This privacy notice outlines how Allazo Ltd gathers and uses personal information in compliance with the General Data Protection Regulation (GDPR). This notice provides you with the necessary information regarding your rights and obligations and explains how, why and when we collect and process your personal data.
Who we are
Allazo Ltd is a company registered in England and Wales under number 07938971, registered address 2 Claridge Court, Lower Kings Road, Berkhamsted, HP4 2AF. We are registered on the Information Commissioner's Office Register of Data Controllers under registration number ZA187049, and act as the data controller. Our designated Data Protection Officer for the organisation is Jon Pugsley, who can be contacted at the registered address.
Information that we collect
|Personal details||Including name, address, date of birth, telephone numbers, email addresses, marital status, bank account details and more.|
|Sensitive details||Including items required by law to satisfy Money Laundering requirements such as photo ID and proof of address.|
|Accounting records||Supporting documentation required to enable us to perform our duties such as bank statements, invoices and other records.|
|Payroll records||Including PAYE references and details of salary, hourly pay, tax code notices and pension details|
|Tax information||Including National insurance numbers, unique tax references, VAT numbers, government gateway credentials and other tax details.|
|Corporate entities||Companies House records and webfiling authentication codes.|
Information is collected direct from our clients, from HMRC, from publicly available sources such as Companies House and from previous accountants.
How we use your personal data
Allazo Ltd takes your privacy very seriously and will never disclose, share or sell your data without your consent, unless required to do so by law.
We only retain your data for as long as is necessary and for the purposes specified in this notice. Allazo Ltd does not undertake general direct marketing to our clients. However, we will send relevant business related information to you from time to time. These may include, changes to legislation, tax rates and allowances, deadline reminders or other notices we feel are specifically relevant to you. You are free to withdraw consent at any time.
The purposes and reasons for processing your personal data are to fulfill our responsibilities to you as per the terms of our Letter of Engagement. Your personal data is crucial for us to be able to carry out the services you instruct us to on your behalf.
You have the right to access any personal information that Allazo Ltd processes about you and to request information about: -
- What personal data we hold about you
- The purposes of the processing
- The categories of personal data concerned
- The recipients to whom the personal data has/will be disclosed
- How long we intend to store your personal data for
- If we did not collect the data directly form you, information about the source
If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to update/correct it as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
You also have the right to request erasure of your personal data or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us and to be informed about any automated decision-making that we use.
If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the relevant request; this is to ensure that your data is protected and kept secure.
Sharing and Disclosing Your Personal Information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement.
Allazo Ltd uses third parties to provide solutions which enable us to adhere to our terms of engagement. Such third parties include software providers, sub-contractors and support. Allazo Ltd takes steps to ensure that all third parties have privacy policies and controls which comply with GDPR and beyond. Allazo Ltd replies upon cloud services all of which have provided assurances in their contract to Allazo Ltd of their GDPR compliance.
With your express permission your personal data may be transferred to appropriate third parties as follows:
- HMRC for the purpose of complying with statutory requirements, e.g. filing tax returns, VAT returns, CIS returns and real-time reporting
- Companies House for the purpose of statutory company reporting
- Your payroll pension provider
- To and from any of your cloud based systems such as accounting and invoicing platforms
- Mortgage companies and landlord reference check agencies but only with your consent
- Any other accountancy practice but only with your written consent
Allazo Ltd will never sell, rent or share your data with a third party unless there it is necessary in order to provide the services agreed in our Letter of Engagement and never for the sole purpose of benefitting Allazo Ltd.
Allazo Ltd takes your privacy seriously and we take every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: -
- Computers are password protected for each user with automatic log offs if unattended.
- All of the software we use is password protected with access only granted to authorized individuals. Additionally, we utilise two-step verification to add another layer of security.
- Physical records are not kept by Allazo Ltd as we operate a paperless office.
- Original documents held are returned to clients at the earliest convenience, where records are temporarily held these are kept securely in our office.
- Working papers and print outs are always shredded.
- Electronic transfers of information are encrypted with a password.
- Backups of electronic information are held securely in a remote location.
How long we keep your data
We will typically hold your personal information for 7 years after the closure of your account in line with regulatory data retention requirements. Data may be retained longer than 7 years if required for legal purposes, for an on-going litigation (litigation hold), or where explicitly requested by you.
Allazo Ltd do not collect or process any personal data from the website. We do not monitor IP addresses from your computer, nor do we perform any form of analysis on visits. The website does include some cookies but these are solely for the basic operation of the site. No monitoring, tracking or data collection is performed by the cookies.
Allazo Ltd do use some social networking sites. However, no personal information that is ‘volunteered’ by visitors, by liking and sharing content, is collected, used or analysed by Allazo Ltd.
Where do we store client data
Allazo Ltd uses cloud based storage located within the European Union (EU) and outside of the EU. We take steps to ensure that appropriate measures and controls are in place to protect any data that is transferred outside of the EU in accordance with applicable data protection laws and regulations.
Allazo Ltd only uses reputable third parties who offer services which adhere to GDPR.
Changes to this policy