
Privacy policy.
GTP Tax Ltd – Privacy Policy
INTRODUCTION
We respect your privacy and are committed to protecting your Personal Data. This privacy policy will inform you as to how we look after your Personal Data when you visit our website (regardless of where you visit it from) and/or engage us to provide Services to you and explain your privacy rights.
This website is not intended for children and we do not knowingly collect data relating to children.
It is important that you read this privacy policy together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy policy supplements other notices and privacy policies and is not intended to override them.
DATA CONTROLLER
GTP Tax Ltd is the controller and responsible for your personal data (collectively referred to as "GTP Tax", "we", "us" or "our" in this privacy policy).
We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
FULL NAME OF DPO: HAYLEY POPE
EMAIL ADDRESS: HAYLEY@GTPTAX.CO.UK
POSTAL ADDRESS: ABBEY HOUSE, 282 FARNBOROUGH ROAD, FARNBOROUGH ROAD, HAMPSHIRE, GU14 7NA
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
THIRD-PARTY LINKS
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
TYPES OF DATA COLLECTED
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
• Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.
• Contact Data includes registered office address, home address, email address and telephone numbers.
• Financial Data includes bank account and payment card details.
• Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
• Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
• Profile Data includes your username and password, engagements made by you, your interests, preferences, feedback and survey responses.
• Usage Data includes information about how you use our website, products and services.
• Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
We may collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity for the purposes of satisfying our identification, compliance and ‘know you client’ checks when client onboarding. We do not collect any information about criminal convictions and offences. We shall carry out DPIA in respect of the processing of Special Categories of Personal Data.
IF YOU FAIL TO PROVIDE PERSONAL DATA
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide services to you). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
Users are responsible for any third-party Personal Data obtained, published or shared and confirm that they have the third party's consent to provide the Data to us.
DATA COLLECTION
We use different methods to collect data from and about you including through:
• Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
o apply for our products or services;
o subscribe to our service or publications;
o request marketing to be sent to you;
o enter a survey; or
o give us feedback or contact us.
• Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. Please see our cookie policy for further details.
• Third parties or publicly available sources. We will receive personal data about you from various third parties and public sources as set out below:
o Companies House;
o Professional clearance obtained from previous accountant(s).
• Technical Data from the following parties:
(a) Analytics providers such as Google Analytics (Google Ireland Limited), a web analysis service provided by Google Ireland Limited (“Google”). Google utilises the Data collected to track and examine the use of this Application, to prepare reports on it’s activities and share them with other Google services. Google may use the Data collected to contextualise and personalise the ads of it’s own advertising network.
1. Personal data processed: Cookies, Usage Data
2. Place of processing: Ireland;
(b) Platform servies and hosting providers. These services have the purpose of hosting and running our systems, therefore allowing the provision of services from within a unified platform. Such platforms provide a wide range of tools such as analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored. Platform service providers may include:
1. Squarespace (located in the USA and therefore outside the EEA)
2. Dropbox (located in the USA and therefore outside the EEA)
3. Sharepoint (located in the USA and therefore outside the EEA)
(c) Tag management service providers such as Google Tag Manager (Google Ireland Limited) located in Ireland and therefore outside the EEA. This type of service helps us to manage the tags or scripts needed on our systems in a centralised fashion. This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.
• Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the EEA.
MODE AND PLACE OF PROCESSING THE DATA
METHODS OF PROCESSING
We will take the appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In some cases, the Data may be accessible to certain types of persons within GTP Tax (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Data Controller. The updated list of these parties may be requested from us at any time.
LEGAL BASIS OF PROCESSING
We may process Personal Data relating to Users if one of the following applies:
• Users have given their consent for one or more specific purposes. Note: Under some legislations we may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law. In any event, the User has a right to withdraw at any time;
• provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
• processing is necessary for compliance with a legal obligation;
In any case, the we will explain the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract if required to do so.
PLACE OF PROCESSING
The Data is processed at our operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organisation governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
We share your personal data this will involve transferring your data outside the European Economic Area (EEA). Some of our external third parties are based outside the European Economic Area (EEA) so their processing of your personal data will involve a transfer of data outside the EEA.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
• We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries. Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
• Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between the Europe and the US. For further details, see European Commission: EU-US Privacy Shield.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
RETENTION TIME
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
• Personal Data collected for purposes related to the performance of a contract between GTP Tax and the User shall be retained until such contract has been fully performed; and
• Personal Data collected for the purposes of our legitimate interests shall be retained as long as needed to fulfill such purposes. You may find specific information regarding the legitimate interests within the relevant sections of this document or by contacting the DPO.
We may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority. We may also retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements. Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
DATA SECURITY
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
THE PURPOSES OF PROCESSING
The Data concerning the User is collected to allow us to provide services, comply with our legal obligations, respond to enforcement requests, protect our rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Analytics, Platform services and hosting and Tag Management.
We have set out below, in a table format, a description of all the ways we plan to use your personal data and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
When collecting Special Categories of Personal Data from Data Subjects, either directly from Data Subjects or indirectly (for example from a third party or publicly available source).
MARKETING
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
THIRD-PARTY MARKETING
We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
OPTING OUT
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a service or product purchase, service or product experience or other transactions.
THE RIGHTS OF USERS
Users may exercise certain rights regarding their Data processed by us.
In particular, Users have the right to do the following:
• Withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
• Object to processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
• Access their Data. Users have the right to learn if Data is being processed by us, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Data undergoing processing.
• Verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
• Restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, we will not process their Data for any purpose other than storing it.
• Have their Personal Data deleted or otherwise removed. Users have the right, under certain circumstances, to obtain the erasure of their Data.
• Receive their Data and have it transferred to another controller. Users have the right to receive their Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the Data is processed by automated means and that the processing is based on the User's consent, on a contract which the User is part of or on pre-contractual obligations thereof.
• Lodge a complaint. Users have the right to bring a claim before to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).
If you wish to exercise any of the rights set out above, please contact the DPO.
NO FEE USUALLY REQUIRED
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
WHAT WE MAY NEED FROM YOU
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
TIME LIMIT TO RESPOND
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
COOKIE POLICY
This Application uses Cookies and other Identifiers. To learn more, the User may consult the Cookie Policy.
ADDITIONAL INFORMATION ABOUT DATA COLLECTION AND PROCESSING
ADDITIONAL INFORMATION ABOUT USER'S PERSONAL DATA
In addition to the information contained in this privacy policy, this Application may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
SYSTEM LOGS AND MAINTENANCE
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) use other Personal Data (such as the IP Address) for this purpose.
INFORMATION NOT CONTAINED IN THIS POLICY
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
CHANGES TO THIS PRIVACY POLICY
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Should the changes affect processing activities performed on the basis of the User’s consent, the Owner shall collect new consent from the User, where required.
DEFINITIONS AND LEGAL REFERENCES
PERSONAL DATA (OR DATA)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
SPECIAL CATEGORIES OF PERSONAL DATA
Information revealing racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health conditions, sexual life, sexual orientation, biometric or genetic data.
USAGE DATA
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilised by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilised by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
USER
The individual providing the Personal Data or Special Categories of Personal Data to GTP Tax, unless otherwise specified, coincides with the Data Subject.
DATA SUBJECT
The natural person to whom the Personal Data refers.
DATA PROCESSOR
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.
DATA CONTROLLER
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.
DATA PRIVACY IMPACT ASSESSMENT (DPIA)
Tools and assessments used to identify and reduce risks of a data processing activity. A DPIA can be carried out as part of Privacy by Design and should be conducted for all major system or business change programmes involving the Processing of Personal Data.
SERVICE
The service provided by GTP Tax as described in the relative terms and conditions.
EEA
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
COOKIES
Small sets of data stored in the User's device.
LEGAL INFORMATION
This privacy statement has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy policy relates solely to this Application, if not stated otherwise within this document.