Privacy & Cookies
Ellis & Co (Accountants & Business Advisors) Limited takes your privacy extremely seriously. This policy sets out how we collect and process any personal data you may provide to us when you use our website, sign up for any of our services or sign up to our digital marketing.
This policy applies where Ellis & Co (Accountants & Business Advisors) Limited (referred to as “we”, “us” or “our” in this privacy notice) identify as the data controller and where we are responsible for your personal data.
Ellis & Co (Accountants & Business Advisors) Limited have appointed a Data Protection Manager, who will be responsible for privacy matters and the protection of personal data we hold as an organisation, our Data Protection Manager is:
Name: Natalie Tomlinson
Email address: firstname.lastname@example.org
Telephone number: 0800 371 595
Ellis & Co (Accountants & Business Advisors) is a company registered in England and Wales registration number 03313474 whose registered office is 114-120 Northgate Street, Chester, Cheshire, CH1 2HT.
If you are unhappy with the way we collect or process your personal information, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) who are the UK’s supervisory authority for data protection.
Complaints and concerns can be lodged with the ICO via this link: https://ico.org.uk/concerns/
We kindly ask that before any complaints are lodged with the ICO, that you contact us first to try and resolve any issues you may have.
What data do we collect?
Personal information we may collect and process from you includes:
- Contact information – such as your name, address, telephone number and email address.
- Financial information – such as your bank account details or payment-related data.
- Technical information – this may include your IP address, browser details, location analytics, login details and any other technology information related with you using our site.
- Information provided to us by our clients which enable us to provide our services to their staff – this could include email addresses, account details or device identifiers.
- Any other personal information you may provide to us in the process of us providing you with our services.
Under the General Data Protection Regulation/Data Protection Act 2018, sensitive personal data is data which includes information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data.
Ellis & Co (Accountants & Business Advisors) Limited does not collect sensitive personal data about you – if we were to require it for any reason, we would seek explicit consent from you to gather this.
How do we use your personal data?
We will only use your personal data for the following reasons:
- To provide you with the services we offer as a business
- To provide you with information you have requested from us
- To keep you updated on our business, offers and news we may have
- To manage our relationship with you as an existing or potential client
- To fulfil any legal or contractual obligations we may have which require the processing of personal data
How do we obtain your data?
We can collect data about you via a variety of methods:
- From direct actions we may have with you by communicating via phone, email or post
- When you submit an enquiry via our website
- From automated technologies or interactions as you use our website from analytics engines and cookies – please see section 9 for more details
- When you provide information to us as part of our sign-up process with you as a client
- From third parties and/or publicly available sources such as your employer Companies House
Our lawful purposes for collecting and processing your information
We have identified that we will use your information for the following reasons:
- Where we need to perform the contract between us
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
- Where we need to comply with a legal or regulatory obligation
- With your explicit consent
Where we rely on consent as a lawful purpose for processing your personal data (when you sign up to our marketing or sign up as a client), you have the right to withdraw consent (where applicable) at any time by emailing us at email@example.com.
Who do we share your information with?
We may need to share your information with third parties in order to provide you with our services or to market to you, these third parties include:
- Her Majesty’s Revenue and Customs (HMRC)
- Companies House
- Our cloud providers, or any cloud-based accountancy software we may use
- Credit, reference and tenancy check agencies
- Anti-money laundering service providers
- Third-party marketing systems
Where we do share your information with third-parties, we ensure that the highest levels of data protection are in place in accordance with the law. Third parties with whom we share data are only permitted to process this data for the specified purposes we stipulate with them.
We do not sell your information onto third-parties.
Where possible, we ensure that your data is stored within the European Economic Area (EEA), however some of our storage locations and service providers may be hosted outside of the EEA. When we do need to transfer your personal data out of the EEA, we ensure one of the following safeguards are in place to provide a similar level of security of your data:
- Your personal data has been transferred to a country that has been deemed to provide an adequate level of protection for personal data by the European Commission; or
- the hosting environment we use has specific contracts, codes of conduct or certification mechanisms in-place which have been approved by the European Commission; or
- where we transfer data to the United States, we ensure our providers are certified as part of the EU-US Privacy Shield programme.
If none of these safeguards are available, we will only transfer your data with your explicit consent – which can be removed at any time by contacting us.
Please email us at firstname.lastname@example.org if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Your personal information will be retained in accordance with our data retention policy which categorises all of the data assets held by us and specifies the appropriate retention period for each data asset.
These periods are based on the requirements to keep the data for as long as necessary to fulfil the purpose for which it was collected, to meet any legal requirements or to satisfy any reporting, accounting or contractual needs.
Please contact our Data Protection Manager if you would like further information on our retention periods.
Under the General Data Protection Regulation/Data Protection Act (2018), you have certain rights regarding your personal data, these include the right to:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Right to withdraw consent
You may exercise any of these rights by raising a subject access request with us. You can do this by contacting our Data Protection Manager.
We will not charge you for making a request and we will make all reasonable efforts to respond to you within 30 days. Sometimes it may take longer than 30 days to gather all the information we may hold on you, in this situation we will keep you updated at all times.
You can instruct us at any time to stop processing your personal data for the purposes of marketing.
We may refuse your request or withhold any personal information that you request if there is an overriding legal reason for us to do so.
Ellis & Co (Accountants & Business Advisors) takes the security of your information extremely seriously. In order to protect your data, we implement a risk-based approach to adopt the strongest organisational and technical controls in order to protect the confidentiality, integrity and availability of your data.
Our website uses some third-party cookies to track the use of it. This allows us to better understand patterns on our website and how we can develop and improve it, as well as analysing the traffic on our site for marketing or advertising purposes.
A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.
Third Party Cookies
For more information on Google Analytics or LiveChat cookies, see the official Google Analytics and LiveChat pages.
- From time to time we test new features and make subtle changes to the way that our websites are delivered. When we are still testing new features, these cookies may be used to ensure that you receive a consistent experience whilst on our websites whilst ensuring we understand which optimisations our users appreciate the most.
Most browsers allow you to refuse to accept cookies and to delete cookies. The method for doing so differs with each browser, the following guides for the most common internet browsers detail the processes for doing this:
- https://support.google.com/chrome/answer/95647?hl=en (Google Chrome)
- https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences (Mozilla Firefox)
- https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer)
- https://support.apple.com/kb/PH21411 (Safari)
- https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Microsoft Edge)
Blocking cookies may impact your experience on our website as you may not be able to make full use of the features on it.
We keep this policy under regular review. This policy was last reviewed on 15th December 2018. Any questions about this policy can be directed to our Data Protection Manager.