← Back to dashboard

Privacy Policy

Last updated: 3 August 2026

1. Who we are

This Privacy Policy explains how ACSYS, the internal client-management system operated by The Accounting Crew Limited ("we", "us", "our", "the firm"), collects, uses and protects personal data. ACSYS is used only by our authorised staff; it is not a public-facing service.

Data Controller: The Accounting Crew Limited
Registered in England & Wales, company number: 08097388
Registered office: Office Suite 3, Shrieves Walk, Stratford-upon-Avon, Warwickshire, CV37 6GJ, United Kingdom
Data protection contact: rowan@thecrew.co.uk

We are registered with the Information Commissioner's Office (ICO) as a data controller. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy covers the personal data of three groups: our accounting clients; individuals associated with those clients (such as company directors, shareholders, partners, secretaries and named contacts); and our staff who use the system.

2. The personal data we hold

Depending on the individual and their relationship with the firm, ACSYS may hold the following categories of personal data:

  • Identity data: full name, preferred / known-as name, date of birth, gender, National Insurance number
  • Contact data: email addresses, telephone and mobile numbers, postal and correspondence addresses
  • Business & registration data: company name and registered name, Companies House number, registered office and trading addresses, directors, shareholders, persons with significant control, secretaries and associated / linked entities
  • Tax & compliance data: Unique Taxpayer References (UTR), VAT registration numbers and schemes, PAYE and Accounts Office references, Corporation Tax details, Making Tax Digital (MTD) status, accounting year ends, filing and submission dates, anti-money-laundering / client-verification records
  • Financial data: invoices, invoice amounts and payment status, fees and service agreements, estimated turnover, credit-control notes, and accounting data synchronised from connected bookkeeping systems
  • HMRC tax-account data: where authorised as your agent, VAT obligations, returns, liabilities, payments and penalties retrieved from HMRC on your behalf
  • Relationship & service data: the services we provide, workflow and job status, deadlines, onboarding checklists, and file / activity notes
  • Correspondence data: the content of emails we send to you or your associated contacts from within the system, and records that they were sent
  • Staff data: for system users - names, work contact details, job role, access permissions, and human-resources records including leave, entitlements and absence
  • Technical & usage data: sign-in records, audit logs of changes to key records, and the device / connection information described in section 4

3. Where we obtain your data

Most of the personal data we hold is provided directly by our clients and their representatives during onboarding and in the course of providing our services. We also obtain and refresh certain data from third parties, namely:

  • Companies House - company registration details, officers and filing history, which we monitor for changes
  • HM Revenue & Customs (HMRC) - VAT registration verification and, where we act as your authorised agent, your VAT tax-account data
  • Xero and FreeAgent - where a client uses these bookkeeping platforms, invoice, contact and account data synchronised into ACSYS

Where we receive personal data about an individual from a source other than that individual, we handle it under the same protections set out in this policy.

4. Information collected automatically, and fraud-prevention data

Fraud-prevention headers (HMRC): HMRC requires all software that connects to its APIs to submit "fraud prevention" data with each request, to help protect the tax system. When a member of staff uses ACSYS to interact with HMRC on a client's behalf, the system collects technical information about the device and connection being used - including device identifier, IP address, browser and operating-system details, screen and window size, and time zone - and transmits it to HMRC in the header format that HMRC mandates. We collect this data solely to meet that legal requirement.

Essential cookies: ACSYS uses only strictly-necessary cookies - the session tokens required to keep authorised users securely signed in. We do not use advertising, analytics or tracking cookies.

Location for the weather panel: the dashboard shows local weather. To do this, your browser may share an approximate location (from your device or IP address) with third-party weather and geolocation services. This is a convenience feature only and involves no client or tax data.

5. Lawful bases for processing

We rely on the following lawful bases under UK GDPR, depending on the activity:

  • Contract: processing necessary to provide the accountancy, tax, VAT, payroll and related services our clients engage us for.
  • Legal obligation: processing required to meet our obligations as a regulated firm - including HMRC reporting and Making Tax Digital submissions, submitting HMRC-mandated fraud-prevention data, Companies House filings, and anti-money-laundering / know-your-client duties.
  • Legitimate interests: operating a secure internal system to manage client relationships, workflow, deadlines and credit control efficiently, and to keep our records accurate. We balance these interests against individuals' rights.
  • Consent: where we rely on your specific consent for an optional activity; you may withdraw consent at any time.

Where we process staff human-resources data (including absence records that may reveal health information), we do so under our obligations and rights in the field of employment law, in accordance with the relevant UK GDPR conditions and our internal HR policies.

6. How we use your data

Personal data in ACSYS is used only to run our practice and serve our clients - specifically to:

  • Deliver accountancy, tax, VAT, payroll and related professional services
  • Manage client onboarding, engagement and anti-money-laundering compliance
  • Track workflow, jobs, deadlines and service delivery, and manage credit control
  • Verify and monitor business registrations with HMRC and Companies House
  • Act as your authorised agent with HMRC, including establishing digital authorisation and retrieving and submitting Making Tax Digital data
  • Synchronise invoicing and accounting data from connected bookkeeping platforms
  • Correspond with clients and their associated contacts, including sending emails from staff mailboxes
  • Make the firm's own records searchable to authorised staff through our internal Microsoft 365 tools
  • Meet our legal, regulatory and professional obligations, and keep secure audit trails

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects, and we do not sell personal data or share it with third parties for their own marketing.

7. Special category data

ACSYS is not designed to hold special category data about clients, and we ask clients not to submit it. The main exception is limited staff human-resources information: where we record staff absence, this may reveal health information (for example, sickness absence). We process this only as necessary to administer employment and under the appropriate UK GDPR employment-law condition.

8. Who we share your data with

We share personal data only where necessary to deliver our services and meet our obligations. The organisations below either process data on our behalf under a written data-processing agreement, or receive it because the law or your instructions require it. Each acts as described:

OrganisationPurposeLocationBasis / safeguard
SupabaseDatabase hosting, file storage and authentication (our processor)EU (Ireland - AWS eu-west-1)Data Processing Agreement / SCCs
VercelApplication hosting / web servers (our processor)Compute in London (lhr1); Vercel Inc. is US-basedData Processing Agreement / SCCs & EU-US Data Privacy Framework
MicrosoftStaff single sign-on (Entra ID), sending email from staff mailboxes (Microsoft Graph), and making the firm's records searchable to authorised staff (Microsoft 365 / Copilot connector)UK / EUMicrosoft Data Protection Addendum
HM Revenue & CustomsVAT verification, Making Tax Digital data, agent authorisation, and mandatory fraud-prevention dataUKUK Government service (controller in its own right)
Companies HouseCompany registration verification and record monitoringUKUK Government service (controller in its own right)
XeroSynchronising invoice and contact data for clients who use XeroData centres in the EU / United StatesData Processing Agreement / SCCs
FreeAgentSynchronising client and account data for clients who use FreeAgentUnited KingdomData Processing Agreement

We may also disclose personal data where required by law, by a regulator, or by our professional body. We do not otherwise transfer your data to third parties.

9. International data transfers

Our systems and client data are hosted within the UK and the European Economic Area (EEA): application servers in London and the database in Ireland. Some of the processors above are, or are owned by, organisations based outside the UK/EEA. Where personal data is transferred outside the UK, it is protected by an appropriate safeguard recognised under UK data protection law - such as UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework - as noted in the table above.

10. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure, including:

  • Authentication required for all access - staff sign in with their Microsoft 365 work account (single sign-on, protected by the firm's multi-factor authentication policy)
  • Database-level row security so that only active, authorised staff accounts can read or write client data, with additional restrictions protecting clients flagged as confidential
  • Role-based access controls limiting administrative and sensitive functions to designated staff
  • All data encrypted in transit using TLS, and encrypted at rest (AES-256) in the database and backups; the most sensitive secrets - such as integration credentials and access tokens - carry an additional layer of application-level AES-256-GCM encryption
  • Data hosted within the UK / EEA (application servers in London, database in Ireland)
  • Daily backups with restore capability, and audit trails recording changes to key records

11. Data retention

We keep personal data only for as long as necessary for the purposes for which it was collected and to meet our legal, regulatory and professional obligations:

  • Active client records: held for the duration of the client relationship
  • Closed client records: retained for a minimum of 7 years after the engagement ends, in line with HMRC guidance and our professional obligations
  • Staff records: retained for 6 years after an individual's employment or engagement ends
  • Integration tokens and technical / fraud-prevention data: retained only as long as needed for the connection or to meet HMRC's requirements

When a retention period ends, data is securely deleted or anonymised.

12. Your rights

Under UK GDPR, individuals whose personal data we hold have the right to:

  • Access - request a copy of the personal data we hold about you
  • Rectification - ask us to correct inaccurate or incomplete data
  • Erasure - request deletion of your data where there is no overriding legal or regulatory reason for us to keep it
  • Restriction - ask us to pause processing in certain circumstances
  • Portability - receive certain data in a structured, commonly used, machine-readable format
  • Object - object to processing carried out on the basis of our legitimate interests
  • Withdraw consent - where we rely on consent, withdraw it at any time

Some of these rights are qualified where we have a legal or regulatory obligation to retain data. To exercise any right, contact rowan@thecrew.co.uk. We will respond within one calendar month.

13. Complaints

If you have concerns about how we handle your personal data, you can complain to the Information Commissioner's Office (ICO):

Website: ico.org.uk
Telephone: 0303 123 1113

We would appreciate the chance to address your concerns directly before you contact the ICO.

14. Changes to this policy

We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last revised. Where changes are significant we will take reasonable steps to make users aware.

Terms & ConditionsBack to dashboard