1. Introduction
At BrightLedger Limited, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data in line with the UK General Data Protection Regulation (UK GDPR)and the Data Protection Act 2018.
2. Who We Are
3. What Data We Collect
We may collect and process the following personal data:
- Identification details (name, date of birth, NI number, UTR, passport/ID, address).
- Contact details (email, phone, address).
- Financial information (bank details, tax records, income, expenses).
- Employment and company information (director details, payroll data).
- Communication records (emails, meeting notes, phone calls).
We only collect the data necessary to provide our services.
4. How We Collect Your Data
- Directly from you (meetings, forms, correspondence).
- From HMRC, Companies House, or other official sources.
- From your previous accountant or bookkeeper (with your consent).
- Through accounting and tax software you authorise us to use.
5. Why We Use Your Data (Lawful Basis)
We process your data for the following purposes under lawful bases defined by UK GDPR:
- Contract – to provide the accounting and tax services you request.
- Legal Obligation – to comply with UK law (e.g. HMRC, AML regulations).
- Legitimate Interests – to manage our business, improve services, and protect against fraud.
- Consent – where you have given clear consent (e.g. marketing communications).
6. How We Use Your Data
We use your personal data to:
- Provide accounting, tax, and advisory services.
- Prepare and submit statutory filings (HMRC, Companies House).
- Communicate with you regarding services.
- Carry out anti-money laundering and identity verification checks.
- Maintain our business and financial records.
7. Sharing Your Data
We will not sell or share your data with third parties for marketing.
We may share your data with:
- HMRC, Companies House, and other regulators.
- Our professional advisers (lawyers, insurers, auditors).
- Third-party service providers (e.g. cloud accounting software, secure document storage).
All third parties we use are required to comply with data protection law.
8. International Transfers
If we transfer your data outside the UK (e.g. cloud services), we ensure appropriate safeguards are in place (adequacy decision, Standard Contractual Clauses).
9. How Long We Keep Your Data
We will retain your data for as long as required by law:
- Typically 6 years from the end of our relationship, in line with HMRC requirements.
- AML records are retained for 5 years.
After this period, data will be securely deleted or anonymised.
10. Your Rights
You have the right to:
- Access your data (Subject Access Request).
- Correct inaccurate or incomplete data.
- Request erasure of your data (where legally permitted).
- Restrict or object to processing.
- Data portability (transfer to another provider).
- Withdraw consent (where processing is based on consent).
To exercise your rights, contact us at info@brightledger.co.uk.
11. Security
We take appropriate technical and organisational measures to protect your data, including encrypted systems, secure storage, and access controls.
12. Complaints
If you are unhappy with how we handle your data, please contact us at info@brightledger.co.uk
13. Updates to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.