PRIVACY NOTICE

This privacy notice should be read alongside our engagement letter, schedule of services, and standard terms and conditions.

PRIVACY NOTICE issued by Makesworth Bristol

Introduction

The Data Protection Act 2018 (“DPA 2018”) and the General Data Protection Regulation (“GDPR”) establish legal requirements for handling personal data.

Makesworth Bristol acts as a data controller under GDPR and processes personal data accordingly. Our contact details are as follows:

Sanjay Kumar Sah
Makesworth Bristol
557 Filton Ave, Horfield,
Bristol BS7 0QH,
United Kingdom
info@makesworthbristol.co.uk

At Makesworth Bristol, we are committed to protecting your privacy. Please read this notice carefully, as it explains what personal information we collect from you and how we use it.

Where we act as a data processor on behalf of a data controller (e.g., for payroll processing), we provide an additional schedule of information. This schedule should be read in conjunction with this privacy notice.

Information We Collect

We may collect the following types of personal information when you engage with us:

  • Date of birth

  • Postal address, email address, and telephone number

  • Information relevant to the service we provide

  • Information submitted in job or work experience applications

Additionally, we may collect data from other sources to support our services or meet legal obligations, particularly for anti-money laundering purposes.

We may also log IP addresses for administrative and statistical purposes. Cookies may be used on our website to enhance your browsing experience.

We do not collect sensitive information unless legally required during recruitment processes. This may include details such as racial/ethnic background, political opinions, religious beliefs, health data, sexual orientation, or criminal records.

Purpose of Processing Personal Data

We process your data for the following purposes:

  • Providing professional services in line with our contract

  • Complying with statutory or regulatory obligations (e.g., MLR 2017)

  • Fulfilling professional requirements as members of the Association of Chartered Certified Accountants (ACCA)

  • Issuing invoices and handling fee disputes

  • Informing you about additional services (if consent is provided)

  • Monitoring and improving service quality

  • Managing records for administrative purposes

Legal Basis for Processing Personal Data

Our legal grounds for processing your data are:

  • Your consent provided when instructing us

  • Processing necessary for fulfilling contractual obligations

  • Compliance with legal requirements (e.g., MLR 2017)

  • Legitimate interests, such as investigating or defending claims

If you decline to provide the required information, we may be unable to provide services to you.

Sharing Personal Data

We may share your data with:

  • HMRC

  • Third parties you permit or require us to contact

  • Subcontractors

  • An appointed alternate in case of incapacity or death

  • Tax insurance providers

  • Professional indemnity insurers

  • The Association of Chartered Certified Accountants (ACCA) and/or the Office of Professional Body Anti-Money Laundering Supervisors (OPBAS)

If legally required, we may also share your data with:

  • Police and law enforcement agencies

  • Courts and tribunals

  • The Information Commissioner’s Office (ICO)

If you request us not to share your data with third parties necessary for legal compliance, we may be unable to continue our services.

Outsourcing Data within Makesworth Group

We may share your data with other Makesworth Group entities to deliver accounting and taxation services. Data-sharing agreements are in place to ensure appropriate protection.

Retention of Personal Data

We retain records following best practices in the tax and accountancy sector:

  • Tax return records are kept for six years from the end of the tax year.

  • Ad hoc advisory work records are retained for six years from the end of the relationship.

  • Ongoing client records are kept throughout the engagement and deleted six years after termination unless otherwise agreed.

You are responsible for retaining important information, such as tax records and documentation sent to you.

Data Security

We implement technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse. All employees are bound by confidentiality agreements, and only authorized personnel access your data when required.

Subject Access Requests (SARs)

You have the right to request access to your personal data. Requests should be submitted in writing to:

Sanjay Kumar Sah
Makesworth Bristol
557 Filton Ave, Horfield,
Bristol BS7 0QH,
United Kingdom
info@makesworthbristol.co.uk

We will respond to SARs within one month. Complex requests may require additional time, and we will notify you if an extension is necessary.

Your Rights

You have the right to:

  • Request rectification of inaccurate data

  • Request data deletion in certain cases

  • Restrict or object to data processing

  • Request data portability for transfer to another provider

  • Withdraw consent at any time without affecting previous lawful processing

Complaints

If you believe we have not complied with GDPR or DPA 2018, please contact us at:

Sanjay Kumar Sah
Makesworth Bristol
557 Filton Ave, Horfield,
Bristol BS7 0QH,
United Kingdom
info@makesworthbristol.co.uk

If you are not satisfied with our response, you have the right to file a complaint with the ICO (www.ico.org.uk).

This Privacy Notice was last updated in March 2025.