Privacy Policy

Last updated: 24/09/2026

Clearview Digital Accountancy Ltd explains in this policy how we collect, use, share and retain personal information when you visit our website, contact us or use our accounting and tax services.

Personal information means information that identifies an individual or can be used to identify them.

It covers prospective and existing clients, people who contact us on behalf of businesses, and other individuals whose information we receive in connection with our work, such as directors, beneficial owners and employees of our clients.

1. Who we are and how to contact us

In this policy, “Clearview”, “we”, “us” and “our” mean Clearview Digital Accountancy Ltd.

We are the data controller, where we decide why and how personal information is used, including for our inquiries, client relationships and professional or legal responsibilities.

For some activities, such as particular payroll-processing tasks performed solely on a client’s documented instructions, we may act as a data processor. The client is then responsible for the relevant controller decisions and its own privacy information. The same engagement can involve different roles for different activities.

If you are unsure who is responsible for information about you, contact us and we will help identify the appropriate organisation. This policy does not replace any data processing agreement required for services we perform as a processor.

2. Information we collect

The information we need depends on your enquiry, the services agreed with you and our legal responsibilities. It may include:

  • Identity and contact information: your name, address, email address, telephone number, date of birth and relevant identity-verification documents.
  • Business information: business name, role, company ownership or directorship details, and information about the business’s activities.
  • Accounting and tax information: income, expenses, invoices, receipts, bank statements, financial records, National Insurance number, Unique Taxpayer Reference, VAT details and correspondence with HMRC.
  • Payroll information: employee identity and contact details, pay, working hours, tax codes, deductions, pension information and relevant absence or statutory-pay information, where needed for the payroll service.
  • Payment and engagement information: services selected, agreed fees, invoices, payment references, transaction status, engagement documents and communications.
  • Website and communication information: information you submit, records of our correspondence, IP address, browser/device information and relevant website activity or security logs.
  • Preferences: your communication choices and records of consent or objections.

Some business records contain information about other individuals. We only need information relevant to the work we have agreed to undertake.

Please use the document-sharing method agreed with us for sensitive records rather than including unnecessary financial or identity documents in a general enquiry.

3. Where information comes from

We receive information directly from you through enquiries, correspondence, meetings and documents supplied for our work.

Depending on the service, we may also receive relevant information from:

  • the business or employer that has engaged us;
  • your authorised representatives or previous accountant, where an appropriate handover has been arranged;
  • HMRC and other relevant public authorities;
  • publicly available sources, such as Companies House;
  • payment providers, banks or accounting systems involved in the service; and
  • identity-verification providers used for required checks.

[TO BE FILLED: identify any verification agencies, other public sources or third-party data sources actually used. Remove categories that do not apply.]

If you give us another person’s information, you should be entitled to share it and make them aware of this policy where appropriate. We remain responsible for our own obligations to explain our use of personal information.

4. Why we use information and our lawful bases

We use personal information only where there is an appropriate lawful basis. The table below describes the bases for activities where we act as controller.

Purpose

Lawful basis

Responding to an enquiry or preparing a proposal requested by you

Taking steps towards a contract with you; otherwise our legitimate interest in responding to genuine enquiries and managing business relationships.

Providing agreed accounting and tax services to an individual client, including a sole trader

Performance of our contract with that individual.

Working with a company client and communicating with its directors, staff or representatives

Our legitimate interest in delivering the services requested by that organisation and maintaining the relationship.

Carrying out identity checks, anti-money-laundering checks and required reporting

Compliance with legal obligations that apply to us.

Issuing invoices, collecting fees and administering payments

Performance of a contract with an individual; otherwise our legitimate interest in administering and receiving payment for our services. Our own statutory accounting records are also kept to meet legal obligations.

Protecting our systems, preventing misuse and maintaining reliable services

Our legitimate interest in protecting information, operating our business and resolving technical problems.

Handling complaints, managing professional risks or dealing with legal claims

Our legitimate interest in resolving concerns and protecting legal rights, and compliance with legal obligations where applicable.

Sending marketing or using optional tracking technologies

Consent where required; otherwise a lawful basis appropriate to the specific activity, as explained in sections 8 and 9.

Where we rely on legitimate interests, we consider whether the processing is necessary and whether your interests and rights outweigh those interests.

Providing information needed to verify your identity or deliver an agreed service may be a legal or contractual requirement. If you do not provide it, we may be unable to accept an engagement or complete the relevant work. We will explain what is required and why.

Marketing choices are separate from the information needed to deliver our services. Reading this policy or using the website does not, by itself, give consent to marketing or optional tracking.

5. Information requiring additional protection

Some work may involve health-related information, for example where it is needed for statutory pay or relevant payroll absence records. Certain checks may also involve information about criminal offences.

These types of information have additional legal protections. Where we act as controller, we need the relevant additional legal condition as well as a lawful basis described above. Where we act as processor, we handle the information under the client’s documented instructions and the applicable processing agreement.

[TO BE FILLED: describe the special-category or criminal-offence information actually processed as controller, its specific purpose, and the applicable UK GDPR Article 9 or Article 10/DPA 2018 condition. If there is no such controller processing, replace this paragraph with an accurate statement of that position. Confirm any required appropriate policy document separately.]

We ask for this information only where it is necessary for the relevant work or obligation.

6. Who we share information with

We share relevant information where necessary for the agreed service, a legal obligation or another purpose explained in this policy. Recipients may include:

  • HMRC, Companies House and other authorities relevant to the work;
  • anti-money-laundering authorities, supervisors or law-enforcement bodies where reporting or disclosure is required;
  • payment providers and banks involved in a transaction;
  • suppliers supporting our accounting, communications, website, document storage or other business systems;
  • professional advisers, insurers or other parties involved in a complaint or legal claim; and
  • another accountant or representative involved in an authorised handover.

We limit disclosures to what is necessary. Suppliers processing information on our behalf must be covered by appropriate data processing terms. Some recipients, including public authorities and payment providers for certain activities, act as independent controllers.

[TO BE FILLED: confirm the recipients actually used. Name the providers or describe sufficiently specific recipient categories, including any hosting, email, accounting/payroll, booking, chat, CRM, document-storage, analytics or advertising services receiving personal information. Include GoloGolo only if its actual access and role make it a recipient; remove unused services.]

7. Payments through Stripe and GoCardless

We use Stripe and GoCardless for relevant payment methods. When you pay using one of these services, the provider processes the information needed for the transaction and related activities such as fraud prevention and legal compliance.

We use the payment information available to us to reconcile fees, maintain payment records and deal with payment enquiries.

[TO BE FILLED: describe the actual checkout or payment-link flow and the payment fields Clearview receives and retains. Confirm whether full card or bank credentials ever reach Clearview’s systems; do not claim that they never do without checking the implementation.]

These providers explain their own processing, including processing carried out for their own purposes, in their notices:

Our payment, cancellation and refund conditions are set out separately in Payments, Cancellations & Refunds.

8. Marketing and your choices

For marketing emails or similar messages to individuals, including sole traders, we obtain consent unless a permitted existing-customer exception applies. That exception requires us to obtain the contact details directly during a sale or negotiations for a sale, market our own similar services, and give a clear opportunity to opt out both when details are collected and in each message.

For marketing permitted without consent, including appropriate corporate-contact marketing, we rely on our legitimate interest in promoting relevant services, subject to your rights and reasonable expectations. We must still respect objections.

You can object to direct marketing at any time. Use the unsubscribe method in the message or contact our privacy contact. This includes profiling related to direct marketing.

We may retain a limited record of your objection so that we continue to respect it. Opting out of marketing does not stop necessary communications about work you have asked us to carry out.

9. Cookies and similar technologies

Our Cookie Policy explains the technologies actually used on the website, their purposes and how to manage your choices.

Where consent is required, the relevant technology must not operate until you have given it. Any technology used under a permitted exception must meet that exception’s conditions, including any requirement to provide a simple, free way to object.

Technologies that store or access information on your device for advertising or measuring advertising conversions require consent. An exception for limited statistical purposes does not automatically cover all analytics tools or advertising measurement.

10. International processing

Where UK international-transfer rules apply, a permitted transfer mechanism must be in place. Depending on the actual transfer, this may involve UK adequacy regulations or appropriate contractual safeguards with the required assessment and additional measures.

You can contact us for information about these safeguards and how to obtain a copy, subject to appropriate protection of confidential information.

11. How long we keep information

We retain information for the relevant service or purpose and for applicable legal, regulatory or justified record-keeping needs. Different information has different retention periods.

Information

Retention period or decision criteria

Enquiries that do not become a client engagement

[TO BE FILLED: maximum period and starting point, such as the last substantive contact.]

Client accounting and tax files, working papers and engagement records

[TO BE FILLED: actual schedule by record type, with the event that starts each period. Consider statutory duties, professional requirements and relevant legal-claim periods.]

Customer due-diligence records retained under anti-money-laundering requirements

Normally five years after the business relationship ends, or after completion of an occasional transaction where applicable. Further retention requires an applicable lawful exception.

Our own invoices, fee records and statutory accounting records

Normally six years from the end of the last company financial year they relate to, or longer where the relevant legal rules require it.

Payroll information processed solely for a client

The agreed instructions and processing terms, subject to any legal requirement to retain particular information. [TO BE FILLED: the actual period or return/deletion arrangements.]

Marketing preferences and objections

While needed to act on your choices; a limited suppression record may be retained to prevent further unwanted marketing.

Website/security logs and backup copies

[TO BE FILLED: actual log periods and backup expiry/deletion arrangements.] Cookie durations are explained in the Cookie Policy.

A specific legal requirement, investigation or legal claim may justify retaining relevant records for longer. We do not use that as a reason to retain unrelated information indefinitely.

When information is no longer required, we delete it or make it anonymous in accordance with the applicable retention arrangements.

12. Protecting information

We use organisational and technical measures appropriate to the information and the risks involved.

[TO BE FILLED: add a concise, verified description of the measures actually implemented, covering access, storage, transfer of documents, supplier access and deletion where relevant. Do not claim particular encryption, certifications or portal protections without verification.]

If a personal-data breach occurs, we assess it and notify the regulator and affected individuals where the law requires us to do so.

13. Your rights

Depending on the circumstances and the basis for processing, you may have the right to:

  • ask for access to your personal information and a copy;
  • ask for inaccurate information to be corrected;
  • ask for information to be erased;
  • ask for its use to be restricted;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests; and
  • withdraw consent at any time where consent is the basis for processing.

Your right to object to direct marketing is unconditional. For other objections, the law may allow processing to continue where the relevant grounds apply.

Withdrawing consent does not affect processing already carried out lawfully before withdrawal. Some other rights have exceptions; for example, we may need to retain information to meet a legal obligation.

To exercise a right, contact us using section 1. We may need proportionate information to verify your identity or understand the request. Requests are normally free of charge; a fee or refusal is possible only where the law permits.

We respond without undue delay and normally within one calendar month. Where the law permits an extension or a pause for necessary clarification or identity information, we will explain what is needed and the effect on the response time. A permitted extension for complexity or multiple requests can add up to two months.

If we cannot fulfil a request, we explain the reason and the available complaint routes.

14. Automated decisions

[TO BE FILLED: confirm whether Clearview makes decisions based solely on automated processing that have legal or similarly significant effects. If none are made, say so. If they are made, explain the activity, information and logic involved, its likely consequences and the safeguards, including how to obtain human intervention, express a view and challenge a decision.]

Payment providers may make their own automated fraud or transaction decisions. Their privacy notices explain the activities for which they are responsible. This does not remove our responsibility for decisions or processing that we control.

15. Questions and complaints

If you have a concern about how we use your personal information, contact our privacy contact in section 1. You can also follow the data-protection route in our Complaints Procedure.

We acknowledge a data-protection complaint within 30 days, investigate appropriately and keep you informed of progress and the outcome without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection regulator. Its complaints service explains how to raise a concern. You do not have to give up that right to use our own complaints process.

16. Changes and related information

We review this policy when our services, processing arrangements or legal requirements change. The latest version and its update date will appear on this page. Where required, we will explain significant changes before using information for a new purpose and obtain consent if it is needed.

Contractual matters are covered separately by our Website Terms of Use, Accounting Services Terms and Payments, Cancellations & Refunds. Cookie choices and complaints are explained on the separate pages linked above.