Marsh Accounting - Privacy Notice
This Privacy Notice provides details of the personal data we collect from you, what we do with it, how you might access it and who it might be shared with.
Our Contact Information (Data Controller)
Marsh Accounting
4 Cornfield Terrace
Eastbourne
BN21 4NN
Telephone: 01323 411416
Company Email: info@marshac.co.uk
What we do with your personal data
We process personal data only for the purpose for which they are collected. The purpose is dependent on whether you use only our website, or additionally, our services. If you use our services you are required to register and we collect your personal data. We use this personal data for the provision of the service or the performance of the contract. We may use your personal data for other similar purposes, including marketing and communications, but that will only occur in the case we have your consent or another legal justification for doing so.
From our Service Providers we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose Legal basis Retention period
Organisation's administration and management 6(1)(f) - it's in our legitimate interest (Business operations and due Diligence) Until tax or other retention period expires
From our Suppliers we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose Legal basis Retention period
Contact management 6(1)(b) - we have a contract with the data subject Until contract completed
From our Customers and Clients we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose Legal basis Retention period
Administrative enquiries 6(1)(a) - we have the data subject's consent Until consent withdrawn
Payment Card Processing 6(1)(b) - we have a contract with the data subject Until contract completed
Support requests 6(1)(b) - we have a contract with the data subject Until tax or other retention period expires
Customer analysis 6(1)(b) - we have a contract with the data subject Until tax or other retention period expires
Communications, marketing and intelligence 6(1)(b) - we have a contract with the data subject Until contract completed
Contact management 6(1)(b) - we have a contract with the data subject Until tax or other retention period expires
Employee monitoring 6(1)(b) - we have a contract with the data subject Until contract completed
Employee performance management 6(1)(b) - we have a contract with the data subject Until contract completed
Employee Recruitment and Employment 6(1)(b) - steps are required prior to a contract with the data subject Until contract completed
Business operations and due diligence 6(1)(b) - steps are required prior to a contract with the data subject Until tax or other retention period expires
Archiving 6(1)(b) - we have a contract with the data subject Until tax or other retention period expires
Identity verification 6(1)(b) - steps are required prior to a contract with the data subject Until contract completed
Industry specific regulation, standards and intelligence 6(1)(b) - steps are required prior to a contract with the data subject Until contract completed
Legal and regulatory compliance 6(1)(b) - steps are required prior to a contract with the data subject Until tax or other retention period expires
Organisation's administration and management 6(1)(b) - we have a contract with the data subject Until contract completed
Supplier Management 6(1)(b) - we have a contract with the data subject Until contract completed
From our Governing Body we process and retain personal data for the following purposes and periods, with the applicable legal basis.
Processing purpose Legal basis Retention period
Organisation's administration and management 6(1)(f) - it's in our legitimate interest (Industry specific regulation, standards and intelligence) Until tax or other retention period expires
Legal and regulatory compliance 6(1)(f) - it's in our legitimate interest (Legal and regulatory compliance) Until tax or other retention period expires
Industry specific regulation, standards and intelligence 6(1)(f) - it's in our legitimate interest (Legal and regulatory compliance) Until tax or other retention period expires
Fraud detection and prevention 6(1)(f) - it's in our legitimate interest (Legal and regulatory compliance) Until tax or other retention period expires
Identity verification 6(1)(f) - it's in our legitimate interest (Legal and regulatory compliance) Until tax or other retention period expires
What personal data do we collect?
The personal data we collect depends on whether you just visit our website or use our services. If you visit our website, you do not need to provide us with any personal data. However, your browser transmits some data automatically, such as the date and time of retrieval of one of our web pages, your browser type and settings, your operating system, the last web page you visited, the data transmitted and the access status, and your IP address.
If you use our services, personal data is required to fulfill the requirements of a contractual or service relationship, which may exist between you and our organisation.
We collect:
Employment History
Family
Financial Details
Identification Number
Location Information
Name
Online Identifiers
Photographs together with Identifiers
Telephone contact details
Banking Details
Confidential Correspondence
Credit History
Digital Images
Education History
Email, Social Networks
Employee Performance Data
Visual Images
We collect your personal data from the following indirect sources
Data subject type Personal data type Indirect source name
Customers and Clients Banking Details Stripe or Go Cardless payment service
Customers and Clients Banking Details Stripe payment serviceHow do we look after personal data?
We limit the amount of personal data collected only to what is fit for the purpose, as described above. We restrict, secure and control all of our information assets against unauthorised access, damage, loss or destruction; whether physical or electronic. We retain personal data only for as long as is described above, to respond to your requests, or longer if required by law. If we retain your personal data for historical or statistical purposes we ensure that the personal data cannot be used further. While in our possession, together with your assistance, we try to maintain the accuracy of your personal data.
How can you access your personal data?
You have the right to request access to any of your personal data we may hold. If any of that information is incorrect, you may request that we correct it. If we are improperly using your information, you may request that we stop using it or even delete it completely.
If you would like to make a request to see what personal data of yours we might hold, you may make a request from our company website.
Where you have previously given your consent to process your personal data, you also have the right to request that we port or transfer your personal data to a different service provider or to yourself, if you so wish.
Where it may have been necessary to get your consent to use your personal data, at any moment, you have the right to withdraw that consent. If you withdraw your consent, we will cease using your personal data without affecting the lawfulness of processing based on consent before your withdrawal.
Our Supervisory Authority
You have the right to lodge a complaint with any Supervisory Authority. See our Supervisory Authority contact details below.
Information Commissioner’s Office
Water Lane, Wycliffe House
Wilmslow - Cheshire SK9 5AF
United Kingdom
casework@ico.org.uk
0303 123 1113
www.ico.org.uk