Brick Accounting Ltd is a firm of accountants providing outsourced finance function services to multi-entity groups. We are registered in England and Wales, company number 17075192, at St. Brandons House, 29 Great George Street, Bristol BS1 5QT.
We are supervised by HM Revenue & Customs for anti-money laundering purposes, and registered with the Information Commissioner's Office under registration reference ZC106880.
We are responsible for the personal data described in this notice. If you have a question about it, or want to exercise any of your rights, contact privacy@brickaccounting.com.
This notice explains what we do with personal data about people who visit our website, contact us, we approach about our services, work with us as clients or suppliers, or appear in records we handle for our clients.
Three related documents sit alongside it. If you work for us or apply to work with us, our privacy notice for directors, employees and applicants applies instead. If you are a client, the data protection schedule to your engagement letter contains the detailed terms governing your engagement and takes precedence over this notice where the two overlap. Our cookie policy explains what we set on this website and how to change your preferences.
If you have received a request from us to verify your identity and are wondering why, section 5 explains it.
Retention periods for every category of information are collected in one place at section 14.
When you visit brickaccounting.com we collect your IP address, information about your device and browser, the pages you view, and how you reached us.
We use this to keep the site working and to understand how it is used. Our lawful basis is our legitimate interest in operating and improving the site.
With your consent, we also use tracking that can connect your visits to you if you later contact us or engage with us, so that, for example, we can see that someone who enquired had previously read a particular page. If you do not consent, this does not happen and your visit stays anonymous to us.
We ask for your consent before setting anything that is not strictly necessary, and you can withdraw that consent or change your preferences at any time. Our cookie policy lists what we set, what each one does, and how long it lasts.
When you use our contact form or email us, we collect your name, email address, telephone number if you give it, your organisation, and whatever you write to us.
We use it to respond to you and, if it leads somewhere, to discuss working together. Our lawful basis is taking steps at your request before entering a contract, or our legitimate interest in responding to enquiries.
If we discuss working together, we collect the information we need to scope the work and prepare a proposal: your name and role, contact details, your group structure and the entities in it, and the commercial terms we discuss.
Our lawful basis is taking steps at your request before entering a contract.
Our proposals are issued through a web-based proposal tool, which records when a proposal is opened and which sections are viewed. We use that to know when to follow up. If you would rather we did not, tell us and we will send a document instead.
If we record a proposal call, we tell you at the start.
Once you engage us, most of the personal data we handle is covered by the data protection schedule to your engagement letter rather than by this notice. That schedule is the authoritative document and we would encourage you to read it. What follows is a summary.
In some of what we do we act on your instructions, and in some we act on our own account. The distinction matters because it determines who is answerable for what.
When we keep your books, prepare your management reporting or draft your company secretarial documents, you decide what happens to the information and we act on your instructions. In data protection terms you are the controller and we are your processor. If someone in your records wants to know what is held about them, that is a question for you, and we help you answer it.
When we verify identities, meet our anti-money laundering obligations, or keep our own record of the work, we act on our own account and not on your instructions. In those areas we are a controller in our own right, because those are duties the law places on us directly and you cannot instruct us out of them.
Before we can act for you, and periodically afterwards, the Money Laundering Regulations 2017 require us to establish who you are and who owns and controls your business.
That means we collect and verify identity information about directors, beneficial owners and people with significant control: name, date of birth, address, nationality and identity documents. Our verification includes a photograph check to confirm that the person presenting the document is the person in it. We also screen against sanctions lists, politically exposed persons data and adverse media sources.
This involves two categories of information the law treats as particularly sensitive: biometric data, arising from the photograph check, and information relating to criminal offences, arising from screening. We process both because we are legally required to, and we maintain an appropriate policy document explaining how we handle them, which is available on request.
We use a specialist verification provider to carry out these checks.
We are also required to report suspicions of money laundering to the National Crime Agency. The law restricts what we can tell you about this, and in some circumstances prohibits us from telling you anything at all.
We keep our working papers and the records supporting them after an engagement ends. This is not a copy of your accounting records. It is the evidence of what we did, when, and why.
We keep it to evidence our work, to answer regulatory inspection, and to defend claims, which can be brought years after the work was done. This is our own purpose rather than something we do on your instruction, which is why we are a controller for it.
We may record working sessions with you, such as process-mapping sessions, and produce a transcript, so that what was agreed is evidenced. We tell you at the start of any session we record, and you can ask us not to record a particular session. The recording is deleted once the written record of the session is agreed; the written record becomes part of our working papers. Our lawful basis is our legitimate interest in evidencing scope and sign-off decisions.
We may send clients accounting updates, regulatory news and information about our services. Our lawful basis is our legitimate interest in keeping clients informed, and we rely on the soft opt-in under the Privacy and Electronic Communications Regulations. Every message carries an unsubscribe link, and you can opt out at any time without affecting the service we provide.
You may be reading this because you have received a request from us to verify your identity, and you have never dealt with us before. That is normal, and this section explains it.
Why we are asking. The law requires us to establish who owns and controls any business we act for. That means we have to verify the directors, the beneficial owners and the people with significant control, whether or not you were involved in appointing us, and whether or not you have any direct dealings with us. If you are a shareholder or director of a group that has engaged us, that includes you.
Providing this information is a legal requirement rather than a choice we are offering. If we cannot verify the people the Regulations require us to verify, we cannot act for the business concerned.
What we collect. Your name, date of birth, residential address, nationality, and an image of an identity document. We also ask for a photograph of you, taken at the time, which is checked against the photograph in your document to confirm you are its holder. Separately, we check your name against sanctions lists, records of politically exposed persons, and adverse media sources.
Two things the law treats as particularly sensitive. The photograph check involves biometric data. The screening can produce information relating to criminal offences. We process both because we are legally required to, and we maintain an appropriate policy document setting out how we handle them, which is available on request.
Our lawful basis is compliance with a legal obligation, under the Money Laundering Regulations 2017.
Results are reviewed by a person. No decision about you is taken on the basis of an automated result alone.
Who carries this out. We use a specialist verification provider. The identity check and the screening are performed by its own suppliers. Your photograph is used to perform the check and is retained with your verification record.
How long we keep it. Five years from the end of our relationship with the business concerned, as the Regulations require, and then we delete it.
Your rights. You can ask us for a copy of what we hold, and ask us to correct it. We cannot delete it before the five years are up, because the law requires us to keep it. We are also required to report suspicions of money laundering, and the law restricts what we can tell you about that, and in some circumstances it prevents us from telling you anything at all.
Where we got your details. We identify organisations that might benefit from what we do, and the person in each whose role makes them the right one to speak to. We find those details in public sources: the Companies House register, company websites and published material, press and trade coverage, LinkedIn, and business email lookup services, which locate addresses published somewhere on the web and tell us where they were found.
If you want to know more about where your information came from, ask us.
What we hold. Your name, job title, employer, business email address, business telephone number where we have it, your LinkedIn profile, publicly filed information about your directorships, and a record of whether we have contacted you and what you said.
We only hold business contact details. We do not use personal email addresses, personal phone numbers or home addresses.
Why. Our lawful basis is our legitimate interests. We are a new firm, and approaching the organisations we think we can help is how we find our clients. We have carried out a written assessment weighing our interests against yours, and you can ask us for a copy.
How often we will contact you. We approach people a limited number of times. We have set a maximum number of approaches across all the ways we might contact you, and we keep to it. Once we have reached it we stop, and we do not begin again later.
How to stop this. Reply to any message and tell us. We will remove you immediately and permanently, and we will keep a minimal record of your request so that you cannot be added back by accident. You do not have to give a reason and we will not ask for one.
Stopping it at source. Removing you from our records stops us contacting you, but it does not remove your details from the sources we found them in, so another firm could find you the same way. If you would like to deal with that too, ask us and we will tell you where your information came from so that you can go to the source directly.
If you sign up for our updates, we hold your name, business email address, organisation, and a record of which messages you opened.
Our lawful basis is your consent, or our legitimate interest in sending business updates to people who have asked for them.
We do not add people to this list because we have approached them. If we contacted you about our services and you did not reply, that is the end of it. You will not start receiving updates instead.
Every message has an unsubscribe link. When you unsubscribe we keep a minimal record of your address indefinitely, so that we do not contact you again by mistake.
If you are a customer, supplier, tenant, contractor or employee of one of our clients, your information may pass through our hands while we do their bookkeeping or prepare their reporting. Depending on your dealings with them, that can include your name, contact details, bank account details, and the invoices, payments and other transactions recorded in their accounts.
While we are working for them, we act on our client's instructions and they are the ones responsible for it. If you want to know what is held about you, or want it corrected or deleted, ask them. If you approach us, we will pass your request on and help them answer it.
After an engagement ends, we keep our own working papers and the records supporting them for six years, as explained at section 4. Your information may appear in those. That copy is ours rather than our client's, so if your question relates to a period after we stopped acting for them, come to us directly.
If you supply goods or services to us, we hold your name, contact details, contract terms, invoices and payment details, so that we can work with you and pay you. Our lawful basis is our contract with you, or our legitimate interest in managing our supplier relationships.
Covered by our separate privacy notice for directors, employees and applicants, available on request or at the point of application.
We share personal data with:
The categories of provider we use are cloud-based email and file storage, a practice management and client records system, a client portal, a customer relationship management system, proposal software, an identity verification and screening provider, website hosting, integration tooling connecting these systems, and artificial intelligence tools used in the general course of our business.
Where artificial intelligence tools are used in our work, anything relating to our clients is handled only on commercial terms which require confidentiality, prevent the provider from using what we enter to train its models, and limit how long it is retained. Clients authorise the specific provider through the data protection schedule to their engagement letter. Information connected to our anti-money laundering work is never entered into these tools.
Each is bound by a written data processing agreement. We keep a current list of these providers, including where each holds information, and will give it to you on request. Clients are given the list by name in the data protection schedule to their engagement letter, and we notify them in advance if it changes.
We do not sell personal data. We do not share it with anyone for their own marketing.
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse. Access is restricted to those who need it to do their work, removed when it is no longer needed, and subject to confidentiality obligations. We hold information in governed business systems rather than on individual devices, and we maintain a written information security policy which is reviewed annually.
Most of the systems we use store information in the United Kingdom or the European Economic Area. Some are provided by companies based in the United States.
Where information leaves the United Kingdom, we rely on an approved safeguard: a country the UK Government has decided offers adequate protection, the UK International Data Transfer Addendum, or another mechanism approved under UK law. The right mechanism depends on the provider, and you can ask us which one applies to any system we use, and for a copy of the safeguard itself.
Where we are required by law to keep something for longer, we will.
You have the right to:
If you object to us using your details for marketing, that right is absolute. We will stop immediately and there is nothing to weigh up.
Other rights have limits. We cannot delete records we are legally required to keep. Where our anti-money laundering obligations are involved, the law may prevent us from telling you what we hold or whether we hold anything at all. Where we act as our client's processor, the request is properly theirs to answer and we will pass it on.
To exercise any of these rights, contact us at privacy@brickaccounting.com. We will respond within one month, or tell you if we need longer and why. There is no charge.
We do not make decisions about you by automated means and we do not profile you. Identity verification produces an automated result, but no decision is taken on that result alone. A person reviews the evidence and decides, as explained at section 5.
If you are unhappy with how we have handled your personal data, please tell us at privacy@brickaccounting.com. We aim to acknowledge complaints within five working days, and in any event within 30 days, and we will respond as quickly as we can after that.
When you complain, we hold your contact details, your complaint, our investigation and our response, so that we can deal with it and demonstrate how we did. We keep that record for six years.
You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You do not need to come to us first, though we would rather have the chance to put things right.
We review this notice at least once a year and update it when what we do changes.