Skip to main content
Exclusively for UK Accountancy Practices 100% White-Label Production Support
UK GDPR & IDTA Aligned Jurisdiction: England & Wales

Privacy Policy

Last updated: 1 January 2026 • Effective Date: 1 January 2026

Legal Notice: This policy constitutes a structural framework aligned with UK GDPR requirements. Prior to formal client contracting, all provisions should be reviewed by qualified UK legal counsel.

1. Company Disclosure & Identity of the Controller

Ferret BizServe Pvt. Ltd. ("Ferret", "we", "us", or "our") is a private limited company incorporated under the Companies Act in India, providing business services and white-label accounting production support exclusively to professional accountancy practices in the United Kingdom.

For website visitors, general commercial enquiries, and marketing communications, Ferret BizServe acts as a Data Controller. When providing white-label accounting production support on behalf of UK accountancy firms, Ferret acts strictly as a Data Processor under UK GDPR Article 28.

2. Distinction Between Controller and Processor Roles

It is critical to distinguish between the two distinct processing contexts:

  • Website & Commercial Leads (Controller): We collect B2B contact data (name, work email, practice details) to respond to discovery call bookings and evaluate pilot qualification.
  • Client Accounting Records (Processor): Any financial, personal, or corporate accounting data accessed during the course of providing bookkeeping, VAT, or year-end accounts support is processed strictly under the documented instructions of the contracting UK accountancy practice (the Data Controller).

3. Categories of Personal Data Collected (Website Inquiries)

When you submit an enquiry, download resources, or book a discovery call on our website, we may collect:

  • Full Name and Professional Title (e.g. Partner, Director, Practice Manager)
  • Business Email Address and Telephone Number
  • Practice / Firm Name, Website URL, and Registered Office Location
  • Practice demographic metrics (number of team members, primary software stack, monthly workload volume)
  • Technical data via cookies (IP address, browser type, device information) subject to your consent

4. Lawful Bases for Processing

We process personal data under the following legal bases recognized by the UK General Data Protection Regulation (UK GDPR):

  • Legitimate Interests (Article 6(1)(f)): Processing B2B commercial enquiries and providing requested outsourcing benchmarks to accounting practice decision-makers.
  • Contractual Performance (Article 6(1)(b)): Taking steps prior to entering into a contract, including scoping a One-Client Pilot and executing mutual NDAs.
  • Consent (Article 6(1)(a)): For non-essential analytics cookies and opt-in educational email newsletters.

5. International Transfers of Personal Data (UK to India)

Because our production facilities and personnel are located in India, access to personal data originating in the United Kingdom constitutes an international data transfer under Chapter V of the UK GDPR.

To ensure appropriate safeguards in the absence of an adequacy regulation for India:

  • All client accounting production support is governed by a formal Data Processing Agreement (DPA) incorporating the Information Commissioner’s Office (ICO) approved International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
  • We provide practice partners with a completed Transfer Risk Assessment (TRA) evaluating technical and legal protections.
  • Access is maintained strictly via remote cloud logins without persistent local data storage in India.

6. Technical & Organisational Measures (Security Controls)

We implement conservative technical safeguards in accordance with UK GDPR Article 32:

  • Centrally managed company laptops with full disk encryption and enforced antivirus.
  • Administrative disabling of external USB storage and peripheral copying ports.
  • Mandatory multi-factor authentication (MFA) and enterprise password management for all credentials.
  • Strict role-based access controls; zero shared team logins.
  • Documented 60-minute access revocation SLA upon employee departure.
  • Physical biometric entry controls and clear-desk rules in production centers.

7. Data Retention Policy

B2B commercial inquiry data is retained for 24 months from the date of last communication, after which it is securely deleted or anonymized unless ongoing engagement occurs. For client accounting production data, records are retained or expunged strictly in accordance with the UK practice's written DPA instructions.

8. Your Statutory Rights

Under the UK GDPR, you have enforceable rights regarding your personal data, including:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request correction of inaccurate records.
  • Right to Erasure ("Right to be Forgotten"): In certain circumstances, you may request deletion of your data.
  • Right to Restrict or Object to Processing: You may object to direct marketing or processing based on legitimate interest.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time via cookie preferences or unsubscribe links.

9. Contact Details & Supervisory Authority

To exercise any rights or enquire about our data handling practices, contact our Data Governance team at:

Email: privacy@ferretbizserve.com
Subject Line: UK GDPR Rights Request
Entity: Ferret BizServe Pvt. Ltd. (UK Accounting Support Division)

If you are dissatisfied with our response, you have the right to lodge a complaint with the UK supervisory authority: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (www.ico.org.uk).

Mandatory Senior QA

Line-by-line second-level review before any file leaves our office.

Zero Client Contact

100% white-label. Your practice retains exclusive client ownership.

Remote Cloud Access

Encrypted company hardware, zero local persistent database downloads.

One-Client Pilot

Start with one controlled assignment. Scale only when justified.