Privacy policy

How we protect your personal data

Last updated: 18 February 2026

1. Introduction

Emilia Accountancy Ltd ("we", "us", "our") is a company registered in England and Wales (Company No. 09941485), with its registered office at Peel House, 34-44 London Road Office 203, London SM4 5BT.

This privacy policy explains how we collect, use, store and protect your personal data when you visit or use our website www.emiliaaccountancy.uk or when you use our accountancy services.

Please read this policy carefully. By using our website or services, you acknowledge the practices described in this document.

2. Data controller

The data controller responsible for your personal data is:

3. Legislation we comply with

We process personal data in accordance with the following regulations:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • EU GDPR (where applicable)
  • Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017
  • Proceeds of Crime Act 2002

4. What data we collect

We collect the following categories of personal data:

Via the website

Contact forms

  • Name, email address, phone number, message

UTR registration

  • Name, phone number, email address, activity type, start date

Service inquiries

  • Name, email address, phone number, service-specific fields

Online bookings

  • Name, email address, phone number, selected service, date and time of appointment (processed via SimplyBook.it)

Via accountancy services

When you use our accountancy services, we may collect and process:

  • Full name, date of birth, address
  • National Insurance number
  • Unique Taxpayer Reference (UTR)
  • Identity documents (passport, driving licence) - required under AML regulations
  • Bank statements and financial records
  • Tax information and tax returns
  • Employment and income details
  • Company number and director information (for limited companies)
  • VAT registration numbers
  • Payroll and employee information (for payroll services)

Technical data collected automatically

  • IP address, browser type, pages visited (collected via Google Analytics, only with your consent)
  • Anti-bot verification data (Cloudflare Turnstile) - does not include personally identifiable information
  • Cookies - please see our cookie policy for full details

5. How we collect your data

We collect personal data in the following ways:

  • Directly from you - when you fill in forms on our website, contact us by email or phone, make a booking, or provide documents required for our accountancy services
  • From third parties - HMRC (in connection with your tax affairs), Companies House, your bank (with your permission)
  • Automatically - through cookies and analytics tools when you browse our website (only with your consent)

6. Why we process your data

We process your personal data for the following purposes and on the following lawful bases:

Purpose Lawful basis
Responding to enquiries Legitimate interest (Art. 6(1)(f))
Processing service requests and delivering accountancy services Performance of contract (Art. 6(1)(b))
Preparing and filing tax returns with HMRC Performance of contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Anti-money laundering (AML) compliance Legal obligation (Art. 6(1)(c))
Sending service-related notifications Legitimate interest (Art. 6(1)(f))
Website analytics Consent (Art. 6(1)(a)) - via cookie banner
Website security and performance Legitimate interest (Art. 6(1)(f))
Anti-bot and anti-spam protection (Cloudflare Turnstile) Legitimate interest (Art. 6(1)(f))

7. Professional and regulatory obligations

As an accountancy practice, we are subject to legal and professional obligations that require us to collect and retain certain personal data:

Anti-money laundering (AML)

Under the Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002, we are legally required to:

  • Verify client identity (Customer Due Diligence - CDD) before providing services
  • Retain copies of identity documents and proof of address
  • Monitor transactions for suspicious activity
  • Report suspicious activities to the National Crime Agency (NCA) where necessary
  • Retain CDD records for a minimum of 5 years after the business relationship ends

Important: Legislation prohibits us from informing you if a suspicious activity report has been made (tipping off).

Tax obligations

We are required to submit information to HMRC on your behalf, including Self Assessment tax returns, Corporation Tax returns, VAT returns, and PAYE/NIC information for employees.

Professional bodies

We are members of the Institute of Certified Public Accountants (ICPA) and CPAA. These professional bodies may require access to client files as part of quality assurance and compliance reviews.

8. Who we share your data with

We may share your data with the following parties:

Authorities and regulators

  • HM Revenue & Customs (HMRC) - for filing tax returns and compliance
  • Companies House - for filing annual accounts and returns
  • National Crime Agency (NCA) - if required by AML legislation
  • ICPA / CPAA - during professional quality reviews

Technology service providers

Provider Purpose Data processed
Google Analytics Website traffic analysis (only with your consent) Anonymised IP address, browsing behaviour
Google Tag Manager Analytics script management Consent data
Cloudflare CDN, DDoS protection and site security IP address, request metadata
Cloudflare Turnstile Anti-bot protection for forms Browser metadata (no personally identifiable data)
SimplyBook.it Online booking system Name, email, phone, booking details
Trustpilot Customer review display Public reviews (no data transfer from us)
Gmail API (Google) Sending email notifications Email address, message content

We do not sell your personal data to anyone.

9. International transfers

Some of our service providers (Google, Cloudflare, SimplyBook.it) may transfer data outside the United Kingdom. Where this happens, we ensure appropriate safeguards are in place:

  • UK adequacy decisions
  • Standard contractual clauses (SCCs)
  • Other equivalent protections

10. How long we keep your data

Data type Retention period Reason
Client accountancy records Minimum 6 years after the relationship ends HMRC tax obligations and professional best practice
AML/CDD documents (identity verification) Minimum 5 years after the relationship ends Money Laundering Regulations 2017
Tax returns and supporting documents Minimum 6 years (individuals) / 6 years (companies) HMRC may request checks within this period
Website form submissions 2 years Enquiry management
Analytics data 14 months (Google default) Website improvement
Email logs 1 year Delivery monitoring
Cookies See our cookie policy Varies by type

Once the retention period expires, data is securely deleted or irreversibly anonymised.

11. Data security

We have implemented appropriate technical and organisational measures to protect your personal data:

  • SSL/TLS encryption for all website communications
  • Cloudflare protection against DDoS attacks and unauthorised access
  • Cloudflare Turnstile verification to prevent automated form submissions
  • Security headers (Content Security Policy, X-Frame-Options, HSTS)
  • Restricted access to client data for authorised personnel only
  • Encrypted communications with HMRC via official channels
  • Regular security reviews and software updates

12. Your rights

Under data protection law, you have the following rights:

Right What it means
Right of access You can request a copy of the personal data we hold about you.
Right to rectification You can ask us to correct inaccurate data or complete incomplete data.
Right to erasure You can ask us to delete your personal data in certain circumstances. Please note that we cannot delete data we are legally required to retain (e.g. AML records, tax documents).
Right to restriction You can ask us to limit the processing of your data in certain situations.
Right to portability You can request that we transfer your data to another service provider in a structured format.
Right to object You can object to the processing of your data in certain circumstances, including direct marketing.
Right to withdraw consent Where processing is based on consent (e.g. analytics cookies), you can withdraw it at any time via our cookie settings or by contacting us directly.

Important limitations: Certain rights may be limited where we have legal obligations to retain your data (for example, under AML regulations or HMRC requirements). We will inform you if any such limitation applies.

13. How to exercise your rights

To exercise any of the rights listed above, please contact us:

We may need to verify your identity before processing your request. We will respond within one month of receiving your request. If the request is complex, we may extend this by a further two months, but we will let you know.

14. Children's privacy

Our services are not directed at anyone under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it as soon as possible.

15. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We recommend contacting us first so we can try to resolve your concern before you approach the ICO.

16. Changes to this policy

We may update this privacy policy from time to time. The date of the last update is shown at the top of this page. For material changes, we will make reasonable efforts to notify you.

17. Contact us

If you have any questions about this privacy policy or our data protection practices, please get in touch: