Privacy Policy
Last updated: August 2026
Charities trust us with sensitive financial and governance information. We treat that trust as central to our work. We collect only what we need, we never sell your data, and we handle every record with the same confidentiality we apply to client accounting files.
1. Introduction
Charity Accounting Partners ("CAP", "we", "us", "our") is committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, store, and safeguard your personal information when you use our website and services. Charity Accounting Partners is the trading name of Stride Financial Ltd, a company incorporated in the British Virgin Islands, providing outsourced finance services to UK charities. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in respect of all personal data we process, and we act as the data controller for personal information collected through this website and our marketing activities.
2. Information We Collect
We may collect the following types of personal data:
- Name and contact information (email address, telephone number)
- Organisation details (charity name, registered charity number, size, sector)
- Information you provide through forms, enquiries, and correspondence
- Website usage data including IP addresses, browser type, and pages visited
- Information collected through cookies and similar technologies
3. Lawful Basis for Processing
Under UK GDPR, we process your personal data on the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract
- Legitimate interests: Where processing is necessary for our legitimate interests (such as improving our services) provided these do not override your rights
- Legal obligation: Where processing is necessary to comply with UK law
4. How We Use Your Information
We use your information to:
- Respond to your enquiries and provide our accountancy and finance services
- Send relevant communications, updates, and marketing (where you have opted in)
- Improve our website and services
- Comply with legal and regulatory obligations, including requirements of the Charity Commission for England and Wales
- Prevent fraud and maintain security
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements under UK law. For client records, we typically retain data for seven years after the end of our engagement, in line with professional accounting standards and HMRC requirements.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction, as required by UK GDPR. In practice, this means:
- Data is encrypted in transit and stored in secure, access controlled systems
- Access is granted on a need to know basis and reviewed when roles or engagements change
- Accounts used to access client information are protected by strong authentication
- We use reputable, established software providers rather than untested tools
- We review our security measures regularly and update them as our systems and risks change
- All devices used to access client information are centrally managed and monitored by our specialist IT security partner
7. Confidentiality and Professional Standards
Everything you share with us, financial records, board papers, governance concerns, and funding information, is treated as confidential. Our team works to the confidentiality expectations that apply to chartered accountancy practice, and confidentiality obligations continue after an engagement ends. We do not discuss a client's affairs with another client, and we do not use your information as marketing material without your written agreement.
8. Data Minimisation
We ask for the minimum information needed to answer your enquiry or deliver the service you have engaged us for. If you offer information we do not need, we will tell you. Where we can work with anonymised or aggregated figures, we do.
9. Who We Share Information With
We share personal data only where it is necessary, and only with:
- Service providers who support our operations, such as secure hosting, email, scheduling, and customer relationship tools, acting on our instructions under a written agreement
- Professional advisers, where required for legal or regulatory reasons
- Regulators or authorities, where we are legally obliged to disclose information
Providers are chosen with care and are only permitted to process your data for the purposes we specify.
10. What We Never Do
- We never sell, rent, or trade your personal data
- We never share your donor, beneficiary, or staff data with third parties for their own marketing
- We never add you to marketing communications you have not opted into, unless we are permitted to contact you on the basis of legitimate interest under UK data protection law
- We never keep client records longer than our stated retention periods require
11. If Something Goes Wrong
If a personal data breach occurs, we will investigate promptly, take steps to contain it, and notify the Information Commissioner's Office within 72 hours where the breach is reportable. Where a breach is likely to result in a high risk to individuals, we will tell the people affected without undue delay and explain what we are doing about it. You will hear from us directly rather than finding out second hand.
12. International Transfers
Where your data is stored
All personal data we collect is stored in the United Kingdom or the European Economic Area. Our core systems, including database, file storage, email, and backup services, are hosted with providers that maintain UK/EU-based infrastructure and are contracted to process your data only within those jurisdictions.
Who accesses it, and from where
CAP operates a distributed team. Alongside our UK presence, vetted team members based in South Africa, Thailand, and the Philippines deliver client work by accessing our UK/EU-hosted systems remotely. Your data remains stored in the UK/EU at all times. It is accessed only through secure, encrypted connections, on managed and monitored devices, protected by multi-factor authentication and role-based access controls. Client data is not downloaded to or stored on local devices.
The safeguards we have in place
Because members of our team access personal data from outside the UK, we treat this as a restricted transfer under UK GDPR and apply ICO-approved safeguards. Every overseas team member is engaged under a written agreement that incorporates international data transfer clauses (the ICO's International Data Transfer Agreement, or EU Standard Contractual Clauses with the UK Addendum), together with binding confidentiality and security obligations. We complete, and keep under review, a transfer risk assessment (the "data protection test" under UK law) for each country in which our team members are based.
We do not store your personal data in non-UK/EU data centres as part of our standard operations. If that ever changes, we will only proceed where appropriate safeguards are in place, and we will tell you before the transfer takes place.
13. Your Rights Under UK GDPR
Under the UK General Data Protection Regulation, you have the following rights:
- Right of access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data in certain circumstances
- Right to restrict processing: Request limitation of how we use your data
- Right to data portability: Request transfer of your data to another organisation
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: Not be subject to decisions based solely on automated processing
To exercise any of these rights, please contact us using the details below. We will respond to your request within one month, as required by UK law.
14. Cookies
Our website uses cookies to improve your experience and analyse website traffic. You can control cookie settings through your browser. For more information about the cookies we use, please refer to our cookie settings.
15. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO at ico.org.uk or by calling their helpline on 0303 123 1113.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes by posting the updated policy on our website with a new "Last updated" date.
17. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us at:
Charity Accounting Partners