Privacy notice
1. Who we are and how to contact us
CLOUDLEDGER COLLECTIVE LIMITED provides rescue bookkeeping, ongoing bookkeeping and digital downloads. For privacy questions or to exercise your rights, contact Deborah Massey at info@cloudledgercollective.co.uk.
Company number: 16942202. Registered in England and Wales. Registered office and postal contact: 61 Bridge Street, Kington, United Kingdom, HR5 3DJ. Companies House record.
We act as a controller for enquiries, client administration, our billing and our own legal obligations. Where we handle personal data solely on a business client’s instructions, we may act as that client’s processor. The role and any required data-processing agreement must be settled in the engagement terms. This notice does not replace a client’s own privacy notice to its employees or customers.
2. Information we handle
We work within clients’ existing bookkeeping systems or help them choose suitable software. Client bookkeeping records remain in the client’s chosen system wherever practical. If separate documents are necessary for an engagement, they will only be stored in restricted Microsoft 365 SharePoint or OneDrive for Business folders after the required access controls and multifactor authentication are enabled. Accessing information in a client’s system still involves processing personal data. Contact, booking, billing and required compliance records are considered separately from client bookkeeping files.
- Enquiries and bookings: name, contact details, business name, appointment information and messages you choose to send.
- Client records: invoices, receipts, bank transactions, bookkeeping records and relevant information about directors, partners, customers, suppliers or employees, to the extent needed for the agreed work.
- Identification and compliance: identity and business-ownership information where required for client checks or legal obligations.
- Orders and billing: product purchased, order reference, correspondence, invoice details and payment status available to us. Etsy handles its checkout; this website has no card-payment form.
- Website use: ChatGPT Sites and its infrastructure providers may receive IP addresses, browser/device information and request logs needed to deliver, protect and maintain the website.
Information may come from you, an authorised colleague, your appointed accountant, records or software you authorise us to access, Etsy orders or Calendly bookings. Public registers may be used where needed for business verification. Please do not include bank login credentials, identification documents or sensitive records in a booking message; agree an appropriate transfer method first.
3. Why we use information
- Responding to enquiries and arranging work: taking steps at your request before a contract, or performing a contract with you. When you contact us for a company, our legitimate interest is communicating with its representatives.
- Delivering and administering services: performing our contract with you; for business contacts who are not personally parties to the contract, our legitimate interests in providing and managing the service.
- Billing, tax and required client checks: meeting applicable legal obligations. Debt recovery, dispute handling and protecting records may also involve our legitimate interests.
- Website security: our legitimate interest in operating a secure, reliable service, balanced against visitors’ rights.
- Optional marketing: where consent is required, we will ask separately. You can withdraw it or object to direct marketing at any time. Booking a call or purchasing a download does not automatically enrol you in a mailing list.
For processing undertaken solely on your business’s instructions, the client determines the lawful basis and we follow the agreed processing instructions. If a service requires health or other special-category information, we must identify and explain an additional legal condition before handling it; an ordinary contract basis alone is not sufficient.
Providing enquiry information is voluntary. We may be unable to quote, accept an engagement or complete work if necessary contact, financial or legally required identification information is missing. We do not make solely automated decisions that have legal or similarly significant effects.
4. Sharing and service providers
Only information necessary for the relevant purpose is shared. Our principal providers are Microsoft 365 for business email and, where needed, SharePoint or OneDrive for Business document storage; Calendly for appointment booking; Etsy for digital-download listings, orders and checkout; and OpenAI’s ChatGPT Sites service and its infrastructure providers for website hosting. Client-selected bookkeeping, payroll and accounting platforms may also process information for an engagement and will be identified where relevant.
Information may be provided to your authorised accountant or representatives, HMRC, regulators or law-enforcement bodies where authorised or legally required. Some legal disclosures cannot be notified to you. Information is not sold.
This website links to Calendly’s privacy notice and Etsy’s privacy policy. Visiting those platforms means their privacy arrangements also apply. We use relevant booking or order information they make available to respond to you and administer our services. This does not mean all of their processing is under our control.
5. Website cookies, fonts and external links
The current website code contains no advertising pixels, analytics scripts, embedded Etsy checkout, embedded Calendly calendar, enquiry form or mailing-list form. It links out to Etsy and Calendly. Its fonts are loaded from Google Fonts, which causes your browser to request font resources from Google and disclose connection information such as your IP address. See Google’s privacy policy.
The hosting platform may use strictly necessary cookies or similar technologies for security and reliable delivery. We do not currently set non-essential analytics or advertising cookies through the website. Any future non-essential tracking will be assessed and consent obtained where required.
6. International transfers
Some providers may process data outside the UK. Where UK transfer rules apply, we rely on an appropriate safeguard made available by the relevant provider, such as UK adequacy regulations, the UK International Data Transfer Agreement or an approved UK addendum to standard contractual clauses, together with any required assessment. You can contact us for information about the safeguards relevant to your data. Links to independent platforms are also subject to those platforms’ transfer arrangements.
7. How long information is kept
- Enquiries that do not become engagements: normally 12 months after the last meaningful contact.
- Client engagement records and correspondence needed to evidence our work: normally six years after the engagement ends, subject to applicable statutory requirements, a justified dispute hold and periodic review.
- Our own accounting and tax records: for the applicable statutory period, normally at least six years from the end of the relevant company financial year.
- Client-owned source data handled as a processor: returned or deleted under the agreed instructions and processing agreement, except where retention is legally required. It is not automatically kept for six years.
- Identity and anti-money-laundering records: normally five years after the business relationship ends or an occasional transaction completes, unless applicable law requires or permits a different period.
- Security logs and backups: retained according to the relevant provider’s operational and deletion schedule.
When information is no longer required, it is securely deleted or anonymised. Relevant data may need to be held longer for a live claim or legal requirement; the reason and review date will be recorded.
8. Security
We use restricted access, strong passwords, multifactor authentication where available, secure transfer methods and access reviews. Separate client-document storage will not be used until restricted Microsoft 365 business folders and multifactor authentication are enabled. Clients should not send bank login credentials or identification documents by ordinary email. No internet service can guarantee absolute security.
9. Your rights and complaints
Depending on the circumstances and lawful basis, you may request access, correction, deletion, restriction or portability of your personal data, or object to its use. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing. Some rights have legal exceptions; we will explain any that apply. We may need proportionate information to verify your identity.
Contact info@cloudledgercollective.co.uk. We will respond within the applicable statutory time limit and explain any permitted extension. If we act only as a processor, we will assist the relevant controller with your request.
Please contact us first if possible, but you may complain directly to the Information Commissioner’s Office at ico.org.uk/make-a-complaint/.
10. Changes
We will review this notice when our services, systems or use of information change and explain material changes where required. The effective date at the top shows when it was last adopted.