Skip to content
A.C.T. Audit
Home Services About Careers Resources
Contact us

A.C.T. AUDIT LIMITED

Website Privacy Policy (UK)

  • Last updated: 29 July 2026
  • Effective from: 29 July 2026
  • Version: First

1. Who we are and what this policy covers

This policy applies to http://www.actaudit.london and to any other website operated by A.C.T. Audit Limited that expressly links to this policy. References to "we", "us" and "our" are to A.C.T. Audit Limited.

A.C.T. Audit Limited is the controller of the personal data described in this policy. This means that we decide why and how your personal data is processed when you visit or interact with our website.

Company A.C.T. Audit Limited
Company number 10485471
Registered office Berkeley Suite, 35 Berkeley Square, Mayfair, London, United Kingdom, W1J 5BF
Correspondence address 27 Hill Street, Mayfair, London W1J 5LP, United Kingdom
Data Protection Officer We have not appointed a statutory Data Protection Officer. Privacy compliance is overseen by our Head of Legal and Compliance
Privacy contact Head of Legal and Compliance
Website covered by this policy http://www.actaudit.london
Website platform WordPress.com
Cookie preference tool CookieYes
Contact for privacy queries GDPR@act.audit / +44 (0) 207 4326 050 / Fax +44 (0) 207 4326 051
Supervisory authority Information Commissioner’s Office (ICO), ico.org.uk

1.1 Relationship with our other privacy documents

This policy explains how we handle personal data collected through our website and through the enquiries, applications and communications that begin there. It should be read together with:

  • the Data Privacy section of our Terms of Business, which explains how we process personal data in connection with the provision of our professional services, including the purposes for processing, lawful bases, data sharing, international transfers, security measures, and the rights and responsibilities of both parties under applicable data protection law; and

  • our Cookie and Similar Technologies Policy, which identifies each cookie and similar technology used on our website, its provider, purpose, consent status, and duration.

Where a client engagement follows from a website enquiry, the processing of your personal data will also be governed by our engagement terms.

We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR).

2. The personal data we collect about you

2.1 Personal data you give us

You may give us personal data when you complete a form on our website, contact us by email or telephone, or otherwise correspond with us. This may include:

  • your name;

  • your business or personal contact details, including email address, and telephone number; and

  • the content of your enquiry or message and any documents you choose to send us.

Please do not submit special category data (such as information about health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, or sexual orientation) or details of criminal offences through our website forms. We do not seek such data through the website and it is not necessary for us to respond to a general enquiry. Where the provision of such data is genuinely required, for example in connection with a recruitment or a specific engagement, we will tell you what we need, why we need it and the lawful basis on which we will process it.

General website forms must not be used to send confidential client files or sensitive personal data. Client documents should be sent only through the secure facilities we provide.

2.2 Personal data we collect automatically

When you visit our website, we and our service providers may automatically collect:

  • your IP address and the approximate location derived from it;

  • your device type, operating system, browser type and version, screen and language settings;

  • the pages you view, the time and duration of your visit, the links you follow and the website or source from which you reached us; and

  • interaction data such as mouse movement, scrolling and clicks, including heatmaps and session replays generated by Microsoft Clarity.

Technologies that are strictly necessary for the secure and proper operation of the website are always active. All other technologies, including analytics, functionality and targeting technologies, are switched off unless and until you consent to them through our cookie preference centre.

2.3 Personal data we obtain from other sources

We may also obtain personal data about you from:

  • publicly available sources, including Companies House and other commercial registers, published accounts, the press and the internet;

  • advertising and social media platforms, including LinkedIn and Meta, where you have interacted with our advertising and where the relevant technologies have been enabled with your consent;

  • our website platform, security, analytics and technology providers, where you have consented to the relevant cookies and technologies; and

  • third parties who refer you to us, such as introducers, banks and other professional advisers, and, where an engagement is contemplated.

We process personal data obtained from these sources in accordance with data protection law and, where we have not obtained the data from you directly, we will provide the information required by Article 14 of the UK GDPR unless an exemption applies.

3. How and why we use your personal data

The table below sets out the categories of personal data we process through or in connection with our website, the purposes for which we process it and the lawful basis we rely on under Article 6 UK GDPR.

This section describes processing that arises from your use of our website. It does not describe the personal data we process when we act for you as a client — including identity and verification data, financial and tax information, and client due diligence records. That processing is described in our terms of business.

Processing activity Personal data Purpose Lawful basis
Enquiries and contact form Name, email address, phone number, the content of your message, and any other information you choose to provide. To respond to your enquiry, to provide information about our services and to keep a record of the correspondence. Article 6(1)(f) — our legitimate interest in responding to enquiries and keeping a record of them. Where your enquiry is a request that we provide services to you, Article 6(1)(b) — steps taken at your request before entering a contract.
Enquiries that progress to an engagement The enquiry and contact details described above. To assess whether we are able to act, to carry out conflict checks and to open a client file. If you become a client we then process a wider set of personal data — including identity, financial and due diligence information — which is described in the data privacy clauses in our terms of business, and not in this policy. Article 6(1)(b) — steps taken at your request before entering a contract.
Website security and availability IP address, device and browser information, access times, pages requested, referring URL and server log data. To operate the website securely, to balance load, to prevent and detect fraud, bot activity and attacks, and to diagnose faults. Article 6(1)(f) — our legitimate interest in maintaining a secure and functioning website.
Website analytics and performance Pages visited, session duration, device and browser type, approximate location, referral source, and mouse movement, scrolling and clicks. To measure how the website is used, to identify usability problems and to improve our website and content. Article 6(1)(a) — consent, given through our cookie preference centre. Consent under PECR is also required for the underlying technologies.
Advertising and audience measurement Advertising and device identifiers, pages viewed, and interaction and conversion events transmitted to advertising platforms through the LinkedIn Insight Tag and the Meta Pixel (if used in the future). To measure the results of our advertising on LinkedIn and Meta platforms and to build retargeting, matched, custom and lookalike audiences. Article 6(1)(a) — consent, given through our cookie preference centre.
Embedded content IP address, device and browser information, and the fact that you viewed or interacted with the content, collected by the provider of the embedded video. To display embedded video within our pages. Embedded content is blocked until you consent. Article 6(1)(a) — consent, given through our cookie preference centre.
Legal and regulatory matters Personal data collected through the website, as described above. To respond and comply with legal and regulatory enquiries and to comply with court orders. Article 6(1)(c) — legal obligation.
Legal claims Personal data collected through the website, as described above. To establish, exercise or defend legal claims, and to comply with court orders. Article 6(1)(f) — our legitimate interest in protecting our legal position.

4. Cookies and similar technologies

We use cookies, pixels, web beacons, tags, scripts, local storage and similar technologies on our website. The technologies we use, the organisations that provide them, their purposes, their categories and their durations are set out in our Cookie and Similar Technologies Policy.

Consent to non-essential technologies is collected and recorded through CookieYes. When you first visit our website, technologies that require consent are switched off. You may select "Accept all", "Reject all" or "Save My Preferences" through our cookie banner, and you may change or withdraw your choices at any time by selecting the "Cookie " icon in the website footer.

5. Marketing communications

Where PECR’s soft opt-in applies, we may email an individual about our own similar services only where we obtained their contact details directly during a sale or negotiation for sale and offered a clear opportunity to opt out when the details were collected and in every subsequent message.

6. Who we share your personal data with

We do not sell your personal data. We may share it with:

  • our own personnel, on a need-to-know basis;

  • service providers who process personal data on our behalf under a written contract meeting the requirements of Article 28 UK GDPR, including our website platform, hosting, analytics, advertising, IT, cloud storage, practice management, payroll and communications providers;

  • other professional advisers, including lawyers, auditors, insurers and banks;

  • HM Revenue & Customs, Companies House, the National Crime Agency, our professional and anti-money laundering supervisory bodies, the Association of Chartered Certified Accountants (ACCA) and other regulators, law enforcement agencies and courts, where required or permitted by law; and

  • a purchaser or prospective purchaser of our business or assets, or their advisers.

The third-party technologies used on our website, and the providers of those technologies, are identified in the table at section 4 of our Cookie and Similar Technologies Policy.

The following third-party service providers may also process personal data on our behalf:

  • Website platform/hosting and embedded video: WordPress.com (Automattic)

  • Consent tool: CookieYes and Google Tag Manager

  • Backup: UpdraftPlus and All-in-One WP Migration

  • Analytics: Google Analytics 4, Jetpack Stats, Microsoft Clarity

  • Advertising: LinkedIn Insight Tag, Meta

7. International transfers

Several of the providers identified in section 6 are established outside the United Kingdom, principally in the United States, and personal data may therefore be transferred outside the UK and the European Economic Area based on UK-US Data Bridge. We rely on the UK Extension to the EU–US Data Privacy Framework where the particular recipient is validly participating in it, supported by a transfer risk assessment. You may contact us using the details in section 1 to request further information or a copy of the safeguards used for a particular transfer.

8. How long we keep your personal data

We keep personal data only for as long as is necessary for the purposes for which it was collected. The table sets out the periods applicable to personal data collected through our website.

Category Retention period Basis
Enquiries that do not become engagements Twelve months from last contact Legitimate interests
Enquiries that become engagements Transferred to the client file and retained in accordance with the data privacy clauses of our terms of business Contract; legal obligation
Cookies and similar technologies As stated in our Cookie and Similar Technologies Policy Consent; PECR
Website server logs Twelve months Legitimate interests

At the end of the applicable period we will securely delete the personal data, unless we are required to retain it for longer by law or in connection with an actual or anticipated legal claim, regulatory investigation or professional complaint.

9. How we protect your personal data

We maintain technical and organisational measures appropriate to the risk, including access controls, encryption of data in transit, secure configuration of our website and hosting environment, logging and monitoring, staff confidentiality obligations and training, and contractual controls on our processors.

We have procedures in place to deal with any suspected personal data breach and will notify you and the Information Commissioner’s Office (ICO) where we are legally required to do so.

No transmission of information over the internet is entirely secure. Where you send us confidential information, we encourage you to use the secure facilities we make available rather than ordinary email.

10. Your rights

The rights listed in the table below are the Articles 15 to 21 rights, the Article 7(3) right to withdraw consent, and the Article 77 right to complain. The clause commits to responding within one month, extendable by two further months, and free of charge unless the request is manifestly unfounded or excessive.

Right What it means
Access (Article 15) To be told whether we process your personal data and, if so, to receive a copy of it and information about how it is processed.
Rectification (Article 16) To have inaccurate personal data corrected and incomplete personal data completed.
Erasure (Article 17) To have your personal data deleted in certain circumstances. This right does not apply where we are required by law to retain the data, including under the Money Laundering Regulations 2017.
Restriction (Article 18) To have the processing of your personal data restricted in certain circumstances.
Data portability (Article 20) To receive personal data you have provided to us in a structured, commonly used and machine-readable format, where we process it by automated means on the basis of consent or contract.
Objection (Article 21) To object to processing carried out on the basis of legitimate interests, and to object at any time and without qualification to processing for direct marketing purposes.
Withdraw consent (Article 7(3)) To withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Complain (Article 77) To lodge a complaint with the Information Commissioner's Office. See section 17.

11. Automated decision-making and profiling

We do not make decisions about you based solely on automated processing which produce legal effects concerning you or similarly significantly affect you.

Where you have consented to analytical and advertising technologies, information about your use of our website may be used by the relevant providers to build audiences and to make advertising more relevant to you. This may constitute profiling for direct marketing purposes, and you may object to it at any time by withdrawing your consent through our cookie preference centre.

12. Children

Our website is directed at businesses and their professional advisers and is not intended for children.

13. Third-party links

Our website may contain links to, and embedded content from, third-party websites, plug-ins and applications. Following a link or interacting with embedded content may allow the third party to collect or share data about you. We do not control those third parties and are not responsible for their privacy notices. We encourage you to read the privacy notice of every website you visit.

14. Changes to this policy

We may update this policy from time to time to reflect changes to our website, our services, our service providers or our legal obligations. We will change the "Last updated" date at the top of this policy whenever we do so.

Where a change introduces a materially different purpose or a new recipient that is not covered by information we have already given you, we will bring the change to your attention and, where consent is required, obtain fresh consent before proceeding.

We recommend that you review this policy periodically.

15. Contact us and how to complain

If you are unhappy with how we have handled your personal data, please contact us first at GDPR@act.audit so that we have the opportunity to resolve the matter. We will acknowledge your complaint and respond to it without undue delay.

We will acknowledge receipt of your complaint within 30 days, investigate it appropriately and without undue delay, keep you informed of its progress where appropriate, and communicate the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

Field Detail
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline 0303 123 1113
Website ico.org.uk

Making a complaint to the ICO does not affect any other legal remedy available to you.

A.C.T. Audit provides independent audit, assurance, accounting, tax, and advisory support for organisations operating in complex and regulated environments.
Linkedin-in

Explore

  • About
  • Services
  • Careers
  • Resources
  • Contact us

Services

  • Audit & Assurance
  • Accounting & Reporting
  • Tax Compliance
  • Tax Technical Advisory
  • Transaction Support
  • Business Process

Contact Us

Address

27 Hill Street Mayfair London W1J 5LP UK

Phone

+44 (0) 207 434 5804

Email

info@actaudit.london

ACCA-Logo
Member of the Association of Chartered Certified Accountants (ACCA No. 3984782) | Copyright © 2026 A.C.T. Audit
Privacy Policy
Sitemap
Cookie Policy