I Sumar & Co Ltd

Privacy Notice

ISC-PRIVACY-v2.0

1. WHO WE ARE I Sumar & Co Ltd, company number 07901135, VAT registration GB 201388928, of 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, is the controller of personal data processed for the purposes described in this notice. Contact: info@isumarco.com; 020 7183 1432; www.isumarco.com. Our AML supervisor is HMRC, reference XSML00000151117. HMRC is our sole AML supervisory body. We do not claim membership of, affiliation with, or supervision by any professional accountancy or tax body. The Information Commissioner is the statutory authority responsible for UK data-protection law. ICO registration number: ZA123828. 2. WHO THIS NOTICE COVERS This notice covers clients and, where relevant, directors, shareholders, PSCs, partners, LLP members, trustees, employees, authorised representatives, beneficial owners and other persons whose information is processed in connection with our work. A connected person's data may be processed even though that person is not our client. A separate short Non-Client Person AML and Privacy Notice is available for those persons. 3. WHAT INFORMATION WE PROCESS Depending on the engagement and legal obligations, we may process identity and contact details; Companies House and ownership/control information; tax references; financial, accounting, payroll, pension and employment information; bank/payment information; correspondence and call/meeting notes; identity-verification and AML screening information; source-of-funds/source-of-wealth information; device/portal records; Companies House personal-code information supplied for an authorised filing; and information relating to advisers, employees, family members, beneficial owners and other connected persons where relevant. We may also process special-category or criminal-offence information where it arises and there is an applicable lawful basis and additional condition, including information required for AML, employment/payroll or legal-claims purposes. 4. WHY WE PROCESS INFORMATION AND OUR LAWFUL BASES We process information to take steps before engagement; perform our contract with a client; prepare accounts, tax, payroll, VAT, bookkeeping and Companies House work; communicate; manage billing; prevent fraud and impersonation; protect systems; comply with tax, AML, sanctions, company-law and other legal duties; maintain records; establish or defend legal claims; and administer and quality-control our services. The lawful basis depends on the purpose. It may include UK GDPR Article 6(1)(b) (contract or pre-contract steps with the relevant individual), Article 6(1)(c) (legal obligation), and Article 6(1)(f) (legitimate interests). For a person who is not our client, we do not rely on a contract with that person merely because they are connected to a client. Mandatory AML processing is principally based on legal obligation. We use consent only where a genuine choice is appropriate or another law requires it. Signing a Letter of Engagement acknowledges this Privacy Notice but is not blanket UK GDPR consent. 5. AML DATA - PURPOSE LIMITATION To comply with MLR 2017 we must obtain and verify information about clients and, where applicable, beneficial owners and persons acting on their behalf. This may include identity/address evidence and electronic identity, PEP, sanctions and adverse-media checks. FirmCheck is currently used as part of our AML/KYC workflow and screening process. Personal data obtained for MLR 2017 purposes will be processed only for the purposes of preventing money laundering, terrorist financing or proliferation financing unless use for another purpose is permitted by another enactment or the data subject has consented to that other use. Mandatory AML processing is not made optional by seeking consent. 6. HOW WE COLLECT INFORMATION We collect information directly from the person concerned and authorised representatives; from a client or another person connected to the engagement; from Companies House, HMRC and other public authorities/registers; from previous advisers; from systems the client authorises; from FirmCheck and other AML/identity/sanctions providers; and from information generated in the course of the relationship. Where we obtain personal data from someone other than the person it relates to, we provide the applicable Article 14 privacy information within the period required by law, subject to any lawful exemption. 7. COMMUNICATIONS, CALLS AND MEETINGS We may use secure portal, email, telephone, SMS/text, WhatsApp Business, Microsoft Teams, Zoom, cloud-accounting platforms and post. Material communications may be copied, exported or summarised to the client file. Where a call or online meeting is recorded or transcribed, we provide appropriate notice. We recommend the secure portal for sensitive identity, banking, tax-reference and Companies House-code information. Ordinary messaging/email providers may process communications under their own terms and our processor arrangements where applicable. 8. ARTIFICIAL INTELLIGENCE AND AUTOMATION We may use AI and automation to assist staff with document classification, data extraction, summaries, drafting, workflow, quality review and administrative support. We apply human review to professional advice, filings and AML determinations. We do not use solely automated decision-making that produces legal or similarly significant effects without the safeguards required by law. AI and cloud suppliers may process limited information as processors where necessary to provide services. Our current processor register must reflect the systems actually in production, and restricted transfers are handled under applicable UK data-protection safeguards. 9. WHO WE SHARE INFORMATION WITH Where necessary and lawful, recipients may include HMRC; Companies House; the CIC Regulator or a charity regulator where relevant to the client's legal form; pension providers; payroll/accounting software providers; banks/payment processors where relevant; FirmCheck and other AML/identity/sanctions providers; IT, cloud, email, portal, communications and AI providers; professional indemnity insurers; solicitors and other professional advisers; an authorised successor/alternate practitioner; law-enforcement bodies, the NCA, courts, tribunals and statutory authorities; and other persons authorised by the relevant client or data subject. We do not sell personal data to advertisers. 10. PROCESSORS AND INTERNATIONAL TRANSFERS We maintain an Article 28 processor register for systems actually used by the Firm. A current list of material processors is available on reasonable request. Supplier names, sub-processors and hosting arrangements can change, so the operational register is the controlling list and must be kept current. If personal data is transferred outside the UK, we use an applicable adequacy regulation or appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where required. 11. RETENTION We keep records only for as long as reasonably necessary for the purposes for which they are held and to meet tax, accounting, AML, contractual, insurance and legal-claims requirements. AML/CDD records are normally retained for five years from the end of the relevant business relationship or other statutory point, subject to lawful exceptions. Other engagement records may be retained for longer where necessary for tax history, continuity, legal claims or another lawful reason. Companies House personal codes and other security credentials are stored only where necessary for the authorised filing/agency purpose, with access restricted, and are not used for unrelated purposes. 12. YOUR RIGHTS Subject to legal conditions and exemptions, individuals may have rights of access, rectification, erasure, restriction, objection, portability and rights relating to automated decision-making. Where we genuinely rely on consent for a purpose, it may be withdrawn for that purpose at any time without affecting earlier lawful processing. A request to erase data does not override our duty to keep AML records, tax records, evidence required for legal claims or other information law requires us to retain. AML/tipping-off and crime-prevention rules may also lawfully restrict information we can provide in particular circumstances. 13. MARKETING Professional-service communications about an existing engagement are not direct marketing. We comply with UK GDPR and PECR for optional marketing communications. Opting out of marketing does not affect professional services. 14. SECURITY We use proportionate technical and organisational measures including controlled accounts, access controls, authentication, backups, staff procedures and independent verification of sensitive instructions. No electronic system is completely risk-free; please notify us promptly if you suspect compromise of an account, device, email address, phone number or credential. 15. COMPLAINTS AND CONTACT Contact us first at info@isumarco.com if you have a data-protection question or complaint. You also have the right to complain to the Information Commissioner's Office. Details are available at ico.org.uk. 16. CHANGES TO THIS NOTICE We may update this notice when law, technology, suppliers or our services change. We make the current notice available through our normal channels and draw attention to material changes where appropriate.