This Privacy Policy explains how ACSYS, the internal client-management system operated by The Accounting Crew Limited ("we", "us", "our", "the firm"), collects, uses and protects personal data. ACSYS is used only by our authorised staff; it is not a public-facing service.
Data Controller: The Accounting Crew Limited
Registered in England & Wales, company number: 08097388
Registered office: Office Suite 3, Shrieves Walk, Stratford-upon-Avon, Warwickshire, CV37 6GJ, United Kingdom
Data protection contact: rowan@thecrew.co.uk
We are registered with the Information Commissioner's Office (ICO) as a data controller. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy covers the personal data of three groups: our accounting clients; individuals associated with those clients (such as company directors, shareholders, partners, secretaries and named contacts); and our staff who use the system.
Depending on the individual and their relationship with the firm, ACSYS may hold the following categories of personal data:
Most of the personal data we hold is provided directly by our clients and their representatives during onboarding and in the course of providing our services. We also obtain and refresh certain data from third parties, namely:
Where we receive personal data about an individual from a source other than that individual, we handle it under the same protections set out in this policy.
Fraud-prevention headers (HMRC): HMRC requires all software that connects to its APIs to submit "fraud prevention" data with each request, to help protect the tax system. When a member of staff uses ACSYS to interact with HMRC on a client's behalf, the system collects technical information about the device and connection being used - including device identifier, IP address, browser and operating-system details, screen and window size, and time zone - and transmits it to HMRC in the header format that HMRC mandates. We collect this data solely to meet that legal requirement.
Essential cookies: ACSYS uses only strictly-necessary cookies - the session tokens required to keep authorised users securely signed in. We do not use advertising, analytics or tracking cookies.
Location for the weather panel: the dashboard shows local weather. To do this, your browser may share an approximate location (from your device or IP address) with third-party weather and geolocation services. This is a convenience feature only and involves no client or tax data.
We rely on the following lawful bases under UK GDPR, depending on the activity:
Where we process staff human-resources data (including absence records that may reveal health information), we do so under our obligations and rights in the field of employment law, in accordance with the relevant UK GDPR conditions and our internal HR policies.
Personal data in ACSYS is used only to run our practice and serve our clients - specifically to:
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects, and we do not sell personal data or share it with third parties for their own marketing.
ACSYS is not designed to hold special category data about clients, and we ask clients not to submit it. The main exception is limited staff human-resources information: where we record staff absence, this may reveal health information (for example, sickness absence). We process this only as necessary to administer employment and under the appropriate UK GDPR employment-law condition.
We share personal data only where necessary to deliver our services and meet our obligations. The organisations below either process data on our behalf under a written data-processing agreement, or receive it because the law or your instructions require it. Each acts as described:
| Organisation | Purpose | Location | Basis / safeguard |
|---|---|---|---|
| Supabase | Database hosting, file storage and authentication (our processor) | EU (Ireland - AWS eu-west-1) | Data Processing Agreement / SCCs |
| Vercel | Application hosting / web servers (our processor) | Compute in London (lhr1); Vercel Inc. is US-based | Data Processing Agreement / SCCs & EU-US Data Privacy Framework |
| Microsoft | Staff single sign-on (Entra ID), sending email from staff mailboxes (Microsoft Graph), and making the firm's records searchable to authorised staff (Microsoft 365 / Copilot connector) | UK / EU | Microsoft Data Protection Addendum |
| HM Revenue & Customs | VAT verification, Making Tax Digital data, agent authorisation, and mandatory fraud-prevention data | UK | UK Government service (controller in its own right) |
| Companies House | Company registration verification and record monitoring | UK | UK Government service (controller in its own right) |
| Xero | Synchronising invoice and contact data for clients who use Xero | Data centres in the EU / United States | Data Processing Agreement / SCCs |
| FreeAgent | Synchronising client and account data for clients who use FreeAgent | United Kingdom | Data Processing Agreement |
We may also disclose personal data where required by law, by a regulator, or by our professional body. We do not otherwise transfer your data to third parties.
Our systems and client data are hosted within the UK and the European Economic Area (EEA): application servers in London and the database in Ireland. Some of the processors above are, or are owned by, organisations based outside the UK/EEA. Where personal data is transferred outside the UK, it is protected by an appropriate safeguard recognised under UK data protection law - such as UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework - as noted in the table above.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure, including:
We keep personal data only for as long as necessary for the purposes for which it was collected and to meet our legal, regulatory and professional obligations:
When a retention period ends, data is securely deleted or anonymised.
Under UK GDPR, individuals whose personal data we hold have the right to:
Some of these rights are qualified where we have a legal or regulatory obligation to retain data. To exercise any right, contact rowan@thecrew.co.uk. We will respond within one calendar month.
If you have concerns about how we handle your personal data, you can complain to the Information Commissioner's Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
We would appreciate the chance to address your concerns directly before you contact the ICO.
We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last revised. Where changes are significant we will take reasonable steps to make users aware.