Welcome to the MaLa Accounts Privacy and Cookie Policy
Your privacy matters to us.
At MaLa Accounts, we’re committed to protecting your personal data and being transparent about how we use it. This policy explains how we collect, use, store and protect your information, including how we use cookies and similar technologies.
- Who we are
MaLa Accounts is a self-employed accounting practice based in Birmingham, United Kingdom.
For privacy and data protection enquiries, please contact:
Email: dpo@malaaccounts.co.uk
Website: malaaccounts.co.uk
For the purposes of UK data protection law, MaLa Accounts acts as a data controller where we determine how and why personal data is processed.
For some services, particularly payroll and administrative processing carried out strictly on behalf of a business client, MaLa Accounts may act as a data processor. In those circumstances, the business client remains the data controller and is responsible for determining the lawful basis for processing and providing appropriate privacy information to its employees or other data subjects.
- Personal information we may collect
The personal data we collect depends on how you interact with MaLa Accounts.
Website and contact enquiries
If you contact us through our website or by email, we may collect information including your:
- name;
- email address;
- telephone number, where provided;
- business details;
- information contained in your enquiry or correspondence; and
- technical information generated when you use the website, such as IP address, browser/device information and website usage information.
Website contact enquiries are currently submitted through Contact Form 7. We do not intentionally maintain a separate database of Contact Form 7 submissions within WordPress; enquiries are delivered to our email system.
Accounting and tax clients
Where you engage MaLa Accounts to provide accounting, tax or related professional services, we may process information including:
- name, address and contact details;
- date of birth;
- National Insurance number;
- Unique Taxpayer Reference and other tax references;
- business and company information;
- financial and accounting records;
- income, expenses, invoices and receipts;
- bank and transaction information;
- tax returns and tax calculations;
- payroll and pension information;
- correspondence and supporting documentation;
- identity verification documents; and
- information required to comply with anti-money laundering and other legal or professional obligations.
The exact information required depends on the services we provide.
Payroll data
Where we provide payroll services to a business client, the client may provide personal information relating to its employees, directors or workers.
This may include:
- name and address;
- date of birth;
- National Insurance number;
- tax code;
- salary, pay and working hours;
- pension information;
- bank details;
- statutory payment information, including SSP, SMP or other statutory payments; and
- other information required to operate payroll and make the appropriate submissions.
Some payroll information may include special category personal data, for example health information connected with statutory sick pay or information connected with maternity-related statutory payments.
Where we process such information solely on the instructions of an employer or other business client, we generally act as a data processor and the business client is the data controller.
Anti-money laundering and identity checks
As an accounting practice, we may be required to carry out identity verification, client due diligence and ongoing monitoring.
This may involve identification documents, residential address information, ownership and control information and other information necessary to comply with applicable anti-money laundering requirements.
We currently use Xama as part of our identity verification and AML processes. Xama states that it may act as a data processor when handling data on behalf of its customers.
Appointments and payments
We use Square to facilitate appointment bookings and payments.
When you book an appointment or make a payment, information processed through Square may include your name, surname, email address, telephone number, appointment information, transaction information and payment details.
Square processes payment and card information through its own systems. Square explains that it may process identification information, financial information and transaction information when customers book appointments or make payments through a Square seller.
Mailing list and newsletters
If you voluntarily subscribe to the MaLa Accounts mailing list, we collect:
- your first name;
- your email address;
- information relating to your subscription and confirmation; and
- information about your interaction with emails, where email tracking is enabled.
We use a double opt-in process. After submitting the subscription form, you are asked to confirm your email address before becoming an active subscriber.
We use MailerLite to collect and manage mailing-list subscriptions, send emails and operate email automations. MailerLite acts as a processor in relation to subscriber data processed on our behalf.
You can unsubscribe at any time using the unsubscribe link included in our marketing emails.
- Email analytics and open tracking
We currently use MailerLite’s email analytics functionality, which may include open and engagement tracking.
MailerLite may use technologies such as tracking pixels or similar technologies to provide information about whether an email has been opened and how recipients interact with emails.
We use this information to understand how useful our communications are and to improve future emails.
Tracking pixels embedded in emails may involve accessing information from a recipient’s device. UK regulatory guidance treats tracking pixels as storage and access technologies to which PECR may apply.
You may also be able to limit some email tracking by changing privacy or remote-image settings in your email application.
- How and why we use personal information
We only process personal data where we have a lawful reason to do so.
|
Purpose |
Typical lawful basis |
|
Responding to enquiries and discussing potential services |
Legitimate interests and/or steps requested before entering into a contract |
|
Providing accounting, tax and related services |
Performance of a contract and, where applicable, legal obligations |
|
Client administration and communication |
Performance of a contract and legitimate interests |
|
AML, identity checks and regulatory compliance |
Legal obligation |
|
Preparing and maintaining tax/accounting records |
Contract and/or legal obligation |
|
Billing and payment administration |
Contract and legal obligation |
|
Booking appointments |
Steps before entering into a contract and/or performance of a contract |
|
Sending newsletters to people who have subscribed |
Consent |
|
Website analytics |
Consent where required |
|
Protecting our website, systems and business against misuse, fraud or security threats |
Legitimate interests and/or legal obligations |
|
Responding to data protection requests or regulatory requirements |
Legal obligation |
Consent to marketing can be withdrawn at any time. UK rules require electronic marketing consent to be freely given, specific, informed and demonstrated through a clear positive action, and recipients must be given an easy way to unsubscribe.
- Where we obtain personal data
We may receive personal data:
- directly from you;
- from a business client where they provide information about employees, directors or other individuals for the purpose of providing professional services;
- through systems that you or our clients use to provide information to us;
- through appointment and payment systems;
- through our website and mailing-list forms; and
- from official, regulatory or public sources where obtaining such information is necessary for the services we provide or our legal obligations.
Where personal data is obtained from someone other than the individual concerned, UK GDPR transparency requirements may also apply.
- Service providers and organisations we may share information with
We do not sell personal data.
Where necessary for our business and professional services, personal information may be processed by service providers including:
Capium – accounting, tax, payroll and practice software.
Engager – client and practice management services.
Xama – AML and identity verification.
Google Workspace, Gmail and Google Drive – email, document storage and business productivity services.
Square – appointment booking and payment processing.
MailerLite – mailing-list management, subscription forms, email marketing and automation.
Google Analytics – website usage analytics.
Microsoft Clarity – website analytics, interaction analytics and session replay functionality.
CookieYes – management and recording of cookie preferences.
We may also disclose information to HMRC, Companies House, regulators, law-enforcement bodies, professional advisers or other organisations where this is necessary to provide the requested service, comply with a legal obligation, protect legal rights or meet regulatory requirements.
Square states that it processes customer information when customers interact with businesses using its services, including for payments and appointments.
- International transfers
Some of the technology and service providers we use operate internationally.
Where personal data is transferred outside the United Kingdom, we take appropriate steps to ensure the transfer complies with UK data protection law. Depending on the destination and provider, this may include UK adequacy regulations or other legally recognised safeguards such as appropriate contractual transfer mechanisms.
The ICO recognises UK adequacy regulations as one mechanism that can permit international transfers without additional transfer safeguards.
For MailerLite subscribers, MailerLite currently states that subscriber data belonging to UK customers is hosted in the European Union and, for its current platform, its Google Cloud data centre is located in the Netherlands. MailerLite’s contractual documentation also provides transfer safeguards for relevant international processing.
Other providers, including Google, Microsoft and Square, may use international infrastructure and their own approved transfer safeguards.
- How long we keep personal information
We do not keep personal information longer than reasonably necessary for the purpose for which it was collected, subject to legal, regulatory, tax and professional record-keeping requirements.
Our general retention approach is:
|
Information |
General retention approach |
|
Enquiries that do not become clients |
Normally up to 12 months after the last meaningful contact |
|
Active client records |
For the duration of the engagement |
|
Accounting and tax client files |
Generally up to 6 years after the end of the relevant accounting/tax period or engagement, unless a different period is legally required |
|
AML / client due-diligence records |
Generally 5 years after the business relationship ends or an occasional transaction is completed, subject to applicable AML rules |
|
Payroll records |
Generally up to 6 years after the relevant tax year where needed to cover payroll, tax, minimum-wage and related record-keeping requirements |
|
Appointment and transaction records |
Normally up to 6 years where required for accounting, tax, contractual or legal purposes |
|
Newsletter subscriber information |
While you remain subscribed |
|
Marketing opt-out / suppression information |
A minimal record may be retained for as long as reasonably necessary to ensure your opt-out continues to be respected |
|
Cookie and analytics information |
According to the relevant cookie/service settings and the retention periods shown by the relevant provider |
HMRC requires ordinary PAYE records to be kept for at least three years from the end of the tax year, while minimum-wage records may need to be retained for at least six years.
Self-employed business records generally need to be retained for at least five years after the relevant 31 January filing deadline, while company tax/accounting record requirements may require longer retention.
AML client due-diligence records are generally subject to a five-year retention requirement after the relevant business relationship or transaction ends.
Where a legal dispute, HMRC enquiry, regulatory matter or other legal requirement applies, we may retain relevant information for longer where necessary.
- Security
We use appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, alteration, disclosure or misuse.
Measures may include access controls, password protection, secure cloud services, encryption provided by our service providers, restricted system access and appropriate data-handling procedures.
No internet-based system can be guaranteed to be completely secure, but we take reasonable steps appropriate to the nature of the information we process.
- Cookies and similar technologies
Our website uses cookies and similar technologies.
Cookies are small files or pieces of information stored on or accessed from your device. Similar technologies can include tracking pixels, scripts, tags and local browser storage. ICO guidance confirms that PECR rules can apply to these technologies as well as traditional cookies.
We use CookieYes to provide cookie-consent controls and record cookie preferences.
Depending on your choices and the functionality being used, our website may use the following categories of technology.
Strictly necessary and security technologies
These technologies support essential website functions, security and preference management.
They may include CookieYes consent-management technology and anti-abuse/security functionality associated with forms and reCAPTCHA.
Analytics technologies
With the appropriate consent, we use analytics tools to understand how visitors use our website and to improve its performance.
Google Analytics may collect information such as user/session statistics, approximate location and browser/device information. Google Analytics uses a first-party _ga cookie to distinguish users where analytics storage is permitted.
Microsoft Clarity helps us understand website interactions and may provide heatmaps and session replay information. Microsoft’s documented cookies include technologies such as _clck and _clsk as well as Microsoft-domain identifiers. Microsoft requires a valid consent signal for full Clarity functionality for users in the UK, EEA and Switzerland.
The exact cookies, purposes and current durations may change as the services we use are updated. The most current cookie information and controls should be available through the cookie-preferences tool on our website.
Managing cookie choices
When you visit our website, you can use the CookieYes banner or cookie settings to accept, reject or customise non-essential cookie categories.
Your choices can be changed later through the cookie-preferences control available on the website.
Except where an exemption applies, non-essential cookies and similar technologies should not be used before the required consent has been obtained.
- Google Analytics and Microsoft Clarity
Google Analytics is used to understand website traffic and usage patterns.
Google explains that Analytics can collect information including user numbers, sessions, approximate geolocation and browser/device information.
Microsoft Clarity may be used to understand how visitors interact with website pages, for example through interaction analytics and session recordings. Clarity uses cookies and requires appropriate consent signalling for UK users.
These tools are used to improve website usability and understand overall website performance, rather than to make decisions producing legal or similarly significant effects about visitors.
- reCAPTCHA
Our newsletter form uses reCAPTCHA to help protect the website and mailing list from automated submissions, abuse and spam.
reCAPTCHA may process technical information relating to the visitor’s browser, device and interaction with the page in order to distinguish legitimate activity from automated activity.
The operation of reCAPTCHA is also subject to the privacy and data-processing terms of its provider.
- Newsletter and direct marketing
We send marketing or informational emails to mailing-list subscribers who have actively signed up to receive them.
We use a double opt-in process to help confirm the validity of subscription requests.
We do not automatically add accounting clients to the mailing list simply because they are clients.
Every newsletter includes an unsubscribe mechanism. You may withdraw your consent or object to direct marketing at any time. The right to object to direct marketing is absolute and marketing must stop when a valid objection or unsubscribe request is received.
MailerLite processes subscriber information on our behalf for the purpose of managing subscriber lists and sending our emails.
- Your data protection rights
Depending on the circumstances, UK data protection law gives you rights including:
- the right to be informed about how your personal data is used;
- the right to request access to your personal data;
- the right to request correction of inaccurate or incomplete data;
- the right to request deletion of personal data in certain circumstances;
- the right to request restriction of processing;
- the right to object to certain processing, including direct marketing;
- the right to data portability where applicable; and
- the right to withdraw consent at any time where processing is based on consent.
Not every right applies in every circumstance. For example, we may need to retain certain records where we have a legal or regulatory obligation to do so.
To exercise your rights, please contact:
dpo@malaaccounts.co.uk
ICO guidance confirms that individuals must be told about relevant rights and must be given clear information about purposes, retention and recipients of their personal data.
- Complaints
If you have concerns about how MaLa Accounts handles your personal information, please contact us first at:
dpo@malaaccounts.co.uk
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office (ICO)
ico.org.uk
- Changes to this policy
We may update this Privacy & Cookie Policy where our services, technology, legal obligations or data-processing practices change.
The latest version will be published on this website and the „Last updated” date at the bottom of the policy will be amended accordingly.
Last updated: 18 September 2026