Last updated: 12 May 2026
FirmBooks ("we", "us") provides white-label accounting support to UK accountancy practices. We are registered in the UK and act as a data processor on behalf of the accountancy firms (controllers) who instruct us. Contact: hello@firmbooks.co.uk.
We process firm contact data under legitimate interest and contract. Client source documents are processed on the instruction of the accountancy firm (controller) under a Data Processing Agreement.
To deliver the requested accounting service, communicate with you about the job, and meet our legal obligations (e.g. AML record-keeping).
We use vetted sub-processors including cloud hosting (Supabase / AWS, EU region) and email delivery. All accounting work is performed by our in-house, UK-based team. A current list of sub-processors is available on request.
All accounting work is processed in-house within the UK. Where any limited processing by a sub-processor occurs outside the UK/EEA (e.g. cloud infrastructure regions), transfers are protected by the UK International Data Transfer Agreement (IDTA) and/or Standard Contractual Clauses, plus appropriate organisational and technical measures.
Submitted files are retained for up to 24 months after job completion, then deleted, unless a longer period is required by law (e.g. AML obligations: 5 years).
All data is encrypted in transit (TLS) and at rest. Storage buckets are private with row-level access control. Access is restricted to authorised staff on a need-to-know basis.
Under UK GDPR you may request access, rectification, erasure, restriction, portability or to object. Email hello@firmbooks.co.uk. You may also complain to the ICO (ico.org.uk).
We will post any updates on this page and notify active customers by email.