Privacy Notice | The Little Bookkeeping Company

Privacy Notice

The Little Bookkeeping Company — Last updated: 1st September 2026

Who we are

The Little Bookkeeping Company ("we", "us", "our") provides bookkeeping, payroll, and Self-Assessment tax services to sole traders and small businesses. We are the data controller for the personal data described in this notice — meaning we decide how and why your personal data is processed, and we are responsible for complying with data protection law in relation to it.

As a sole practice, we don't have separate staff or an appointed Data Protection Officer — Molly Harrington is both the data controller and the point of contact for any data protection query or concern.

The data protection principles we follow

In handling your personal data, we follow the principles set out in UK GDPR. Your data will be:

  1. Processed lawfully, fairly, and transparently
  2. Collected only for the specific purposes explained in this notice
  3. Adequate, relevant, and limited to what's necessary for those purposes
  4. Kept accurate and up to date
  5. Kept only for as long as necessary (see "How long we keep your data" below)
  6. Kept secure, with appropriate technical and organisational protections in place

What personal data we collect

We do not intentionally collect special category data (such as health, racial or ethnic origin, or religious belief data). Where payroll processing incidentally involves a reason connected to special category data (for example, statutory sick pay), we use only what's strictly necessary to process that entry correctly, and do not use it for any other purpose.

How we collect it

Why we process your data, and our lawful basis

Purpose Lawful basis
Providing the bookkeeping, payroll, or tax services you've engaged us for Contract
Carrying out ID verification / AML checks Legal obligation (Money Laundering Regulations 2017)
Filing with HMRC and holding agent authorisation Legal obligation
Contacting your previous accountant/bookkeeper for clearance Your explicit consent
Keeping financial and compliance records Legal obligation
Responding to your queries and requests Legitimate interest (providing you with a responsive service)

We only process your data for the purposes set out here. If we ever needed to use it for a new purpose not covered by this notice, we would contact you first to explain and, where required, ask for your consent.

Who we may share your data with

We do not sell your personal data to third parties, and we do not use your data for marketing purposes.

International transfers

Some of the third-party providers we use may store data outside the UK or EEA. Where this happens, we only use providers with appropriate safeguards in place, such as a UK adequacy decision or Standard Contractual Clauses.

How long we keep your data

Once data is no longer needed for any of the above purposes, we take reasonable steps to securely delete or destroy it.

Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, contact us using the details above.

Verifying your identity

If you contact us by phone to request or discuss your personal data, we may need to confirm your identity before disclosing anything, or ask you to put the request in writing. This is to make sure your information is only ever given to you.

Responding to your request

We will respond within one month of receiving your request. If a request is particularly complex, we may extend this by up to two further months and will explain why. We do not charge a fee for reasonable requests; a small administrative fee may apply only if a request is manifestly unfounded, excessive, or repetitive.

How we keep your data secure

Complaints

If you're unhappy with how we've handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO):

Changes to this notice

We may update this notice from time to time. The latest version will always be available on our website.