Privacy Policy
Last updated: 30 September 2026
1. Who we are
This website and our accounting, tax and audit services are provided by DALTON & HOLLAND ACCOUNTING LTD, trading as Dalton & Holland Accounting, a company registered in England and Wales under company number 17434455.
Registered office: 35 Little Close, Kingsteignton, Newton Abbot, England, TQ12 3YZ.
For our own clients, enquirers and website visitors we are the controller of personal data. You can contact us about anything in this policy at [email protected] or on +44 7700 900417.
2. Personal data we collect
What we hold depends on the services you use. It can include:
- Contact details — name, business name, postal address, e-mail address and phone number of clients, directors and contacts.
- Enquiry data — the content of e-mails and phone calls you send us, including any request for a quote. This website has no forms: when you click a contact button, your own e-mail program opens and you choose what to send.
- Financial data — bank statements, invoices, receipts, ledgers, loan and asset records, dividend and director's loan account records.
- Tax data — Unique Taxpayer Reference (UTR), National Insurance number, VAT registration number, Corporation Tax references, income, gains, reliefs and previous returns.
- Payroll data about your employees — names, addresses, dates of birth, NI numbers, tax codes, salaries, hours, bank details for payment, pension scheme membership, statutory pay (sickness, maternity, paternity) and student loan deductions.
- Identity verification data — copies of passports or driving licences, proof of address, date of birth and the results of electronic identity checks required under anti-money laundering law, for clients, directors and people with significant control.
- Engagement records — engagement letters, correspondence, file notes, invoices we issue and payments you make to us.
- Technical data — when you visit this site, your browser sends your IP address and device information to the servers that deliver the pages and web fonts.
Payroll data may include health information, for example reasons for statutory sick pay. We process it only where employment and social security law requires it.
3. Purposes and lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Replying to enquiries and preparing quotes | Steps at your request before entering a contract; legitimate interests in answering business enquiries |
| Providing bookkeeping, accounts, tax, VAT, payroll and audit services | Performance of a contract |
| Filing returns and accounts with HMRC and Companies House | Performance of a contract; legal obligation |
| Identity checks and client due diligence under the Money Laundering Regulations 2017 | Legal obligation |
| Keeping working papers and records for statutory periods | Legal obligation |
| Invoicing, recovering fees and managing our practice | Performance of a contract; legitimate interests |
| Defending legal claims and dealing with our insurers | Legitimate interests |
| Sending occasional updates on tax deadlines or changes | Consent, which you can withdraw at any time |
Where we process health data in payroll, we rely on Art. 9(2)(b) UK GDPR and Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 (employment and social security). Where AML checks reveal information about criminal convictions, we rely on Schedule 1, paragraph 12 of the Data Protection Act 2018 (regulatory requirements).
4. When we act as a processor
When we work inside your own cloud accounting or payroll system, the records there — including data about your customers, suppliers and employees — belong to you. In that role you are the controller and we act as your processor under Article 28 UK GDPR.
- We process that data only on your documented instructions, set out in our engagement letter.
- Everyone on our team who accesses it is bound by confidentiality.
- We apply appropriate security measures and tell you without undue delay about any personal data breach affecting your data.
- We help you respond to requests from individuals exercising their rights.
- At the end of our engagement we return or delete that data, except where the law requires us to keep a copy.
Where we file returns for your business with HMRC or Companies House in our own name as agent, or carry out an audit, we act as an independent controller for that processing.
6. International transfers
Some of our software and hosting providers store or access data outside the UK. When that happens, we make sure the transfer is protected by UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. You can ask us for details of the safeguards used.
7. How long we keep data
- Client due diligence and identity records — at least 5 years after our business relationship ends, as required by regulation 40 of the Money Laundering Regulations 2017.
- Accounting, tax and payroll working papers — 6 years after the end of the relevant accounting period or tax year, reflecting HMRC enquiry and record-keeping time limits.
- Audit files — at least 6 years after the audit report is signed.
- Engagement letters and correspondence — 6 years after the engagement ends, the limitation period for contract claims.
- Enquiries that do not lead to an engagement — up to 12 months.
After these periods we securely delete or anonymise the data, unless it is needed for an ongoing claim or investigation.
8. Security
We use two-factor authentication on every system that holds client data, encrypted devices and connections, role-based access, secure document portals instead of ordinary e-mail attachments for sensitive files, and regular backups. Paper documents are kept locked away and returned or shredded. If a breach is likely to put your rights at risk, we will tell you and report it to the ICO within 72 hours where required.
10. Your rights
Under UK data protection law you have the right to:
- Access — receive a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete data, where we have no legal reason to keep it.
- Restriction — ask us to limit how we use your data while a concern is resolved.
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time.
Some rights are limited where we must keep records by law, for example AML records. To exercise any right, e-mail [email protected]. We reply within one month and do not charge a fee in most cases. If your request is about data held in your employer's accounting system, we will pass it to them as the controller and help them respond.
11. Withdrawing consent
If you have agreed to receive updates from us, you can withdraw that consent at any time by replying to any update or e-mailing [email protected]. Withdrawal does not affect processing carried out before it, or processing we do on another lawful basis such as delivering your services.
12. Complaints
If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: ico.org.uk, telephone 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
13. Children
Our services and this website are intended for businesses and adults aged 18 and over. We do not knowingly collect data from children, except where a client's payroll includes an employee under 18, in which case we process only what employment and tax law requires.
14. Changes to this policy
We review this policy when our services, suppliers or the law change. The current version is always published on this page with its "Last updated" date. If a change materially affects how we use your data, we will tell existing clients directly.
Last updated: 30 September 2026.