Privacy Policy
Introduction
Apex Bookkeeping Ltd ("we," "our," or "us") is committed to protecting and respecting your privacy. We are registered with the Information Commissioner’s Office (ICO) under registration number ZB695692. This policy explains how we collect, use, and disclose your personal data through our website www.apexbooks.uk and our professional services.
The Data We Collect We process the following categories of data:
-
Identity and Contact Data: Name, business address, email, and telephone numbers.
-
Compliance Data: Information required for Anti-Money Laundering (AML) checks, including government-issued identification and, where legally required, biometric verification data processed via our AML provider (Xama).
-
Financial and Transaction Data: Bank account details, VAT records, and payroll data.
-
Special Category Data: We may process Special Category Data (such as trade union membership or health data) only where strictly necessary for payroll processing and where appropriate safeguards and lawful conditions under UK GDPR are in place.
Roles: Controller vs. Processor
-
Data Controller: We act as a Controller for data used to manage our relationship with you and for our own regulatory compliance (e.g., AML records).
-
Data Processor: When providing bookkeeping, VAT, and payroll services, we act as a Data Processor on your behalf. Our obligations in this role are governed by the Data Processing Agreement (DPA) within your Engagement Documents.
Legal Basis for Processing We process data under the following legal bases:
-
Contractual Necessity: To perform the services in your Engagement Documents.
-
Legal Obligation: To comply with the Money Laundering Regulations 2017 and HMRC reporting requirements.
-
Legitimate Interests: For the effective management and security of our business.
Data Security & Remote Workflow
-
Portal-First Policy: For the protection of financial data, all records must be exchanged via our secure portal (Engager). We will not accept books or records via email or unencrypted methods.
-
Encryption: All data is stored in secure, cloud environments with multi-factor authentication (MFA).
Location of Processing Your data is primarily processed within the UK and EEA. Where third-party tools use servers outside the UK/EEA, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms are in place.
Disclosures of Your Data We may share your data with:
-
HMRC: As your authorized agent.
-
Regulators: The Institute of Certified Bookkeepers (ICB) for practice monitoring.
-
Service Providers: Essential software providers (e.g., Xero, QBO, Engager, Xama).
Data Retention
-
Statutory Records: We retain data relevant to your tax and compliance obligations for seven years.
-
AML Data: Identity verification records are kept for five years after the end of the business relationship.
Your Legal Rights Under UK GDPR, you have the right to access, correct, erase, restrict, or object to the processing of your personal data. You also have the right to data portability, to withdraw consent where processing is based on consent, and to lodge a complaint with the Information Commissioner’s Office (ICO).
Contact Details To exercise your rights or ask questions about this policy, please contact us at: info@apexbooks.uk


