EU GDPR PRIVACY NOTICE
Effective May 2020
Cordium Accounting Limited and its subsidiaries (hereinafter referred to collectively as “Wheelhouse Advisors,” “we” or “us”) are committed to respecting your privacy.
This Notice explains how we handle the personal information we collect through our website, www.wheelhouse-advisors.com, and any other website or application where this GDPR Notice is posted (each, a “Site”), the personal information we collect when individuals engage with us or use our products or services (our “Services”), the personal information we receive about individuals as a result of providing Services to our clients, and the personal information we receive from applicants for employment opportunities with Wheelhouse Advisors, whenever such personal information is subject to GDPR.
For the purposes of this Notice, “personal information” means information relating to an identified or identifiable person who is a resident of the European Union.
Wheelhouse Advisors provides services to its clients through one or more operating subsidiaries, all of which do business as Wheelhouse Advisors.
The Personal Information We Collect
We may collect personal information directly from you, including through your use of the Site, when you contact us or request information from us by email, telephone, post or social media, when you apply for an employment opportunity with Wheelhouse Advisors, when you request a proposal from us in respect of the services we provide, when you engage us for Services, when an entity with which you are associated as an employee, officer or member provides us with such information, or as a result of your attendance at one of our conferences or other events.
With respect to personal information collected directly by Wheelhouse Advisors, we are the independent data controller responsible for your personal information. The information we collect typically consists of your contact information, including your name, address, business affiliation, business title, email address, and telephone number. Where the scope of our engagement includes Personal Client Tax services, the information we collect will typically additionally include employment-related details, national insurance numbers, gender, marital status, details of income including gains and losses, bank account details and other information required to deliver our Personal Client Tax services. Further, we may collect appropriate personal information to fulfil our Know-Your-Customer obligations under applicable Anti-Money Laundering legislation.
We also may obtain personal information indirectly from or on behalf of our clients. With respect to personal information that we receive from or on behalf of our clients in order to provide Services, our client remains the independent data controller and Wheelhouse Advisors acts as a processor of such personal information. We typically are retained by corporate entities in the financial services industry. In connection with providing Services pursuant to contracts with our corporate clients, we often obtain personal information of our client’s customers, employees and/or agents. This personal information varies based on the Services provided, but may include names, contact information, account numbers and other similar financial data. Where the scope of our engagement by an entity with which you are associated as an employee, officer or member, includes HR and/or payroll services, the information we collect directly from that entity will typically additionally include employment-related details and may include your national insurance, gender and other information required to deliver our payroll services. Further, we may collect appropriate personal information to fulfil our Know-Your-Customer obligations under applicable Anti-Money Laundering legislation.
We only use, disclose, or otherwise process personal information when we have a lawful basis for doing so under applicable laws, including fulfilling our contractual obligations, complying with legal obligations, protecting the vital interests of a person, furthering our legitimate interests as a company and employer, and otherwise for reasons you have consented to such processing.
For example, we use the personal information you provide directly to us to provide you with the information you requested (for example, Wheelhouse Advisors blog posts or other informational materials) or to evaluate your application for employment. To the extent required by law, by providing personal information to us, you consent to our use of the personal information as explained herein.
How We Share Personal Information
Wheelhouse Advisors only shares personal information when it has a lawful basis for doing so, as described above. Wheelhouse Advisors may share the information that we collect or that you provide to us with our affiliates. We also may share personal information with the following categories of third parties as necessary:
- Sub-contractors we have engaged in connection with providing Services to our clients.
- Our professional advisers, including our lawyers and auditors.
- Our insurers and insurance brokers.
- Third parties to whom we outsource certain services to assist with operating our business, such as IT managed service providers, document shredding services, software providers, information storage providers and other related service providers.
- Third parties to whom our clients have directed us to share information in connection with our Services, such as our clients’ lawyers and auditors.
- Third-party service providers that assist us with client data analytics.
- Third-party postal or courier providers that assist us with delivering marketing and other documents to you.
We do not share personal information with unaffiliated third parties, other than for the reasons stated herein.
As described above, we may provide certain third parties (“Sub-Processors”) with your personal information. Our Sub-Processors process personal information for us at our direction. We conduct reasonably appropriate due diligence on our Sub-Processors and include in our contracts with our Sub-Processors provisions requiring them to keep the personal information confidential, to process the personal information in accordance with our instructions, and to maintain reasonably appropriate information security systems.
We may appoint new Sub-Processors to assist us with providing Services and/or conducting our business. You can view a list of our current Sub-Processors at www.wheelhouse-advisors.com/sub-processors-list. We will provide notice to you of the addition of new Sub-Processors by updating this list.
Where We Transfer Personal Information
Wheelhouse Advisors is located in the United Kingdom. Depending on the nature of the Services we provide to our client, your personal information may be stored in the United States by a member of the ACA Compliance Group (“ACA”) under a Transitional Services Agreement between Wheelhouse Advisors and ACA. Wheelhouse Advisors is a former member of the ACA group of companies.
For transfers of personal information by ACA from the European Economic Area (EEA) to the United States, we rely on ACA’s certification of their participation in the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, respectively. You may view ACA’s GDPR Notice at https://www.acacompliancegroup.com/GDPRNotice.
Period of Retention
Wheelhouse Advisors retains personal information for as long as necessary to provide you with our Services and to comply with our obligations under applicable laws. We may destroy personal information without notice or following termination of our Services in accordance with the applicable Terms of Business.
Confidentiality and Information Security
Wheelhouse Advisors is committed to keeping your personal information secure. We have taken reasonably-designed steps to protect personal information from unauthorised access, use or disclosure. We also require our vendors to maintain reasonably appropriate information security policies and procedures and to maintain personal information confidentially.
Personal Data Rights
You are entitled to see any EU personal data held about you and you may ask us to make any necessary changes to ensure that it is accurate and kept up to date.
Under GDPR your rights with respect to EU personal data are:
Right to access - You have the right to request copies of your EU personal data that Wheelhouse Advisors holds about you in our databases. We will provide you with all the details that we hold about you, both online and offline, upon request.
Right to erasure - Under certain conditions, you have the right to request that we erase your EU personal data.
Right to restrict processing or object - You also may restrict or object to the processing of your EU personal data, in some circumstances.
Right to rectify - We want to make sure your EU personal data is correct and up to date. You may ask us to correct or remove information you think is inaccurate.
Right to data portability - You have the right to have your EU personal data transmitted to another controller, where technically feasible and if it does not adversely affect the rights and freedoms of others.
Rights related to automated decision making and profiling – Wheelhouse Advisors do not make decisions about you using automated decision making or profiling of your EU personal data.
Right to complain – you may have the right to lodge a complaint to an applicable supervisory authority or other regulator if you are not satisfied with our responses to your requests or how we manage your EU personal data.
Changes to This Notice
We reserve the right to make changes to this Notice, which may reflect changes to our business practices or changes required by law. Any material changes will be reflected in an updated Notice or provided via other means as may be required by applicable law.
How You Can Contact Us
If you have any questions about this Notice or want to exercise any of your rights under this Notice, please contact us at firstname.lastname@example.org.