top of page

DJM ACCOUNTANCY LTD

Privacy Notice

Last updated: 23 September 2026

 

 

1. About this notice

This privacy notice explains how DJM Accountancy Ltd ("we", "us", "our") collects, uses, shares and protects personal information, and the rights you have over it. It applies to our clients and prospective clients, to people connected with our clients (such as directors, shareholders, partners, family members and employees), and to visitors to our website.

 

We are the controller of the personal data we hold, which means we decide how and why it is used. We are responsible for it under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and related laws.

 

 

2. Who we are and how to contact us

DJM Accountancy Ltd is a private limited company registered in Scotland (company number SC777145). Our registered office is 20–22 King Street, Bathgate, West Lothian, EH48 1AX.

 

We are registered with the Information Commissioner’s Office (ICO) under registration number ZC170851.

 

If you have any questions about this notice or about how we handle your personal data, please contact Daniel Miller, Director:

  • Email: Daniel@djmaccountancy.com

  • Phone: 07347 736339

  • Post: DJM Accountancy Ltd, 20–22 King Street, Bathgate, West Lothian, EH48 1AX

 

 

3. The personal data we collect

Depending on the services we provide, we may collect:

  • Identity details: name, title, date of birth, nationality, signature, and copies of identity documents such as your passport or driving licence.

  • Contact details: home and business addresses, email addresses and telephone numbers.

  • Tax and financial information: National Insurance number, Unique Taxpayer Reference, income, pensions, benefits, savings, investments, property, bank statements and account details, business transactions and records, VAT information, and correspondence with HMRC.

  • Payroll and employment information (where we run payroll for an employer): employees' names, addresses, dates of birth, National Insurance numbers, pay, tax codes, pension contributions, bank details, and records of statutory payments such as sick, maternity and paternity pay.

  • Business information: details of companies and other organisations you are involved with, including directors, shareholders, partners, persons with significant control and beneficial owners.

  • Anti-money laundering information: the results of identity and address checks, information about the source of funds and wealth, and the results of screening against sanctions and politically exposed person (PEP) lists.

  • Communications: emails, messages, notes of calls and meetings, and any other information you choose to give us.

  • Website information: details you send us through our contact forms or live chat, and technical information such as your IP address, browser and device type, and how you use our website (see section 12).

 

Some of this information may be "special category" data, such as health information that is relevant to a tax relief or to statutory sick pay, or information about criminal offences, for example if it comes to light during anti-money laundering checks. We only collect this kind of information where it is necessary and the law allows it.

 

If you give us personal data about other people, such as your partner, children or employees, please make sure they know you are sharing it with us and point them to this notice.

 

 

4. Where we get your personal data

Most of the information we hold comes directly from you. We may also receive it from:

  • HMRC and other government bodies, once you have authorised us to act as your agent;

  • Companies House and other public registers;

  • your bank and other financial institutions, for example through bank feeds you connect to your accounting software;

  • your employer, if we provide payroll services to them;

  • your business partners, fellow directors or family members, where they instruct us on matters that involve you;

  • your previous accountant, when we take over your affairs;

  • identity verification and screening services; and

  • people who refer you to us.

 

 

5. How we use your personal data and our lawful basis

We only use your personal data where the law allows us to. The main purposes, and the lawful basis we rely on for each, are:

  • Providing our accounting, bookkeeping, tax, VAT, payroll, company secretarial and advisory services under our engagement letter. Lawful basis: performance of our contract with you. Where you are not our client yourself (for example, you are an employee or director of a client), our legitimate interests and those of our client in delivering the services they have asked for.

  • Verifying your identity and carrying out customer due diligence and ongoing monitoring. Lawful basis: legal obligation, under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.

  • Submitting returns and dealing with HMRC, Companies House, The Pensions Regulator and other authorities on your behalf. Lawful basis: performance of our contract with you, and our legal obligations.

  • Meeting our other legal and regulatory duties, including keeping records, co-operating with our anti-money laundering supervisor and reporting suspicious activity to the National Crime Agency where the law requires. Lawful basis: legal obligation.

  • Running our business: billing and collecting fees, managing our records and IT systems, keeping information secure, arranging professional indemnity insurance, handling complaints, and establishing or defending legal claims. Lawful basis: our legitimate interests.

  • Replying to enquiries you send us through our website, live chat, email or phone. Lawful basis: taking steps at your request before entering into a contract, or our legitimate interests.

  • Keeping existing clients informed with deadline reminders, updates on changes to tax rules and information about our services. Lawful basis: our legitimate interests. You can opt out at any time.

  • Sending marketing to people who are not clients. Lawful basis: your consent, which you can withdraw at any time.

  • Using non-essential cookies on our website. Lawful basis: your consent.

 

Where we use special category data or criminal offence data, we do so only where it is necessary to establish, exercise or defend legal claims; to meet obligations under employment and social security law (for example, when running payroll); where a condition in Schedule 1 to the Data Protection Act 2018 applies, such as preventing or detecting unlawful acts or meeting regulatory requirements; or with your explicit consent.

 

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.

 

Anti-money laundering checks

We are supervised by HM Revenue & Customs for anti-money laundering purposes, and the law requires us to check the identity of our clients before we act for them. We may use an electronic identity verification service to help us do this.

 

Personal data we obtain for the purposes of the Money Laundering Regulations will be used only for the prevention of money laundering and terrorist financing, unless another law permits us to use it for another purpose or you have agreed to us doing so.

 

In some circumstances the law requires us to report suspicions to the National Crime Agency, and it may prohibit us from telling you that we have done so.

 

If you do not provide the information we need, we may be unable to act for you or to continue acting for you.

 

 

6. Who we share your personal data with

We only share your personal data where it is necessary for the purposes described above. This may include sharing it with:

  • HMRC, Companies House, The Pensions Regulator, pension providers and other public bodies, as needed to provide our services;

  • trusted providers who handle data on our behalf under contract, including our cloud accounting and payroll software (such as Xero), our email, file storage and IT providers, identity verification and screening providers, and our website provider, Wix;

  • HMRC in its role as our anti-money laundering supervisor, and the National Crime Agency, the police or other authorities where the law requires it;

  • our professional advisers, insurers and auditors, where necessary;

  • banks, lenders, mortgage brokers and other third parties, but only when you ask us to, for example to confirm your income; and

  • another accountancy practice or business if our practice is sold, merged or transferred, in which case your personal data will continue to be protected in line with this notice.

 

We do not sell your personal data.

 

 

7. International transfers

Some of our service providers store or access data outside the UK. Where this happens, we make sure your personal data is protected, for example because the UK has recognised that the country provides adequate protection, or by using contract terms approved under UK data protection law. Please contact us if you would like more details.

 

 

8. How long we keep your personal data

We keep personal data only for as long as we need it for the purposes described in this notice, including to meet legal, tax, accounting and regulatory requirements. As a general guide:

  • Client files and accounting and tax records: 6 years after our engagement ends, or longer if they are needed for an ongoing HMRC enquiry, dispute or legal claim.

  • Anti-money laundering records: 5 years after our business relationship with you ends, as the Money Laundering Regulations require. We then delete them unless another law or legal proceedings require us to keep them.

  • Payroll records: at least 3 years after the end of the tax year they relate to, and normally for as long as our client files.

  • Enquiries that do not lead to us acting for you: up to 12 months.

  • Marketing preferences: until you ask us to stop, after which we keep a brief record so that we do not contact you again.

 

When we no longer need personal data, we securely delete it or make it anonymous.

 

 

9. How we keep your personal data secure

We use appropriate technical and organisational measures to protect your personal data, including access controls, multi-factor authentication, encryption, reputable cloud providers and confidentiality obligations. Email is not a completely secure means of communication, so please let us know if you would prefer us to use a more secure method for sensitive documents.

 

 

10. Your rights

You have the right to:

  • ask for a copy of the personal data we hold about you (a "subject access request");

  • ask us to correct personal data that is inaccurate or incomplete;

  • ask us to delete your personal data;

  • ask us to restrict how we use your personal data;

  • object to our use of your personal data where we rely on legitimate interests, and object to direct marketing at any time;

  • ask us to transfer personal data you have given us to you or to another organisation in a commonly used electronic format; and

  • withdraw your consent at any time, where we rely on consent.

 

Some of these rights do not apply in every situation. For example, we cannot delete records that we are legally required to keep, and we may be unable to disclose information where doing so would prejudice the prevention or detection of crime.

 

To exercise any of your rights, please contact us using the details in section 2. There is normally no charge. We may need to confirm your identity, and we will respond within one month. If your request is complex we may need up to two further months, in which case we will tell you why.

 

 

11. Complaints

If you are unhappy with how we have handled your personal data, please tell us. You can complain to us in whatever way suits you, including by email, phone or post using the details in section 2. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.

 

You also have the right to complain to the ICO, the UK's data protection regulator:

 

We would appreciate the chance to deal with your concerns first, but you can contact the ICO at any time.

 

 

12. Cookies and our website

Our website is built and hosted on Wix. It uses cookies that are essential for the site to work and to keep it secure. Other cookies, such as those used for analytics or by embedded content like our Instagram feed, are only used with your consent, which you can give or withdraw at any time using the cookie banner on our website. Our contact forms and live chat are provided through Wix, and the information you send through them comes to us.

 

Our website may link to other websites, such as HMRC or our social media pages. We are not responsible for how those websites handle personal data, so please read their privacy notices.

 

 

13. Changes to this notice

We may update this notice from time to time. The latest version will always be available on this page, with the date it was last updated shown at the top.

  • Instagram
  • Facebook
  • Whatsapp
CONTACT
LOCATION
OPENING HOURS

Email: Daniel@DJMAccountancy.com
Phone: 07347736339

 

DJM Accountancy Ltd (SC777145)
20-22 King Street 

Bathgate

West Lothian

​EH48 1AX 

Open 24 Hours

DJM Accountancy Ltd · Registered in Scotland, company no. SC777145 · Registered office: 20–22 King Street, Bathgate, EH48 1AX · Supervised by HMRC for anti-money laundering purposes.

bottom of page