Privacy Policy

Last updated: 5 October, 2026

This policy explains how Mutu Accountancy Ltd collects, uses, shares and protects personal data. It covers people who visit our website, contact us, or become our clients, and the individuals connected with our clients. It also explains your rights and how to use them.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and the Data (Use and Access) Act 2025 (together, “Data Protection Legislation”).

If you are a client, this policy should be read with your engagement letter, schedules of services and terms and conditions. If anything here conflicts with your engagement letter, the engagement letter takes priority.

1. Who we are

Mutu Accountancy Ltd (“Mutu”, “we”, “us”, “our”) is a limited company registered in England & Wales (company number 09597916). Our registered office and trading address is 1.07 Newark Works, 2 Foundry Lane, Bath, BANES, BA2 3GZ. We are members of, and regulated by, the Institute of Chartered Accountants in England and Wales (ICAEW).

Controller or processor. For most of our accountancy and tax services, we are a data controller: we decide how and why your personal data is processed to deliver the agreed services. For some services, such as payroll, we act as a data processor. In that case our client is the controller and we process the data on their instructions.

Data protection contact. Emma D’Aubyn is responsible for data protection compliance. Contact her about anything to do with your personal data, including a subject access request:

2. The personal data we collect

Personal data is any information about a living person who can be identified, directly or in combination with other information. Examples include a name, an identification number, location data or an online identifier.

Website visitors and enquirers. When you use our website or contact us, we may collect:

Clients and connected individuals. To provide our services, we collect and process:

We only collect what is necessary to provide the agreed services, meet our legal and regulatory obligations, contact you about other services (where you have consented), and protect ourselves against claims or disciplinary action.

If you do not give us the information we need, we may not be able to provide our services. In that case we may need to stop acting for you under the disengagement terms in our terms and conditions.

3. Where we get your personal data

We collect personal data from:

You authorise us to contact appropriate third parties for information we need to carry out our engagement.

4. How we use your data and our lawful basis

We follow the UK GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

What we use it forLawful basis
Taking you on and keeping you as a client, including identity checks under anti-money laundering regulationsLegal obligation
Preparing and filing accounts and tax returns, advising on tax and National Insurance, and giving ad hoc adviceContract
Corresponding with HMRC and third parties you ask us to deal withContract; legal obligation
Replying to website and email enquiriesLegitimate interests (and steps before entering a contract)
Running, securing and improving our websiteLegitimate interests; consent for non-essential cookies
Telling you about other services we offerConsent (you can withdraw it at any time)
Quality assurance reviews by ICAEW or another qualified reviewerLegal obligation; legitimate interests
Keeping records so we can defend legal claims or disciplinary actionLegitimate interests; legal obligation

We may also process personal data without your knowledge or consent where the law requires or permits it, in line with this policy.

Sometimes we anonymise or pseudonymise personal data so it can no longer be linked to you. We may then use it without further notice, for example to produce comparative data for clients.

No automated decisions. We do not make decisions about you using solely automated processing.

5. Software and artificial intelligence (AI)

We use software, AI tools and internal and external search engines to help deliver our services. These include, but are not limited to, Microsoft Copilot and Claude.

6. Who we share your data with

Everything you tell us is confidential under our professional code of ethics. We only disclose information with your authority or where the law or regulation requires it. We never sell personal data.

To provide our services, we may share personal data with:

We need to share this information to meet our contract with you, so you cannot opt out of it. If you ask us not to share it, we may have to stop acting for you.

Where the law allows or requires it, during or after our engagement, we may share information with the police and law enforcement agencies, courts and tribunals, and the Information Commissioner’s Office (ICO).

After we stop acting for you, we may also share information with:

Business transfers. If our business is sold or merged, personal data may transfer to the new owner. We will tell you before this happens.

7. Transfers outside the UK

Some of the software and cloud services we use, including AI tools such as Microsoft Copilot and Claude, may store or process personal data outside the UK, for example in the European Economic Area (EEA) or the United States. When this happens, we make sure the transfer is protected as UK GDPR requires. Either the destination is covered by UK adequacy regulations (such as the EEA, or US organisations certified under the UK Extension to the EU-US Data Privacy Framework), or appropriate safeguards are in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Contact us if you would like more information about these safeguards.Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.

8. Keeping your data secure

We have appropriate, proportionate security measures to stop personal data being lost, misused, altered or accessed without authorisation. Only people with a business need can access personal data, and they only process it on our instructions. All staff and subcontractors are bound by our confidentiality and security policies.

No internet transmission is ever completely secure. We have procedures to deal with any suspected data breach and will tell you and the ICO where we are legally required to. Our policies are reviewed regularly.

How we communicate. We communicate with you and agreed third parties by a secure method agreed with you. This may include post, password-protected or encrypted email, unencrypted email (without attachments), secure portals and cloud-based software. If you give us your email address, we take that as authority to email you until you tell us otherwise. Email carries some risk of non-receipt, delay, misdirection or interception. Please virus-check attachments and tell us promptly if your postal or email address changes.

9. How long we keep your data

We keep records in line with recognised good practice in the tax and accountancy sector, so we can meet legal requirements and defend claims within statutory time limits.

Type of recordHow long we keep it
Tax returns and accounts we have prepared7 years from the end of the tax year the information relates to
Ad hoc advisory work7 years from the date our business relationship ended
Permanent information needed for more than one year (e.g. capital gains base costs, claims and elections submitted to HMRC)For the whole relationship, then deleted 7 years after it ends, unless you ask us to keep it longer
Anti-money laundering records (Regulation 40(5), Money Laundering Regulations 2017)Length of the engagement plus 5 years
Website enquiries that do not lead to an engagement2 years from your last contact
Website usage dataA shorter period, unless needed for security, to improve the site, or by law

When the engagement is complete we return documents that belong to you, unless we agree otherwise.

10. Your rights

To use any of these rights, write to Emma D’Aubyn using the contact details in section 1. We will respond without undue delay and within one month. For complex requests, or if we receive several, we may extend this by a further two months; if so, we will tell you why within the first month.

Right of access (subject access request). You can ask for a copy of the personal data we hold about you. To help us respond quickly, we may ask for proof of identity and address. Someone else, such as a relative or solicitor, can make the request for you if you give them written authority. We may refuse or limit a request where the law allows, for example where it repeats a recent request with little change, or where release would be likely to:

If we refuse a request, we will explain why in writing.

Right to rectification. If information we hold is wrong, tell us straight away and we will correct it.

Right to erasure. In some circumstances you can ask us to delete your records. We will consider your request. We may refuse where we have a legal obligation to keep the data, such as the retention periods above, and will explain why.

Right to restrict processing and right to object. In some circumstances you can ask us to limit or stop processing your data. You can always object to direct marketing.

Right to withdraw consent. Where we rely on consent, such as for telling you about other services, you can withdraw it at any time, including after our engagement ends. This does not affect processing on other lawful bases, such as our contract or legal obligations.

Right to data portability. Where you gave us the data, we process it by automated means, and we rely on consent or contract, you can ask for it in a format that can be passed to another organisation.

The ICO website has more detail on all these rights.

11. Cookies

Cookies are small files placed on your device when you visit a website. We use essential cookies to make our website work. We only use non-essential cookies (such as analytics) with your consent, which you can give or withdraw through our cookie banner at any time.

Cookie typeSession or persistentPurpose
Necessary / essentialSessionMake the website and its features work, and help prevent fraud. The site cannot work properly without them.
Cookie consentPersistentRemember whether you have accepted or declined cookies.
FunctionalityPersistentRemember your choices, such as preferences, so you do not need to re-enter them.

12. Children

Our website is not aimed at children, and we do not knowingly collect children’s personal data through it. Where our services involve a child’s information, for example as a beneficiary of a trust, we collect it from their parent, guardian, trustee or representative, and only as needed to provide the service. If you think a child has given us personal data through our website, please contact us and we will delete it.

13. Links to other websites

Our website may link to sites we do not run, such as HMRC, ICAEW and the ICO. We are not responsible for their content or privacy practices, so please read their privacy policies.

14. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the “Last updated” date at the top. Where changes significantly affect our clients, we will also tell them directly. Please check this page from time to time.

15. Complaints

If you have a question or concern about how we handle your personal data, please contact Emma D’Aubyn first (details in section 1). We will look into it carefully and promptly.

You can also raise concerns with our professional body, the Institute of Chartered Accountants in England and Wales (ICAEW).

16. Contact us

If you have any questions about this policy, please contact us: