Privacy Policy

1. Who we are

We are MSF Associates. We are a firm of accountants based in Leeds. We help limited company directors with their accounts, tax and business finances.

This policy tells you what personal data we collect, why we collect it, and what we do with it. It also tells you your rights and how to use them.

We want this to be easy to read. If anything is not clear, just ask us.

Our details

  • Company name: MSF Associates Ltd
  • Registered in: England and Wales
  • Company number: 05905773
  • Address: Suite 21, Call House Business Centre, Leeds, LS7 1RF
  • Email: hello@msfassociates.co.uk
  • Phone: 0113 240 4100
  • ICO registration number: Z3452666
  • Professional body: We are regulated by the AAT (Association of Accounting Technicians)

Who this policy covers

This policy covers:

  • people who visit our website
  • people who contact us or book a call
  • our clients, and the directors, shareholders and staff of our client companies
  • people who sign up to our emails or follow us on social media
  • suppliers and people we work with

Our role

For most of what we do, we are the "data controller". This means we decide how and why your data is used. We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

When we run payroll for a client, we may process their staff's data on the client's behalf. In that case the client is the controller and we are the "processor".

2. What data we collect

We only collect what we need. What we collect depends on how you deal with us.

Type of data Examples
Identity Name, title, date of birth, photo ID (passport or driving licence)
Contact Email, phone number, home and business address
Tax and government National Insurance number, Unique Taxpayer Reference (UTR), Companies House details, HMRC records
Financial Bank statements, income, dividends, pensions, investments, property income, expenses
Business Company name, number, shareholders, directors, sales, costs, VAT and payroll records
Payroll (for our clients' staff) Employee names, addresses, pay, tax codes, pension details, NI numbers
Anti-money laundering checks ID documents, proof of address, source of funds, results of ID and credit checks
Billing Fees, payment history, direct debit or card details (held by our payment provider)
Communications Emails, WhatsApp messages, call notes, meeting recordings and notes
Website and technical IP address, browser type, device, pages you visit, how you found us
Marketing Your email preferences, what emails you open, how you engage with our posts

Special category data

Sometimes we may be told about things like your health. For example, if you need more time to file because you are unwell. We only record this when it is needed, and we treat it with extra care.

Data about other people

If you give us data about someone else, like a spouse, business partner or employee, please make sure they know. You should point them to this policy.

Children

Our services are for adults. We do not knowingly collect data from children, except where it is needed for tax work (for example, a child's name for childcare or trust records).

3. How we collect your data

From you directly. When you:

  • fill in a form on our website
  • book a call or meeting
  • email, phone or message us (including WhatsApp and social media)
  • become a client and send us your records
  • upload documents or receipts to our apps
  • sign up to our emails

From other places. We may also get data from:

  • HMRC and Companies House, when we act as your agent
  • your bank or accounting software, when you connect it to us
  • your previous accountant, when you move to us
  • ID check and anti-money laundering providers
  • public sources like the Companies House register
  • people who refer you to us

Automatically. When you use our website, cookies and similar tools collect some technical data. See section 9 for more on cookies.

Calls and meetings. Some of our calls and video meetings are recorded and turned into notes. We do this so we get your details right and do not miss anything. We will always tell you at the start. If you do not want to be recorded, just say and we will turn it off.

4. Why we use your data

The law says we must have a good reason, called a "lawful basis", for using your data. Here is what we use it for and why.

What we use it for Lawful basis
Doing your accounts, tax returns, VAT, payroll and company secretarial work Contract: we need it to do the work you asked for
Giving you quotes and proposals before you sign up Contract: steps before a contract
ID checks and anti-money laundering checks Legal obligation: the Money Laundering Regulations 2017
Reporting suspicious activity where the law requires it Legal obligation
Keeping records for HMRC and our regulator (AAT) Legal obligation
Sending you invoices and collecting fees Contract
Recording calls and meetings to make accurate notes Legitimate interests: getting your work right
Improving our services, training our team, and keeping quality high Legitimate interests
Running and protecting our website and systems Legitimate interests
Sending useful updates and news to clients Legitimate interests (you can opt out at any time)
Sending marketing emails to people who are not clients Consent
Using non-essential cookies Consent
Dealing with complaints and legal claims Legitimate interests and legal obligation

What "legitimate interests" means

This means we have a fair business reason to use your data, and it does not unfairly affect your rights. We always weigh this up first.

Using technology and AI tools

We use software and some AI tools to help us work faster. For example, to sort documents, draft emails or summarise meeting notes. A qualified member of our team always checks the work. We do not make decisions about you that have a legal or big effect on you using automated tools alone.

If you do not give us data

Some data we must have by law, or to do the work. If you do not give it to us, we may not be able to act for you.

5. Who we share your data with

We never sell your data. We only share it when we need to, and only with people who must keep it safe.

Government and regulators

  • HMRC, to file your tax returns and deal with your tax affairs
  • Companies House, to file accounts and company changes
  • The Pensions Regulator and pension providers, for payroll
  • AAT, our professional body, if they review our work
  • The National Crime Agency, if the law says we must report something

Software and service providers

We use trusted providers to run our firm. They only use your data to provide their service to us. The main types are:

Type of provider What they do
Accounting and bookkeeping software (e.g. Xero, Dext, QuickBooks, Apron and more) Store your books and receipts
Tax and payroll software Prepare and file tax returns and payroll
Practice and client management Manage proposals, engagement letters and client records
Payments and billing Collect fees and send invoices
Email, messaging and calls Talk with you
Marketing and social Send emails and reply to messages
Booking and meetings Book calls and make meeting notes
File storage and notes Store documents safely
Automation and AI tools Move data between our systems and help our team work faster
ID and anti-money laundering check providers Confirm who you are
Website hosting and analytics Run our website and show us how it is used

We have contracts with our providers. These say they must keep your data safe and only use it as we tell them.

Other people

  • Your bank, lender, mortgage broker or solicitor, but only if you ask us to
  • Your previous or next accountant, when you move
  • Our insurers and professional advisers, like lawyers
  • Anyone who buys or merges with our business, under the same rules as this policy
  • The police or courts, if the law requires it

6. Sending data outside the UK

Some of our software providers store data outside the UK. For example, in the European Union or the United States.

When this happens, we make sure your data is still protected. We do this by using one of these:

  • countries the UK Government says have good data protection laws (called "adequacy")
  • the UK-US Data Bridge, for US companies signed up to it
  • legal contracts approved by the UK Information Commissioner (the International Data Transfer Agreement or the UK Addendum)

You can ask us for more details about this at any time.

7. How long we keep your data

We only keep data for as long as we need it. After that we delete it safely.

Type of data How long we keep it
Client files, accounts and tax records 6 years after the end of the tax year or accounting period they relate to
Anti-money laundering and ID records 5 years after our work with you ends (as the law says)
Engagement letters and contracts 6 years after our work with you ends
Payroll records 6 years after the end of the tax year
Enquiries from people who did not become clients 2 years from last contact
Call and meeting recordings 12 months, then deleted. Notes made from them go in your client file
Marketing lists Until you unsubscribe, or 2 years with no contact
Website analytics Up to 26 months

Sometimes we keep data longer. For example, if there is an HMRC enquiry, a complaint or a legal claim. We will only keep it for as long as that takes.

8. How we keep your data safe

We take data security seriously. Here are some of the things we do:

  • only staff who need your data can see it
  • all staff are trained on data protection and sign confidentiality terms
  • we use strong passwords and two-step login on our systems
  • we use secure, encrypted software and cloud storage
  • we keep devices up to date and protected
  • we use secure portals to share files, not open email where we can avoid it
  • paper records are kept locked away and shredded when no longer needed

If something goes wrong

If there is a data breach that could put you at risk, we will tell you without delay. Where the law says so, we will also tell the Information Commissioner's Office (ICO) within 72 hours.

Please help us too

We will never ask you to send bank details or passwords in an unexpected email or message. If you get something that looks odd and seems to come from us, call us first on our usual number.

9. Cookies

Cookies are small files saved on your device when you visit a website. They help the site work and show us how people use it.

Type of cookie What it does Do we ask first?
Essential Makes the website work, like forms and security No, the site needs them
Analytics Shows us which pages people visit, so we can improve the site Yes
Marketing Helps us show relevant ads and measure if they work Yes
Third party (e.g. booking tools, embedded videos) Lets features from other providers work on our site Yes

When you first visit our website, a banner asks if you are happy with non-essential cookies. You can change your mind at any time using the cookie settings link at the bottom of our website.

You can also block or delete cookies in your browser settings. Some parts of the site may not work properly if you do.

10. Marketing

We may send you emails or messages with tax tips, deadline reminders, news and offers.

  • If you are a client, we may send you updates about similar services. You can opt out at any time.
  • If you are not a client, we will only send you marketing if you have said yes.

Every marketing email has an "unsubscribe" link. You can also just reply and tell us to stop. We will not pass your details to other companies for their marketing.

Social media

If you follow us, comment or message us on Instagram, LinkedIn, Facebook or other sites, those sites also use your data. Their own privacy policies explain how.

Opting out of marketing does not stop us sending you important messages about your work, like tax deadlines or documents we need.

11. Your rights

You have rights over your data. It is free to use them in most cases.

Your right What it means
Right to be informed To know how we use your data. This policy does that.
Right of access To ask for a copy of the data we hold about you
Right to correct To ask us to fix data that is wrong or incomplete
Right to delete To ask us to delete your data, where we do not need to keep it by law
Right to restrict To ask us to pause using your data while an issue is sorted
Right to object To object to us using your data for legitimate interests or marketing
Right to move your data To ask for your data in a common format, to give to someone else
Rights about automated decisions Not to be subject to decisions made only by computers that seriously affect you
Right to withdraw consent Where you gave consent, you can take it back at any time

How to use your rights

Email us at hello@msfassociates.co.uk or write to our office address. Tell us what you would like us to do.

We may ask you to prove who you are first. This keeps your data safe.

We will reply within one month. If your request is complex, it may take up to two more months. We will let you know if so.

When we might say no

Sometimes the law says we must keep data, even if you ask us to delete it. For example, tax and anti-money laundering records. If we cannot do what you ask, we will explain why.

12. Complaints, changes and contact

If you are not happy

Please talk to us first. We would like the chance to put things right. Email hello@msfassociates.co.uk or call 0113 240 4100.

If you are still not happy, you can complain to the Information Commissioner's Office (ICO). They are the UK regulator for data protection.

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Changes to this policy

We may update this policy from time to time. The latest version will always be on our website. If we make a big change, we will tell our clients.

Other websites

Our website may link to other websites. We are not responsible for how they use your data. Please read their privacy policies.

Contact us

If you have any questions about this policy or your data, get in touch:

Last updated: 30 September 2026