Skip to main content
Data security

What we actually do with your data.

Clients hand us their books, their contracts and their correspondence with the authorities. This page describes how we handle that, and does not claim certifications the firm does not hold.

Access

Client data is accessible only to the team members assigned to that engagement. Access is granted on joining an engagement and withdrawn on leaving it. Accounts used to reach client systems and our own are protected by multi-factor authentication.

Transfer and storage

Documents are exchanged through access-controlled shared folders rather than as email attachments wherever the client’s systems allow. Working files are held on managed accounts, not on personal devices or personal storage.

People

Every person at the firm is bound by written confidentiality obligations covering client information, which continue after they leave. Team members working on overseas engagements are additionally bound by any confidentiality terms in the client’s own engagement documentation.

Retention and return

At the end of an engagement, working papers are retained for the period required by law and by professional obligation. Client records provided to us are returned or securely destroyed on request, subject to that retention requirement.

Local data protection requirements

Where an engagement involves personal data governed by the law of another jurisdiction, we work to the client’s instructions and to their own controller obligations under the applicable regime. We are processors acting on client instruction, not independent controllers of that data.

What we do not claim

The firm does not currently hold ISO 27001, ISO 27701 or SOC 2 certification. We have set out our actual practices above rather than implying accreditation we do not have.