Legal

Privacy Policy

Last updated: July 2026 · ICO Registration: ZC182101

This privacy policy explains how Aethon Accountancy collects, uses, shares, and protects your personal data. It applies to our website, our services, and our secure client portal. It has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Money Laundering Regulations 2017, and the AAT Professional Standards.

1. Who We Are

Aethon Accountancy is a professional accountancy practice regulated by the Association of Accounting Technicians (AAT). We are the data controller for the personal data we process.

  • Business name: Aethon Accountancy Ltd
  • Company number: 17284774 (registered in England and Wales)
  • VAT number: GB 522 7131 23
  • Registered address: 2 Western Close, Bradford, BD6 2BZ
  • ICO registration number: ZC182101
  • AAT membership number: 1010198
  • Privacy contact: hello@aethonaccountancy.co.uk

2. What Personal Data We Collect

2.1 Clients and prospective clients

When you engage us or enquire about our services, we may collect:

  • Identity data: full name, date of birth, national insurance number (NINO), unique taxpayer reference (UTR)
  • Contact data: address, email address, telephone number
  • Financial data: bank account details (for Direct Debit mandate), income, expenses, tax records, VAT details
  • Business data: company number, VAT registration number, PAYE reference, year end date
  • Anti-money laundering data: identity verification documents (passport, driving licence), source of funds, AML risk rating
  • Engagement data: signed letters of engagement, proposals, correspondence

2.2 Website visitors

When you visit aethonaccountancy.co.uk, we collect:

  • Technical data: IP address, browser type, pages visited, time and date of visit
  • Enquiry data: name, email address, and message content submitted via contact or quote forms

2.3 Client portal users

When you access our secure client portal, we collect:

  • Account credentials: email address and encrypted password
  • Activity data: files you upload, tasks you complete, documents you sign, and portal access logs
  • Electronic signatures: your typed name, timestamp, and confirmation when you sign documents via the portal

2.4 Free online tools (Business Health Check, LTV:CAC Calculator, and other calculators)

When you use a free tool on our website, such as the Business Health Check or the LTV:CAC Ratio Calculator, any file you upload (for example, a trial balance) and any figures you enter are processed entirely within your own web browser, on your own device. The underlying file and your individual account balances are never transmitted to, uploaded to, or stored on our servers.

If you choose to unlock your full result and provide your details, we store only:

  • The details you enter — your name, email address, and (optionally) business name
  • The headline results — the calculated ratios, percentages and tiers (for example, “gross margin: 76%”), never the underlying pounds-and-pence balances from your file

We use these headline results only to understand your enquiry and to have a more informed conversation with you if you choose to get in touch. The report itself is generated in your browser, so downloading it involves no further transfer of your financial data to us.

3. Why We Use Your Data and Our Legal Basis

We only process personal data where we have a valid legal basis under UK GDPR Article 6.

PurposeLawful basis
Providing accountancy services (tax returns, bookkeeping, VAT, payroll)Performance of a contract — Article 6(1)(b)
Anti-money laundering checks and ongoing monitoringLegal obligation — Money Laundering Regulations 2017, AAT AML supervision — Article 6(1)(c)
Reporting to HMRC and other regulatory bodiesLegal obligation — various HMRC, Companies House obligations — Article 6(1)(c)
Setting up and managing your Direct Debit mandatePerformance of a contract — Article 6(1)(b)
Responding to enquiries and quotes from prospective clientsLegitimate interests — to respond to your enquiry and assess suitability — Article 6(1)(f)
Sending marketing communications about our servicesLegitimate interests for existing clients; consent for prospective clients — Article 6(1)(a) or (f). You may opt out at any time.
Maintaining audit logs of access to sensitive recordsLegitimate interests — to protect client data and demonstrate compliance — Article 6(1)(f)

4. Our Regulatory Obligations Under the AAT

As an AAT-licensed practice, we are subject to AAT Professional Standards, which include obligations relating to client confidentiality, anti-money laundering, and data protection. These regulatory obligations mean that:

  • We are required to verify the identity of all clients before providing services (AML/KYC checks). This is a legal requirement under the Money Laundering Regulations 2017, not optional.
  • We may be required to submit a Suspicious Activity Report (SAR) to the National Crime Agency (NCA) if we have reasonable grounds to suspect money laundering or terrorist financing. We cannot inform you if such a report is made, as this would constitute tipping off and is a criminal offence.
  • We are supervised for AML purposes by the Association of Accounting Technicians (AAT). Our AML obligations take precedence over normal client confidentiality duties.
  • Client files and records must be retained for a minimum of five years following the end of the client relationship (AML Regulations, Regulation 40).

5. Who We Share Your Data With

We do not sell your personal data. We share it only where necessary.

5.1 HMRC and regulatory bodies

We submit tax returns, VAT returns, payroll filings, and other statutory documents to HMRC and Companies House on your behalf. This is required by law.

5.2 Technology service providers (data processors)

We use the following third-party services to operate our practice. Each acts as a data processor under a written Data Processing Agreement:

  • Supabase Inc — secure cloud database and file storage. Data hosted in the UK (London, AWS eu-west-2). No transfer outside the UK.
  • GoCardless Ltd — Direct Debit payment processing. FCA-authorised payment institution.
  • Resend Inc — email delivery, covering transactional messages (portal invitations, notifications, quotes) and any marketing communications you have consented to receive.

5.3 Professional third parties

We may share data with solicitors, barristers, or other professionals where required to deliver your services, or with our professional indemnity insurers where a claim arises.

5.4 Legal requirements

We may disclose your data to law enforcement, courts, or regulatory authorities if required to do so by law.

6. How Long We Keep Your Data

Data typeRetention period
Client tax records, accounts, and financial data7 years from the end of the relevant tax year (HMRC requirement)
Anti-money laundering records (ID documents, risk assessments)5 years from the end of the client relationship (Money Laundering Regulations 2017, Regulation 40)
Signed engagement letters and proposals7 years
Electronic signature audit trails7 years
Prospect and marketing enquiry data2 years from last contact, or until you request removal
Portal access logs and audit trails3 years
Website visitor data12 months

After these periods, data is securely deleted or anonymised.

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of access — request a copy of all data we hold about you (Subject Access Request)
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — ask us to delete your data (subject to our legal retention obligations)
  • Right to restrict processing — ask us to pause processing in certain circumstances
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests, including marketing
  • Rights related to automated decision-making — we do not make solely automated decisions that have legal or significant effects on you

To exercise any of these rights, contact us at hello@aethonaccountancy.co.uk. We will respond within one month.

Note: some rights are limited where we have a legal obligation to retain data. For example, HMRC requires us to keep tax records for 7 years regardless of an erasure request.

Where we rely on your consent as the legal basis for processing (for example, sending marketing communications to prospective clients), you give that consent via the opt-in checkbox on our website forms. You have the right to withdraw your consent at any time by clicking unsubscribe in any marketing email, by contacting us at hello@aethonaccountancy.co.uk, or by replying to any email asking to be removed. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.

7a. What Happens If You Do Not Provide Your Data

Some personal data we request is necessary for us to fulfil a legal or contractual obligation. If you choose not to provide it, we may be unable to provide the relevant service:

  • Without your Unique Taxpayer Reference (UTR) or National Insurance Number (NINO), we cannot file a self-assessment tax return on your behalf.
  • Without identity verification documents, we cannot onboard you as a client under our AML obligations — this is a legal requirement, not a matter of preference.
  • Without bank account details, we cannot set up a Direct Debit mandate for your fees.

Where data is optional (for example, providing a business description in an enquiry form), there are no consequences to leaving it blank.

8. How We Protect Your Data

Our technical and organisational safeguards include:

  • All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access control — staff can only access data relevant to their role
  • Immutable audit log — every access to sensitive client records is recorded
  • Secure client portal — separate login, encrypted storage, signed URLs for file downloads
  • Private file storage — client documents are never publicly accessible; every download link expires after one hour
  • Core client data is hosted in the United Kingdom (AWS eu-west-2, London via Supabase)

Where personal data is processed by third-party service providers outside the UK, we ensure appropriate safeguards are in place. Transfers to the United States (Resend Inc) are made under Standard Contractual Clauses approved for use under UK law. All other core client data is hosted within the UK.

In the event of a data breach that poses a high risk to your rights and freedoms, we will notify you and the ICO within 72 hours of becoming aware, in accordance with UK GDPR Article 33.

9. Cookies

Our website uses cookies to function correctly and to understand how visitors use our site.

  • Essential cookies — required for the site to work (session management, security). Cannot be disabled.
  • Analytics cookies — help us understand page visits and improve the site. You may decline these.

You can manage cookie preferences through your browser settings. Declining analytics cookies will not affect your ability to use the site.

11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in law, technology, or our services. The current version will always be published on our website with the date it was last updated. For material changes, we will notify existing clients directly.

12. How to Make a Complaint

If you have concerns about how we handle your data, please contact us first at hello@aethonaccountancy.co.uk. We will do our best to resolve the matter.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO):

You may also refer a complaint about our professional conduct to the Association of Accounting Technicians (AAT) at aat.org.uk.

This privacy policy was prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and the AAT Professional Standards. It is reviewed periodically and updated when required. Aethon Accountancy Ltd, July 2026.