Privacy Policy

    Effective Date: 9 February 2026

    This Privacy Policy explains how 360 Accounts & Bookkeeping Ltd ("we", "us", "our") collects, uses, stores, and protects your personal data. As a UK accountancy firm, we process highly sensitive financial and identity information, and we are committed to full compliance with the UK GDPR, Data Protection Act 2018, Anti‑Money Laundering (AML) Regulations, and evolving regulatory reforms.

    1. Who We Are

    360 Accounts & Bookkeeping Ltd is the data controller responsible for your personal data.

    If you have any questions regarding this policy or wish to exercise your data rights, please contact our Data Privacy Manager:

    You may also lodge complaints with the ICO (Information Commissioner's Office) at www.ico.org.uk.

    2. What This Policy Covers

    This policy applies to:

    • Visitors to our website
    • Clients using our professional accountancy, bookkeeping, and compliance services
    • Individuals contacting us by email, phone, post, or via our online forms

    We do not knowingly process children's data.

    3. Personal Data We Collect

    We collect the following categories of information:

    • Identity Data: Name, date of birth, gender, proof‑of‑identity documents (including passports, driving licences) required for AML and ID verification.
    • Contact Data: Address, email, telephone numbers.
    • AML/KYC Verification Data (Enhanced Category): ID verification documents, proof of address, beneficial ownership information, director/PSC verification data, risk assessment notes.
    • Transaction Data: Payment details, service records, financial documents provided for accounting, payroll or tax work.
    • Technical Data: IP address, browser type, device identifiers, cookies, and analytics.
    • Profile & Usage Data: Login details, preferences, website interactions.
    • Marketing Data: Communication and marketing preferences.

    4. How We Collect Your Data

    We collect data through:

    • Direct interactions: forms, onboarding documents, emails, calls, service engagement.
    • Automated technologies: cookies, analytics tools.
    • Third‑party sources: credit reference agencies, Companies House, AML verification systems, public registers.

    5. How We Use Your Data

    We process your data for:

    • Performing accountancy, bookkeeping, payroll, and tax services
    • Meeting legal obligations (AML, HMRC reporting, statutory requirements)
    • Conducting identity verification under AML and ECCTA regulations
    • Managing client relationships and service delivery
    • Internal administration and compliance
    • Marketing (only with your consent)

    AML/KYC Processing (Mandatory)

    We are legally required under AML regulations to:

    • Verify client identities
    • Assess risk levels
    • Document beneficial ownership
    • Retain AML records for statutory periods

    This processing is performed under legal obligation, not consent.

    ID Verification under ECCTA 2025+

    For clients who are company directors or PSCs, we may process verification data to meet enhanced requirements under the Economic Crime and Corporate Transparency Act.

    6. Cookies

    Our website uses functional, analytical, and security‑related cookies. You may disable cookies, but certain features may not function.

    7. Data Sharing

    We may share your information with:

    • Internal authorised staff
    • UK‑based service providers (IT, hosting, secure cloud platforms)
    • AML/KYC verification partners
    • Professional advisers (lawyers, accountants, insurers)
    • HMRC, regulatory bodies, and law‑enforcement agencies
    • Potential business acquirers (with safeguards)

    All third parties must follow strict confidentiality and data‑protection requirements.

    8. International Transfers

    We may transfer your personal data outside the UK for cloud hosting, secure storage, or specialist compliance services. In these cases, we implement:

    • UK adequacy regulations
    • Standard Contractual Clauses (SCCs)
    • Robust security and compliance checks

    Details of specific safeguards are available upon request.

    9. Data Security

    We apply strong organisational and technical measures including:

    • Encryption and secure servers
    • Multi‑factor authentication
    • Access restriction protocols
    • Cyber‑security monitoring
    • Staff confidentiality obligations

    Breach Notification

    If a data breach occurs that risks your rights, we will notify you and the ICO where legally required.

    10. Data Retention

    We retain personal data only as long as necessary for legal, regulatory, and service‑related purposes.

    AML‑related data may be retained for five years as legally required.

    11. Your Legal Rights

    You have the right to:

    • Access your data
    • Request correction
    • Request deletion (when legally permissible)
    • Object to processing
    • Restrict processing
    • Request data portability
    • Withdraw consent (where applicable)

    We may require ID verification for security. If you wish to exercise any of these rights, please contact us.

    12. Updates to This Policy

    We may update this policy to reflect legal or regulatory changes. The most current version will always appear on our website.

    Last Updated: 9 February 2026