Last Updated: 29 April 2026
OP Financial Solutions (“we”, “us”, “our”) is committed to protecting your privacy and personal data. This privacy policy explains how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who We Are
OP Financial Solutions is a data controller registered in England and Wales. We are responsible for deciding how we hold and use personal information about you. For any questions about this privacy policy or how we handle your data, please contact us at:
Email: [your email address]
Address: [your business address]
Phone: [your contact number]
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).
What Information We Collect
When you engage our financial and accounting services, we may collect and process the following personal data:
- Full name and any previous names
- Date of birth
- Contact details (postal address, email address, telephone numbers)
- National Insurance number
- Unique Taxpayer Reference (UTR) number
- VAT registration number (if applicable)
- Bank account details and financial information
- Employment and income details
- Business structure and ownership information
- Correspondence and communication records
- Identity verification documents (passport, driving licence)
- Signature and photographic identification
Legal Basis for Processing
We process your personal data under the following legal bases as defined by the UK GDPR:
- Contractual necessity: To provide accounting and financial services you have engaged us for
- Legal obligation: To comply with tax, anti-money laundering, and regulatory requirements
- Legitimate interests: To manage our business operations, maintain records, and improve our services
- Consent: Where you have given explicit permission for specific processing activities
How We Use Your Information
We use your personal data for the following purposes:
- Preparing accounts, tax returns, and financial statements
- Providing financial advice and consultancy services
- Complying with legal and regulatory obligations (HMRC, Companies House, FCA requirements)
- Communicating with you about our services
- Managing client relationships and billing
- Preventing fraud and money laundering
- Maintaining professional indemnity insurance
- Improving our services and business operations
Data Sharing and Disclosure
We may share your personal data with third parties where necessary:
- HMRC and tax authorities: To file tax returns and fulfill statutory obligations
- Companies House: For company formation and filing requirements
- Financial institutions: For payment processing and banking services
- Professional advisors: Including solicitors, auditors, and regulatory bodies
- Software providers: Cloud-based accounting and practice management systems
- Insurance providers: For professional indemnity cover
We do not sell your personal data to third parties. All third-party service providers are required to maintain appropriate security measures and process data only as instructed.
Data Retention
We retain your personal data for as long as necessary to fulfill our legal and regulatory obligations. Under UK tax law and professional standards, we typically retain client records for a minimum of six years from the end of the accounting period to which they relate. Some records may be retained longer where required by law or regulatory guidance.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: Request copies of your personal data
- Right to rectification: Request correction of inaccurate information
- Right to erasure: Request deletion of your data (subject to legal retention requirements)
- Right to restriction: Request limitation of processing in certain circumstances
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time where this is the legal basis
To exercise any of these rights, please contact us using the details provided above. We will respond within one month of your request.
Data Security
We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access, loss, or misuse. These measures include:
- Encrypted data transmission and storage
- Secure password-protected systems
- Regular security updates and patches
- Access controls limiting staff access to necessary information only
- Regular backup procedures
- Staff training on data protection obligations
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay.
Transfers Outside the UK
If we transfer your personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements. This may include using standard contractual clauses or ensuring the recipient country has an adequacy decision from the UK government.
Cookies and Website Data
Our website may use cookies and similar technologies to improve your browsing experience. You can manage cookie preferences through your browser settings. For detailed information about the cookies we use, please see our separate Cookie Policy.
Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes by posting the updated policy on our website with a revised “Last Updated” date.
Contact Us
If you have any questions about this privacy policy or our data protection practices, please contact us at [your contact details]. We take your privacy seriously and will address any concerns promptly.