Data protection

Your data, and exactly where it sits.

We handle financial data that is sensitive by nature. This page explains where client data is stored, who can access it, and the controls we apply to every engagement.

Storage and processing

Where client data is stored and processed

Client data is stored and processed within the client's approved systems, which may include QuickBooks Online, Xero, Microsoft 365/SharePoint and secure cloud storage selected in the engagement letter. The applicable hosting location is governed by each provider and the client's account configuration.

Access is limited to the assigned accountant, the engagement manager and Usman Dad as engagement supervisor. No other personnel have access to client data.

Client data is never copied, reused or moved outside the agreed systems.

Controls

Security controls applied to every engagement

Encryption in transit and at rest

All data is encrypted in transit using TLS and at rest within the platforms used for each engagement.

Multi-factor authentication

MFA is enforced on every account used to access client data, without exception.

Role-based access

Access to client data is limited to the assigned accountant, the engagement manager and Usman Dad as engagement supervisor.

Managed devices

All team members access client systems from managed devices subject to security policy.

Background-checked staff

All staff are background-checked prior to engagement on client work.

Signed confidentiality undertakings

Every team member signs a confidentiality undertaking before accessing any client data.

Standard documentation

Data processing agreement and confidentiality undertaking

A data processing agreement and confidentiality undertaking are provided as standard with every engagement. These documents set out how data is handled, who may access it, and the obligations of both parties.

Data processing agreement provided as standard with every engagement
Confidentiality undertaking signed by all personnel with access to client data
Named subprocessors listed in the engagement letter and aligned with signed vendor agreements

Subprocessors

Named subprocessors

The platforms used for each engagement are listed in the engagement letter. Typical subprocessors include the following. The published list is kept aligned with signed vendor agreements and the engagement letter for each client.

Intuit QuickBooks Online
Xero
Microsoft 365 / SharePoint
Google Workspace

US clients — IRC §7216 consent

Where we support your CPA with tax return information, we provide the written consent form your CPA needs under IRC §7216 before any return information is disclosed to our team.

Questions about data security?

We are happy to discuss our security arrangements in more detail during your consultation.