This Privacy Notice explains how In The Black Accountants Ltd collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
In The Black Accountants Ltd is the data controller responsible for your personal data.
- Company name: In The Black Accountants Ltd
- Registered address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
- Email: info@intheblackaccountants.com
- Regulatory status: AAT Licensed. AML Regulated under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
2. What Personal Data We Collect
We collect personal data in the following circumstances:
When you contact us via our website enquiry form:
- First and last name
- Business email address
- Business name
- Approximate annual turnover (range, not exact figure)
- Information you provide about your business in the message field
When you become a client:
- Full name, date of birth, and residential address
- Proof of identity and address documents
- National Insurance number and Unique Taxpayer Reference (UTR)
- Company registration details
- Financial records, bank statements, and accounting data
- Employment and income information
- Information about beneficial ownership of your business
3. Why We Collect Your Data and Our Legal Basis
| Purpose | Legal Basis |
|---|---|
| Responding to your enquiry and determining if we can assist you | Legitimate interests (Article 6(1)(f) UK GDPR) |
| Performing AML identity verification and risk assessment | Legal obligation (Article 6(1)(c) UK GDPR) — required under the Money Laundering Regulations 2017 |
| Delivering accounting, tax, and advisory services under our engagement letter | Contract performance (Article 6(1)(b) UK GDPR) |
| Filing returns and communicating with HMRC on your behalf | Legal obligation (Article 6(1)(c) UK GDPR) |
| Maintaining our AML records as required by law | Legal obligation — records must be kept for 5 years |
| Sending service-related communications and updates | Legitimate interests (Article 6(1)(f) UK GDPR) |
4. How We Store and Protect Your Data
Your data is stored securely using password-protected systems and encrypted cloud storage. We use Xero as our primary accounting platform, which is ISO 27001 certified. Enquiry form submissions are processed through Netlify Forms.
We do not store payment card details. We do not sell your personal data to third parties under any circumstances.
Access to your data is restricted to authorised personnel at In The Black Accountants Ltd only.
5. How Long We Keep Your Data
- Enquiry data (non-clients): 12 months from the date of enquiry, then securely deleted
- AML verification records: 5 years from the end of the business relationship, as required by law
- Accounting records and correspondence: 6 years from the relevant tax year end, in line with HMRC requirements
- Company accounts and statutory filings: 6 years minimum
6. Who We Share Your Data With
We only share your personal data where necessary and lawful to do so:
- HMRC — for tax filing and compliance purposes
- Companies House — for statutory filing purposes
- Xero — our cloud accounting platform (data processed under Xero's own privacy policy)
- Netlify — our website host, which processes enquiry form submissions
- Our supervisory body — AAT, where required for regulatory compliance
- Law enforcement or regulatory authorities — where we have a legal obligation to report, including under the Proceeds of Crime Act 2002
We do not transfer your data outside of the UK or EEA without appropriate safeguards in place.
7. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Right of access — to request a copy of the personal data we hold about you
- Right to rectification — to request correction of inaccurate data
- Right to erasure — to request deletion of your data (subject to our legal retention obligations)
- Right to restrict processing — to request that we limit how we use your data
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests
To exercise any of these rights, please email us at info@intheblackaccountants.com. We will respond within 30 days.
Please note that some rights may be limited where we have overriding legal obligations — for example, we cannot delete AML records during the statutory retention period.
8. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
We would appreciate the opportunity to address your concerns directly before you contact the ICO — please email us first.
9. Changes to This Notice
We review this Privacy Notice periodically and will update it when necessary. The date at the top of this page shows when it was last revised. Continued use of our website or services following any update constitutes acceptance of the revised notice.