Legal
Privacy Policy
Lumi Accountancy Limited — how we handle your personal data
Last updated: May 2026
1. Who we are
Lumi Accountancy Limited is the data controller responsible for your personal data.
We are registered with the Information Commissioner's Office (ICO) and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What personal data we collect
We may collect and process the following personal data:
- Contact information — name, email address, phone number
- Business information — company name, turnover, nature of business
- Financial information — provided in the course of delivering accountancy services
- Communications — emails, messages and notes from consultations
- Website enquiry data — information submitted via our contact form
- Newsletter sign-ups — email address if you subscribe to our blog updates
3. How we collect your data
- Directly from you — when you complete our contact form, book a consultation, or email us
- Through our accountancy engagement — when you become a client
- From third parties — where permitted, such as Companies House or HMRC
4. How we use your data
We use your personal data for the following purposes:
- Responding to enquiries and providing quotes
- Delivering accountancy, taxation and payroll services
- Complying with legal and regulatory obligations (including HMRC, ICAEW)
- Sending relevant updates, tax reminders or newsletters (where you have opted in)
- Improving our services and website
5. Legal basis for processing
We process your personal data under the following legal bases:
- Contract — processing is necessary to deliver the services you've engaged us for
- Legal obligation — we must comply with HMRC, ICAEW and other regulatory requirements
- Legitimate interests — responding to enquiries, improving our services
- Consent — for marketing communications and newsletter sign-ups (you can withdraw consent at any time)
6. Who we share your data with
We do not sell your personal data. We may share it with:
- HMRC — as required by law for tax submissions and compliance
- ICAEW — as part of our professional regulatory obligations
- Xero — our recommended accounting software platform
- Web3Forms — used to process contact form submissions securely
- Professional advisers — such as solicitors or insurers, where necessary
All third parties are required to keep your data secure and use it only for the purposes we specify.
7. How long we keep your data
- Client records — retained for a minimum of 7 years after the end of the engagement, as required by HMRC and professional standards
- Enquiry data — retained for up to 12 months if no engagement follows
- Newsletter sign-ups — until you unsubscribe
8. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — request deletion of your data (subject to legal retention obligations)
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — receive your data in a commonly used format
- Right to object — object to processing based on legitimate interests or direct marketing
- Right to withdraw consent — withdraw consent for marketing at any time
To exercise any of these rights, please contact us at Info@lumiaccountancy.co.uk. We will respond within one calendar month.
9. Cookies
Our website uses minimal cookies — primarily those required for basic functionality. We do not use tracking or advertising cookies. By using our website, you consent to the use of essential cookies.
10. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or destruction. All client financial data is handled through secure, encrypted platforms.
11. Complaints
If you have concerns about how we handle your personal data, please contact us in the first instance at Info@lumiaccountancy.co.uk.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk · Helpline: 0303 123 1113
12. Changes to this policy
We may update this Privacy Policy from time to time. The most current version will always be available on this page with the date it was last updated. We recommend reviewing it periodically.