Privacy Notice — United Kingdom

How we collect, use and protect personal data

19 September 2026

1. About this notice

This notice explains how Sterling & Hunter Limited, trading as Sterling & Hunter, collects, uses, shares and protects personal data. It applies to our clients, to the people connected with our clients, and to anyone else whose personal data we hold in connection with our services.

It sits alongside your Letter of Engagement and our Terms of Business. Clause 10 of those terms points you to this notice. Where we act on your behalf in a way that makes you the controller of the personal data and us your processor, our Data Processing Terms apply as well.

This notice is issued under the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

2. Who we are

Sterling & Hunter Limited, trading as Sterling & Hunter, is a private company limited by shares, registered in England and Wales with company number 17404438, whose registered office is at Office 30 Greenbox, Westonhall Road, Stoke Prior, Bromsgrove, England, B60 4AL.

We are the controller of the personal data described in this notice, except where we are processing it on your instructions as your processor. We are registered with the Information Commissioner’s Office under registration number ZC234720.

If you have a question about this notice or about how we handle personal data, contact us at info@sterlingandhunter.com.

Two firms, two notices. Sterling & Hunter is the trading name of two separate companies: Sterling & Hunter Limited in the United Kingdom, and Sterling Hunter Accountancy and Professional Services - FZCO in the United Arab Emirates. This notice covers the work the United Kingdom company does for you. The FZCO issues its own privacy notice under United Arab Emirates law. Where you take services from both, both notices apply to the work each of them does.

3. The personal data we collect

The personal data we hold depends on the services you have engaged us for. It will usually include some or all of the following.

  • Identity and contact details, including name, date of birth, nationality, National Insurance number, passport and driving licence details, photographs, residential and business addresses, telephone numbers and email addresses.
  • Client due diligence information, including proof of identity and address, source of funds and source of wealth information, ownership and control information, and the results of sanctions, politically exposed person and adverse media screening.
  • Financial and business information, including bank details, accounting records, transaction data, invoices, contracts, payroll and pension information, shareholdings, loans and directors’ accounts.
  • Tax information, including your Unique Taxpayer Reference, VAT and PAYE references, returns, computations, correspondence with HM Revenue & Customs, residence and days of presence information, and details of income, gains and assets.
  • Corporate information, including company documents, Companies House filings, registers of members and persons with significant control, and correspondence with registries and regulators.
  • Correspondence and records of our dealings with you, including emails, messages, meeting notes, call records and file notes.

Most of what we hold is ordinary personal data. Two categories need saying separately.

  • Special category data.We do not routinely ask for data about health, religion, trade union membership or similar matters. Where it reaches us because a piece of advice needs it, for example a claim that depends on a health condition or a marriage or civil partnership, we handle it only for that purpose, and we rely on Article 9(2)(f) of the UK GDPR where it is needed to establish, exercise or defend legal claims, or on a condition in Schedule 1 to the Data Protection Act 2018.
  • Criminal offence data.Our anti-money laundering screening can produce information about offences, alleged offences and related proceedings. We process it under Article 10 of the UK GDPR and paragraph 12 of Part 2 of Schedule 1 to the Data Protection Act 2018, which covers processing necessary to prevent or detect unlawful acts.

4. Where we get personal data from

  • From you directly, when you instruct us, complete our onboarding, or send us records and information.
  • From people connected with you, such as your directors, shareholders, employees, family members or other advisers.
  • From public and official sources, including Companies House, HM Revenue & Customs, the Land Registry, the electoral roll, insolvency and charity registers, sanctions lists and other public records.
  • From screening and verification providers we use to meet our anti-money laundering obligations.

Where you give us personal data about other people, you confirm that you are entitled to do so and that those people have been given the information they are entitled to receive about how their data will be used. It helps if you pass this notice on to them.

5. Why we use personal data and on what basis

We use personal data for the purposes below. The lawful basis under Article 6 of the UK GDPR is given for each one.

  • To provide the services set out in your engagement, including accounts, bookkeeping, tax compliance, payroll, company secretarial and advisory work. Our basis is Article 6(1)(b), performance of our contract with you, or taking steps at your request before entering into it. Where our client is a company and the data is about an individual connected with it, our basis is Article 6(1)(f), our legitimate interest in delivering the services we have been engaged to provide.
  • To meet our own legal and regulatory obligations, including the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the Proceeds of Crime Act 2002, sanctions requirements, tax law and company law, and the record-keeping duties that go with them. Our basis is Article 6(1)(c), compliance with a legal obligation.
  • To manage our relationship with you, including billing, collecting fees, keeping our records accurate and dealing with queries and complaints. Our basis is Article 6(1)(b) and Article 6(1)(f), our legitimate interest in running the firm properly.
  • To protect our position, including establishing, exercising or defending legal claims, responding to regulators and professional bodies, and meeting our professional indemnity insurance obligations. Our basis is Article 6(1)(f), our legitimate interest in protecting the firm, and Article 6(1)(c) where a regulator requires it.
  • To run and improve our business, including quality reviews, practice assurance, training, security and the technology described in section 7. Our basis is Article 6(1)(f).
  • To send you information about our services, where you have asked for it or where you are an existing client and we think it is relevant to you. Our basis is Article 6(1)(f), our legitimate interest in keeping clients informed, and your consent where the law requires it. You can ask us to stop at any time and we will.

Where we rely on our legitimate interests, we have considered whether those interests are overridden by your interests, rights and freedoms, and we have concluded they are not. You can ask us for our assessment.

Where we rely on your consent for a particular use, you can withdraw it at any time. Withdrawing consent does not affect anything we did before you withdrew it, and it does not affect processing we carry out on another basis, such as a legal obligation.

6. Who we share personal data with

We do not sell personal data. We share it only where it is necessary, and only with the following.

  • Government and regulatory bodies, including HM Revenue & Customs, Companies House, the Pensions Regulator, the National Crime Agency, the Information Commissioner’s Office, and the Association of Chartered Certified Accountants as our professional body and anti-money laundering supervisor, and any authority we are legally required to report to.
  • Banks, payment providers and pension providers, where this is part of the work you have asked us to do.
  • Auditors, solicitors and other professional advisers, where you have asked us to work with them or where we need advice ourselves.
  • Subcontractors and other accounting or tax professionals to whom we subcontract work. Each is bound by our confidentiality and security terms, as clause 9 of our Terms of Business explains.
  • Our associated company, Sterling Hunter Accountancy and Professional Services - FZCO, where your work has a United Arab Emirates element and you have engaged both of us, or where we need its input to advise you properly.
  • Technology and service providers, including cloud accounting, document management, communications, automation, screening and artificial intelligence providers.
  • Our insurers and professional indemnity insurers, and their advisers.
  • A buyer or successor, if we sell or reorganise our business, subject to appropriate confidentiality protections.

Our current technology and service providers are set out below. We keep this list under review and will update this notice when it changes.

  • Cloud accounting and bookkeeping:Xero.
  • Document management and file storage:Microsoft 365 (SharePoint and OneDrive).
  • Email, calendar and communications:Microsoft 365 (Outlook and Teams).
  • Meeting recording and transcription:Fathom.
  • Artificial intelligence and automation:Anthropic (Claude).
  • Design and marketing:Canva.
  • Client due diligence and screening:Xama.
  • Subcontracted accounting and tax professionals:MPS Accountancy, United Kingdom.

We may also disclose personal data where the law, a regulator, a court or a professional obligation requires it. In some cases we are not permitted to tell you that we have done so. Where we have made a report about suspected money laundering, telling you may itself be a criminal offence, as clause 11 of our Terms of Business explains.

7. Technology, automation and artificial intelligence

We use artificial intelligence, machine learning, automation, document processing, data analytics and cloud software to deliver our services. This is described in clause 8 of our Terms of Business, and it includes document and data extraction, bookkeeping and reconciliation, research assistance, preparation of working papers and drafts, screening, and workflow automation.

The output of these tools is reviewed by us. We do not make decisions about you by automated means alone where that decision would produce a legal effect on you or a similarly significant effect. If that ever changes, we will tell you first, explain the logic involved, and you will be able to ask for a person to look at the decision, to give your point of view and to contest it.

We select providers that offer appropriate security and confidentiality terms, and we do not permit client data to be used to train publicly available models.

8. Transfers outside the United Kingdom

Some of our processing takes place outside the United Kingdom, because we work across the United Kingdom and the United Arab Emirates and because some of our providers host data in other countries. The countries currently involved are the United Arab Emirates, Ireland, the Netherlands, the United States and Australia.

Ireland and the Netherlands are covered by United Kingdom adequacy regulations, so no further safeguard is needed. The United States is covered for transfers to organisations certified under the UK Extension to the EU-US Data Privacy Framework. The United Arab Emirates and Australia are not covered by adequacy regulations.

Where a transfer is not covered by adequacy regulations, we use the Information Commissioner’s International Data Transfer Agreement, or the international data transfer addendum to the European Commission’s standard contractual clauses, and we carry out a transfer risk assessment before the transfer is made. Transfers to Sterling Hunter Accountancy and Professional Services - FZCO are covered by an intra-group agreement on those terms. You can ask us for a copy of the safeguards we rely on.

9. How long we keep personal data

We keep personal data for as long as we need it for the purpose we collected it for, and then for as long as we are required or permitted to keep it.

  • Company and corporation tax records are kept for at least six years from the end of the accounting period.
  • Records for individuals, trustees and partnerships with trading or rental income are kept for at least five years and ten months after the end of the tax year, and otherwise for at least 22 months after the end of the tax year.
  • VAT records are kept for at least six years, and longer where the law requires it for particular assets.
  • Payroll and pension records are kept for the periods required by HM Revenue & Customs and by automatic enrolment law, which is at least three years and in some cases six.
  • Client due diligence records are kept for five years after the end of our business relationship with you, as the Money Laundering Regulations 2017 require.
  • Engagement files, advice and correspondence are kept for at least six years after the engagement ends, so that we can answer queries, meet our professional and insurance obligations and defend claims, and normally no longer than seven.

After those periods we delete personal data or put it beyond use. Original documents are returned to you on request. Clause 23 of our Terms of Business sets out the statutory periods you are responsible for, and explains that we may destroy correspondence and papers more than seven years old, and that following termination we may destroy documents we have been unable to return to you after six months.

10. How we protect personal data

We take appropriate technical and organisational steps to protect personal data against loss, misuse, unauthorised access, disclosure, alteration and destruction. These include access controls, encryption in transit and at rest where available, multi-factor authentication, virus and malware scanning, supplier due diligence, staff confidentiality obligations and training.

No system is completely secure, and email in particular carries a risk of interception and misdirection, as clause 15 of our Terms of Business explains. Tell us if you would prefer us to use a different method for sensitive material.

If a personal data breach occurs, we will act on it promptly. Where the law requires it, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will tell any affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

11. Your rights

Under the UK GDPR you have the following rights, subject to the conditions and exceptions in the legislation.

  • To be told how your personal data is processed, and to ask us for a copy of it. This is often called a subject access request. We will respond within one month, and we may extend that by up to two further months for a complex request, telling you if we do. Where we need to ask you for clarification in order to carry out a reasonable and proportionate search, the clock pauses until you answer.
  • To ask us to correct personal data that is inaccurate, and to have incomplete data completed.
  • To ask us to erase your personal data, where we no longer have a reason to keep it.
  • To ask us to restrict our processing of your personal data in certain circumstances.
  • To object to processing we carry out on the basis of our legitimate interests, and to object at any time to direct marketing.
  • To receive personal data you gave us in a structured, commonly used, machine-readable format, and to ask us to transfer it to someone else, where the processing is based on your consent or on our contract with you and is carried out by automated means.
  • Not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect, and to ask for human intervention where one is made.
  • To withdraw consent, where we rely on your consent.

These rights are not absolute. We may not be able to erase or stop processing personal data where the law requires us to keep it, for example our tax and anti-money laundering record-keeping obligations, or where we need it to establish or defend a legal claim. If we cannot do what you have asked, we will tell you why. There is normally no charge, and we will tell you in advance in the rare case where a request is manifestly unfounded or excessive.

12. How to contact us, and how to complain

To exercise any of your rights, or to ask a question about this notice, contact us at info@sterlingandhunter.com, or write to us at our registered office. We may need to verify your identity before we act.

If you are unhappy with how we have handled your personal data, you have the right to complain to us, and we would rather you did that first so that we have the chance to put it right. You can complain by email, by letter, or by telling your usual Sterling & Hunter contact. We will acknowledge your complaint within five working days, and in any event within the 30 days the law allows, look into it without undue delay, and tell you the outcome. That matches the complaints timescale in clause 21 of our Terms of Business.

If you are not satisfied with our response, or if you would rather go straight there, you can complain to the Information Commissioner’s Office.

  • Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
  • Helpline 0303 123 1113, or online at www.ico.org.uk.

A complaint about the service we have provided, rather than about personal data, is dealt with under clause 21 of our Terms of Business.

13. Changes to this notice

We review this notice from time to time. Where we make a material change, we will tell you in writing, and the updated notice will apply from the date stated in that notice. The current version is shown on the front page.