Last updated: 7-22-2026
- Who we are
This policy explains how Arthur Gait & Co Ltd (“we”, “us”, “our”) collects and uses your personal data. We are the data controller for the data we hold.
- Registered company: Arthur Gait & Co Ltd, company number [number]
- Registered office: [address, Newport]
- ICO registration number: [number]
- Data protection contact: [name/role], [email], [phone]
We handle your data in accordance with the UK GDPR and the Data Protection Act 2018.
- The information we collect
- Identity and contact data — name, business name, email, phone, address.
- Enquiry data — information you provide via our website forms or when you contact us.
- Client data — financial and accounting records, tax information, UTR and National Insurance numbers, payroll and bank details, and business information.
- Audit data — where we act as your auditors, information relating to the entity, its officers, and its financial affairs necessary to perform the audit.
- Identity verification data — documents and information collected for AML and client due diligence.
- Website and technical data — IP address, browser and device information, and cookie data (see our [Cookie Policy]).
We may process special category data or criminal offence data only where necessary for a specific engagement, with an appropriate lawful basis and safeguards.
- How and why we use your data (lawful bases)
- Responding to enquiries — pre-contract steps at your request and our legitimate interests.
- Providing accountancy, audit, tax and payroll services — performance of our contract (the engagement).
- Meeting legal and regulatory obligations — including AML, audit regulation, tax obligations and ICAEW requirements — compliance with a legal obligation.
- Running and improving our practice — administration and record-keeping — our legitimate interests.
- Marketing — only with your consent or under legitimate interests, with an easy opt-out.
- Who we share it with
We do not sell your data. We may share it with:
- Other firms within Adroit Accountax Group, under appropriate safeguards.
- HMRC, Companies House, and other authorities and regulators, including for audit and statutory purposes.
- Service providers processing data on our behalf (cloud accounting, IT, hosting, secure document exchange) under contract.
- Professional advisers, our regulator (ICAEW) and quality reviewers where necessary.
- Successors in a business transfer or reorganisation.
- International transfers
Where a provider processes data outside the UK, we put appropriate safeguards in place (adequacy or the ICO’s IDTA/Addendum). [Confirm which apply.]
- How long we keep it
- Client records and working papers — generally [6–7] years after the engagement ends.
- Audit working papers — retained in line with audit regulation ([typically 6 years] — confirm).
- AML / due diligence records — 5 years after the business relationship ends.
- Enquiries that don’t proceed — [period].
- Marketing data — until you opt out.
- Your rights
You have the rights to access, rectification, erasure, restriction, objection, portability, and to withdraw consent where we rely on it. Some rights may be limited where processing is required by law or regulation (for example, audit and AML records). Contact [email] to exercise a right; we respond within one month.
- Complaints
Please raise any concern with us first at [email]. You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or 0303 123 1113.
- Cookies
See our [Cookie Policy] for details of the cookies our website uses.
- Changes to this policy
We may update this policy periodically; the current version is always shown here with its “last updated” date