UK GDPR & Data Protection Act 2018

Privacy Policy

Last updated: 30 September 2026

1. Who we are

This website and our accounting, tax and audit services are provided by DALTON & HOLLAND ACCOUNTING LTD, trading as Dalton & Holland Accounting, a company registered in England and Wales under company number 17434455.

Registered office: 35 Little Close, Kingsteignton, Newton Abbot, England, TQ12 3YZ.

For our own clients, enquirers and website visitors we are the controller of personal data. You can contact us about anything in this policy at [email protected] or on +44 7700 900417.

2. Personal data we collect

What we hold depends on the services you use. It can include:

  • Contact details — name, business name, postal address, e-mail address and phone number of clients, directors and contacts.
  • Enquiry data — the content of e-mails and phone calls you send us, including any request for a quote. This website has no forms: when you click a contact button, your own e-mail program opens and you choose what to send.
  • Financial data — bank statements, invoices, receipts, ledgers, loan and asset records, dividend and director's loan account records.
  • Tax data — Unique Taxpayer Reference (UTR), National Insurance number, VAT registration number, Corporation Tax references, income, gains, reliefs and previous returns.
  • Payroll data about your employees — names, addresses, dates of birth, NI numbers, tax codes, salaries, hours, bank details for payment, pension scheme membership, statutory pay (sickness, maternity, paternity) and student loan deductions.
  • Identity verification data — copies of passports or driving licences, proof of address, date of birth and the results of electronic identity checks required under anti-money laundering law, for clients, directors and people with significant control.
  • Engagement records — engagement letters, correspondence, file notes, invoices we issue and payments you make to us.
  • Technical data — when you visit this site, your browser sends your IP address and device information to the servers that deliver the pages and web fonts.

Payroll data may include health information, for example reasons for statutory sick pay. We process it only where employment and social security law requires it.

3. Purposes and lawful bases

PurposeLawful basis (UK GDPR Art. 6)
Replying to enquiries and preparing quotesSteps at your request before entering a contract; legitimate interests in answering business enquiries
Providing bookkeeping, accounts, tax, VAT, payroll and audit servicesPerformance of a contract
Filing returns and accounts with HMRC and Companies HousePerformance of a contract; legal obligation
Identity checks and client due diligence under the Money Laundering Regulations 2017Legal obligation
Keeping working papers and records for statutory periodsLegal obligation
Invoicing, recovering fees and managing our practicePerformance of a contract; legitimate interests
Defending legal claims and dealing with our insurersLegitimate interests
Sending occasional updates on tax deadlines or changesConsent, which you can withdraw at any time

Where we process health data in payroll, we rely on Art. 9(2)(b) UK GDPR and Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 (employment and social security). Where AML checks reveal information about criminal convictions, we rely on Schedule 1, paragraph 12 of the Data Protection Act 2018 (regulatory requirements).

4. When we act as a processor

When we work inside your own cloud accounting or payroll system, the records there — including data about your customers, suppliers and employees — belong to you. In that role you are the controller and we act as your processor under Article 28 UK GDPR.

  • We process that data only on your documented instructions, set out in our engagement letter.
  • Everyone on our team who accesses it is bound by confidentiality.
  • We apply appropriate security measures and tell you without undue delay about any personal data breach affecting your data.
  • We help you respond to requests from individuals exercising their rights.
  • At the end of our engagement we return or delete that data, except where the law requires us to keep a copy.

Where we file returns for your business with HMRC or Companies House in our own name as agent, or carry out an audit, we act as an independent controller for that processing.

5. Who we share data with

We do not sell personal data. We share it only where needed for the purposes above, with:

  • HM Revenue & Customs — tax returns, VAT returns, RTI payroll submissions, CIS returns and related correspondence.
  • Companies House — statutory accounts, confirmation statements and officer and PSC details, which become public.
  • Pension providers — auto-enrolment contributions and member details for your employees.
  • Cloud accounting and payroll software providers used to deliver our services.
  • Electronic identity verification providers used for AML checks.
  • IT, e-mail and secure file-sharing providers that host our systems.
  • Our professional indemnity insurers and legal advisers, where needed to manage a claim.
  • Our anti-money laundering supervisory authority and other regulators, when they review our files.
  • The National Crime Agency or law enforcement, where the law requires us to make a report.
  • Your bank, lender or other advisers, only when you ask us to.

All service providers acting for us are bound by written contracts that require them to protect the data and use it only on our instructions.

6. International transfers

Some of our software and hosting providers store or access data outside the UK. When that happens, we make sure the transfer is protected by UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. You can ask us for details of the safeguards used.

7. How long we keep data

  • Client due diligence and identity records — at least 5 years after our business relationship ends, as required by regulation 40 of the Money Laundering Regulations 2017.
  • Accounting, tax and payroll working papers — 6 years after the end of the relevant accounting period or tax year, reflecting HMRC enquiry and record-keeping time limits.
  • Audit files — at least 6 years after the audit report is signed.
  • Engagement letters and correspondence — 6 years after the engagement ends, the limitation period for contract claims.
  • Enquiries that do not lead to an engagement — up to 12 months.

After these periods we securely delete or anonymise the data, unless it is needed for an ongoing claim or investigation.

8. Security

We use two-factor authentication on every system that holds client data, encrypted devices and connections, role-based access, secure document portals instead of ordinary e-mail attachments for sensitive files, and regular backups. Paper documents are kept locked away and returned or shredded. If a breach is likely to put your rights at risk, we will tell you and report it to the ICO within 72 hours where required.

9. Cookies

This website does not set any cookies and does not use analytics, advertising or tracking tools. Pages load our typeface from Google Fonts, which means your browser sends your IP address to Google when the page loads so that the font files can be delivered. No information is stored on your device by this website.

10. Your rights

Under UK data protection law you have the right to:

  • Access — receive a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete data, where we have no legal reason to keep it.
  • Restriction — ask us to limit how we use your data while a concern is resolved.
  • Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another provider.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

Some rights are limited where we must keep records by law, for example AML records. To exercise any right, e-mail [email protected]. We reply within one month and do not charge a fee in most cases. If your request is about data held in your employer's accounting system, we will pass it to them as the controller and help them respond.

12. Complaints

If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: ico.org.uk, telephone 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

13. Children

Our services and this website are intended for businesses and adults aged 18 and over. We do not knowingly collect data from children, except where a client's payroll includes an employee under 18, in which case we process only what employment and tax law requires.

14. Changes to this policy

We review this policy when our services, suppliers or the law change. The current version is always published on this page with its "Last updated" date. If a change materially affects how we use your data, we will tell existing clients directly.

Last updated: 30 September 2026.