Privacy Policy
Last updated: 5 October, 2026
This policy explains how Mutu Accountancy Ltd collects, uses, shares and protects personal data. It covers people who visit our website, contact us, or become our clients, and the individuals connected with our clients. It also explains your rights and how to use them.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and the Data (Use and Access) Act 2025 (together, “Data Protection Legislation”).
If you are a client, this policy should be read with your engagement letter, schedules of services and terms and conditions. If anything here conflicts with your engagement letter, the engagement letter takes priority.
1. Who we are
Mutu Accountancy Ltd (“Mutu”, “we”, “us”, “our”) is a limited company registered in England & Wales (company number 09597916). Our registered office and trading address is 1.07 Newark Works, 2 Foundry Lane, Bath, BANES, BA2 3GZ. We are members of, and regulated by, the Institute of Chartered Accountants in England and Wales (ICAEW).
Controller or processor. For most of our accountancy and tax services, we are a data controller: we decide how and why your personal data is processed to deliver the agreed services. For some services, such as payroll, we act as a data processor. In that case our client is the controller and we process the data on their instructions.
Data protection contact. Emma D’Aubyn is responsible for data protection compliance. Contact her about anything to do with your personal data, including a subject access request:
- Email: [email protected]
- Post: 1.07 Newark Works, 2 Foundry Lane, Bath, BANES, BA2 3GZ
- Telephone 01225 582582
- Website www.mutu.uk
2. The personal data we collect
Personal data is any information about a living person who can be identified, directly or in combination with other information. Examples include a name, an identification number, location data or an online identifier.
Website visitors and enquirers. When you use our website or contact us, we may collect:
- your name, email address and phone number
- the content of your enquiry and our correspondence
- usage data such as your IP address, browser type and version, pages visited, time and date of visit, time spent on pages, device identifiers and other diagnostic data (see Cookies below)
Clients and connected individuals. To provide our services, we collect and process:
- names and addresses
- email addresses and telephone numbers
- identity and verification documents required for anti-money laundering checks
- information held by HMRC
- information needed to prepare tax returns, including details of trustees, personal representatives and beneficiaries where relevant
- information needed to prepare your accounts
- correspondence between us
We only collect what is necessary to provide the agreed services, meet our legal and regulatory obligations, contact you about other services (where you have consented), and protect ourselves against claims or disciplinary action.
If you do not give us the information we need, we may not be able to provide our services. In that case we may need to stop acting for you under the disengagement terms in our terms and conditions.
3. Where we get your personal data
We collect personal data from:
- you
- your spouse or partner
- HMRC
- your organisation
- electronic identity verification providers and databases used for anti-money laundering checks
- other third parties you have authorised, such as banks and investment managers
You authorise us to contact appropriate third parties for information we need to carry out our engagement.
4. How we use your data and our lawful basis
We follow the UK GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
| What we use it for | Lawful basis |
|---|---|
| Taking you on and keeping you as a client, including identity checks under anti-money laundering regulations | Legal obligation |
| Preparing and filing accounts and tax returns, advising on tax and National Insurance, and giving ad hoc advice | Contract |
| Corresponding with HMRC and third parties you ask us to deal with | Contract; legal obligation |
| Replying to website and email enquiries | Legitimate interests (and steps before entering a contract) |
| Running, securing and improving our website | Legitimate interests; consent for non-essential cookies |
| Telling you about other services we offer | Consent (you can withdraw it at any time) |
| Quality assurance reviews by ICAEW or another qualified reviewer | Legal obligation; legitimate interests |
| Keeping records so we can defend legal claims or disciplinary action | Legitimate interests; legal obligation |
We may also process personal data without your knowledge or consent where the law requires or permits it, in line with this policy.
Sometimes we anonymise or pseudonymise personal data so it can no longer be linked to you. We may then use it without further notice, for example to produce comparative data for clients.
No automated decisions. We do not make decisions about you using solely automated processing.
5. Software and artificial intelligence (AI)
We use software, AI tools and internal and external search engines to help deliver our services. These include, but are not limited to, Microsoft Copilot and Claude.
- We only use personal data in these tools where appropriate data protection safeguards are in place, including controls on how long data is retained.
- We do not use them in any way that would breach our duty of confidentiality to you, and we use them with the reasonable skill and care expected of professional accountants.
- With your consent, given in your engagement letter, we may input anonymised data into these tools, including for technological development, research and benchmarking.
- Where data is used in a commercial system, we review the provider’s privacy terms to make sure the risk is acceptable.
6. Who we share your data with
Everything you tell us is confidential under our professional code of ethics. We only disclose information with your authority or where the law or regulation requires it. We never sell personal data.
To provide our services, we may share personal data with:
- HMRC
- third parties you ask us to deal with, such as finance providers, pension providers (including auto-enrolment) and investment brokers
- subcontractors bound by the same professional, ethical and confidentiality obligations as our own staff, and who comply with UK GDPR
- an alternate appointed by us if our principal is incapacitated or dies (their name and address are available on request)
- tax insurance providers
- our professional indemnity insurers
- ICAEW or an external reviewer, for quality assurance
- IT, software and cloud service providers who host or process data on our behalf
We need to share this information to meet our contract with you, so you cannot opt out of it. If you ask us not to share it, we may have to stop acting for you.
Where the law allows or requires it, during or after our engagement, we may share information with the police and law enforcement agencies, courts and tribunals, and the Information Commissioner’s Office (ICO).
After we stop acting for you, we may also share information with:
- our professional indemnity insurers or legal advisers, to defend a claim
- our professional body, if a complaint is made against us
- your new advisers, or other third parties you ask us to share it with
Business transfers. If our business is sold or merged, personal data may transfer to the new owner. We will tell you before this happens.
7. Transfers outside the UK
Some of the software and cloud services we use, including AI tools such as Microsoft Copilot and Claude, may store or process personal data outside the UK, for example in the European Economic Area (EEA) or the United States. When this happens, we make sure the transfer is protected as UK GDPR requires. Either the destination is covered by UK adequacy regulations (such as the EEA, or US organisations certified under the UK Extension to the EU-US Data Privacy Framework), or appropriate safeguards are in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Contact us if you would like more information about these safeguards.Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.
8. Keeping your data secure
We have appropriate, proportionate security measures to stop personal data being lost, misused, altered or accessed without authorisation. Only people with a business need can access personal data, and they only process it on our instructions. All staff and subcontractors are bound by our confidentiality and security policies.
No internet transmission is ever completely secure. We have procedures to deal with any suspected data breach and will tell you and the ICO where we are legally required to. Our policies are reviewed regularly.
How we communicate. We communicate with you and agreed third parties by a secure method agreed with you. This may include post, password-protected or encrypted email, unencrypted email (without attachments), secure portals and cloud-based software. If you give us your email address, we take that as authority to email you until you tell us otherwise. Email carries some risk of non-receipt, delay, misdirection or interception. Please virus-check attachments and tell us promptly if your postal or email address changes.
9. How long we keep your data
We keep records in line with recognised good practice in the tax and accountancy sector, so we can meet legal requirements and defend claims within statutory time limits.
| Type of record | How long we keep it |
|---|---|
| Tax returns and accounts we have prepared | 7 years from the end of the tax year the information relates to |
| Ad hoc advisory work | 7 years from the date our business relationship ended |
| Permanent information needed for more than one year (e.g. capital gains base costs, claims and elections submitted to HMRC) | For the whole relationship, then deleted 7 years after it ends, unless you ask us to keep it longer |
| Anti-money laundering records (Regulation 40(5), Money Laundering Regulations 2017) | Length of the engagement plus 5 years |
| Website enquiries that do not lead to an engagement | 2 years from your last contact |
| Website usage data | A shorter period, unless needed for security, to improve the site, or by law |
When the engagement is complete we return documents that belong to you, unless we agree otherwise.
10. Your rights
To use any of these rights, write to Emma D’Aubyn using the contact details in section 1. We will respond without undue delay and within one month. For complex requests, or if we receive several, we may extend this by a further two months; if so, we will tell you why within the first month.
Right of access (subject access request). You can ask for a copy of the personal data we hold about you. To help us respond quickly, we may ask for proof of identity and address. Someone else, such as a relative or solicitor, can make the request for you if you give them written authority. We may refuse or limit a request where the law allows, for example where it repeats a recent request with little change, or where release would be likely to:
- prejudice the prevention or detection of crime
- prejudice the arrest or prosecution of offenders
- prejudice the assessment or collection of any tax or duty
- reveal the identity of, or information about, another person
If we refuse a request, we will explain why in writing.
Right to rectification. If information we hold is wrong, tell us straight away and we will correct it.
Right to erasure. In some circumstances you can ask us to delete your records. We will consider your request. We may refuse where we have a legal obligation to keep the data, such as the retention periods above, and will explain why.
Right to restrict processing and right to object. In some circumstances you can ask us to limit or stop processing your data. You can always object to direct marketing.
Right to withdraw consent. Where we rely on consent, such as for telling you about other services, you can withdraw it at any time, including after our engagement ends. This does not affect processing on other lawful bases, such as our contract or legal obligations.
Right to data portability. Where you gave us the data, we process it by automated means, and we rely on consent or contract, you can ask for it in a format that can be passed to another organisation.
The ICO website has more detail on all these rights.
11. Cookies
Cookies are small files placed on your device when you visit a website. We use essential cookies to make our website work. We only use non-essential cookies (such as analytics) with your consent, which you can give or withdraw through our cookie banner at any time.
| Cookie type | Session or persistent | Purpose |
|---|---|---|
| Necessary / essential | Session | Make the website and its features work, and help prevent fraud. The site cannot work properly without them. |
| Cookie consent | Persistent | Remember whether you have accepted or declined cookies. |
| Functionality | Persistent | Remember your choices, such as preferences, so you do not need to re-enter them. |
12. Children
Our website is not aimed at children, and we do not knowingly collect children’s personal data through it. Where our services involve a child’s information, for example as a beneficiary of a trust, we collect it from their parent, guardian, trustee or representative, and only as needed to provide the service. If you think a child has given us personal data through our website, please contact us and we will delete it.
13. Links to other websites
Our website may link to sites we do not run, such as HMRC, ICAEW and the ICO. We are not responsible for their content or privacy practices, so please read their privacy policies.
14. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and update the “Last updated” date at the top. Where changes significantly affect our clients, we will also tell them directly. Please check this page from time to time.
15. Complaints
If you have a question or concern about how we handle your personal data, please contact Emma D’Aubyn first (details in section 1). We will look into it carefully and promptly.
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Website: ico.org.uk
You can also raise concerns with our professional body, the Institute of Chartered Accountants in England and Wales (ICAEW).
16. Contact us
If you have any questions about this policy, please contact us:
- By email: [email protected]
- By phone: 01225 582582
- By post: Mutu Accountancy Ltd, 1.07 Newark Works, 2 Foundry Lane, Bath, BANES, BA2 3GZ