GDPR Policy

Effective Date: 21/04/2026.
Business Name: IntouchBS
Website: https://intouchbs.co.uk
1. Introduction

IntouchBS is committed to protecting personal data and ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This GDPR Policy explains how we collect, process, store, and protect personal data, and outlines your rights under data protection laws.

We recognise that as an accounting and financial services provider, we handle sensitive personal and financial data. Therefore, we apply strict data protection principles across all our operations.

2. Our Role Under GDPR

Depending on the service provided, IntouchBS may act as:

Data Controller – when we determine how and why personal data is processed
Data Processor – when we process data on behalf of our clients

We ensure compliance in both roles.

3. Principles of Data Protection

We follow the key principles of UK GDPR:

Lawfulness, fairness, and transparency
Purpose limitation (data used only for specific purposes)
Data minimisation (only necessary data collected)
Accuracy (data kept up to date)
Storage limitation (data retained only as long as needed)
Integrity and confidentiality (secure processing)
Accountability (demonstrating compliance)
4. Types of Data We Process

We may process:

Personal Data:
Name, address, contact details
Date of birth
National Insurance number
Financial Data:
Income and expenses
Tax records
Payroll data
Business Data:
Company details
Financial statements
Sensitive Data (where applicable):
Identification documents
Compliance-related records
5. Lawful Basis for Processing

We process data under the following lawful bases:

Contractual necessity – to deliver agreed services
Legal obligation – HMRC, Companies House, AML regulations
Legitimate interests – improving services and operations
Consent – marketing communications
6. How We Use Personal Data

We use personal data to:

Provide accounting and financial services
Prepare and submit tax returns
Communicate with HMRC and regulatory bodies
Manage payroll and bookkeeping
Provide financial advice
Maintain client records
Improve our services
7. Data Sharing

We may share data with:

HMRC and government authorities
Companies House
Cloud accounting providers (e.g., Xero, QuickBooks)
Payment processors
IT and hosting providers

All third parties are required to comply with data protection laws and maintain confidentiality.

8. International Data Transfers

Where data is transferred outside the UK, we ensure:

Transfers are made to countries with adequate protection
Standard contractual clauses are in place
Appropriate safeguards are implemented
9. Data Security

We take appropriate technical and organisational measures to protect personal data:

Secure cloud-based systems
Encryption and password protection
Access controls (only authorised personnel)
Regular security monitoring
10. Data Retention

We retain data only for as long as necessary:

Accounting and tax records: typically 6 years (HMRC requirement)
Client records: retained during service period and as required by law
11. Your Rights Under GDPR

You have the right to:

Access your personal data
Request correction of inaccurate data
Request deletion (“right to be forgotten”)
Restrict processing
Object to processing
Request data portability
Withdraw consent at any time

To exercise your rights, contact us at:
📧 [Insert Email]

12. Data Breach Policy

In the event of a data breach:

We will investigate immediately
Notify affected individuals if required
Report to the Information Commissioner’s Office (ICO) where necessary
13. Cookies & Tracking

We use cookies to:

Improve website functionality
Analyse website traffic
Enhance user experience

Users can manage cookie preferences via browser settings.

14. Staff Training & Compliance

All staff handling personal data are trained in:

GDPR compliance
Data security
Confidentiality obligations

We regularly review our policies to ensure ongoing compliance.

15. Third-Party Processors

We ensure all third-party service providers:

Are GDPR compliant
Have appropriate security measures
Process data only as instructed
16. Updates to This Policy

We may update this GDPR Policy periodically to reflect legal or operational changes. Updates will be published on this page.

17. Contact Information

If you have questions about this policy or your data:

📧 Email: info@intouchbs.co.uk
📞 Phone: 01375271102