Data protection
Your data, and exactly where it sits.
We handle financial data that is sensitive by nature. This page explains where client data is stored, who can access it, and the controls we apply to every engagement.
Storage and processing
Where client data is stored and processed
Client data is stored and processed within the client's approved systems, which may include QuickBooks Online, Xero, Microsoft 365/SharePoint and secure cloud storage selected in the engagement letter. The applicable hosting location is governed by each provider and the client's account configuration.
Access is limited to the assigned accountant, the engagement manager and Usman Dad as engagement supervisor. No other personnel have access to client data.
Client data is never copied, reused or moved outside the agreed systems.
Controls
Security controls applied to every engagement
Encryption in transit and at rest
All data is encrypted in transit using TLS and at rest within the platforms used for each engagement.
Multi-factor authentication
MFA is enforced on every account used to access client data, without exception.
Role-based access
Access to client data is limited to the assigned accountant, the engagement manager and Usman Dad as engagement supervisor.
Managed devices
All team members access client systems from managed devices subject to security policy.
Background-checked staff
All staff are background-checked prior to engagement on client work.
Signed confidentiality undertakings
Every team member signs a confidentiality undertaking before accessing any client data.
Standard documentation
Data processing agreement and confidentiality undertaking
A data processing agreement and confidentiality undertaking are provided as standard with every engagement. These documents set out how data is handled, who may access it, and the obligations of both parties.
Subprocessors
Named subprocessors
The platforms used for each engagement are listed in the engagement letter. Typical subprocessors include the following. The published list is kept aligned with signed vendor agreements and the engagement letter for each client.
US clients — IRC §7216 consent
Where we support your CPA with tax return information, we provide the written consent form your CPA needs under IRC §7216 before any return information is disclosed to our team.
Questions about data security?
We are happy to discuss our security arrangements in more detail during your consultation.
