Privacy, Confidentiality & Data Security Policy
The Accountant Plus is committed to protecting the privacy, confidentiality, integrity and security of information entrusted to us by our clients, business owners, companies, organizations and other stakeholders.
As an accounting, bookkeeping, tax, costing and financial consultancy firm, we understand that our clients provide us with highly confidential business and financial information. This may include accounting records, financial statements, bank information, tax records, payroll information, invoices, customer and supplier information, business plans, management reports, costing information and other commercially sensitive information.
We therefore maintain appropriate administrative, technical and organizational safeguards designed to protect client information from unauthorized access, disclosure, alteration, misuse, loss or destruction.
Our approach is designed with internationally recognized information-security principles in mind, including principles reflected in the NIST Cybersecurity Framework, modern cloud-security practices and internationally recognized information-security standards such as ISO/IEC 27001, where applicable. NIST specifically recommends controls such as multi-factor authentication, encryption, access restrictions, secure backups, software updates and incident-response practices for small businesses.
1. Scope of This Policy
This policy applies to information provided to or collected by The Accountant Plus in connection with our accounting, bookkeeping, tax, CFO, costing, financial reporting, business advisory and related professional services.
It covers:
- Client accounting records
- Financial statements
- Bank and payment information
- Tax and regulatory information
- Payroll and employee-related business records
- Customer and supplier information
- Invoices and supporting documents
- Business contracts and agreements
- Management reports
- Budgets and financial forecasts
- Costing information
- Business plans and financial projections
- Electronic communications
- Information exchanged through online systems
- Documents uploaded or shared electronically
- Other confidential business information supplied by clients
2. Client Confidentiality
We treat client information as confidential business information.
Information supplied to us is used only for legitimate professional and business purposes connected with the services requested by the client, unless:
- the client has authorized another use;
- disclosure is necessary to perform an agreed service;
- disclosure is required by applicable law, regulation or a legally valid government request; or
- disclosure is necessary to protect our legal rights, systems or security, subject to applicable law.
We do not sell client financial information or confidential business information to third parties.
3. Information Sharing
The Accountant Plus follows a principle of minimum necessary disclosure.
We do not routinely disclose confidential client information to unrelated third parties.
Where information must be shared with a service provider, technology provider, professional adviser, financial institution, government authority or other authorized party, we seek to limit the information shared to what is reasonably necessary for the relevant purpose.
Where appropriate, third-party service providers may be required to maintain confidentiality and appropriate security protections.
4. Government and Tax Department Information
Our clients may provide us with information relating to tax authorities, government departments, regulatory bodies and other statutory organizations.
Such information is treated as confidential.
Where a client authorizes us to prepare, submit or communicate information to a government or tax authority, we use the information only for the relevant professional or regulatory purpose.
If disclosure is legally required by a government authority, court, regulator, tax authority or other lawful authority, we may disclose the information required by applicable law.
We do not voluntarily provide confidential client information to government or tax authorities merely because such information is available to us.
5. Tax Records and Financial Information
Tax records and financial information receive a high level of confidentiality because they may contain commercially sensitive and personally identifiable information.
Depending on the services provided, this may include:
- Tax returns
- Tax computations
- Sales and purchase records
- Bank records
- Payroll information
- Financial statements
- General ledgers
- Trial balances
- Invoices
- Expense records
- Tax correspondence
- Regulatory documentation
Access to such information is restricted to authorized personnel and authorized systems.
6. Secure Electronic Communication
Because modern accounting services frequently involve electronic communication, we take reasonable measures to protect information while it is being transmitted electronically.
Where technically available and appropriate, we use secure connections, encrypted communication channels, authentication controls and other security measures to reduce the risk of unauthorized interception.
Sensitive documents should preferably be exchanged through secure client-approved methods rather than unsecured public channels.
7. Data Encryption
Encryption is an important part of our data-security approach.
Where supported by the relevant technology or service provider, sensitive information may be protected through encryption:
- In transit — while information is being transmitted between systems;
- At rest — while information is stored;
- During backup and recovery — where supported by the applicable infrastructure.
Modern security guidance recommends encryption for sensitive information, including information stored in cloud environments and information transmitted outside an organization.
8. Multi-Factor Authentication
Where available, we use or encourage Multi-Factor Authentication (MFA) for accounts containing sensitive business or financial information.
MFA provides an additional security layer beyond a username and password.
This may involve:
- Password authentication
- Authentication applications
- One-time verification codes
- Security keys
- Other supported authentication mechanisms
NIST identifies MFA as one of the fastest and most effective security improvements available to small businesses.
9. Access Control
Access to confidential client information is controlled according to business need.
Our security approach is based on the principle that personnel should receive access only to the information and systems necessary for their assigned responsibilities.
Where technically supported, access controls may include:
- Individual user accounts
- Strong passwords
- Multi-factor authentication
- Role-based permissions
- Restricted administrative access
- Access reviews
- Removal of access when no longer required
10. Server and Cloud Security
The Accountant Plus does not maintain its primary production client-data server inside our ordinary office premises.
Our client information may be processed or stored through secure third-party/cloud infrastructure and professional software platforms selected for business and security requirements.
This approach can provide additional layers of infrastructure security, including controlled data-center environments, access controls, redundancy, backup systems and professionally managed security infrastructure.
However, because cloud infrastructure is operated by third-party providers, security responsibilities may be shared between the provider and the customer. We therefore take appropriate steps to configure and use such services securely.
11. Protection Against Unauthorized Server Access
We take reasonable technical and organizational measures designed to reduce the possibility of unauthorized access to systems containing client information.
Depending on the applicable system, these controls may include:
- Authentication controls
- MFA
- Access permissions
- Encryption
- Firewall and network-security controls
- Security monitoring
- Software updates and security patches
- Malware protection
- Backup systems
- Restricted administrative privileges
- Secure configuration practices
No internet-connected system can honestly be described as completely immune from cyberattack. Our objective is therefore to maintain reasonable, risk-based and continuously improving security controls rather than make an absolute guarantee of security.
NIST describes cybersecurity as a continuous process because technologies, business requirements and threats continually change.
12. Secure Software and Technology Platforms
Depending on the particular service and client requirements, The Accountant Plus may use reputable accounting, bookkeeping, document-management, communication, cloud-storage and productivity platforms.
Security capabilities of such platforms may include:
- Encryption
- User authentication
- MFA
- Role-based access
- Audit logs
- Backup and recovery
- Secure cloud infrastructure
- Access management
- Security monitoring
Examples of security technologies and platforms that may be used or supported include Microsoft 365, Google Workspace/Google Cloud, secure cloud-storage platforms, accounting software and other professionally maintained SaaS applications, depending on the client’s requirements and the specific engagement.
Where applicable, cloud providers may maintain independent security certifications and controls such as ISO/IEC 27001. For example, Google states that Google Cloud and Google Workspace undergo independent audits and maintain ISO/IEC 27001 certifications for applicable services and infrastructure.
13. Backup and Data Recovery
We recognize that protecting data does not only mean preventing unauthorized access; it also means protecting information against accidental deletion, system failure, ransomware, hardware failure and other events.
Where supported by the relevant systems, appropriate backup and recovery mechanisms may include:
- Regular backups
- Automated backups
- Version history
- Redundant storage
- Recovery copies
- Point-in-time recovery
- Disaster-recovery procedures
- Backup monitoring
- Periodic restoration testing
NIST storage-security guidance recommends documented backup policies, encryption, multiple copies, appropriate retention and periodic testing of backups.
14. Protection Against Malware, Phishing and Cyber Threats
We recognize that cyber threats may arise through:
- Phishing emails
- Malware
- Ransomware
- Stolen passwords
- Unauthorized login attempts
- Malicious attachments
- Unsafe websites
- Compromised devices
- Social engineering
We therefore encourage secure passwords, MFA, updated software, antivirus/endpoint protection, secure email practices and employee awareness.
15. Employee and Personnel Confidentiality
Personnel who have access to client information are expected to maintain confidentiality.
Access to client information should be limited according to job responsibilities.
Where appropriate, confidentiality obligations may continue after an employee, contractor or service provider no longer works with The Accountant Plus.
16. Data Minimization
We seek to collect and retain information that is reasonably necessary for the services being provided.
We do not seek unnecessary personal or business information merely for collection purposes.
Where information is no longer required and there is no legal, contractual or legitimate business requirement to retain it, it may be deleted, destroyed or securely disposed of in accordance with applicable requirements.
17. Data Retention
Client information may need to be retained for:
- Professional record keeping
- Accounting requirements
- Tax requirements
- Regulatory requirements
- Legal obligations
- Contractual requirements
- Dispute resolution
- Internal compliance
- Legitimate business purposes
Retention periods may therefore vary according to the nature of the information and applicable legal or contractual requirements.
18. International Clients and Worldwide Privacy Principles
The Accountant Plus may provide services to clients located in different countries.
Accordingly, our privacy and security approach is designed around internationally recognized principles including:
- Confidentiality
- Integrity
- Availability
- Data minimization
- Purpose limitation
- Access control
- Secure processing
- Data retention
- Secure disposal
- Risk management
- Incident response
Where a particular privacy law applies to a client or engagement, additional contractual or technical requirements may apply.
19. Personal Information
Some accounting and business records may contain personal information relating to business owners, employees, customers, suppliers or other individuals.
Such information is handled only for legitimate business, accounting, tax, legal or professional purposes connected with the engagement.
We seek to limit access and disclosure of personal information to authorized persons and legitimate purposes.
20. Data Integrity
Confidentiality alone is not sufficient.
We also seek to protect the accuracy and integrity of client information against unauthorized alteration, corruption or accidental loss.
Appropriate controls may include:
- Restricted editing rights
- User authentication
- Audit trails
- Version history
- Reconciliation procedures
- Backup copies
- Review procedures
- Controlled access to accounting systems
21. Incident Response
If we become aware of a suspected security incident affecting client information under our control, we will take reasonable steps to:
- investigate the incident;
- contain or limit the impact;
- secure affected systems;
- assess the nature and scope of the incident;
- restore affected services where appropriate; and
- provide notifications where required by applicable law or contractual obligations.
22. Third-Party Service Providers
Some services may depend on third-party technology providers.
Examples may include:
- Cloud hosting providers
- Accounting software providers
- Email providers
- Cloud-storage providers
- Document-management providers
- Communication platforms
- Cybersecurity providers
- Backup providers
We seek to use reputable providers and consider security, privacy, reliability and business requirements when selecting technology platforms.
23. No Sale of Client Information
The Accountant Plus does not sell confidential client accounting records, financial records, tax records or business information to advertisers, data brokers or unrelated commercial parties.
Client information is used for legitimate professional and business purposes associated with the services provided.
24. Client Responsibility
Data security is a shared responsibility.
Clients should also maintain appropriate security over their own:
- Email accounts
- Accounting software accounts
- Banking accounts
- Cloud-storage accounts
- Computers and mobile devices
- Passwords
- Authentication methods
- User permissions
Clients should not send passwords, authentication codes or other security credentials through ordinary email unless specifically required through an approved secure process.
25. Security Limitations
Although we implement reasonable safeguards, no electronic transmission, cloud system, software platform or internet-connected system can be guaranteed to be 100% secure.
Cybersecurity risks can arise from events beyond the reasonable control of any organization, including sophisticated attacks, vulnerabilities in third-party systems, compromised credentials, telecommunications failures and other unforeseen events.
Accordingly, this policy describes our security practices and commitments but does not constitute an absolute guarantee that a security incident can never occur.
26. Continuous Security Improvement
Security requirements change continuously.
We periodically review our technology, processes and security practices and may introduce additional safeguards when appropriate.
Our approach is based on continuous improvement and risk management rather than relying on a single security product or technology.
27. Our Security Framework at a Glance
The Accountant Plus seeks to protect client information through multiple layers:
Client Confidentiality → Access Control → MFA → Encryption → Secure Cloud Infrastructure → Secure Software → Backups → Monitoring → Incident Response → Secure Disposal
This layered approach is intended to reduce the risk associated with unauthorized access, accidental loss, cyberattack, data corruption and inappropriate disclosure.
28. Our Commitment
We understand that a business owner does not give an accounting firm ordinary information.
You may be giving us access to the financial history, tax records, payroll information, bank information, business strategy and commercially sensitive information that represents years of work.
We therefore treat your information with the level of confidentiality and security that we would expect for our own business information.
Your financial information belongs to you. Our responsibility is to protect it, use it only for legitimate professional purposes, restrict unnecessary access and maintain appropriate security controls throughout our professional relationship.
29. Policy Updates
This Privacy, Confidentiality & Data Security Policy may be reviewed and updated periodically to reflect changes in technology, cybersecurity threats, applicable laws, regulations, professional requirements and our business practices.
The latest version published on our website will represent the current version of this policy.
The Accountant Plus
Accounting • Bookkeeping • Tax • Costing • CFO & Financial Advisory Services
