Privacy Notice

Triple Bottom Line Accounting Limited

Last updated: 7th July 2026

WHO WE ARE

Triple Bottom Line Accounting Limited (“TBLA”, “we”, “us”, “our”) is the data controller for the personal information we hold about you.

  • Company number: 06785251
  • Registered office: The Enterprise Centre, University of East Anglia, Norwich, NR4 7TJ
  • VAT number: 254550803
  • ICO registration number: ZA065381
  • Data Protection Officer: Peter Ellington
  • Email address: peter@triplebottomlineaccounting.com.
  • Telephone number: 01603 619 570 
  • Postal Address: See above.

We process personal data in line with the Data Protection Act 2018 and the UK GDPR.

2. WHO THIS NOTICE COVERS

This notice explains how we collect, hold and use personal data about our customers, business contacts and staff.

3. YOUR RIGHTS

Under data protection law you have the right to: be informed about how we use your data; access the data we hold about you; have inaccurate data corrected; have your data erased (“the right to be forgotten”); restrict how we process it; object to our processing; data portability; and rights relating to automated decision-making and profiling. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects about you (see section 7).

4. THE PERSONAL DATA WE COLLECT

Depending on the services we provide, we may collect: names, dates of birth, gender, family relationships, addresses, email addresses and telephone numbers; business details, job titles and National Insurance numbers; directorships, shareholdings, trusteeships, employments and other business interests; loans, assets, financial transactions and tax information (including Government Gateway, PAYE, VAT references and UTR); business invoices, expenses and travel details; employee information; inventory and fixed-asset records; and any other information we need in order to act as your accountant.

5. WHERE WE GET YOUR DATA

Most of the data we hold comes directly from you. We may also obtain or verify information from Companies House, the Charities Commission, HMRC, and Veriphy Ltd (our anti-money-laundering verification provider). When you become a client, we also collect the identity and address information that you — and any company directors or people with significant control — provide during onboarding and verification (see sections 6–8).

6. HOW AND WHY WE USE YOUR DATA

We use your data to provide our services, including: payroll processing; expense reimbursement; staff records; preparing and filing tax returns and company accounts; VAT returns; bookkeeping; charity accounts and gift-aid claims; and pension administration.

Depending on the activity, our lawful basis is the performance of our contract with you, compliance with a legal obligation, or our legitimate interests in running the practice. We may send you marketing communications where you have given permission or where we are otherwise permitted to do so; you can opt out at any time.

Identity and address verification (anti-money-laundering). As an accountancy practice, we are legally required to verify the identity and address of our clients (and of company directors, people with significant control, and self-assessment signatories) before we act. We do this to comply with a legal obligation under the Money Laundering Regulations 2017 (UK GDPR Article 6(1)(c)). The biometric face-match step within identity verification is carried out by Stripe under the explicit consent you give in Stripe’s own process (Article 9(2)(a)).

7. AI-ASSISTED PROCESSING

We use artificial-intelligence tools (Anthropic’s “Claude”) to help our team read and check documents you upload — for example a proof-of-address document — and to assist with bookkeeping review. These tools support our staff: a named member of our team reviews the result and makes every decision. We do not make decisions about you by solely automated means, and we do not use your data for automated profiling. Anthropic does not use your data to train its AI models under our commercial agreement.

8. WHO WE SHARE YOUR DATA WITH

We do not sell your data. We share it only where necessary to provide our services or to meet a legal obligation. This includes:

  • HMRC, Companies House and the Charities Commission — for filings, returns and registrations.
  • QX (our outsourced bookkeeping, accounting and payroll partner in India) — under contract and to the same data-protection standards we apply in the UK. QX holds ISO 27001, ISO 27701, SOC 2 Type II and ISO 9001 certifications.
  • Your independent financial adviser (IFA) — where relevant and with your knowledge.
  • Where required by law, or by a valid order of a court or public authority.

To run our services, we also use a number of trusted technology providers (“sub-processors”) who process personal data on our behalf under written data-protection agreements. We have grouped them below by category of processing activity, with the specific providers we currently use given as examples; the tools we use may change from time to time, but the categories of processing described below will not:

  • Identity verification & anti-money-laundering checks — such as Stripe (Stripe, Inc.) and Veriphy (Veriphy Ltd, Company No. 05066478) — processes your government photo ID and a selfie / biometric face match (Stripe), and your name, date of birth and address for screening against electoral roll, PEP and sanctions databases (Veriphy). Purpose: to verify your identity at onboarding, a legal anti-money-laundering requirement.
  • AI-assisted document-processing tools — such as Anthropic (Anthropic PBC) — processes proof-of-address documents you upload, and certain bookkeeping records, names and figures from your accounts. Purpose: to read and check documents and assist our review using the “Claude” AI (see section 7). Anthropic does not use your data to train its models under our commercial terms.
  • Database & secure document-hosting infrastructure — such as Supabase (Supabase, Inc. — hosted on Amazon Web Services, London UK region) — processes the personal and business information you give us, and the documents you upload, held securely. Purpose: to host our database and store your records and documents.
  • Email & service-communications software — such as Resend (Resend, Inc.) — processes your name, email address and the contents of the messages we send you. Purpose: to send you service emails such as confirmations, document requests and engagement letters.
  • Scheduling & appointment-booking software — such as Calendly (Calendly, LLC) — processes your name, email address and the time you book. Purpose: to let you book calls and meetings with us online.
  • Accounting & bookkeeping software — such as FreeAgent (FreeAgent Central Ltd, UK) — processes your accounting records: contact details, invoices, expenses and bookkeeping transactions. Purpose: the accounting software we use to keep your books.
  • Website hosting & IT infrastructure — such as Vercel (Vercel, Inc.) — processes technical request logs from our secure client website. Purpose: to host and run our client-facing website and application.

9. STORING AND TRANSFERRING YOUR DATA

Your data is held securely, primarily within the UK. Some of our providers process data outside the UK: QX operates in India, and some of our technology providers (including Stripe, Anthropic, Resend, Calendly and Vercel) are based in the United States and may process limited data there. Where data is transferred outside the UK we rely on appropriate safeguards — such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, standard contractual clauses, and each provider’s data-processing agreement — so that your data continues to receive protection equivalent to UK standards.

10. HOW LONG WE KEEP YOUR DATA

We keep your accounting and tax records for at least six years, in line with the Companies Act, the Charities Act and HMRC requirements, and we may retain records for longer where needed to deal with a legal or regulatory investigation. Identity and address-verification records — including verification results and any proof-of-address documents — are kept for five years after our engagement with you ends, after which they are deleted or anonymised, as required by the Money Laundering Regulations 2017. We may keep these records for longer where the law requires it, where legal proceedings need them, or where you’ve consented to a longer period. Access to verification documents is restricted to named members of our team.

11. MAKING A SUBJECT ACCESS REQUEST

You can ask for a copy of the personal data we hold about you. Please make your request in writing to our Data Protection Officer (details in section 1). There is not normally any charge, unless a request is manifestly unfounded or excessive. We will respond within one month; for complex requests this may extend to up to three months, and we will tell you if that is the case.

12. CHANGES TO THIS NOTICE

We may update this notice from time to time. The current version is always published on our website, and the “last updated” date above shows when it last changed.

Scroll to Top