Privacy Policy (UK GDPR)

**Last updated: 19 August 2026**

Bookkeeping Packages Ltd respects your privacy and is committed to protecting personal information.

This Privacy Policy explains what information we collect, how and why we use it, who we may share it with, how long we retain it and the rights available under UK data-protection law.

This policy applies when:

* you visit or contact us through our website;
* you engage us directly for bookkeeping or related services;
* you work for, represent or own an organisation receiving our services;
* your information appears within records that we process for a client;
* we provide confidential white-label or subcontracted services through an accountant, fractional finance director, business adviser or other professional intermediary; or
* you are an employee, customer, supplier, donor, beneficiary, trustee or other individual whose information appears within accounting, payroll or business records processed by us.

This policy should be read alongside our Terms and Conditions, Cookie Policy and any engagement-specific Data Processing Agreement.

## 1. Who we are

Bookkeeping Packages Ltd is a company registered in England and Wales under company number 16601215.

Our registered office is:

167-169 Great Portland Street
London
England
W1W 5PF

In this policy:

* **“we”, “us” and “our”** mean Bookkeeping Packages Ltd;
* **“Direct Client”** means a business, charity, church or other organisation engaging us directly;
* **“Intermediary”** means an accountant, fractional finance director, business adviser, mentor or other professional organisation engaging us to support one or more of its clients;
* **“End Client”** means a client of an Intermediary whose records we process as part of a white-label or subcontracted service;
* **“Services”** means the bookkeeping and related services we have agreed to provide; and
* **“Applicable Data Protection Law”** means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 where applicable, and related UK legislation as amended, including by the Data (Use and Access) Act 2025.

Our privacy contact is:

Stuart Kerr, Privacy Lead
Email: [privacy@bookkeepingpackages.co.uk](mailto:privacy@bookkeepingpackages.co.uk)

## 2. Our data-protection roles

Our role under data-protection law depends on why and how personal information is being processed.

### When we act as a controller

We normally act as an independent data controller for personal information used to:

* operate and secure our website;
* respond to enquiries;
* prepare quotations and proposals;
* administer Direct Client and Intermediary relationships;
* conduct client acceptance, identity and anti-money laundering checks;
* issue invoices and collect payments;
* maintain our own business and professional records;
* comply with legal, tax, regulatory, insurance and professional obligations;
* manage complaints, disputes and legal claims;
* prevent fraud and protect our systems; and
* communicate about our Services where legally permitted.

We may also act as an independent controller where legislation or a professional obligation requires us to determine why or how particular information is processed.

### When we act as a processor

When a Direct Client instructs us to process personal information within its accounting, payroll or document systems, the Direct Client will normally be the controller and we will normally act as its processor.

The Direct Client determines why the underlying business information is used. We process it only to provide the agreed Services, follow documented instructions and comply with applicable law.

### When we act as a sub-processor

When we provide white-label or subcontracted Services through an Intermediary, the End Client will normally be the controller, the Intermediary will normally be a processor and Bookkeeping Packages Ltd will normally act as a sub-processor.

The precise roles depend on the facts of each arrangement. The parties’ responsibilities will be recorded in a binding white-label services agreement, Data Processing Agreement or another appropriate contract.

A white-label arrangement does not prevent us from acting as an independent controller for our own administration, invoicing, legal obligations, security records, insurance, anti-money laundering responsibilities or legal claims.

## 3. Personal information we may process

The personal information we process depends on the agreed Services and the nature of the relevant organisation.

### Contact and relationship information

This may include:

* names;
* business names;
* job titles and professional roles;
* postal addresses;
* email addresses;
* telephone numbers;
* communication preferences;
* meeting and correspondence records; and
* information contained in enquiries, proposals and service instructions.

### Business ownership and identity information

This may include:

* company, charity and partnership details;
* directors, trustees, partners and beneficial owners;
* dates of birth where required for verification;
* identification documents;
* proof of address;
* ownership and control information;
* professional or regulatory status; and
* identity, sanctions, politically exposed person and anti-money laundering checks.

### Accounting and transactional information

This may include:

* sales and purchase invoices;
* receipts and expense records;
* customer and supplier details;
* bank and credit-card transactions;
* payment references;
* account numbers and payment details;
* loan, finance and director-account information;
* debtor and creditor balances;
* tax and VAT information;
* donation and Gift Aid records;
* restricted and unrestricted fund records;
* property, project or departmental information; and
* supporting correspondence and documents.

### Payroll and employment information

Where payroll or payroll-related bookkeeping is included, this may include:

* employee names, addresses and contact details;
* dates of birth;
* National Insurance numbers;
* tax codes;
* salary, hours, bonuses and deductions;
* bank details;
* pension information;
* student-loan information;
* leave and statutory-payment information;
* employment start and leaving dates; and
* information required to calculate pay or meet payroll obligations.

### Website and technical information

This may include:

* IP addresses;
* device and browser information;
* website usage information;
* cookie and analytics identifiers;
* security and access logs;
* form submissions; and
* consent records.

### Communication records

We may retain relevant communications exchanged through email, telephone, video meetings, website forms, messaging services or WhatsApp.

These records may include instructions, approvals, bookkeeping queries and supporting documents.

## 4. Special-category and criminal-offence information

Most bookkeeping work does not require special-category personal information. However, payroll, charity, church or supporting financial records may occasionally reveal information concerning:

* health or disability;
* religion or belief;
* trade-union membership; or
* another protected characteristic.

Where we act as a processor or sub-processor, we process this information only when necessary for the Services, under documented instructions and where the controller has identified an appropriate lawful condition.

Criminal-offence information is not normally required. It will only be processed where it is lawfully provided, relevant to the Services and supported by an appropriate legal basis and safeguards.

We do not intentionally collect more sensitive information than is reasonably necessary.

## 5. Information concerning other individuals

Direct Clients and Intermediaries may provide information about employees, customers, suppliers, donors, trustees, beneficiaries and other individuals.

The organisation providing that information is responsible for ensuring that:

* it has a lawful basis for collecting and using the information;
* the information is relevant, accurate and not excessive;
* affected individuals receive any required privacy information;
* our appointment as processor or sub-processor is properly authorised; and
* any required consent or other legal condition has been obtained.

Individuals whose information appears within client records may contact the relevant organisation directly or contact us using the details in this policy.

Where we act only as processor or sub-processor, we will normally refer the request to the relevant controller or Intermediary and assist it as contractually and legally required.

## 6. How we obtain personal information

We may receive information:

* directly from you;
* from a Direct Client;
* from an Intermediary;
* from an End Client;
* from employees, trustees, directors or authorised representatives;
* through Xero, QuickBooks or other accounting and payroll systems;
* through bank feeds, payment platforms and connected applications;
* through Dropbox or another agreed document-sharing service;
* from HMRC or another public authority where authorised;
* from identity-verification and anti-money laundering providers;
* from Companies House, charity registers and other public sources;
* through our website and analytics systems; and
* through email, telephone, video meetings, WhatsApp or another agreed communication channel.

## 7. Why we use personal information

We may use personal information to:

* respond to enquiries and prepare quotations;
* onboard Direct Clients, Intermediaries and End Clients;
* conduct identity, sanctions and anti-money laundering checks;
* provide bookkeeping, payroll, VAT and reporting Services;
* process and reconcile financial transactions;
* maintain sales and purchase ledgers;
* prepare reports and filing summaries;
* make agreed submissions to HMRC;
* raise queries and obtain instructions or approvals;
* administer white-label and subcontracted relationships;
* manage contracts, invoices and payments;
* maintain professional and business records;
* protect systems and investigate suspected fraud or misuse;
* manage complaints, disputes, insurance matters and legal claims;
* comply with legal, tax, regulatory and professional obligations; and
* improve our website and Services.

We will not use personal information for a materially incompatible purpose unless that use is permitted or required by law.

## 8. Our lawful bases

Where we act as controller, we rely on one or more of the following lawful bases.

### Contract

Processing may be necessary to enter into or perform a contract, including responding to an individual client or sole trader, administering an engagement and providing the Services.

### Legal obligation

We may process information to comply with duties relating to taxation, accounting records, anti-money laundering, sanctions, fraud prevention, regulatory enquiries and other legal requirements.

### Legitimate interests

We may process information where necessary for legitimate business interests, including:

* operating and protecting our business;
* administering commercial relationships;
* communicating with business contacts;
* maintaining accurate professional records;
* recovering unpaid fees;
* preventing fraud;
* improving our Services;
* handling complaints; and
* establishing, exercising or defending legal claims.

We consider the likely effect on individual rights before relying on legitimate interests.

### Consent

We may rely on consent for non-essential cookies, optional marketing communications or another activity where consent is appropriate.

Consent may be withdrawn at any time. Withdrawal does not affect processing lawfully undertaken before consent was withdrawn.

### Processor and sub-processor activities

Where we act as processor or sub-processor, the relevant controller is responsible for identifying its lawful basis and any special-category or criminal-offence condition.

We process the information under documented instructions and an applicable Data Processing Agreement.

## 9. Anti-money laundering information

Professional bookkeeping is an accountancy service for UK anti-money laundering purposes.

Where applicable, we may be required to:

* verify the identity of clients, directors, trustees and beneficial owners;
* understand ownership and control;
* assess the purpose and intended nature of a relationship;
* conduct sanctions and politically exposed person checks;
* monitor relevant relationships;
* retain customer-due-diligence records; and
* report suspicious activity to an appropriate authority.

We may be legally prohibited from telling an individual that a suspicious-activity report or related disclosure has been made.

In a white-label engagement, anti-money laundering responsibilities will be recorded in the applicable agreement.

Receiving due-diligence information from an Intermediary does not automatically transfer our legal responsibilities or mean that we may rely on that information. Any formal reliance or supervision arrangement must be expressly documented and satisfy every applicable legal condition.

Where we serve Direct Clients, we will maintain our own anti-money laundering supervision where required and will not assume that an Intermediary’s supervision covers unrelated direct engagements.

## 10. White-label and subcontracted Services

We may provide bookkeeping Services confidentially under an Intermediary’s brand or as part of its wider professional service.

In these arrangements:

* the Intermediary remains responsible for its commercial relationship with the End Client;
* the Intermediary is normally our contracting client and is responsible for paying our fees;
* we may receive personal information from the Intermediary or access the End Client’s systems;
* we use the information only for the agreed Services and other purposes permitted or required by law;
* we may communicate directly with the End Client where authorised by the Intermediary;
* direct communication does not by itself make us the End Client’s contractual service provider;
* we keep the End Client’s identity, the Intermediary’s pricing and the existence and nature of the white-label relationship confidential; and
* data-processing responsibilities are recorded in an appropriate binding agreement.

The Intermediary must ensure that its contract and privacy arrangements with every relevant End Client:

* permit our appointment as subcontractor and, where applicable, sub-processor;
* authorise the required access to personal information and systems;
* provide any required transparency to affected individuals; and
* allow the Processing described in the applicable Data Processing Agreement.

## 11. Who we share personal information with

Where necessary and lawful, we may share personal information with:

* Direct Clients and their authorised representatives;
* Intermediaries and authorised End Client contacts;
* accountants, tax advisers, auditors or independent examiners authorised by the Client;
* HMRC and other public, regulatory or supervisory authorities;
* accounting, payroll and practice-management software providers;
* document-storage and secure file-sharing providers;
* email, telecommunications and video-meeting providers;
* website-hosting, security and analytics providers;
* banking and payment providers;
* identity-verification and anti-money laundering providers;
* professional advisers, insurers and legal representatives;
* authorised contractors or support personnel subject to confidentiality obligations;
* law-enforcement bodies; and
* courts or other competent authorities where disclosure is required or permitted by law.

Examples of platforms used to deliver or administer our Services may include Xero, QuickBooks, Dropbox, Microsoft services, Google services, WhatsApp, HMRC systems and banking or payment platforms.

The systems used for a particular engagement may be selected by us, the Direct Client, the Intermediary or the End Client.

A platform selected, contracted and controlled directly by a Client, Intermediary or End Client does not become our sub-processor merely because we are instructed to access it.

We do not sell personal information.

## 12. Data Processing Agreements

Where we act as processor or sub-processor, our Processing will be governed by a binding contract or Data Processing Agreement containing the terms required by Article 28 of the UK GDPR.

This will normally address:

* the subject matter, nature, purpose and duration of Processing;
* the categories of personal information and individuals;
* documented instructions;
* confidentiality;
* security measures;
* the appointment of sub-processors;
* assistance with individual rights and regulatory obligations;
* personal-data breaches;
* international access and restricted transfers;
* compliance information, audits and inspections; and
* return or deletion of information when the Services end.

For white-label engagements, these provisions may form a schedule to the commercial white-label services agreement rather than a separate document.

This public Privacy Policy provides general transparency. It does not replace an Article 28 agreement required for a particular engagement.

## 13. International access and transfers

Bookkeeping Packages Ltd is a UK company. Services may be administered and personal information may be securely accessed by authorised personnel working remotely from France.

France is within the European Economic Area and is currently covered by UK adequacy regulations for relevant transfers of personal information from the United Kingdom.

Some service providers may process or store information in other countries. Where a restricted transfer occurs, we will use an appropriate legal mechanism, which may include:

* UK adequacy regulations;
* the UK International Data Transfer Agreement;
* the UK Addendum to the EU Standard Contractual Clauses;
* another legally approved safeguard; or
* a permitted statutory exception where applicable.

We will consider whether supplementary technical or organisational safeguards are appropriate for an international transfer.

## 14. Information security

We use proportionate technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration or disclosure.

These measures may include:

* individual named user accounts;
* multifactor authentication where available;
* password-management controls;
* encrypted communications and supported devices;
* access controls and least-privilege permissions;
* secure document-sharing systems;
* device locking and security updates;
* confidentiality obligations;
* data minimisation;
* separation of client files, tenants or folders where supported;
* incident-response procedures;
* continuity and recovery arrangements; and
* prompt removal of access when it is no longer required.

We do not place identifiable Client or End Client information into publicly available generative artificial-intelligence services unless the Processing has been expressly authorised and appropriate contractual, confidentiality and data-protection safeguards are in place.

No method of electronic storage or transmission is completely secure. We keep our arrangements under review and take reasonable steps to reduce foreseeable risks.

Clients and Intermediaries are responsible for protecting the systems, devices, accounts, passwords and authentication methods under their control.

## 15. Personal-data breaches

We maintain procedures for identifying, recording and responding to suspected personal-data breaches.

Where we act as processor or sub-processor, we will notify the relevant Direct Client or Intermediary without undue delay after becoming aware of a breach affecting personal information processed on its behalf.

The applicable Data Processing Agreement may specify a target notification period and the information to be provided.

Where we act as controller, we will assess whether notification to the Information Commissioner’s Office or affected individuals is legally required.

We may provide information in phases where complete details are not immediately available.

## 16. How long we retain information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, tax, professional, insurance and dispute-resolution requirements.

Typical retention periods are:

* **Enquiries that do not proceed:** normally up to 12 months.
* **Contracts, Engagement Schedules, invoices, approvals and business correspondence:** normally six years after the end of the relevant financial year or engagement.
* **Anti-money laundering and customer-due-diligence records:** normally five years after the relevant relationship ends, unless another period is required or permitted by law.
* **Accounting, payroll and End Client information processed for a controller:** for the period instructed by the controller and specified in the applicable agreement.
* **Complaint, insurance and legal-claim information:** for as long as reasonably necessary to investigate the matter or establish, exercise or defend legal rights.
* **Website and security records:** according to operational, fraud-prevention and security requirements.
* **Cookie and analytics information:** for the periods described in our Cookie Policy or applicable provider settings.

Accounting records may remain within a Client’s own Xero, QuickBooks or other system after our access has been removed. The Client or End Client controls retention within systems it owns or contracts directly.

Relevant documents may also be held temporarily within Dropbox, email, working papers or another approved system.

When information is no longer required, it will be securely deleted, anonymised or returned, subject to applicable legal and contractual requirements.

Protected residual copies may remain temporarily within backup systems until overwritten through the normal backup cycle.

## 17. Your data-protection rights

Depending on the circumstances, you may have the right to:

* request access to your personal information;
* request correction of inaccurate or incomplete information;
* request deletion where there is no lawful reason to retain the information;
* request restriction of Processing;
* object to Processing based on legitimate interests;
* object to direct marketing at any time;
* request transfer of information in certain circumstances;
* withdraw consent where Processing is based on consent; and
* complain to us or the Information Commissioner’s Office.

These rights are not absolute. Legal, regulatory, anti-money laundering and professional record-keeping requirements may prevent us from complying fully with some requests.

We may need to verify your identity and clarify the scope of a request before responding.

We normally respond to a valid rights request within one month. Where legally permitted because a request is particularly complex or numerous, this period may be extended. We will explain any permitted extension.

## 18. Requests concerning Client or End Client records

If your information appears within records that we process for a Direct Client or End Client, that organisation will normally be responsible for responding to your request.

You should usually contact that organisation first.

If you contact us, we may:

* forward the request to the relevant controller or Intermediary;
* ask for information needed to identify the relevant records;
* assist the controller in responding; or
* respond directly where we are legally responsible for the relevant Processing.

We will not disclose Client or End Client information without appropriate authority.

## 19. Marketing

We may contact existing clients, Intermediaries or business contacts about relevant Services where permitted by law and where our legitimate interests are not overridden by individual rights.

Where consent is required, we will obtain it before sending marketing communications.

You may ask us to stop marketing communications at any time by contacting us or using an unsubscribe facility where provided.

Service communications, legal notices, security messages and communications necessary to administer an engagement are not marketing and may continue where relevant.

## 20. Cookies and website analytics

Our website may use essential cookies required for security and operation.

Non-essential analytics or advertising cookies will be used only in accordance with applicable consent requirements.

Further information about the cookies used, their purposes and available controls appears in our Cookie Policy.

## 21. Automated decision-making and artificial intelligence

We do not normally use personal information to make solely automated decisions that produce legal or similarly significant effects.

Software may assist with transaction matching, bookkeeping categorisation, fraud detection or identity verification. Appropriate human review will be applied where necessary to provide the Services or make a significant decision.

Any material use of artificial intelligence involving Client or End Client personal information will be subject to appropriate human oversight, confidentiality, security and contractual controls.

## 22. Children

Our website and Services are intended for businesses, charities, churches and professional organisations rather than children.

We may process limited information relating to children where it legitimately appears within payroll, charity, church or other client records.

In those circumstances, we process the information only for the agreed Services, under appropriate instructions and subject to applicable safeguards.

## 23. Data-protection complaints

If you have concerns about how we use personal information, you may raise a data-protection complaint by contacting:

Stuart Kerr, Privacy Lead
Email: [privacy@bookkeepingpackages.co.uk](mailto:privacy@bookkeepingpackages.co.uk)

Please explain:

* the Processing or information that concerns you;
* what you believe has gone wrong;
* any relevant dates or communications; and
* what outcome you are seeking.

Where the complaint concerns Processing for which we act as controller:

* we will acknowledge receipt within 30 days;
* we will begin investigating without undue delay;
* we may ask for information reasonably required to understand or investigate the complaint;
* we will take appropriate steps to investigate the matter;
* we will keep you appropriately informed of material progress;
* we will communicate the outcome without undue delay; and
* we will explain any action taken or the reasons for our decision.

Where we act only as processor or sub-processor, we may refer the complaint to the relevant controller or Intermediary and assist it in accordance with our legal and contractual obligations.

We keep appropriate records of complaints, investigations, responses and remedial action.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113

We would appreciate the opportunity to investigate and resolve your concerns before you approach the Information Commissioner’s Office, but this does not affect your right to complain to it.

## 24. Changes to this policy

We may update this Privacy Policy to reflect changes in our Services, systems, legal obligations or working arrangements.

The current version will be published on this page with its latest revision date.

Where a change materially affects an existing engagement, we may also notify the relevant Direct Client or Intermediary.

## 25. Contact

Questions, requests or concerns about this Privacy Policy should be sent to:

Bookkeeping Packages Ltd
For the attention of: Stuart Kerr, Privacy Lead
Registered office: 167-169 Great Portland Street, London, England, W1W 5PF
Privacy email: [privacy@bookkeepingpackages.co.uk](mailto:privacy@bookkeepingpackages.co.uk)
General enquiries: [support@bookkeepingpackages.co.uk](mailto:support@bookkeepingpackages.co.uk)
Telephone: 07813 832419