Privacy Policy
This Privacy Policy applies to KAS Accountants Limited ("we", "our" or "us"), a UK limited company, registered and regulated under the Association of Chartered Certified Accountants (ACCA).
The General Data Protection Regulation (GDPR) legislation came into effect on 25 May 2018 and requires UK and EU organisations to clearly state what they use your personal data for, and what your rights are when it comes to this data and how it is used.
These changes will replace the current Data Protection Act 1998 and provide more robust and up-to-date regulations for businesses to follow when handling client and customer data.
The following list of questions accompanied with their answers outline the topics covered in our Privacy Policy relating to GDPR.
- Our commitment to protecting your privacy and personal data
- How we collect personal data?
- Why do we collect personal data?
- What categories of personal data we collect?
- Why do we need personal data?
- Under GDPR what are the reasons we have for processing personal data?
- Do we share personal data with third parties?
- Do we transfer your personal data outside the European Economic Area (EEA)?
- What are your data protection rights under GDPR?
- Do you have the right to access your personal data?
- How do we ensure any personal data we hold is correct and accurate?
- Do you have additional data subject rights under GDPR?
- What measures have we taken to ensure the security of your personal data?
- How long do we retain personal data?
- Do you have a right to withdraw consent to processing personal data?
- How do you make a complaint or if you have a query about your personal data?
Our commitment to protecting your privacy and personal data
KAS Accountants Limited is committed to protecting your privacy and any personal data that we may receive and store on your behalf.
Our Privacy explains your rights under the new GDPR legislation effective from 25th May 2018 in relation to what information we collect Policy as a data controller, how we use this information and how we protect it.
How we collect personal data?
We obtain personal data directly from individuals in a variety of ways and this may include
- obtaining personal data directly from individuals via email, text or other social media platforms (internet search engines) from either yourself or other third parties (Companies House)
- meeting with a prospective or existing clients
- completing our online form on our website
- providing us with literature (business cards, business headed paper, etc.)
- attending meetings which we host for business, professional or other purposes
- performing our professional services through our Letters of Engagement and Letters of Terms and Conditions which you have agree to
- being provided with personal data from a third party by your consent
The above list is not fully exhaustive.
We obtain personal data directly from individuals in a variety of ways and this may include
- obtaining personal data indirectly from individuals via email, text or other social media platforms from either yourself or other third parties
- third party communications or websites
- ascertaining information from search engines on the internet
The above list is not fully exhaustive.
Why do we collect personal data?
We obtain personal data directly and indirectly about individuals with an aim to better serving our existing clients as well as prospective clients and other individuals, pursue our legitimate business interests and fulfil our legal and regulatory obligations.
Our services may also include processing personal data on the various software applications and packages which we may use from time to time, which may be governed by different privacy terms and policies of the software applications and packages providers.
Under our Letters of Engagement and Letters of Terms and Conditions, our clients may engage us to perform professional services which may also involve sharing personal data as part of that engagement. If this is the case then we will obtain specific authority and consent from our clients.
What categories of personal data we collect?
We may obtain personal data from individuals either directly or indirectly through various situations and events (some of which may be mentioned in this Privacy Policy).
The personal data we obtain is obtained specifically in order to carry out our professional services in relation to our Letters of Engagement and Letters of Terms and Conditions and on a legal and regulatory basis.
Below is a list of the personal data we collect from individuals.
- Name and trading name (if different), occupation and professional details
- Contact details (Postal address, work and personal email, fax, work and mobile telephone numbers)
- Professional details relating to their occupation and professional services they require in accordance to our Letters of Engagement and Letters of Terms and Conditions
- Financial information that we require from you which will allow us to act in capacity as your accountants
- Details of family if relevant and financial information (where relevant)
The above list is not fully exhaustive.
It is not our policy to obtain specific personal data which may be sensitive or does not bear any relevance in our carrying our professional services in relation to our Letters of Engagement and Letters of Terms and Conditions, unless an individual has given us specific consent to hold such personal data or there are legitimate grounds to do so.
Why do we need personal data?
We understand the importance explaining to you why we need your personal data and have provided brief examples of why we need your personal data.
- Carrying out our professional duties in accordance to our Letters of Engagement and Letters of Terms and Conditions
- Making sure that the personal data we hold on your behalf is accurate before we communicate with you via email, post or through other media platforms
- Promoting our professional services to existing and prospective business clients
- Ensuring that we are maintaining the correct information securely at all times
- Complying with legal and regulatory obligations relating to countering money laundering, fraud, terrorist financing, and any other forms of financial crime within or outside the EEA
The above list is not fully exhaustive.
Under GDPR what are the reasons we have for processing personal data?
We may rely on the following reasons under GDPR legislation and the law when we collect and use personal data to operate our business and provide our services: we may process personal data in order to perform and fulfil our contractual obligations under our Letters of Engagement and Letters of Terms and Conditions; we may rely on common interests which are legitimate in ensuring that we are delivering our services to you in a fair and timely manner which are relevant to our clienteles' specific needs, which will be beneficial to our clients and also meet the relevant legal and regulatory requirements and you have freely given consent in relation to any personal data you provided your personal data to us.
Do we share personal data with third parties?
We will only share personal data with third parties in order to help us to carry out our professional services in relation to the terms of our Letters of Engagement and Letters of Terms and Conditions, but only after we have received specific communications and instructions by you to do so.
Occasionally we may also share personal data with the following third parties who are contractually bound to safeguard the data we share with them:
- Professional advisers whose services we may use from time-to-time, including talent agents, lawyers, insurers and IFAs
- Parties that support us as we provide our services (e.g., IT system support, Payroll system support, archiving services and document production services)
- UK and overseas' Government and regulatory agencies (e.g., HMRC) or to other third parties as required by, and in accordance with, applicable law or regulation
- UK and overseas' Law enforcement agencies other third parties as required by, and in accordance with, applicable law or regulation
The above list is not fully exhaustive.
Do we transfer your personal data outside the European Economic Area (EEA)?
We store personal data in the UK (European Economic Area (EEA)).
In order to carry out our professional engagements (in conjunction with our Letters of Engagement and Letters of Terms and Conditions) we may transfer personal data to third party organisations within or outside the EEA, who required to keep your personal data secure in accordance with our contractual obligations and data protection legislation.
What are your data protection rights under GDPR?
Under GDPR legislation, individuals have certain rights over their personal data.
As we decide how and why personal data is to be processed, we are a data controller.
Data controllers are responsible for fulfilling these rights.
Do you have the right to access your personal data?
You have a right to access the personal data we hold on your behalf.
Please contact us at kasaccountancy@yahoo.com to make a request in order to access the personal data we hold on your behalf, and although we will respond to any request as soon as possible, currently the legally required time limit is 30 days.
In accordance with applicable law, we reserve the right to charge you when you exercise the right to access your personal data.
How do we ensure any personal data we hold is correct and accurate?
Although we will ensure that the personal data we hold is correct and accurate, if you are made aware to the contrary, please contact us at kasaccountancy@yahoo.com and we will endeavour to amend and make any corrections to your personal data once you have presented us with the information which you deem to be correct and accurate.
Do you have additional data subject rights under GDPR?
The purpose of this privacy statement is to provide information about why and what personal data we collect about you and how we use it.
Under GDPR legislation, individuals may have additional rights in relation to the personal data we hold, such as a right to deleting, restricting or objecting to our processing of personal data.
This section does not cover individual rights in full.
If you wish to exercise any of these rights, please send an email to kasaccountancy@yahoo.com.
What measures have we taken to ensure the security of your personal data?
We have put in place the relevant and appropriate technical and organisational security policies and procedures to protect personal data from loss, misuse, alteration or destruction and that your personal data is limited only to those who need to access it.
Those individuals and other third parties who have access to your personal data are required to maintain the confidentiality of such information under GDPR legislation.
How long do we retain personal data?
We retain personal data to provide our professional services, to comply with applicable laws, regulations and professional obligations (under the Association of Chartered Certified Accountants) that we are subject to.
We retain personal data in accordance with our contractual, legal and regulatory requirements, for a period of seven years.
We will dispose of personal data in a responsible and secure manner when we no longer have a need for it.
Do you have a right to withdraw consent to processing personal data?
Where we process personal data based on your consent, you have a right to withdraw your consent at any time.
In any event, we do not process personal data based on consent as we can usually rely on another legal, regulatory or statutory basis.
We do not send emails generated from a marketing or promotional list, however, if we do so in the future, then you will be given the option to unsubscribe in order to opt out from receiving such emails. As an alternative please contact us at kasaccountancy@yahoo.com.
How do you make a complaint or if you have a query about your personal data?
If you have any queries, concerns or wish to make a complaint about our use of personal data, please contact us at kasaccountancy@yahoo.com specifying the details of those queries, concerns or the nature of your complaint and we will examine any communications we receive from you and respond to you at the earliest possible time.
The UK data protection regulator is the ICO (Information Commissioner's Office) and you have a right to complain with the ICO. Please visit www.ico.org.uk for further information.
Last updated 24 May 2018.
+44 (0) 7967 635740
kasaccountancy@yahoo.com


Mr Kaleem A Saeed is a Fellow member of the Association of Chartered Certified Accountants.
