Skip to main content
Exclusively for UK Accountancy Practices 100% White-Label Production Support
UK GDPR & IDTA Aligned Jurisdiction: England & Wales

Data Processing & Security Statement

UK GDPR Article 28 Framework & Cross-Border Governance

Legal Review Marker: This document outlines Ferret BizServe's standard operational data processing commitments. Individual engagements require formal execution of a bespoke Data Processing Agreement (DPA) and UK IDTA reviewed by each party's legal advisers.

1. Operating as a Data Processor

When a UK accountancy practice engages Ferret BizServe Pvt. Ltd. to perform bookkeeping reconciliations, VAT preparations, or year-end accounts support, the UK practice acts as the Data Controller and Ferret BizServe acts as the Data Processor under Article 28 of the UK General Data Protection Regulation (UK GDPR).

Ferret processes client financial records and personal identifiers strictly on the documented, written instructions of the UK practice, and never for our own commercial purposes.

2. Article 28 Processor Commitments

In accordance with UK GDPR Article 28(3), Ferret contractually commits that it shall:

  • Process personal data only on documented instructions from the controller, including regarding international data transfers.
  • Ensure that all personnel authorised to process personal data have committed themselves to strict non-disclosure obligations.
  • Take all technical and organisational measures required pursuant to Article 32 (Security of Processing).
  • Not engage any subprocessor without the prior specific or general written authorization of the UK practice.
  • Assist the controller by appropriate technical and organisational measures in responding to data subjects exercising their Chapter III rights.
  • Assist the controller in ensuring compliance with Articles 32 to 36 (security, breach notification, impact assessments).
  • At the choice of the controller, delete or return all personal data after the end of the provision of services.
  • Make available to the controller all information necessary to demonstrate compliance and allow for audits conducted by the controller.

3. UK International Data Transfer Agreement (IDTA)

Because production occurs in India, international transfers are governed by the Information Commissioner’s Office (ICO) approved International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).

We provide a standardized Transfer Risk Assessment (TRA) pack that details our compensating security controls, ensuring UK practice compliance files are complete and audit-ready.

4. Subprocessor Register Policy

Ferret BizServe operates its core production support through directly employed staff in our access-controlled facilities. We maintain an up-to-date Subprocessor Register covering third-party infrastructure providers (e.g. enterprise cloud email and document management tools).

No client accounting work is ever subcontracted to freelance individuals or external third-party production agencies without express written consent from the contracting practice.

5. Data Breach Notification SLA

In the event of a confirmed or suspected personal data security incident affecting client data, Ferret BizServe guarantees notification to the contracting UK practice within 24 hours of confirmation, accompanied by technical details and remedial actions taken.

Mandatory Senior QA

Line-by-line second-level review before any file leaves our office.

Zero Client Contact

100% white-label. Your practice retains exclusive client ownership.

Remote Cloud Access

Encrypted company hardware, zero local persistent database downloads.

One-Client Pilot

Start with one controlled assignment. Scale only when justified.