← Back to dashboard

Privacy Policy

Last updated: 4 July 2026

1. Who we are

This Privacy Policy applies to ACSYS, an internal client management system operated by The Accounting Crew ("we", "us", "our").

Data Controller: The Accounting Crew
Contact: rowan@thecrew.co.uk

We are committed to protecting the personal data we hold in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What data we collect and hold

ACSYS holds information about our accounting clients and associated individuals, including:

  • Identity data: Full name, date of birth, gender
  • Contact data: Email address, telephone numbers, postal address
  • Business data: Company name, Companies House number, registered address, VAT registration number, PAYE reference, UTR, NI number
  • Financial data: Estimated turnover, fee information, service agreements
  • Tax & compliance data: Accounting year ends, VAT scheme, MTD status, filing dates
  • Relationship data: Directors, partners, associated individuals, linked businesses
  • Staff data: Staff names, contact details, roles, access permissions (for system users)

3. Lawful basis for processing

We process personal data on the following lawful bases:

  • Contract: Processing is necessary to provide accountancy services to our clients.
  • Legal obligation: Processing is required to comply with our obligations as a regulated accountancy firm (HMRC reporting, anti-money laundering, Companies House filings).
  • Legitimate interests: Operating an internal CRM system to manage client relationships, workflow, and compliance deadlines.
  • Consent: Where we obtain explicit consent for specific activities (e.g. marketing communications).

4. How we use the data

Personal data held in ACSYS is used exclusively to:

  • Deliver accountancy, tax, VAT, payroll, and related professional services
  • Manage client onboarding and compliance obligations
  • Track workflow, deadlines, and service delivery
  • Communicate with clients and associated parties
  • Comply with legal and regulatory obligations
  • Verify business registrations with HMRC and Companies House

We do not use the data for automated decision-making or profiling, and we do not sell or share personal data with third parties for marketing purposes.

5. Third-party processors

We use the following third-party services to operate ACSYS. Each acts as a data processor under our instructions:

ProcessorPurposeLocationSafeguard
SupabaseDatabase hosting, file storage and authenticationEU (Ireland — AWS eu-west-1)Data Processing Agreement / SCCs
VercelApplication hosting (web servers)Compute in London (lhr1); Vercel Inc. is US-basedData Processing Agreement / SCCs & EU–US Data Privacy Framework
MicrosoftStaff sign-in via Microsoft 365 (Entra ID single sign-on)UK / EUMicrosoft Data Protection Addendum
HMRCVAT number verification via HMRC APIUKUK Government service
Companies HouseCompany registration verification and daily record monitoringUKUK Government service

We do not transfer personal data outside the UK or EU other than as described above.

6. Data retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and in accordance with legal and regulatory requirements:

  • Active client records: Held for the duration of the client relationship
  • Closed client records: Retained for a minimum of 7 years following cessation of the engagement, in line with HMRC guidance and our professional obligations
  • Staff records: Retained for 6 years after an individual's employment or engagement ends

After the applicable retention period, data is securely deleted or anonymised.

7. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure, including:

  • Authentication required for all system access — staff sign in with their Microsoft 365 work account (single sign-on, protected by the firm's multi-factor authentication policies) or individually issued credentials
  • Database-level row security: only active, authorised staff accounts can read or write any client data
  • Role-based restrictions — administrative functions are limited to designated administrators
  • All data transmitted over encrypted connections (TLS) and encrypted at rest
  • Data hosted in the UK/EU: application servers in London, database in the EU (Ireland)
  • Daily backups with the ability to restore, and audit trails recording changes to key records

Cookies: ACSYS uses only essential cookies — session tokens required to keep authorised users signed in. No advertising, analytics, or tracking cookies are used.

8. Your rights

Under UK GDPR, individuals whose personal data we hold have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your data where there is no legitimate reason to continue processing it
  • Restriction — ask us to pause processing in certain circumstances
  • Portability — receive your data in a structured, commonly used format
  • Object — object to processing based on legitimate interests

To exercise any of these rights, please contact us at rowan@thecrew.co.uk. We will respond within one calendar month.

9. Complaints

If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk
Telephone: 0303 123 1113

We would appreciate the opportunity to address your concerns directly before you contact the ICO.

10. Changes to this policy

We may update this Privacy Policy from time to time. The date at the top of this page reflects when it was last revised. Continued use of the system following any update constitutes acceptance of the revised policy.

Terms & ConditionsBack to dashboard