Privacy Notice

How we use personal data

Last updated: 1 July 2026

1. Who we are

1.1      Audithelp Ltd ("Audithelp", "we", "us", "our") is a firm of Chartered Certified Accountants registered as auditors in the United Kingdom by the Association of Chartered Certified Accountants (ACCA). We are a private company limited by shares registered in England and Wales under company number 13653495. Our registered office is 86-90 Paul Street, London, EC2A 4NE. We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB668822.

1.2      We are the controller of the personal data described in this notice. We have not appointed a statutory data protection officer; questions about this notice and requests relating to your personal data should be sent to the Director responsible for data protection, Oleksandr Vertyporokh, at Oleksandr.Vertyporokh@audithelp.co.uk, by telephone on +44 20 7112 9389, or by post to the address above.

1.3      This notice explains what personal data we collect, why and on what lawful basis we use it, who we share it with, how long we keep it, and your rights. It applies to visitors to www.audithelp.co.uk (the "Site"), to our clients and prospective clients and their staff, to individuals whose personal data we see while performing audit, assurance, accounting and advisory work, and to our suppliers, contacts and job applicants.

2. Personal data we collect

2.1      Depending on our relationship with you, we may collect and process the following categories of personal data:

  • Identity and contact data: name, job title, employer, postal address, email address, telephone number.

  • Client due diligence data: date of birth, nationality, copies of passports, driving licences or other identity documents, proof of address, details of beneficial ownership and source of funds, and the results of identity, sanctions and politically-exposed-person screening, collected to meet our anti-money laundering obligations.

  • Engagement data: personal data contained in the books, records, contracts, payroll, expense, banking, pension, customer, supplier and other information of our clients that we examine when carrying out audit, assurance, accounting or advisory engagements. This may include data about directors, shareholders, employees, customers, suppliers and other third parties of the client.

  • Financial data: bank account details for invoicing and payment; fee and billing history.

  • Correspondence and marketing data: the content of emails, letters, calls and meetings with you; your marketing preferences.

  • Website and technical data: IP address, browser type and version, device information, pages visited and the date and time of visits, collected through cookies and server logs as described in section 11; information you submit through the contact form.

  • Recruitment data: CVs, qualifications, employment history, references, right-to-work documents and interview notes.

2.2      In the course of engagements we may incidentally see special category data (for example health information in sickness or absence records, or trade union membership in payroll deductions) or data about criminal convictions and offences (for example in the course of client due diligence, sanctions screening or where a matter is relevant to an audit). We do not seek such data unless it is necessary for the engagement, we process it only as described in section 4, and we do not use it for any other purpose.

2.3      We obtain personal data directly from you; from the client or organisation you work for, own or deal with; from public sources such as Companies House, the Register of Statutory Auditors, the Land Registry, sanctions lists and the internet; from identity-verification and credit-reference providers; from other professional advisers, banks, regulators and counterparties; and from our website and email systems.

3. Why we use personal data and our lawful bases

3.1      The UK General Data Protection Regulation ("UK GDPR") requires us to have a lawful basis for each purpose for which we process personal data. The table below sets out our main purposes and the bases we rely on.

How we use your personal data

We use personal data only where we have a lawful basis under UK GDPR.

1. Enquiries and quotes

Data: Identity, contact and correspondence details.
Basis: Steps before entering into a contract, or our legitimate interests in responding to enquiries and developing our business.

2. Client checks and monitoring

Data: Identity, contact and due diligence information.
Basis: Legal obligations, including anti-money laundering, sanctions and PEP screening requirements.

3. Statutory audits

Data: Engagement, identity and contact information.
Basis: Legal obligations under applicable audit and company law, and our legitimate interests in meeting professional standards.

4. Assurance, accounting and advisory services

Data: Engagement, identity and contact information.
Basis: Performance of our contract or our legitimate interests in delivering the engagement.

5. Regulatory and professional requirements

Data: Engagement, identity and contact information.
Basis: Legal obligations and our legitimate interests in complying with professional standards and regulatory requirements.

6. Billing, accounting and tax

Data: Identity, contact and financial information.
Basis: Contractual obligations, legal obligations and our legitimate interests in administering payments and records.

7. Managing our relationship with you

Data: Identity, contact and correspondence information.
Basis: Performance of our contract and our legitimate interests in managing our practice, complaints, disputes and legal claims.

8. Marketing and updates

Data: Identity, contact and marketing preferences.
Basis: Our legitimate interests in promoting our services, or your consent where required. You can opt out at any time.

9. Website operation and security

Data: Website and technical information.
Basis: Our legitimate interests in operating and securing the Site, and consent for non-essential cookies where required.

10. Recruitment

Data: Recruitment and application information.
Basis: Steps before entering into an employment contract, legal obligations and our legitimate interests in selecting candidates.

11. Crime prevention, security and insurance

Data: Relevant personal data described in this notice.
Basis: Legal obligations and our legitimate interests in protecting our business, systems and insurance arrangements.

3.2      Where we rely on legitimate interests, we have considered whether our interests are overridden by your interests, rights and freedoms and concluded that they are not, having regard to the safeguards described in this notice. You can ask us for information about our assessment using the contact details in section 1.

3.3      We do not use personal data to make decisions about you based solely on automated processing, and we do not carry out profiling that produces legal or similarly significant effects.

4. Special category and criminal offence data

4.1      Where we process special category data or criminal offence data in the course of an engagement or client due diligence, we do so under Article 9(2)(g) or Article 10 UK GDPR together with the conditions in Schedule 1 to the Data Protection Act 2018, in particular the conditions relating to statutory and regulatory requirements, the prevention or detection of unlawful acts, protecting the public against dishonesty, and the establishment, exercise or defence of legal claims. We maintain an appropriate policy document for this processing as required by the Act.

5. Our role when we audit

5.1      When we act as statutory auditor we perform an independent statutory function. Our audit working papers, including any personal data they contain, are held by us as an independent controller and not as a processor for the audited entity. We determine what information we need, how long we keep it and to whom we must disclose it under law and professional regulation. The audited entity remains the controller of its own records.

5.2      For accounting, bookkeeping and payroll-type services where the client instructs us what to do with the data, we may act as processor; where that applies, the engagement letter sets out the data-processing terms required by Article 28 UK GDPR.

6. Confidentiality

6.1      All information about clients and their affairs is treated as confidential in accordance with the ACCA Code of Ethics and Conduct and our contractual obligations, whether or not it is personal data. We disclose it only as described in this notice, as required by law or regulation, or with the client's consent.

7. Who we share personal data with

7.1      We may share personal data with:

–     Our regulators and professional bodies: ACCA (including its practice monitoring reviewers, who inspect audit files during compliance visits), the Financial Reporting Council, and, where relevant, the Financial Conduct Authority, the Prudential Regulation Authority and Companies House.

–     Law enforcement and government bodies: the National Crime Agency (suspicious activity reports), HM Revenue & Customs, courts and tribunals, where we are required to do so by law.

–     Engagement quality and file reviewers: independent engagement quality reviewers, external file reviewers and training providers engaged to meet ISQM (UK) 1 and ACCA requirements, all bound by confidentiality.

–     Other auditors and advisers: component or group auditors, predecessor or successor auditors (professional clearance), and the client's other professional advisers, banks and counterparties where necessary for the engagement or with the client's agreement.

–     Our service providers: providers of cloud hosting, email and document storage, audit and accounts software, practice management, e-signature, identity-verification and AML screening, IT support, website hosting and analytics, and professional advisers such as lawyers, insurers and our own accountants.

7.2      Our service providers act on our instructions under written contracts that require them to keep personal data secure and confidential and to use it only for the purposes we specify.

8. International transfers

8.1      We store and process personal data principally in the United Kingdom. Some of our service providers host data, or provide support from, countries outside the UK, including the European Economic Area and the United States. Where personal data is transferred outside the UK we rely on UK adequacy regulations (including for the EEA and, for certified organisations, the UK–US Data Bridge) or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed so that the protection afforded is not materially lower than under UK law. You can ask us for details of the safeguards in place.

9. How long we keep personal data

9.1      We keep personal data only for as long as we need it for the purposes set out above, including to meet legal, regulatory, professional and insurance requirements. Our standard retention periods are:

How long we keep your personal data

We keep personal data only for as long as necessary for legal, regulatory and business purposes.

1. Audit and engagement files

Retention: 6 years from the end of the relevant financial period, or longer where a claim, complaint or regulatory enquiry remains open.

2. Client due diligence and AML records

Retention: 5 years from the end of the business relationship or completion of the relevant transaction, unless we are required to keep them longer.

3. Engagement letters, contracts, invoices and accounting records

Retention: Generally 6 years from the end of the financial year in which the relationship ended. Contracts executed as deeds may be retained for up to 12 years.

4. Enquiries and business-contact information

Retention: Up to 2 years from our last contact with you, unless you ask us to delete it sooner and we have no legal reason to retain it.

5. Recruitment records

Retention: Unsuccessful candidate records are generally retained for 6 months after the recruitment process ends.

6. Website logs and analytics

Retention: Up to 12 months.

9.2      When personal data is no longer needed we securely delete or anonymise it. Where deletion from backups is not immediately possible, the data is put beyond use until the backup is overwritten.

10. Security

10.1    We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, including access controls, multi-factor authentication, encryption of devices and data in transit, secure client portals for exchanging documents, regular software updates and staff training. Access to personal data is limited to those who need it to carry out their role.

10.2    Email is not a secure medium. We will agree a secure method for exchanging confidential client documents at the start of an engagement. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the ICO and, where required, you, in accordance with the UK GDPR.

11. Cookies and the Site

11.1    The Site uses cookies and similar technologies. Strictly necessary cookies are set without consent because the Site cannot function without them. Cookies used solely to collect statistical information about use of the Site or to improve its functionality may be set on the basis permitted by the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Data (Use and Access) Act 2025, provided we give you clear information and a simple way to object; all other non-essential cookies are set only with your consent.

11.2 We use session and security cookies set by our hosting platform to support essential website functions, including page delivery, load balancing, security and form submissions. These cookies are strictly necessary for the Site to operate and are kept for the duration of your session, with some security-related records retained for up to 12 months.

11.3    You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may affect the operation of the Site. The Site may contain links to third-party websites, which have their own privacy notices; we are not responsible for them.

12. Your rights

12.1    Subject to the conditions and exemptions in the UK GDPR and the Data Protection Act 2018, you have the right to:

–     request access to the personal data we hold about you and information about how we use it (we may limit our search to what is reasonable and proportionate);

–     have inaccurate personal data corrected and incomplete data completed;

–     have your personal data erased in certain circumstances;

–     restrict our processing of your personal data in certain circumstances;

–     object to processing based on legitimate interests, and object at any time to direct marketing;

–     receive personal data you have provided to us in a portable format where processing is based on consent or contract and is automated; and

–     withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal.

12.2    Some of these rights are limited where we hold personal data to meet legal or professional obligations — for example, we cannot erase client due diligence records within the statutory retention period, and audit working papers must be retained under auditing standards. The exemption for personal data processed in the course of a statutory audit function may also apply. We will explain the basis for any refusal.

12.3    To exercise any right, contact us using the details in section 1. We will respond within one month of receiving your request, extended by up to two further months where a request is complex or numerous, and we may ask you to verify your identity. We do not charge a fee unless a request is manifestly unfounded or excessive.

13. Complaints

13.1    If you have a complaint about the way we handle your personal data, please tell us. You can complain by email to Oleksandr.Vertyporokh@audithelp.co.uk, by telephone on +44 20 7112 9389, or by post to the address in section 1. We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate it, and inform you of the outcome without undue delay.

13.2    You also have the right to lodge a complaint at any time with the Information Commissioner's Office, the UK supervisory authority for data protection: www.ico.org.uk, telephone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to deal with your concern first.

14. Changes to this notice

14.1    We review this notice at least annually and update it when our processing or the law changes. The current version is published on the Site with the date shown at the top. Significant changes affecting our clients will be notified through our usual channels