Oakmoore Accountants logo Oakmoore
Accountants
Book a call

Privacy policy

Last updated 5 September 2026

Oakmoore Accountants Limited (company number 17008098, registered in England & Wales, registered office 4 Beresford Crescent, West Bromwich, B70 9JB) is the data controller for the information described here and is registered with the Information Commissioner's Office. As a small practice we are not required to appoint a Data Protection Officer. If you have a question about any of it, email info@oakmooreaccountants.co.uk.

What we collect

From website enquiries: your name, email address, telephone number if you give it, and whatever you tell us about your business. Nothing else is captured by the form.

From clients, in the course of the work: financial records, bank data, payroll and personal tax information, and identification documents required by anti-money-laundering law.

Why we use it

To reply to your enquiry, to provide the accountancy services set out in your engagement letter, and to meet our own legal obligations — filing with HMRC and Companies House, and the client due diligence we are required to carry out before we act for you.

Our lawful bases are legitimate interests for responding to enquiries, contract for client work, and legal obligation for anti-money-laundering and statutory filing.

Who we share it with

We do not sell your data, we do not pass it to marketing lists, and we do not send you anything you have not asked for. Your data is shared only with the people and services needed to do the work:

HMRC and Companies House, for the filings we make on your behalf. Xero, for bookkeeping and accounts, and Dext, for receipt capture. GoCardless, for collecting fees by Direct Debit. Microsoft 365, which runs our email and the OneDrive folders your records are kept in. Netlify, which hosts this website and stores enquiries sent through the contact form. Anthropic, whose Claude AI tools we use as described in the next section. ICAEW, our regulator, if it inspects our files. Your previous accountant or your bank, where you ask us to. The National Crime Agency, only where the law requires it.

Every provider processes your data on our instructions and to its own published security standards. Xero, Dext, GoCardless and Microsoft process it in the UK or the European Economic Area.

How we use AI

We use Claude, an AI assistant made by Anthropic, to help draft documents, analyse records, prepare workings and summarise correspondence. It may process personal data you have given us where that is needed to deliver the services in your engagement letter. Our lawful basis is legitimate interests (Article 6(1)(f) UK GDPR) and, where relevant, performance of our contract with you.

A qualified accountant reviews everything the AI produces before it reaches you, HMRC or Companies House. The judgement on every file is human.

Anthropic acts as our data processor under a data processing agreement. It is based in the United States, so this involves a transfer of personal data outside the UK; we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses as the transfer mechanism. Under the terms we use, Anthropic does not use our data to train its models and retains inputs for a limited period for safety and security purposes before deleting them. Its data terms are published at anthropic.com/legal.

Using AI does not change your rights under UK GDPR. If you would prefer AI tools not to be used on your engagement, email us and we will discuss how to accommodate that.

How long we keep it

Only as long as the purpose or the law requires. Client accounting records: at least six years from the end of the accounting period. Self Assessment records: five years after the 31 January filing deadline for that tax year. Anti-money-laundering identity records: five years after the end of the client relationship, after which they are deleted unless the law requires otherwise. Payroll records: at least three years from the end of the tax year. Correspondence: six years from the end of the engagement. Enquiries that do not become clients: twelve months.

When a period ends, the data is securely deleted or anonymised.

How we keep it safe

Client files are held in encrypted cloud storage with multi-factor authentication, access is limited to the people doing your work, and documents are shared through secure links rather than unencrypted email. We would tell you and, where required, the ICO without undue delay if a breach affected your data.

Cookies and analytics

This site sets no advertising or tracking cookies and loads no third-party scripts; fonts are served from our own site. The contact form is stored by Netlify, our hosting provider, until we have replied and moved the enquiry to our own records. If analytics are ever added, this section will name the provider and what it measures before it goes live.

Your rights

Under UK GDPR you can ask for a copy of what we hold, ask us to correct it, ask us to delete it where we are not required to keep it, and object to how we use it. Email us and we will respond within one month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.

Contact

Oakmoore Accountants Limited · info@oakmooreaccountants.co.uk · 07856 778045

Oakmoore Accountants Limited · Company number 17008098 · VAT registration GB 526 0744 01 Registered in England & Wales · Registered office: 4 Beresford Crescent, West Bromwich, B70 9JB Terms of use