The Purpose of this notice
The intention of this notice is to outline our procedures for gathering and utilising your personal information, in compliance with the UK General Data Protection Regulation (UK GDPR) modified by the Data Protection Act 2018, which may be revised periodically.
We kindly request that you carefully review the following information to comprehend our approach to handling your personal data and our commitment to its proper handling.
About us
Empirical Tax Ltd, Company number 14974552 (hereafter the Company) is a consultancy business providing tax consultancy services.
The Company is registered at 41 Burgh Wood Way, Chorley, Lancashire, PR7 2FF
In accordance with the UK GDPR and the content of this notification, we assume the role of the 'data controller.' This signifies that we bear the responsibility of determining the methods by which we store and utilize your personal data. It is mandatory for us to inform you, in compliance with the UK GDPR, about the details provided within this privacy notice.
How your data could be collected
We collect personal data about you through various means, including but not limited to the following scenarios: when you request a proposal for our services, when you or your employer or our clients engage us to provide services and throughout the provision of those services, when you contact us via in-person interactions, email, telephone, post, or social media (for example, when you have inquiries about our services), and when we receive information from third parties such as introducers or publicly available resources (such as your employer, Companies House, the Electoral Register, Experian, or your business website). The personal data we may gather includes, but is not limited to, your name, home address, email address, date of birth, telephone numbers, and email addresses.
Details of Associated individuals
In order to effectively provide our services to you, there may be instances where we need to collect personal information about your immediate family members. It is your responsibility to ensure that you have obtained the necessary consent from the individuals involved to share their information with us. We will provide a copy of this privacy notice to them, or if appropriate, request you to share the privacy information with them.
The type of information we retain about you
The information we hold about you may encompass the following:
Your personal particulars, which may include, but are not limited to, names, addresses, gender, date of birth, nationality, telephone and mobile numbers, email addresses, familial connections, lifestyle and social circumstances, passport details, national insurance and tax codes, identification numbers, employment details, income and financial particulars, bank account information, investment details, pension and insurance information, as well as any documentation related to the aforementioned categories and notes from meetings.
The Company shall retain details of any contact in relation to the provision, or the proposed provision, of our services and details of any services you have received from the company. The Company will hold data relating to interactions and communications with you such as details regarding any complaints or inquiries made, information obtained through research, surveys, and marketing initiatives and information received from external sources, including publicly available information and information provided by your employer.
The Company may process your personal data and, when necessary, share it with third parties to fulfill our legal obligations. We may process your personal data for the performance of our contractual obligations with you, your employer, or our clients. This includes processing personal data when you are an employee, director, subcontractor, shareholder, partner, LLP member, supplier, or customer of our client.
In line with our legitimate interests, provided they do not override your own interests, rights, and freedoms that require personal data protection, we may process your personal data for marketing, business development, statistical, and management purposes.
For certain additional purposes, we may process your personal data with your consent. If your consent is required for specific processing purposes, you have the right to withdraw your consent.
Please note that we may rely on more than one lawful basis to process your personal data, depending on the specific purpose for which we use it.
Instances in which we will utilize your personal data:
Please be aware that if you refuse to provide certain requested information, we may not be able to fulfill the contract we have with you, or we may be unable to comply with our legal or regulatory obligations.
We may also process your personal data without your knowledge or consent in accordance with this notice, when legally required or permitted to do so.
Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. When determining the appropriate retention period, we consider:
Change of Purpose
If we need to use your personal data for a purpose other than the one for which it was initially collected, we will only do so if that reason is compatible with the original purpose. If it becomes necessary to process your personal data for a new purpose not mentioned in the sections above, we will inform you and communicate the legal basis that allows us to do so before commencing any new processing.
Data Sharing
Why would your personal data be shared with third parties?
The Company may share your personal data with third parties in the following circumstances: when required by law, to administer our relationship with you, with your consent, or when there is another legitimate interest to do so.
Which third-party service providers process my personal data?
Third parties encompass third-party service providers and information providers. The following activities are carried out by third-party service providers: IT and cloud services, Anti Money Laundering verification services, professional advisory services, administration services, marketing services, customer relationship management (CRM) and portal services, financial services, banking services, and training services.
All third-party service providers we engage are required to implement commercially reasonable and appropriate security measures to safeguard your personal data. We only permit them to process your personal data for specific purposes and in accordance with our instructions.
Data Security
We have implemented commercially reasonable and appropriate security measures to prevent accidental loss, unauthorized access, use, alteration, or disclosure of your personal data. Additionally, we restrict access to your personal data to employees, agents, contractors, and other third parties who have a legitimate business need to know. They will only process your personal data based on our instructions and are bound by confidentiality obligations.
We have established procedures to address any suspected data security breaches. If legally required, we will notify you and the relevant regulatory authorities of any suspected breaches.
Rights of Access, Correction, Erasure, and Restriction
It is your responsibility to inform us of any changes to your data. We strive to ensure that the personal data we hold about you is accurate and up to date. If there are any changes, please notify us by contacting us using the provided contact details.
You have the right, under certain circumstances, to request access to your personal data, allowing you to receive details of the personal data we hold about you and verify its lawful processing.
You may request the correction or erasure of your personal data. This enables you to request the deletion or removal of personal data when there is no valid reason for us to continue processing it. You also have the right to request the deletion or removal of your personal data when you have exercised your right to object to the processing (see below).
You can object to the processing of your personal data when we rely on a legitimate interest (or that of a third party), and there is something specific about your situation that leads you to object to processing based on this ground. You also have the right to object when we process your personal information for direct marketing purposes.
To exercise any of the aforementioned rights, please email our Risk & Compliance Manager. There is no fee required to access your personal data or to exercise your rights. However, if your request is clearly unfounded or excessive, we may charge a reasonable fee or refuse to comply with the request in such circumstances.
Right to Withdraw Consent
In limited circumstances where you have provided your consent for the collection, processing, and transfer of your personal data for a specific purpose (e.g., receiving direct marketing communications from us), you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please email our Compliance Officer.
Once we receive notification that you have withdrawn your consent, we will no longer process your personal information or personal data for the purpose(s) you originally agreed to, unless we have another legitimate basis for doing so under the law.
Changes to this Notice
Any future changes to our privacy notice will be made available on our website. You can request a copy by emailing our Compliance Officer. The last update to this privacy notice was on 1st August 2023.
Contact Us
If you have any questions regarding this notice or if you would like to discuss how we process your personal data, please contact: info@empiricaltax.co.uk