Legal
Privacy notice
Last updated 3 September 2026
This notice explains how Geldarts Ltd (“Geldarts”, “we”, “us”) collects, uses, shares and protects personal data, and the rights you have over it. It applies to visitors to geldarts.co.uk and its subdomains, people who enquire about our services, our clients and their staff, suppliers and contractors, and anyone whose personal data appears in the records we process for clients.
1. Who we are
Geldarts Ltd is a limited company registered in England and Wales. We are the data controller for the personal data described in this notice, except where we act as a processor on a client's instructions (see section 9). Our registration with the Information Commissioner's Office (ICO) is in progress; the registration number will be published here once issued.
Questions about this notice or your data: ryan@geldarts.co.uk, or write to our registered office marked “Data protection”.
2. The data we collect
- Website visitors. Technical data needed to serve pages (IP address, browser type, pages requested) held briefly in server logs by our hosting provider. We do not use tracking or advertising cookies. See our cookie policy.
- Enquirers. Name, email address, telephone number, business type, package of interest and the content of your message, plus the browser user-agent string, when you submit a form or email us.
- Prospective and current clients. Identity data (name, date of birth, address, photographic ID, proof of address, National Insurance number, Unique Taxpayer Reference); business data (company details, directors, shareholders and beneficial owners, VAT and PAYE references); financial data (bank and card transactions, invoices, bills, receipts, payroll data, tax computations); correspondence and meeting notes; identity-verification and sanctions/PEP screening results; risk assessments required by anti-money-laundering law.
- Client employees, customers and suppliers. Names, contact details, payment details and pay information to the extent they appear in the records we keep for a client.
- Suppliers and contractors. Contact and payment details.
- Special category and criminal-offence data. We may process limited data of this kind where it appears in client records (for example statutory sick pay or trade union subscriptions in payroll) or where anti-money-laundering law requires checks against sanctions and adverse-media lists. We do so only where a lawful condition applies under the Data Protection Act 2018.
3. Where we get it
Directly from you; from your business's systems and bank accounts with your authorisation (including Open Banking connections you approve); from public registers such as Companies House and HMRC; from identity-verification and screening providers; and from third parties acting for you such as your accountant, solicitor or lender.
4. Why we use it and our lawful bases
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Responding to enquiries and providing quotes | Steps at your request prior to entering a contract; legitimate interests |
| Providing bookkeeping, VAT, MTD and payroll services | Performance of a contract |
| Client due diligence, ongoing monitoring, and suspicious activity reporting | Legal obligation (Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017; Proceeds of Crime Act 2002) |
| Filing returns and submissions with HMRC and Companies House | Performance of a contract; legal obligation |
| Keeping business and tax records for the statutory period | Legal obligation |
| Invoicing, collecting payment and managing our accounts | Performance of a contract; legal obligation |
| Running, securing and improving our website and systems | Legitimate interests |
| Handling complaints, claims and disputes | Legitimate interests; legal obligation |
| Occasional service updates relevant to existing clients | Legitimate interests (you can opt out at any time) |
| Marketing to people who are not clients | Consent |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded the processing is necessary and proportionate. You can ask for details of that assessment.
5. Who we share it with
- HMRC, Companies House and other regulators when filing on your behalf or where the law requires.
- The National Crime Agency where we are legally required to make a report.
- Our anti-money-laundering supervisor during inspections.
- Service providers acting on our instructions under written contracts: cloud hosting and database (UK/EU data centres), email and calendar, transactional email, Open Banking data providers, identity-verification and screening providers, receipt-capture processing, payment collection, IT support and backup.
- Your other advisers (accountant, solicitor, lender) where you ask us to.
- Professional indemnity insurers and legal advisers in connection with a claim or complaint.
- A successor if we sell or transfer the practice, subject to the same protections.
We do not sell personal data and we do not share it with advertisers.
6. International transfers
We store data in the UK or the European Economic Area wherever possible. Where a provider processes data outside the UK, we rely on the UK's adequacy regulations or the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, and we assess the destination's protections before transferring.
7. How long we keep it
- Enquiries that do not become clients: 12 months from last contact.
- Client accounting, VAT and payroll records: 6 years from the end of the accounting or tax period they relate to (HMRC requirement), or longer where a return is under enquiry.
- Anti-money-laundering identity and due-diligence records: 5 years from the end of the business relationship, then deleted unless a legal hold applies.
- Contracts, engagement letters and correspondence about the engagement: 6 years after the engagement ends.
- Complaint files: 6 years after closure.
- Server logs: up to 30 days.
When retention ends, data is deleted or irreversibly anonymised.
8. How we protect it
Data is encrypted in transit and at rest. Access is restricted by role, protected by multi-factor authentication, and logged. Systems are backed up daily and backups are tested. Staff and contractors are bound by confidentiality. We review security regularly and have a documented procedure for handling any personal-data breach, including notifying the ICO within 72 hours and affected individuals where required.
9. When we act as a processor
Where we run payroll or keep records containing personal data of a client's employees, customers or suppliers, the client is the controller and we act as processor on their documented instructions under a data processing agreement forming part of our terms of business. Those individuals should direct rights requests to the client in the first instance; we will assist the client in responding.
10. Your rights
- To be told how your data is used (this notice).
- To access a copy of your personal data.
- To have inaccurate data corrected.
- To have data erased where there is no continuing lawful reason to hold it. This does not apply to records we must keep by law.
- To restrict or object to processing, including to any direct marketing.
- To receive data you provided to us in a portable format.
- To withdraw consent at any time where consent is the basis.
- Not to be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.
To exercise a right, email ryan@geldarts.co.uk. We respond within one month, extendable by two months for complex requests, and we may ask for proof of identity. There is no fee unless a request is manifestly unfounded or excessive.
You have the right to complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113. We would appreciate the chance to address your concern first.
11. Children
Our services are for businesses. We do not knowingly collect data from anyone under 18 except where it appears incidentally in a client's records.
12. Links to other sites
Our website links to HMRC, Companies House and other third-party sites. Their privacy practices are their own; this notice does not cover them.
13. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The date at the top shows the current version. Significant changes will be notified to clients directly.