protection: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; ico.org.uk; 0303 123 1113.

15

Changes to this policy

We may update this Privacy Policy to reflect legal, regulatory or operational changes. The version and last-reviewed date appear at the head of this page. Material changes affecting clients will be communicated through the client workspace or by email where practicable. Continued use of our website after an update constitutes notice of the revised policy; engagement terms continue to be governed by your letter of engagement and our Terms & Conditions.