
Privacy Policy
Introduction
We respect your privacy and are committed to protecting your Personal Data. This privacy policy will inform you as to how we look after your Personal Data when you visit our website (regardless of where you visit it from) and/or engage us to provide Services to you and explain your privacy rights.
This website is not intended for children and we do not knowingly collect data relating to children.
It is important that you read this privacy policy together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
Data Controller
GTP Accounting & Business Services is the controller and responsible for your personal data (collectively referred to as "GTP", "we", "us" or "our" in this privacy policy).
We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
Full name of DPO: Hayley Pope
Email address: hayley@gtpabs.co.uk
Postal address: office 8, no.11 riverside, riverside park, Farnham, Surrey GU9 7UG.
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Third-party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
Types of Data collected
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
Contact Data includes registered office address, home address, email address and telephone numbers.
Financial Data includes bank account and payment card details.
Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
Profile Data includes your username and password, engagements made by you, your interests, preferences, feedback and survey responses.
Usage Data includes information about how you use our website, products and services.
Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
We may collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity for the purposes of satisfying our identification, compliance and ‘know you client’ checks when client onboarding. We do not collect any information about criminal convictions and offences. We shall carry out DPIA in respect of the processing of Special Categories of Personal Data.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide services to you). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
Users are responsible for any third-party Personal Data obtained, published or shared and confirm that they have the third party's consent to provide the Data to us.
Data Collection
We use different methods to collect data from and about you including through:
Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
apply for our products or services;
subscribe to our service or publications;
request marketing to be sent to you;
enter a survey; or
give us feedback or contact us.
Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. Please see our cookie policy for further details.
Third parties or publicly available sources. We will receive personal data about you from various third parties and public sources as set out below:
Companies House;
Professional clearance obtained from previous accountant(s).
Technical Data from the following parties:
(a) Analytics providers such as Google Analytics (Google Ireland Limited), a web analysis service provided by Google Ireland Limited (“Google”). Google utilises the Data collected to track and examine the use of this Application, to prepare reports on it’s activities and share them with other Google services. Google may use the Data collected to contextualise and personalise the ads of it’s own advertising network.
Personal data processed: Cookies, Usage Data
Place of processing: Ireland;
(b) Platform servies and hosting providers. These services have the purpose of hosting and running our systems, therefore allowing the provision of services from within a unified platform. Such platforms provide a wide range of tools such as analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored. Platform service providers may include:
Squarespace (located in the USA and therefore outside the EEA)
Dropbox (located in the USA and therefore outside the EEA)
Sharepoint (located in the USA and therefore outside the EEA)
(c) Tag management service providers such as Google Tag Manager (Google Ireland Limited) located in Ireland and therefore outside the EEA. This type of service helps us to manage the tags or scripts needed on our systems in a centralised fashion. This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.
Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the EEA.
Mode and place of processing the Data
Methods of processing
We will take the appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In some cases, the Data may be accessible to certain types of persons within GTP (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Data Controller. The updated list of these parties may be requested from us at any time.
Legal basis of processing
We may process Personal Data relating to Users if one of the following applies:
Users have given their consent for one or more specific purposes. Note: Under some legislations we may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law. In any event, the User has a right to withdraw at any time;
provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
processing is necessary for compliance with a legal obligation;
In any case, the we will explain the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract if required to do so.
Place of Processing
The Data is processed at our operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organisation governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
We share your personal data this will involve transferring your data outside the European Economic Area (EEA). Some of our external third parties are based outside the European Economic Area (EEA) so their processing of your personal data will involve a transfer of data outside the EEA.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries. Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US. For further details, see European Commission: EU-US Privacy Shield.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Retention time
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
Personal Data collected for purposes related to the performance of a contract between GTP and the User shall be retained until such contract has been fully performed; and
Personal Data collected for the purposes of our legitimate interests shall be retained as long as needed to fulfill such purposes. You may find specific information regarding the legitimate interests within the relevant sections of this document or by contacting the DPO.
We may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority. We may also retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
The purposes of processing
The Data concerning the User is collected to allow us to provide services, comply with our legal obligations, respond to enforcement requests, protect our rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics, Platform services and hosting and Tag Management.
We have set out below, in a table format, a description of all the ways we plan to use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
When collecting Special Categories of Personal Data from Data Subjects, either directly from Data Subjects or indirectly (for example from a third party or publicly available source).
Marketing
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
Third-party marketing
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Opting out
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a service or product purchase, service or product experience or other transactions.
The rights of Users
Users may exercise certain rights regarding their Data processed by us.
In particular, Users have the right to do the following:
Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
Access their Data. Users have the right to learn if Data is being processed by us, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, we will not process their Data for any purpose other than storing it.
Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data.
Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User's consent, on a contract which the User is part of or on pre-contractual obligations thereof.
Lodge a complaint. Users have the right to bring a claim before to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).
If you wish to exercise any of the rights set out above, please contact the DPO.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Cookie Policy
This Application uses Cookies and other Identifiers. To learn more, the User may consult the Cookie Policy.
Additional information about Data collection and processing
Additional information about User's Personal Data
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
System logs and maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) use other Personal Data (such as the IP Address) for this purpose.
Information not contained in this policy
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
Changes to this privacy policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
Definitions and legal references
Personal Data (or Data)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Special Categories of Personal Data
Information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilised by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilised by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
User
The individual providing the Personal Data or Special Categories of Personal Data to GTP, unless otherwise specified, coincides with the Data Subject.
Data Subject
The natural person to whom the Personal Data refers.
Data Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
Data Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
Data Privacy Impact Assessment (DPIA)
Tools and assessments used to identify and reduce risks of a data processing activity. A DPIA can be carried out as part of Privacy by Design and should be conducted for all major system or business change programmes involving the Processing of Personal Data.
Service
The service provided by GTP as described in the relative terms and conditions.
EEA
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Cookies
Small sets of data stored in the User's device.
Legal information
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy policy relates solely to this Application, if not stated otherwise within this document.
Cookie Policy
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer's hard drive.
We use the following cookies:
Strictly necessary cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, use a shopping cart or make use of e-billing services.
Analytical or performance cookies. These allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
Functionality cookies. These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests.
How to provide or withdraw consent
Users can provide or withdraw consent to the use of Cookies and other Identifiers by setting their preferences within the cookie notice or by updating such preferences via the relevant consent-preferences widget accordingly, if available.
Additionally, Users can manage preferences regarding Identifiers directly from within their own device settings and prevent – for example – the storing of third-party Identifiers. It is also possible, via relevant browser or device features, to delete previously stored Identifiers, including those used to remember the User’s initial consent. Users can, for example, find information about how to manage Identifiers in the most commonly used browsers at the following addresses: Google Chrome, Mozilla Firefox, Apple Safari and Microsoft Internet Explorer.
With regard to any Identifiers stored by third parties, Users can manage their preferences and withdraw their consent by clicking the related opt-out link (where provided), by using the means indicated in the third party's privacy policy, or by contacting the third party.
Notwithstanding the above, Users are hereby informed that they may follow the instructions provided by YourOnlineChoices (EU), the Network Advertising Initiative (US) and the Digital Advertising Alliance (US), DAAC (Canada), DDAI (Japan) or other similar services. Such initiatives allow Users to select their tracking preferences for most of the advertising tools. The Owner thus recommends that Users make use of these resources in addition to the information provided in this document.
Owner and Data Controller
GTP Accounting & Business Services
Owner contact email: hayley@gtpabs.co.uk
Since the storing of third-party Cookies and other Identifiers through the services used within this Application cannot be technically controlled by the Owner, any specific references to Identifiers stored by third parties are to be considered indicative. In order to obtain complete information, the User is kindly requested to consult the privacy policies of the respective third-party services listed in this document.
Given the objective complexity surrounding technologies related to Cookies and other Identifiers, Users are encouraged to contact the Owner should they wish to receive any further information on the use of such Identifiers by this Application.
Privacy Notice
This privacy notice provides information on how GTP Accounting & Business Services collects and processes your personal data when you visit our website to sign up for a newsletter or engage us to provide a service.
It is important that you read this privacy notice together with our website privacy policy which contains more detailed information about our data processing and can be accessed at www.gtpabs.co.uk
1. Important information and who we are
GTP Accounting & Business Services is the controller and responsible for your personal data.
We have appointed a data protection officer (DPO). If you have any questions about this privacy notice or our data protection practices please contact the DPO.
CONTACT DETAILS
Our full details are:
Name of DPO: Mrs Hayley Pope
Email address: hayley@gtpabs.co.uk
Postal address: Office 8, No. 11 Riverside, Riverside Park, Farnham, Surrey GU9 7UG.
2.The data we collect about you
We may collect, use, store and transfer different kinds of personal data about you as follows:
Identity Data.
Contact Data.
Financial Data.
Transaction Data.
Technical Data.
Profile Data.
Usage Data.
Marketing and Communications Data.
We explain these categories of data in our Privacy Policy.
We use different methods to collect data about you, which are explained in our Privacy Policy.
3.How we use your personal data
We will only use your personal data for the purpose for which we collected it which include the following:
To register you as a new customer.
To process and provide services to you.
To manage your relationship with us.
To enable you to participate in completing a survey.
To improve our website, products/services, marketing or customer relationships.
To recommend products or services which may be of interest to you.
4. How we share your personal data
We may share your personal data with external third parties. More detail can be found in our Privacy Policy.
5. How we use particularly sensitive personal information
We will use your particularly sensitive personal information to satisfy our ‘know your client’ checks. More detail can be found in our Privacy Policy.
6. International transfers
We may transfer, store and process your personal data outside the European Economic Area. More detail can be found in our Privacy Policy.
7. Your legal rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data including the right to receive a copy of the personal data we hold about you and the right to make a complaint at any time to the Information Commissioner's Office, the UK supervisory authority for data protection issues (www.ico.org.uk).
More detail can be found in in our Privacy Policy.
8. Further details
If you are looking for more information on we process your personal data including on data security, data retention and lawful processing bases, please access our website privacy policy.