TX Accountants Ltd

 

Privacy Policy

Last updated: 23 September 2026

 

1. Who we are

 

TX Accountants Ltd is the controller of personal information described in this notice. We are registered in England and Wales under company number 12163394. Our registered office is 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. Our ICO registration number is ZA725806.

This notice applies to clients, prospective clients, website users, client personnel, suppliers and other individuals whose information we handle in connection with our accountancy, tax, payroll, bookkeeping, company secretarial and related professional services. Where we process personal information solely on a client’s documented instructions, for example, some payroll information, the client may be the controller, and we may act as its processor.

 

2. Information we collect

 
  1. Contact and identity details, including names, addresses, dates of birth, signatures, identification documents, tax references, National Insurance numbers and company roles.
  2. Financial, accounting and tax information, including income, expenses, assets, liabilities, transactions, bank details, payroll, pension, VAT and tax return records.
  3. Business and engagement information, including ownership and control, services requested, instructions, correspondence, meeting notes, deadlines, approvals, invoices and payment records.
  4. Due diligence and compliance information, including source of funds or wealth, sanctions and politically exposed person checks, risk assessments and information relevant to fraud, money laundering or other unlawful activity.
  5. Special-category information where necessary, such as health information relevant to a tax claim, and criminal-offence information where it is relevant to our legal or regulatory obligations.
  6. Website and technical information, including IP address, device and browser data, pages viewed, referral data and cookie choices. See our Cookie Policy.
  7. Information about other people contained in records supplied to us, such as employees, directors, shareholders, family members, tenants, customers or suppliers.

 

3. Where we obtain information

 

We normally obtain information from you or the organisation you represent. We may also obtain it from authorised representatives, employers, employees, previous advisers, banks and payment providers, accounting and payroll platforms, identity-verification and screening providers, HMRC, Companies House, The Pensions Regulator, other public registers and authorities, and publicly available sources. If you give us information about another person, you should ensure that you are authorised to do so and, where appropriate, direct them to this notice.

 

4. Why we use information and our lawful bases

 

Purpose

Typical lawful basis

Responding to enquiries, preparing proposals and onboarding

Steps at your request before a contract; legitimate interests in managing enquiries and developing our practice.

Providing and administering agreed professional services

Performance of a contract; legitimate interests where the client is an organisation and we process its personnel’s information.

Identity checks, AML monitoring, tax and regulatory compliance

Legal obligation; legitimate interests in preventing fraud and protecting the profession. Additional DPA 2018 conditions are used where sensitive or criminal-offence data is involved.

Submitting information to HMRC, Companies House, pension bodies or other authorities

Performance of a contract and legal obligation, depending on the filing and our role.

Billing, payment collection, service quality, complaints and legal claims

Performance of a contract; legitimate interests in operating the practice, recovering debts, improving service and establishing or defending legal rights.

Security, backups, audit trails and fraud prevention

Legal obligation where applicable; legitimate interests in protecting clients, systems and the practice.

Service updates and direct marketing

Consent where required by PECR; otherwise legitimate interests where permitted. Every message will provide an opt-out.

Non-essential cookies and similar technologies

Consent. Necessary technologies are used for operation and security as permitted by PECR.

Where we rely on legitimate interests, we consider the benefit, necessity and impact on individuals before processing. Consent is not used where the processing is actually required to perform our contract or comply with law.

 

5. If you do not provide information

 

Some information is needed to enter into or perform our contract or to meet legal and professional obligations. If it is not provided, we may be unable to accept instructions, complete work, submit a filing, verify identity or continue acting. We will explain the practical consequences where it arises.

 

6. Sensitive information and AML obligations

 

We only use special-category or criminal-offence information where necessary and where both an Article 6 lawful basis and an additional condition under the Data Protection Act 2018 apply. This may include legal claims, substantial public interest conditions relating to regulatory requirements, preventing or detecting unlawful acts, protecting the public against dishonesty, preventing fraud, or suspicion of money laundering. We maintain additional documentation where the law requires it.

Anti-money laundering and related laws may require us to retain and disclose information to competent authorities. Those laws can restrict what we may tell you about a report or investigation.

 

7. Sharing information

 

We may share information where necessary with HMRC, Companies House, The Pensions Regulator and other public or regulatory bodies; professional bodies and oversight authorities; banks, pension providers and payment providers; identity, sanctions and AML screening providers; accounting, tax, payroll, document management, client portal, email, hosting, security, backup and IT support providers; insurers, auditors, legal advisers and debt recovery providers; and a new adviser where you authorise a professional handover.

Our providers must protect information and may use it only for agreed purposes. We do not sell personal information. We may also disclose information where required by law, court order, a regulator, or to protect legal rights, security or the public.

 

8. International transfers

 

Some service providers may store information or allow support access from outside the United Kingdom. Before making a restricted transfer, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU contractual clauses, or another permitted safeguard. Where required, we assess the protection available in the destination and apply supplementary security measures. You may ask us for further information about the relevant safeguard.

 

9. Security

 

We use proportionate technical and organisational measures designed to protect personal information, including access controls, authentication, encryption where appropriate, backups, staff confidentiality and supplier due diligence. No system is completely secure, but we investigate suspected incidents and notify individuals and the ICO when the law requires it.

 

10. Retention

 

We keep information only for as long as reasonably necessary for the purpose collected, including legal, tax, regulatory, insurance and dispute requirements. Our typical periods are:

Record

Typical period

Client engagement, advice, accounts, tax and supporting working papers

Usually 6 years after the end of the relevant accounting or tax period, or the end of the engagement if later; longer where law, an enquiry, litigation, insurance or the nature of the record requires it.

AML identity and transaction records

5 years after the business relationship ends or an occasional transaction completes, unless a lawful reason permits or requires longer retention.

Payroll records and related submissions

Normally 6 years after the relevant tax year or engagement, subject to the applicable statutory minimum and any live claim or enquiry.

Prospective client enquiries that do not proceed

Normally up to 2 years, unless needed for conflict, fraud-prevention or legal reasons.

Invoices and accounting records for our own business

Normally at least 6 years, in line with tax and company record-keeping duties.

Cookie consent records and website security logs

For the period needed to demonstrate consent and maintain security, normally up to 2 years unless a shorter period is configured.

When retention ends, information is securely deleted or anonymised. Backup copies may remain for a limited cycle and are protected from ordinary use.

 

11. Your rights

 

Depending on the circumstances, you may ask us to access your information; correct it; erase it; restrict its use; object to processing based on legitimate interests or to direct marketing; or provide information you supplied in a portable format. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.

These rights are not absolute. For example, legal and regulatory record-keeping duties, legal privilege, third-party rights or the prevention and detection of crime may limit what we can provide or delete. We may ask for information to verify identity. We normally respond within one month and do not charge unless a request is manifestly unfounded, excessive or repeated as permitted by law.

 

12. Automated decisions

 

We may use software to assist with checks, risk indicators or workflow. We do not intend to make decisions about you based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.

 

13. Marketing and cookies

 

You can opt out of marketing at any time by using the unsubscribe method in a message or contacting us. Our use of cookies and similar technologies is described in the Cookie Policy. You can change non-essential cookie choices through the website’s cookie settings control.

 

14. Contact and complaints

 

To exercise a right or ask a privacy question, contact TX Accountants Ltd through the contact details or contact form on www.ghostwhite-leopard-205060.hostingersite.com, or write to our registered office above. Please mark correspondence for the attention of the Privacy Lead.

Please contact us first so we can try to resolve any concern. You may also complain to the Information Commissioner’s Office at www.ico.org.uk/make-a-complaint or by telephone on 0303 123 1113. You may contact the ICO at any time, although it generally expects concerns to be raised with the organisation first.

 

15. Changes to this notice

 

We may update this notice when our services, systems or legal obligations change. The current version will be published on our website with its revision date. We will draw material changes to the attention of affected individuals where appropriate.

 

 

Issued and maintained by:

TX Accountants Ltd
Registered in England & Wales
Company Registration No: 12163394 and ICO No: ZA725806.
Registered Office: 167–169 Great Portland Street, 5th Floor, London, W1W 5PF

 

 

Scroll to Top