Legal

Privacy Policy

Last updated: 29 September 2026.

Who we are

SMB Accountancy Group Ltd ("we", "us") is registered in England and Wales (company number 16609652), registered office 7 De Havilland Drive, Estuary Commerce Park, Speke, Liverpool L24 8RN. We are the holding company for a group of accountancy practices (our "member firms"), and we provide the software and IT systems those firms use to run their practices.

We have applied to register with the Information Commissioner's Office (ICO); our registration number will be shown here once it is issued.

Contact us about anything in this policy at hello@smbaccountancygroup.com.

This policy has two parts:

  • Part A covers this website and its enquiry forms.
  • Part B covers the software and systems we provide to our member firms, which are used by the firms' staff and which hold information about the firms' clients.

Part A: this website

For this website, we are the data controller.

General enquiries. When you submit the contact form we collect your name, email address, phone number (if given) and your message. We use these solely to respond to your enquiry. Legal basis: legitimate interests (responding to a request you initiated).

Practice sale enquiries. When you register interest in selling your practice we additionally collect the practice details you choose to share (practice name, location, approximate fee income, timescale). We treat these enquiries as strictly confidential: they are read only by the group's directors, and are never shared with member firm staff or third parties without your agreement. Legal basis: legitimate interests (assessing and responding to an enquiry you initiated).

Hosting and security. This site is hosted on Cloudflare Pages. Basic technical data (IP address, browser type) is processed by Cloudflare to serve and secure the site. Our forms are protected by Cloudflare Turnstile, which processes technical signals to distinguish humans from bots. We do not run advertising trackers.

Analytics. If we enable Google Analytics, it loads only after you give consent through the cookie banner, and you can withdraw consent at any time using the cookie icon at the bottom left of the page. With consent declined or not given, no analytics cookies are set.

How long we keep it. General enquiry details are kept for up to 12 months, then deleted if no ongoing relationship has followed. Practice sale enquiries are kept for up to 24 months, reflecting the longer timescales on which owners typically plan a sale, unless you ask us to delete them sooner.

Sharing. We do not sell personal information. We share it only with the service providers that run this website's infrastructure acting as processors (Cloudflare for hosting and form storage, and our email delivery provider for notifications), with professional advisors where a transaction proceeds and you have agreed, and where required by law.

Part B: the group's software and systems

What the software is, and who uses it

We provide our member firms with shared software and IT systems: a client records system (the Clients Portal), tools for preparing clients' bookkeeping from bank statements, secure storage for client files, and the sign-in and security systems behind them. This software is not offered to the public. It is used only by the staff of our member firms, each of whom signs in with a work account issued by the group.

Whose information, and who is responsible for it

Clients of our member firms. Each member firm is the data controller for information about its own clients, and publishes its own privacy information. We hold and process that information on each firm's behalf, to provide the firm with the software it uses to act for you. If you are a client and want to exercise your rights, please contact your firm; we will help them respond.

Staff of our member firms. We are the data controller for the information we need to give staff secure access to the software: their work account, sign-in records and a record of the actions they take in it.

Fraud prevention data sent to HMRC. Where the software connects to HMRC on a firm's behalf, we are responsible for the fraud prevention data described below, which we collect and send to HMRC because the law requires it.

What information the software holds

About a firm's clients:

  • identity and contact details: name, business name and any trading name, address, telephone, email, and the member firm staff looking after the client;
  • the nature of the business and its SIC codes;
  • tax and company references: Unique Taxpayer Reference, VAT registration number and registration date, PAYE and Accounts Office references and who runs the payroll, and Companies House number and filing dates;
  • the Companies House authentication code the firm uses to file for the client;
  • the people behind the business (directors, partners, the proprietor and contacts): name, address, date of birth, National Insurance number, telephone, email and Companies House personal code;
  • notes and reminders written by firm staff;
  • invoices raised by the firm to the client, taken from the firm's own accounting records;
  • documents in the client's file, held in the firm's secure file storage;
  • bank statements and transactions the client provides for bookkeeping, and how each transaction has been categorised.

About member firm staff: name, work email address, which firm or firms they work for, sign-in records (including when and how they last completed multi-factor authentication), and records of what they did in the software (for example, who changed a record).

Companies House codes. The Companies House authentication codes and personal codes above are held so that the firm can file with Companies House on the client's behalf. They are shown only to staff of the firm that acts for the client.

What the software does not hold. We do not store clients' passwords for HMRC or any other online service, or their HMRC sign-in details.

Connecting to HMRC

The software can connect to HMRC's services for a member firm, so that firm staff can see information such as a client's VAT return deadlines and which returns have been submitted.

  • A partner of the firm authorises the connection by signing in to HMRC directly, on HMRC's own website. The software never sees or stores the firm's HMRC sign-in details. It receives an access key from HMRC, which it stores encrypted and uses only for that firm.
  • HMRC only returns information about clients who have authorised that firm to act as their agent.
  • The information HMRC returns is shown to the member of staff who asked for it and is not stored by the software.
  • The firm can ask us to end the connection at any time, and a client can remove a firm's authority through HMRC.

Fraud prevention data. HMRC requires, by law, software that connects to certain of its services (including VAT) to send information about the connection with every request, to help protect taxpayers from fraud. When a member of staff uses a feature that contacts HMRC, the software sends HMRC:

  • the public IP address and network port of the staff member's connection, and when it was seen;
  • an identifier for the staff member's device (a random value stored in a cookie on that device);
  • details of their browser: its user agent, screen size, window size and time zone;
  • the staff member's work sign-in identifiers;
  • when they last completed multi-factor authentication, and the type of method used (for example, a passkey), with a one-way coded reference to that method rather than the method itself;
  • the name and version of our software, the public address of our service, and a coded identifier for the member firm.

Legal basis: legal obligation. HMRC uses this data to detect and prevent fraud, and explains its use in its own privacy information at gov.uk.

Why we use it, and our legal bases

  • To provide the software to our member firms, so they can deliver the services their clients have engaged them for: on the firms' instructions, and for the firms' own lawful bases for acting for their clients.
  • To give staff secure access, keep the systems secure and investigate problems: legitimate interests (protecting client information and our systems).
  • To send fraud prevention data to HMRC: legal obligation.

We do not use clients' or staff information for marketing, and we do not sell it.

Automated tools and AI

Some features use artificial intelligence to suggest how bank transactions should be categorised, or to help staff reformat documents. These AI models run on infrastructure provided to us by Node Digital Ltd and are hosted in the United Kingdom: the information does not leave the UK. Every automated categorisation is checked and approved by a member of firm staff, and the software does not make decisions about clients on its own.

Where the information is held

The software and its data, including the AI models it uses, are hosted in the United Kingdom, on infrastructure provided to us by Node Digital Ltd, with sign-in and client file storage provided by Microsoft 365 with its data location set to the United Kingdom.

Who else is involved

We use the following service providers to run the software. Each acts on our instructions and only for this purpose:

  • Microsoft (Microsoft 365 and Entra ID): staff sign-in, security logs and client file storage.
  • Node Digital Ltd: provides the UK hosting platform and the UK-hosted AI models on which the software runs.
  • Cloudflare: secure connections between staff browsers and the software.

We also exchange information with HMRC as described above, and look up public company information from Companies House.

How we protect it

  • All connections to the software are encrypted, and staff must sign in with their work account using multi-factor authentication.
  • Staff can see only the clients of the firm or firms they work for.
  • The access keys HMRC issues for a firm are stored encrypted, separately from the key that opens them.
  • The software is run on isolated, security-scanned systems, and access to administer them is restricted to named individuals.

How long it is kept

  • Client information is kept for as long as a member firm needs it to act for the client and to meet its legal and professional record-keeping obligations. Client files are normally kept for seven years after they were last changed, in line with the firms' retention practice.
  • Information returned by HMRC is not stored.
  • A firm's HMRC access keys are kept until the firm ends the connection, and in any case expire after 18 months unless the firm renews its authorisation.
  • Staff sign-in and activity records are kept for as long as needed to keep the systems secure.

Your rights

Under UK GDPR you can ask for access to, correction of, or deletion of your personal information, ask for it to be transferred, object to our processing, and complain to the Information Commissioner's Office (ico.org.uk). If you are a client of one of our member firms, please contact your firm first. Otherwise, email hello@smbaccountancygroup.com.

Reporting a security concern

If you believe you have found a security weakness in our software or systems, or that information held in them may have been put at risk, please email hello@smbaccountancygroup.com straight away. We act on reports promptly and, where personal information is affected, notify the ICO, HMRC and anyone else we are required to within the legal time limits.