Client Privacy Notice
Phoenix Advisory Limited · Version 1.1 · 29 September 2026
Last updated: 29 September 2026
This notice explains how Phoenix Advisory Limited handles personal data about you, your officers and the people we deal with at your business. It forms part of our engagement letter, alongside the schedules of services and our standard terms and conditions of business.
Who we are
Phoenix Advisory Limited is the data controller for the personal data described in this notice. We are registered with the Information Commissioner’s Office. Ross Radford is the point of contact for data protection questions and can be reached at rossradford@phoenixadvisory.co.uk.
Where instead we process personal data about your employees or other people on your behalf and on your instructions (payroll is the clear case), you are the controller and we are your processor. That processing is governed by our Data Processing Schedule, not by this notice.
The information we hold
- Identity and contact details: name, date of birth, nationality, address, email, telephone number.
- Identification and verification records obtained for anti-money laundering purposes, including the results of electronic identity checks, and information about beneficial ownership and control.
- Screening results, including politically exposed person, sanctions and adverse media screening.
- Financial and business information about you and your business, including the records and explanations you give us in order for us to do the work.
- Correspondence and records of our dealings with you, including notes of meetings and calls.
- Billing and payment records.
Where we get it
Mostly from you. We also obtain information from public registers such as Companies House and the register of persons with significant control, from electronic verification and screening providers, from HM Revenue & Customs, and, where you have authorised it, from your previous adviser.
What we use it for, and our lawful basis
We set out the basis for each purpose, because the basis determines which rights you have.
- To decide whether to accept you as a client and to agree terms: Article 6(1)(b), steps taken at your request before entering into a contract.
- To provide the services in the schedules in force between us, and to administer and bill for them: Article 6(1)(b), performance of our contract with you.
- Client due diligence, screening and ongoing monitoring under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017: Article 6(1)(e), a task carried out in the exercise of a function of a public nature. Regulation 41(7) of those Regulations treats this processing that way. It is not, as is often stated, a legal obligation case, and the difference matters: under Article 6(1)(e) you have the right to object, and we will consider any objection you make.
- To meet our other legal, regulatory and professional obligations, including to Companies House, HM Revenue & Customs and the Chartered Institute of Management Accountants as our supervisory authority: Article 6(1)(c), legal obligation.
- To keep business and engagement records, to defend or bring claims, and to run and improve our practice: Article 6(1)(c) where a statutory duty applies, and otherwise Article 6(1)(f), our legitimate interest in operating and protecting the firm. We have assessed those interests against your rights and will provide the assessment on request.
- To send you information about other services we provide: Article 6(1)(a), your consent. You can withdraw it at any time and we will stop.
Special category and criminal offence data
Anti-money laundering screening returns information about politically exposed persons, sanctions and adverse media, and can return allegations and convictions. That is criminal offence data under Article 10, and screening can also return special category data under Article 9.
We process it under section 10 of, and Schedule 1 to, the Data Protection Act 2018, on the conditions in Part 2 of that Schedule relating to the prevention and detection of unlawful acts and to regulatory requirements. Where the law requires us to have an Appropriate Policy Document in place for that processing, we have one, and we will provide a copy on request.
Anti-money laundering data is ring-fenced
Personal data we obtain in order to prevent money laundering, terrorist financing or proliferation financing is used only for those purposes. We may not use it for anything else unless you consent, or unless an enactment other than those Regulations or the UK GDPR permits it. We keep it for five years from the end of our business relationship with you, unless you consent to a longer period or we are otherwise required to keep it.
Who we share it with
We share personal data only where we need to, and only with:
- Our software and service providers, who process data on our instructions: practice management, electronic identity verification and screening, cloud accounting and payroll, document storage and signature, email and productivity, and our website and scheduling tools.
- HM Revenue & Customs, Companies House, The Pensions Regulator and other bodies where the work requires it or the law does.
- The Chartered Institute of Management Accountants, as our supervisory authority, and any independent reviewer of our files, all of whom are bound by confidentiality.
- The National Crime Agency, where we are required to make a report. Where we do, we are prohibited by law from telling you.
- Our professional indemnity insurers and, where necessary, our own legal advisers.
- A successor practice under our continuity arrangement, if we become unable to act.
We do not sell personal data, and we do not share it for anyone else’s marketing.
Transfers outside the United Kingdom
Some of our providers process data outside the United Kingdom. Where that happens we make the transfer only on a lawful basis under the UK GDPR: either the destination is covered by a UK adequacy decision, or we put approved safeguards in place (the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses), supported by a transfer risk assessment, together with appropriate technical measures including encryption. Tell us if you would like to know which countries your data may reach and what safeguards apply.
How long we keep it
We keep personal data for as long as we need it for the purpose we collected it for, and then for as long as we are required or reasonably need to keep it in order to meet a legal or regulatory obligation, to resolve a query, or to bring or defend a claim. Two periods are fixed:
- Anti-money laundering identification and due diligence records: five years from the end of our business relationship, under Regulation 40.
- Enquiries that do not become engagements: 24 months from our last contact with you.
For other records we apply the criteria above rather than a single period, because the right period depends on the record. We are currently reconciling the retention periods across our own documents and will publish a single retention schedule when that work is complete. Ask us at any time and we will tell you what we hold and why.
Your rights
Under data protection law you have the right to be informed about how we use your data (which is what this notice is for) and, subject to conditions, the rights to:
- Ask for a copy of the personal data we hold about you.
- Have inaccurate data corrected, and incomplete data completed.
- Ask us to erase data, where we no longer have a good reason to hold it.
- Ask us to restrict how we use it while a question about it is resolved.
- Object to processing we carry out on the basis of our legitimate interests, or in the exercise of a function of a public nature, which includes our anti-money laundering processing.
- Receive data you gave us in a portable form, where we process it with your consent or in order to perform our contract with you.
- Withdraw consent at any time, where consent is the basis we rely on.
Some of these rights are limited where we are required by law to keep or process the data, our anti-money laundering records being the clearest example. Where a right is limited we will tell you why.
Automated decision-making
We do not make decisions about you by solely automated means. Our electronic verification and screening tools produce a risk rating and may return a referral, but a person (Ross Radford, as Money Laundering Reporting Officer) reviews the result and takes the decision. We may use artificial intelligence tools to assist our work, as described in paragraph 8 of our standard terms and conditions of business; their output is reviewed by a qualified professional before it is relied on, and professional judgement is not delegated to any such tool.
If you are unhappy
Please tell us first: contact Ross Radford and we will look into it. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or by telephone on 0303 123 1113. We would rather have the chance to put things right ourselves.
Changes to this notice
We review this notice periodically and will update it before we use your personal data for a new purpose. Where we make a material change we will tell you, and the current version, showing the date it was last updated, will always be available at phoenixadvisory.co.uk/client-privacy and on request. This is version 1.1, dated 29 September 2026.