1. About this policy
This policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over your information. We've tried to write it in plain English. If anything's unclear, please get in touch.
We're committed to protecting your data and being transparent about what we do with it. This policy is written to meet our obligations under the UK GDPR and the Data Protection Act 2018.
2. Who we are
The data controller is No Worries Company Services Ltd, a company registered in England and Wales under company number 05505951, with its registered office at Suite 7, Apple Market Hub, 9 Crown Passage, Kingston upon Thames, KT1 1JD.
We trade as No Worries Accounting and are a registered Authorised Corporate Service Provider (ACSP) with Companies House, reference number AP002533. We are FCSA accredited for our umbrella-company service.
We are not a licensed practice of the AAT or ACCA. Where individual team members are personal members of those bodies, their personal conduct is subject to the relevant body's rules, but the practice itself is not regulated by them.
3. Personal data we collect
Information you give us when you become a client or prospective client:
- Your name, email address, phone number, postal address, date of birth, nationality and National Insurance number
- Government-issued photographic identification (e.g. passport, driving licence) and proof of address, required for ACSP identity verification under the Economic Crime and Corporate Transparency Act 2023
- Tax reference numbers, UTRs, PAYE references and similar statutory identifiers
- Bank account details, card details (where relevant for direct debits or invoicing), income and expenditure records
- Information about your business, including directors, shareholders, payroll, contracts, VAT returns and company accounts
- Any correspondence you have with us
Information we collect automatically when you use our website:
- Your IP address, device and browser information, and the pages you visit
- Form submission metadata (e.g. timestamp, user-agent, referrer) for security and audit purposes
- Information set or read by cookies — see Section 8
Information we receive from third parties:
- Identity verification results from ACSP checks
- Data from HMRC, Companies House and similar statutory bodies in the course of representing you
- Payment confirmation data from Stripe where you pay us online
4. How we use your data
We only process your personal data where we have a lawful basis to do so. The table below summarises our main processing activities and the legal ground for each.
| What we do | Lawful basis |
|---|---|
| Provide accounting, tax and company-secretarial services set out in your Letter of Engagement | Performance of a contract |
| Verify your identity as an ACSP and submit the required particulars to Companies House | Legal obligation (ECCTA 2023, Companies Act 2006, Money Laundering Regulations 2017) |
| File your statutory returns with HMRC and Companies House | Legal obligation |
| Process payments, invoices and direct debits | Performance of a contract |
| Send you transactional emails — login codes, password resets, invoices, engagement letters, service notifications | Performance of a contract |
| Send marketing emails about our services | Consent (you can unsubscribe at any time) |
| Measure website usage and the effectiveness of our advertising | Consent (non-essential cookies — see Section 8) |
| Protect our forms from bots and abuse (Cloudflare Turnstile) | Legitimate interests (site security) |
| Investigate complaints, resolve disputes, defend legal claims | Legitimate interests / legal obligation |
| Keep records for the periods required by law | Legal obligation |
We do not use automated decision-making or profiling to produce legal or similarly significant effects on you.
5. Who we share data with
We share your personal data with the third parties below, each of which acts either as a joint controller (a statutory body), a data processor on our behalf, or an independent controller in their own right. We have written data-processing agreements in place with our processors where required.
Statutory bodies:
- Companies House — identity verification results, directors' and shareholders' particulars, statutory filings
- HMRC — tax returns, PAYE submissions, VAT returns and related correspondence
Processors we use to run our service:
| Who | What they do for us |
|---|---|
| Cloudways (managed hosting) | Host our website |
| Cloudflare | Bot protection on our sign-up and forgot-password forms (Turnstile) |
| Google LLC | Website analytics and tag management (Google Analytics, Google Tag Manager) — only where you've given consent |
| Meta Platforms | Advertising measurement (Meta Pixel) — only where you've given consent |
| Mailgun / Mailjet | Email delivery (transactional and marketing) |
| Stripe | Card and direct-debit payment processing |
| Joy Pilot Limited | The accounting platform on which your client records are stored. Joy Pilot Limited is a separate company, registered in New Zealand (company number 6259916). |
Joy Pilot's own subprocessors. Because Joy Pilot stores your accounting data on our behalf, some of Joy Pilot's own subprocessors will also process your personal data. The key ones are Amazon Web Services (cloud hosting, primarily in New Zealand), OpenAI and Google (AI and machine-learning features — see the AI note below), Stripe (payments), and regulated bank-feed providers that you authorise via OAuth. Full details, including the safeguards that Joy Pilot has in place, are set out in Joy Pilot's Privacy Policy.
AI and automated processing (via Joy Pilot). Joy Pilot uses artificial intelligence for certain features you may choose to use, including receipt and invoice scanning, bank-transaction categorisation, business-card extraction, voice transcription, and the in-app "Jodie" assistant. To perform these functions, Joy Pilot sends the minimum necessary data to OpenAI and Google under data-processing agreements. Those providers do not use your data to train their general-purpose models. Voice and audio data is processed in real time and discarded after transcription. Use of AI features is optional — you can enter data manually instead. If you'd rather we didn't use AI on your behalf, please let us know.
Other recipients:
- Our professional advisors (e.g. legal, insurance, auditors) where strictly necessary
- Law enforcement, regulators or courts where we're required or permitted by law to disclose
- A prospective or actual buyer in the event we sell the business, in which case we would notify you beforehand
We do not sell your personal data. We also do not share client data with the other businesses owned by our directors or shareholders (for example Capital City Accountancy, No Worries Red Umbrella Ltd or Relax Accounting). These are separate companies with separate client relationships.
6. International transfers
We process your data within the United Kingdom wherever possible. The key international transfers of personal data that affect our clients are:
- New Zealand — Joy Pilot Limited is based there, and your accounting data is primarily stored on Amazon Web Services infrastructure in New Zealand.
- United States — several of our and Joy Pilot's processors (Google, Meta, Stripe, Mailgun, OpenAI) are US-based or transfer data internationally as part of their global infrastructure. AI features within Joy Pilot involve the transient transfer of specific items of your data to OpenAI and Google for processing.
Where we transfer personal data outside the UK, we rely on one or more of the following safeguards:
- A valid UK adequacy decision in favour of the destination country (New Zealand currently holds UK adequacy status)
- The UK International Data Transfer Agreement (IDTA)
- The UK Addendum to the European Commission's Standard Contractual Clauses (SCCs)
You can ask us for a copy of the safeguards used for any particular transfer using the contact details in Section 13.
7. How long we keep your data
We only keep your personal data for as long as we need it for the purpose it was collected, plus any period required by law.
- Tax returns and related records: 7 years from the end of the relevant tax year (HMRC requirement)
- Company books and accounting records: 6 years from the end of the relevant accounting period (Companies Act)
- ACSP identity-verification records: 7 years from the end of our business relationship with you (Money Laundering Regulations and Companies Act requirements)
- Ad-hoc advisory work: 3 years from the end of the business relationship
- Client files and correspondence: 7 years after our business relationship ends, unless you've asked us to keep them for longer
- Marketing preferences: until you unsubscribe or withdraw consent
- Website analytics: up to 14 months in Google Analytics; Meta Pixel events are retained per Meta's defaults
- Encrypted backups: routinely rotated and overwritten
When records reach the end of their retention period they are securely deleted or anonymised. We'll make reasonable efforts to contact you before destroying files that were yours to keep.
A note on Joy Pilot: Joy Pilot retains documents you upload (such as receipt scans) for as long as your account with them is active. Once your accounting relationship with us ends and your Joy Pilot account is closed, those items may be removed from Joy Pilot sooner than the retention periods above. We separately keep the records we're statutorily required to keep (tax returns, ACSP verification records, etc.) in our own systems for the full periods listed.
8. Cookies and tracking
Our website uses cookies and similar technologies for the following purposes:
- Strictly necessary: keeping you signed in, remembering your session, handling form submissions and protecting against CSRF. These do not require consent.
- Analytics (Google Analytics via Google Tag Manager): so we can understand which pages are useful and which journeys cause friction. Set only with your consent.
- Advertising (Meta Pixel): so we can measure the effectiveness of our campaigns and reach people with similar interests. Set only with your consent.
- Bot protection (Cloudflare Turnstile): a small script on our sign-up and forgot-password forms that scores traffic to stop automated abuse. This runs on the basis of our legitimate interest in keeping the site working; it does not set advertising cookies.
You can opt out of analytics and advertising cookies at any time:
- Google Analytics opt-out add-on: tools.google.com/dlpage/gaoptout
- Meta advertising preferences: facebook.com/settings?tab=ads
- You can also block or clear cookies through your browser settings
9. Your rights
Under UK data protection law you have the following rights. To exercise any of them, contact us and we'll respond within one month.
- Access — you can ask for a copy of the personal data we hold about you.
- Rectification — you can ask us to correct inaccurate or incomplete data.
- Erasure — you can ask us to delete your data. This right is limited where we have a legal obligation to retain records (e.g. tax records).
- Restriction — you can ask us to stop processing your data while we deal with a query.
- Portability — you can ask us to provide a copy of your data in a structured, machine-readable format, or to transmit it to another provider.
- Objection — you can object to processing we do on the basis of legitimate interests.
- Withdraw consent — where we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing done beforehand.
- Automated decisions — you have the right not to be subject to decisions made solely by automated means with legal or similarly significant effect. We don't currently do this.
10. Security
We take reasonable steps to protect your data against unauthorised access, loss, misuse or disclosure. These include:
- Encrypting data in transit using TLS (HTTPS)
- Encrypting client-data at rest on our accounting platform
- Role-based access controls, with access only granted to team members who need it
- Strong authentication for internal systems
- Regular reviews of our security practices and supplier contracts
No online system is ever perfectly secure. If we were to become aware of a personal-data breach that was likely to result in a risk to your rights, we would notify you and the ICO in line with our legal obligations.
11. Children's data
Our services are for adults and businesses, and we do not knowingly collect personal data from anyone under the age of 16. If you believe we've inadvertently collected such data, please contact us and we'll delete it.
12. Changes to this policy
We may update this policy from time to time to reflect changes to our practices or the law. When we do, we'll update the "Last updated" date at the top of this page. If the changes are material we will give you at least 30 days' notice by email or by a notice on the site before they take effect.
13. Contact us and complaints
If you have any questions about this policy, or you'd like to exercise your rights, please get in touch:
- Email: hello@no-worries.co.uk
- Phone: 020 7731 1117
- Post: No Worries Company Services Ltd, Suite 7, Apple Market Hub, 9 Crown Passage, Kingston upon Thames, KT1 1JD
If you're not satisfied with how we've handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Details and complaint forms are at ico.org.uk/make-a-complaint. We'd really appreciate the chance to resolve matters with you directly first.
No Worries Company Services Ltd
Suite 7, Apple Market Hub, 9 Crown Passage, Kingston upon Thames, KT1 1JD
Company number: 05505951 · ACSP reference: AP002533