Privacy Policy
How we collect, use and protect personal data, and the rights you have over it under UK data protection law.
Last updated: 28 August 2026
1. Who we are
RRH Advisory Limited (“RRH Advisory”, “we”, “us” or “our”) is a company registered in England & Wales under company number 17283513. Our registered office is at 88 Miswell Lane, Tring, England, HP23 4EX.
For the purposes of UK data protection law, RRH Advisory Limited is the data controller for the personal data described in this policy. That means we are responsible for deciding how and why your personal data is used.
We are committed to protecting your privacy and handling your personal data lawfully, fairly and transparently, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Scope of this policy
This policy explains how we handle personal data relating to:
- visitors to this website;
- people who make an enquiry with us;
- our clients, and the directors, officers, partners, employees and beneficial owners of our clients;
- suppliers, contractors and other business contacts.
Where we process personal data on behalf of a client — for example, employee data supplied to us so that we can run a payroll — we act as a data processor and the client remains the data controller. In those cases, we process the data only in accordance with the client's instructions and our engagement terms, and the client's own privacy notice will govern how that data is used.
3. Personal data we collect
Depending on your relationship with us, we may collect and hold the following categories of personal data.
Enquiry and contact data
- your name and the name of your business;
- your email address and telephone number;
- your preferred method and time of contact;
- the content of your enquiry and any subsequent correspondence.
Client and engagement data
- contact and role details for directors, partners, officers and staff we deal with;
- identification and verification data required by anti-money-laundering law, which may include a copy of a passport, driving licence or other identity document, proof of address, and date of birth;
- information about beneficial ownership and control of the business;
- financial and accounting records, tax references, National Insurance numbers and Unique Taxpayer References;
- bank account details, where needed to provide our services or to take payment of our fees;
- payroll data where we provide payroll services, which may include salary, tax codes, pension contributions and absence records;
- records of the advice we have given and the work we have carried out.
Technical data
- information about your device, browser type and operating system;
- your IP address, which may indicate your approximate location;
- pages visited on this website and the dates and times of those visits.
Technical data is collected automatically by our web hosting infrastructure. Please see our Cookie Policy for details of the cookies this website uses.
Where we obtain the data
Most of the personal data we hold is provided directly by you or by the business you represent. We may also obtain personal data from:
- your previous accountant, where you instruct us to request professional clearance and the handover of records;
- publicly available sources, including Companies House and the HMRC public registers;
- identity verification and anti-money-laundering screening providers;
- cloud accounting platforms that you have authorised us to access, such as Xero, QuickBooks or Sage;
- HMRC, where we are appointed as your authorised agent.
4. Why we use personal data and our lawful basis
We only use personal data where the law allows us to. The table below sets out our purposes and the lawful basis we rely on for each.
| Purpose | Lawful basis |
|---|---|
| Responding to an enquiry and providing a quotation | Legitimate interests — responding to a request made of us and pursuing potential business; or steps taken at your request prior to entering a contract |
| Providing accountancy, tax, reporting and advisory services | Performance of a contract with you, or with the business you represent |
| Client due diligence and anti-money-laundering checks | Compliance with a legal obligation, including the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 |
| Filing returns and accounts with HMRC and Companies House | Compliance with a legal obligation; performance of a contract |
| Invoicing, collecting payment and maintaining our own accounting records | Performance of a contract; compliance with a legal obligation; legitimate interests in recovering sums owed |
| Maintaining records of advice given, for quality and to protect our legal position | Legitimate interests in defending potential claims and demonstrating professional standards |
| Keeping our systems secure and preventing fraud | Legitimate interests in protecting our business and our clients' data; compliance with a legal obligation |
| Sending occasional updates about our services to existing clients | Legitimate interests; or consent where required |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights and freedoms, and we have concluded that they are not. You may object to processing carried out on this basis — see section 10.
5. Special category data
We do not generally seek out special category data (such as data revealing health, racial or ethnic origin, or religious beliefs). However, we may come across it incidentally in the course of our work — for example, health information within payroll or sickness absence records, or when advising on a matter where a person's health is relevant.
Where we process special category data we do so only where a condition under Article 9 of the UK GDPR applies, most commonly because processing is necessary in connection with employment or social security law, or for the establishment, exercise or defence of legal claims.
6. Who we share personal data with
We do not sell personal data, and we do not share it with third parties for their own marketing purposes. We may share personal data with the following categories of recipient.
- HM Revenue & Customs and Companies House — where we submit returns, accounts or filings on your behalf as your authorised agent.
- Cloud software providers — the accounting, payroll, tax filing, document management and practice management platforms in which your records are held and processed.
- IT and hosting providers — including email, backup, file storage and website hosting suppliers who support our systems.
- Identity verification and screening providers — used to carry out the client due diligence checks the law requires of us.
- Professional advisers — our own legal advisers, insurers and, where relevant, tax specialists or counsel instructed on a client matter.
- Our professional body and quality reviewers — who may inspect a sample of client files as part of practice monitoring, subject to strict confidentiality.
- Banks and payment providers — in connection with the payment of our fees.
- Third parties you instruct us to deal with — such as your bank, lender, solicitor or an incoming accountant.
- Law enforcement and regulators — where we are required or permitted by law to disclose information. In particular, we are obliged to report knowledge or suspicion of money laundering to the National Crime Agency, and we are prohibited by law from telling you that we have done so.
Where a third party acts as our processor, we put a written contract in place requiring them to keep the data secure, to use it only for the purposes we specify, and to delete or return it at the end of the arrangement.
7. International transfers
We aim to keep personal data within the United Kingdom or the European Economic Area. Some of our software and IT suppliers may store or access data outside the UK. Where that happens, we ensure an appropriate safeguard recognised under UK data protection law is in place — normally UK adequacy regulations covering the destination country, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
8. How long we keep personal data
We keep personal data only for as long as we need it, taking into account our legal and regulatory obligations and the possibility of future claims. Our general periods are set out below.
| Type of record | Retention period |
|---|---|
| Enquiries that do not become engagements | Up to 12 months from the last contact |
| Client engagement files, accounting and tax records, and records of advice | 7 years from the end of the engagement or the relevant tax year, whichever is later |
| Anti-money-laundering identification and due diligence records | 5 years from the end of the business relationship, as required by law |
| Payroll records processed on behalf of a client | In accordance with the client's instructions, and generally not less than 6 years |
| Our own invoicing and accounting records | 7 years |
| Website server logs | Typically no more than 12 months |
At the end of the applicable period we securely delete or anonymise the data, unless we are required to retain it for longer by law or because it is relevant to an ongoing or reasonably anticipated legal matter.
9. How we protect personal data
We take the security of personal data seriously and maintain technical and organisational measures appropriate to the risk, including:
- encryption of data in transit and at rest within the platforms we use;
- access controls, so that advisers and staff can only reach the data they need for their work;
- multi-factor authentication on our email, accounting and practice management systems;
- secure channels for exchanging sensitive documents, rather than ordinary email attachments;
- use of reputable, established suppliers who are themselves subject to recognised security standards;
- regular backups, and confidentiality obligations binding everyone who works with us.
No transmission of information over the internet can be guaranteed to be completely secure. If you need to send us sensitive financial information, please ask us for a secure link rather than attaching it to an email or entering it into the enquiry form on this website. We have procedures in place to deal with any suspected personal data breach and will notify you and the Information Commissioner's Office where we are legally required to do so.
10. Your rights
Under UK data protection law you have the following rights, which you can exercise free of charge.
- Access — to be told what personal data we hold about you and to receive a copy of it.
- Rectification — to have inaccurate data corrected, or incomplete data completed.
- Erasure — to have data deleted where there is no good reason for us to continue holding it.
- Restriction — to ask us to suspend the processing of your data in certain circumstances.
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Portability — to receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Withdrawal of consent — where we rely on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.
These rights are not absolute. In particular, we may not be able to delete or stop processing data that we are required by law to retain, such as anti-money-laundering records or information needed for statutory filings. If we cannot comply with a request, we will explain why.
To make a request, please contact us using the details in section 15. We may need to verify your identity before responding. We will reply within one month, and will tell you if we need longer because the request is complex.
We do not carry out automated decision-making or profiling that produces legal effects concerning you.
11. Marketing preferences
We may send existing clients occasional updates about our services and about changes in tax or reporting requirements that are likely to affect them. We do not send unsolicited marketing to people who have simply visited this website, and we do not pass contact details to third parties for marketing.
You can ask us to stop sending marketing communications at any time, either by using the unsubscribe link in any message or by contacting us directly. Opting out of marketing will not stop us sending you communications that are necessary to provide our services, such as reminders about filing deadlines.
12. Cookies
This website uses only the cookies and similar technologies necessary for it to function and to remain secure. Full details are set out in our Cookie Policy.
13. Complaints
If you are unhappy with how we have handled your personal data, please contact us first so that we have the opportunity to put matters right. We take all such concerns seriously and will investigate promptly.
You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
14. Changes to this policy
We review this policy regularly and may update it to reflect changes in our practices, our software suppliers, or the law. The date at the top of this page shows when it was last revised. Where a change materially affects how we use your personal data, we will take reasonable steps to notify you directly.
15. Contacting us
For any question about this policy, or to exercise any of your rights, please contact us:
RRH Advisory Limited
Email: contact@rrhadvisory.net
Telephone: +44 1887 593331
Post: 88 Miswell Lane, Tring, England, HP23 4EX
Please mark data protection enquiries clearly so that they reach the right person without delay.