I Sumar & Co Ltd
Privacy Notice
ISC-PRIVACY-v2.0
1. WHO WE ARE
I Sumar & Co Ltd, company number 07901135, VAT registration GB 201388928, of
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, is the controller of
personal data processed for the purposes described in this notice. Contact:
info@isumarco.com; 020 7183 1432; www.isumarco.com.
Our AML supervisor is HMRC, reference XSML00000151117. HMRC is our sole AML
supervisory body. We do not claim membership of, affiliation with, or
supervision by any professional accountancy or tax body. The Information
Commissioner is the statutory authority responsible for UK data-protection
law. ICO registration number: ZA123828.
2. WHO THIS NOTICE COVERS
This notice covers clients and, where relevant, directors, shareholders,
PSCs, partners, LLP members, trustees, employees, authorised
representatives, beneficial owners and other persons whose information is
processed in connection with our work. A connected person's data may be
processed even though that person is not our client. A separate short
Non-Client Person AML and Privacy Notice is available for those persons.
3. WHAT INFORMATION WE PROCESS
Depending on the engagement and legal obligations, we may process identity
and contact details; Companies House and ownership/control information; tax
references; financial, accounting, payroll, pension and employment
information; bank/payment information; correspondence and call/meeting
notes; identity-verification and AML screening information;
source-of-funds/source-of-wealth information; device/portal records;
Companies House personal-code information supplied for an authorised filing;
and information relating to advisers, employees, family members, beneficial
owners and other connected persons where relevant.
We may also process special-category or criminal-offence information where
it arises and there is an applicable lawful basis and additional condition,
including information required for AML, employment/payroll or legal-claims
purposes.
4. WHY WE PROCESS INFORMATION AND OUR LAWFUL BASES
We process information to take steps before engagement; perform our contract
with a client; prepare accounts, tax, payroll, VAT, bookkeeping and
Companies House work; communicate; manage billing; prevent fraud and
impersonation; protect systems; comply with tax, AML, sanctions, company-law
and other legal duties; maintain records; establish or defend legal claims;
and administer and quality-control our services.
The lawful basis depends on the purpose. It may include UK GDPR Article
6(1)(b) (contract or pre-contract steps with the relevant individual),
Article 6(1)(c) (legal obligation), and Article 6(1)(f) (legitimate
interests). For a person who is not our client, we do not rely on a contract
with that person merely because they are connected to a client. Mandatory
AML processing is principally based on legal obligation. We use consent only
where a genuine choice is appropriate or another law requires it. Signing a
Letter of Engagement acknowledges this Privacy Notice but is not blanket UK
GDPR consent.
5. AML DATA - PURPOSE LIMITATION
To comply with MLR 2017 we must obtain and verify information about clients
and, where applicable, beneficial owners and persons acting on their behalf.
This may include identity/address evidence and electronic identity, PEP,
sanctions and adverse-media checks. FirmCheck is currently used as part of
our AML/KYC workflow and screening process.
Personal data obtained for MLR 2017 purposes will be processed only for the
purposes of preventing money laundering, terrorist financing or
proliferation financing unless use for another purpose is permitted by
another enactment or the data subject has consented to that other use.
Mandatory AML processing is not made optional by seeking consent.
6. HOW WE COLLECT INFORMATION
We collect information directly from the person concerned and authorised
representatives; from a client or another person connected to the
engagement; from Companies House, HMRC and other public
authorities/registers; from previous advisers; from systems the client
authorises; from FirmCheck and other AML/identity/sanctions providers; and
from information generated in the course of the relationship.
Where we obtain personal data from someone other than the person it relates
to, we provide the applicable Article 14 privacy information within the
period required by law, subject to any lawful exemption.
7. COMMUNICATIONS, CALLS AND MEETINGS
We may use secure portal, email, telephone, SMS/text, WhatsApp Business,
Microsoft Teams, Zoom, cloud-accounting platforms and post. Material
communications may be copied, exported or summarised to the client file.
Where a call or online meeting is recorded or transcribed, we provide
appropriate notice.
We recommend the secure portal for sensitive identity, banking,
tax-reference and Companies House-code information. Ordinary messaging/email
providers may process communications under their own terms and our processor
arrangements where applicable.
8. ARTIFICIAL INTELLIGENCE AND AUTOMATION
We may use AI and automation to assist staff with document classification,
data extraction, summaries, drafting, workflow, quality review and
administrative support. We apply human review to professional advice,
filings and AML determinations. We do not use solely automated
decision-making that produces legal or similarly significant effects without
the safeguards required by law.
AI and cloud suppliers may process limited information as processors where
necessary to provide services. Our current processor register must reflect
the systems actually in production, and restricted transfers are handled
under applicable UK data-protection safeguards.
9. WHO WE SHARE INFORMATION WITH
Where necessary and lawful, recipients may include HMRC; Companies House;
the CIC Regulator or a charity regulator where relevant to the client's
legal form; pension providers; payroll/accounting software providers;
banks/payment processors where relevant; FirmCheck and other
AML/identity/sanctions providers; IT, cloud, email, portal, communications
and AI providers; professional indemnity insurers; solicitors and other
professional advisers; an authorised successor/alternate practitioner;
law-enforcement bodies, the NCA, courts, tribunals and statutory
authorities; and other persons authorised by the relevant client or data
subject.
We do not sell personal data to advertisers.
10. PROCESSORS AND INTERNATIONAL TRANSFERS
We maintain an Article 28 processor register for systems actually used by
the Firm. A current list of material processors is available on reasonable
request. Supplier names, sub-processors and hosting arrangements can change,
so the operational register is the controlling list and must be kept
current.
If personal data is transferred outside the UK, we use an applicable
adequacy regulation or appropriate safeguard such as the UK International
Data Transfer Agreement or UK Addendum to the EU Standard Contractual
Clauses, together with supplementary measures where required.
11. RETENTION
We keep records only for as long as reasonably necessary for the purposes
for which they are held and to meet tax, accounting, AML, contractual,
insurance and legal-claims requirements. AML/CDD records are normally
retained for five years from the end of the relevant business relationship
or other statutory point, subject to lawful exceptions. Other engagement
records may be retained for longer where necessary for tax history,
continuity, legal claims or another lawful reason.
Companies House personal codes and other security credentials are stored
only where necessary for the authorised filing/agency purpose, with access
restricted, and are not used for unrelated purposes.
12. YOUR RIGHTS
Subject to legal conditions and exemptions, individuals may have rights of
access, rectification, erasure, restriction, objection, portability and
rights relating to automated decision-making. Where we genuinely rely on
consent for a purpose, it may be withdrawn for that purpose at any time
without affecting earlier lawful processing.
A request to erase data does not override our duty to keep AML records, tax
records, evidence required for legal claims or other information law
requires us to retain. AML/tipping-off and crime-prevention rules may also
lawfully restrict information we can provide in particular circumstances.
13. MARKETING
Professional-service communications about an existing engagement are not
direct marketing. We comply with UK GDPR and PECR for optional marketing
communications. Opting out of marketing does not affect professional
services.
14. SECURITY
We use proportionate technical and organisational measures including
controlled accounts, access controls, authentication, backups, staff
procedures and independent verification of sensitive instructions. No
electronic system is completely risk-free; please notify us promptly if you
suspect compromise of an account, device, email address, phone number or
credential.
15. COMPLAINTS AND CONTACT
Contact us first at info@isumarco.com if you have a data-protection question
or complaint. You also have the right to complain to the Information
Commissioner's Office. Details are available at ico.org.uk.
16. CHANGES TO THIS NOTICE
We may update this notice when law, technology, suppliers or our services
change. We make the current notice available through our normal channels and
draw attention to material changes where appropriate.