Privacy Notice
Perfect Support Services Limited
Version 2026.1 — last updated [DATE]
1. About this Privacy Notice
Perfect Support Services Limited (PSS, we, us, our) respects your privacy and is committed to protecting your personal information.
This Privacy Notice explains how we collect, use, share, store and protect personal information, the lawful bases on which we do so, how long we keep it, and the rights you have in relation to it. It applies to our website, our research and development (R&D) tax relief and related professional services, our training and educational activities, our business development and marketing, and our dealings with clients, partners, suppliers and other business contacts.
This Privacy Notice is not limited to our website. Our website and our use of cookies form part of it rather than defining its scope. Our detailed Cookie Policy is published separately at /cookies and should be read alongside this Notice.
We may also provide you with additional or more specific privacy information at the point at which we collect your information — for example in an engagement letter, a client onboarding pack, an event registration form or a supplier contract. Those notices supplement this one. Where there is a genuine conflict between a specific notice and this one, the more specific notice takes precedence for the processing it describes.
We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), each as amended by the Data (Use and Access) Act 2025, together with other applicable data protection law.
Please read this Notice carefully. If anything is unclear, or if you would like this Notice in an alternative format, please contact us using the details in section 25.
2. Who we are and who is responsible for your information
Perfect Support Services Limited is the data controller responsible for the personal information described in this Notice. This means we decide why and how your personal information is processed.
Legal entity: Perfect Support Services Limited
Registered in: England and Wales, company number 06200085
Registered office: 35 Ruddlesway, Windsor, Berkshire, SL4 5SF
Correspondence address: 3 Parsonage Chambers, Manchester, M3 2HV
Email (general): info@pss-tax.co.uk
Email (privacy and data protection): [privacy@pss-tax.co.uk]
Telephone: 0161 358 0820 (main) / 01489 533666
We have appointed a Data Privacy Manager with day-to-day responsibility for overseeing compliance with this Notice and for handling questions and requests about personal information. You can contact the Data Privacy Manager using the privacy email address above or by writing to our correspondence address marked for their attention.
We are not required to appoint a statutory Data Protection Officer under Article 37 of the UK GDPR, and the Data Privacy Manager is not appointed as one.
In some limited circumstances we act as a data processor rather than a controller — for example where we process personal information contained in payroll or employee records supplied to us by a client purely on that client’s documented instructions in order to prepare an R&D claim. In those circumstances the client is the controller and their own privacy notice governs that processing. Our contract with the client sets out our obligations under Article 28 of the UK GDPR.
3. Who this Privacy Notice applies to
This Notice applies to personal information we process about:
Visitors to our website and users of our online tools, including our eligibility checker and any assessment, pre-notification, calculator or portal functionality we make available now or in the future
Enquirers and prospective clients, and the directors, officers, employees, agents and representatives of prospective client companies
Clients, and the directors, officers, shareholders, employees, contractors, technical staff and other representatives of client companies whose information we process in the course of providing our services
Accountants, tax advisers and other professional partners, including where they operate as limited companies, limited liability partnerships, partnerships, sole traders or individuals
Introducers, referrers and affiliates
Attendees, registrants and participants in the PSS Academy, webinars, seminars, events, training sessions and other educational activities, and people who download our resources
Business contacts on our marketing and business development lists
Suppliers, subcontractors and their personnel
Individuals whose business information we obtain from legitimate public or commercial sources, as described in section 6
Anyone who contacts us, including by telephone, email, post, web form, live chat, social media or video meeting, and anyone who makes a complaint or exercises a data protection right
This Notice does not cover applications for employment with PSS. If you apply for a role with us, we will provide you with a separate candidate privacy notice at the point of application.
Our website and services are intended for businesses and business professionals. They are not directed at children, and we do not knowingly collect personal information relating to children. If you believe a child has provided us with personal information, please contact us and we will delete it.
4. Personal information we collect
Personal information means any information relating to an identified or identifiable living individual. It does not include information that has been anonymised so that the individual can no longer be identified.
We may collect, use, store and transfer the following categories of personal information:
Identity information — first name, last name, title, preferred name, job title, role and position within a business, company directorship and shareholding details where relevant to our services, professional qualifications, and business-related date of birth or national insurance number where these are strictly necessary for a specific purpose (for example verifying an individual’s involvement in qualifying R&D activity or complying with anti-money laundering obligations).
Contact information — business and, where you provide it, personal postal address, email address, telephone and mobile numbers, and business social media or professional networking profile details.
Business and company information — company name, company registration number, registered and trading addresses, VAT and PAYE reference numbers, HMRC Unique Taxpayer Reference, group and ownership structure, sector, size, turnover, employee numbers, accounting reference dates, and information about your company’s activities, projects and technical work. Where this information relates only to a company it is not personal information, but we treat it as personal information where it identifies or relates to an identifiable individual.
Engagement and claim information — information you or your advisers provide or that we generate in the course of providing our services, including project descriptions, technical narratives, details of competent professionals and the individuals involved in R&D activity, time and apportionment records, staff cost and payroll data, subcontractor and externally provided worker information, expenditure records, financial statements, tax computations and returns, correspondence with HMRC, claim notification and additional information form data, and enquiry, dispute and appeal records.
Financial and transactional information — bank and payment details, invoices, fee arrangements, payments made and received, credit control records, and information about services you have purchased from us.
Communications and correspondence information — the content and metadata of your communications with us by email, letter, telephone, web form, messaging or social media, notes of meetings and calls, and records of your enquiries, instructions, feedback and complaints.
Recording information — audio and video recordings, transcripts, automatically generated summaries and associated metadata relating to telephone calls, video meetings, webinars and events, as described in sections 9 and 10.
Training and event information — registration details, attendance and participation records, questions asked and content submitted, assessment or certification records where applicable, and feedback.
Marketing and communications preferences — your preferences for receiving marketing from us, the channels you have agreed to or objected to, records of consents and opt-outs, and suppression records held so that we can honour your choices.
Technical information — internet protocol (IP) address, approximate location derived from it, device type and identifiers, browser type and version, operating system and platform, screen resolution, language and time zone settings, referring website and, where you have an account or log-in, authentication data.
Usage information — information about how you use our website, online tools and communications, including pages and content viewed, full URLs and clickstream to, through and from our site, dates and times, page response times, download and search activity, length of visits, scrolling, clicks and other interactions, methods used to browse away from a page, and whether you opened or clicked links in our emails.
Profile and interaction information — information we derive or record in our customer relationship management system about your relationship with us, including enquiry history, engagement stage, interests indicated, event attendance, content downloaded, and internal notes made by our team.
Security and access information — records of access to our systems and premises, authentication and multi-factor authentication logs, and information generated by our cybersecurity and monitoring tools.
We also collect and use aggregated information such as statistical and demographic data. Aggregated information may be derived from personal information but is not personal information in law because it does not identify you. If we combine aggregated information with personal information so that you can be identified, we treat the combined information as personal information governed by this Notice.
If you do not provide personal information
Some of the information we ask for is required by law — for example identity information we must collect where anti-money laundering rules apply. Some is required under a contract with you or your company — for example the information we need to prepare and support a claim. Where that is the case we will tell you at the point we collect it, and you are obliged to provide it. Where information is optional, we will say so.
If you do not provide information we are required to collect, we may be unable to provide the relevant services, complete a claim, respond to an enquiry or meet a legal obligation, and we may have to end or decline the engagement. We will tell you at the time if this is the case.
5. Special category and criminal offence information
We do not routinely seek or require special category personal information — that is, information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, health information, or data concerning sex life or sexual orientation.
Occasionally such information may reach us incidentally — for example where a client’s payroll or absence records supplied for an R&D claim disclose sickness absence, where health information is provided to explain a delay or a reasonable adjustment, or where an individual chooses to disclose it to us. Where this happens we will process it only where we have a lawful basis under Article 6 of the UK GDPR and a separate condition under Article 9, which will be:
the establishment, exercise or defence of legal claims (Article 9(2)(f));
your explicit consent, where we have asked for and you have given it (Article 9(2)(a)); or
a substantial public interest condition in Schedule 1, Part 2 to the Data Protection Act 2018.
Where special category information reaches us incidentally and none of those conditions applies, we will not use it. We will redact or delete it and ask that it is not supplied to us again. In all cases we keep such information to the minimum necessary and restrict access to it.
We do not routinely process information about criminal convictions or offences or related security measures. Where such information is necessary — for example in connection with an HMRC enquiry involving allegations of fraud or careless or deliberate behaviour, in connection with the establishment or defence of legal claims, or where required for anti-money laundering or fraud prevention purposes — we will process it only where authorised by law under Article 10 of the UK GDPR and Schedule 1 to the Data Protection Act 2018.
Where we rely on a Schedule 1 condition that requires one, whether for special category or criminal offence information, we maintain an appropriate policy document setting out how we comply with the data protection principles and our retention and erasure policies for that information.
6. How we obtain personal information
We obtain personal information in the following ways.
Where we obtain your information from someone other than you
Where we obtain your personal information from a source other than you — whether from your company or its advisers, from an introducer, from a public register or commercial data source, from a service provider, or from HMRC — data protection law requires us to tell you about it. We must do so within a reasonable period and at the latest within one month of obtaining it; or, if we use it to communicate with you, at the latest when we first communicate with you; or, if we disclose it to someone else, at the latest when we first disclose it — whichever of those happens first.
We meet this obligation by providing or referring you to this Privacy Notice in our first communication with you, and by asking the company or adviser who gave us your details to make you aware of it.
The categories of personal information we obtain from third-party sources are identity, contact, business and company, engagement and claim, financial and communications information and, from public and commercial sources, identity, contact, business and company information and publicly stated professional interests or role information.
Some of the sources we use are publicly accessible — including Companies House and other public registers, corporate websites, professional networking services, business directories and published news and industry sources.
Directly from you
When you complete a form on our website, use our eligibility checker or other online tools, request a call back or book a meeting, contact us by telephone, email, post, messaging or social media, register for the PSS Academy, a webinar, seminar, event or training session, download a resource, subscribe to our communications, provide instructions or documents in the course of an engagement, enter a competition, promotion or survey, give us feedback, make a complaint or exercise a data protection right.
Automatically when you interact with us
Through cookies, tags, pixels, server logs, software development kits and similar technologies when you use our website and online tools, and through email tracking technologies that record whether our emails are delivered, opened and clicked. Our Cookie Policy at /cookies explains this in detail and tells you how to manage your preferences.
From your organisation and its advisers
Where you are a director, employee, contractor or representative of a client or prospective client, we commonly receive your information from your company, its accountant, its tax adviser, its bookkeeper, its payroll provider or a colleague — for example where you are identified as a competent professional, a project contact, an authorised signatory or a person involved in qualifying R&D activity.
From introducers, referrers and professional partners
Accountants, professional advisers, introducers, referral partners and affiliates may pass your details to us so that we can contact you about our services. Where they do, we expect them to have a lawful basis for doing so and, where the law requires it, to have obtained your consent. If you are contacted by us following a referral and you would rather we did not hold your details, please tell us and we will act on that.
From legitimate public and commercial sources
We obtain business contact and company information from sources including company and corporate websites, Companies House and other public registers, professional networking services, business directories and listings, published news and industry sources, commercial business data providers and list vendors, trade bodies and membership organisations, event and conference organisers, publicly available information, and other legitimate business-to-business sources. Where we use commercial data providers we take reasonable steps to satisfy ourselves that the information was lawfully collected and may lawfully be shared with us.
From our service providers and other third parties
We receive information from providers of website hosting and analytics, marketing and advertising platforms, customer relationship management systems, webinar and event platforms, telephony and video conferencing systems, payment and accounting providers, identity verification and anti-money laundering screening services, credit reference agencies where relevant, and professional advisers.
From HMRC and other public authorities
We may receive information about you or your company from HMRC or another public authority in connection with a claim, enquiry, dispute or statutory requirement, including where you have authorised us to act as your agent.
7. How and why we use your personal information, and our lawful bases
We will only use your personal information where the law allows us to. In most cases we rely on one or more of the following lawful bases:
Performance of a contract — where processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract.
Legitimate interests — where processing is necessary for our legitimate interests or those of a third party, and those interests are not overridden by your interests, rights and freedoms. We carry out a balancing assessment before relying on this basis and you may ask us for information about it.
Legal obligation — where processing is necessary to comply with a legal or regulatory obligation to which we are subject.
Consent — where you have given clear, affirmative consent to a specific use, for example certain marketing communications or non-essential cookies. Where we rely on consent you may withdraw it at any time.
We may rely on more than one lawful basis for a given activity. If you would like to know which basis we are relying on for a particular use, please contact us.
We set out below the main ways we use personal information and the lawful bases we rely on.
Responding to enquiries, providing information about our services, and assessing whether we can help you
Categories of information: Identity; Contact; Business and company; Communications
Lawful basis: Steps at your request prior to entering a contract; Legitimate interests (responding to enquiries and developing our business)
Operating our eligibility checker and other online assessment and pre-notification tools
Categories of information: Identity; Contact; Business and company; Technical; Usage
Lawful basis: Steps at your request prior to entering a contract; Legitimate interests (assessing eligibility efficiently and improving our tools)
Onboarding you or your company as a client, including identity checks, conflict checks and anti-money laundering and sanctions screening where applicable
Categories of information: Identity; Contact; Business and company; Financial; Criminal offence information where applicable
Lawful basis: Performance of a contract; Legal obligation; Legitimate interests (protecting our business from fraud and financial crime)
Preparing, submitting and supporting R&D tax relief claims and related professional services, including technical and financial reports, claim notifications and additional information forms
Categories of information: Identity; Contact; Business and company; Engagement and claim; Financial; Communications
Lawful basis: Performance of a contract; Legitimate interests (providing our services to the client and maintaining an evidential record)
Corresponding with HMRC as your agent, and handling HMRC enquiries, compliance checks, alternative dispute resolution, appeals and tribunal proceedings
Categories of information: Identity; Contact; Business and company; Engagement and claim; Financial; Communications; Recordings
Lawful basis: Performance of a contract; Legal obligation; Legitimate interests (establishing, exercising or defending legal claims)
Managing our relationship with you, including notifying you of changes to our terms or this Notice, requesting feedback and administering surveys
Categories of information: Identity; Contact; Communications; Marketing preferences
Lawful basis: Performance of a contract; Legal obligation; Legitimate interests (keeping our records accurate and improving our services)
Invoicing, collecting payment, credit control, accounting and financial reporting
Categories of information: Identity; Contact; Business and company; Financial
Lawful basis: Performance of a contract; Legal obligation; Legitimate interests (recovering sums owed to us)
Recording telephone calls, video meetings and other communications for the purposes described in section 9
Categories of information: Identity; Contact; Communications; Recordings
Lawful basis: Legitimate interests (training and quality assurance, accuracy of records, evidencing instructions and information provided); Performance of a contract, where the recording is necessary to deliver the service
Operating the PSS Academy and delivering webinars, seminars, events, training and educational content
Categories of information: Identity; Contact; Business and company; Training and event; Recordings; Marketing preferences
Lawful basis: Performance of a contract; Consent, where you have registered for optional communications; Legitimate interests (delivering and improving our educational activities)
Business-to-business marketing and business development, including email, telephone, post, targeted advertising and outreach to corporate contacts
Categories of information: Identity; Contact; Business and company; Profile and interaction; Marketing preferences; Technical; Usage
Lawful basis: Legitimate interests (promoting our services to businesses and developing our business); Consent, where required by PECR — see section 11
Building and maintaining prospect and business contact records from public and commercial sources
Categories of information: Identity; Contact; Business and company
Lawful basis: Legitimate interests (identifying businesses that may benefit from our services)
Segmenting our contacts and tailoring the content and timing of our communications and website content
Categories of information: Identity; Contact; Business and company; Profile and interaction; Technical; Usage; Marketing preferences
Lawful basis: Legitimate interests (making our communications relevant and avoiding irrelevant contact); Consent, where non-essential cookies or similar technologies are involved
Placing and reading cookies and similar technologies, and measuring website and advertising performance
Categories of information: Technical; Usage
Lawful basis: Consent, for all non-essential technologies; Legitimate interests, for strictly necessary technologies — see our Cookie Policy
Administering, maintaining and protecting our business, systems and website, including troubleshooting, testing, support, backup, monitoring, logging and information security
Categories of information: Identity; Contact; Technical; Usage; Security and access
Lawful basis: Legitimate interests (running our business securely and reliably); Legal obligation
Detecting, investigating and preventing fraud, misuse of our services, and breaches of our terms
Categories of information: All categories as relevant
Lawful basis: Legitimate interests (protecting our business, clients and staff); Legal obligation
Complying with legal, regulatory, tax, accounting and professional obligations, responding to lawful requests from authorities, and meeting professional indemnity insurance requirements
Categories of information: All categories as relevant
Lawful basis: Legal obligation; Legitimate interests (meeting professional and insurance obligations)
Establishing, exercising or defending legal claims, and handling complaints and disputes
Categories of information: All categories as relevant
Lawful basis: Legitimate interests (protecting our legal position); Legal obligation
Managing supplier, subcontractor, introducer and partner relationships
Categories of information: Identity; Contact; Business and company; Financial; Communications
Lawful basis: Performance of a contract; Legitimate interests (managing our supply chain and partnerships)
Business reorganisation, restructuring, merger, acquisition or disposal, and related due diligence
Categories of information: All categories as relevant
Lawful basis: Legitimate interests (managing and developing our business)
Producing anonymised and aggregated statistics, insights, case studies and service improvements
Categories of information: Aggregated information derived from the above
Lawful basis: Legitimate interests (understanding and improving our services). Case studies naming individuals or clients are published only with permission
How these bases apply to different people. Where we rely on performance of a contract, we do so only in relation to the individual who is a party to that contract. Where we process information about directors, employees, contractors, competent professionals or other representatives of a client, supplier or partner company — who are not themselves parties to our contract — we rely on our legitimate interests in performing that contract, delivering our services and maintaining an accurate evidential record, and, where relevant, on legal obligation. Where a row above lists more than one basis, the first named is our primary basis and the others apply only in the specific circumstances described. If you would like to know which basis applies to you for a particular activity, please ask and we will tell you.
Change of purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you would like an explanation of how processing for a new purpose is compatible with the original purpose, please contact us. If we need to use your personal information for an unrelated purpose, we will notify you and explain the lawful basis that allows us to do so. We may process your personal information without your knowledge or consent where this is required or permitted by law.
8. R&D tax relief and professional services
Our core service involves identifying, preparing, supporting and defending claims for R&D tax relief and related reliefs on behalf of company clients.
This work necessarily involves processing personal information about the individuals connected with a claim, including:
Competent professionals and other technical staff whose qualifications, experience, roles and activities evidence the technological or scientific advance and uncertainty being claimed
Directors, officers and shareholders, including their roles, remuneration and involvement in qualifying activity
Employees, contractors, agency workers and externally provided workers whose time, costs and activities are apportioned to qualifying projects
Subcontractors and their personnel
Authorised signatories, agents and contacts for HMRC purposes
Much of this information reaches us from the client company rather than from the individual. Where you are one of these individuals, we will normally be relying on our legitimate interests in providing professional services to our client and maintaining an accurate evidential record, and on our client’s own lawful basis for disclosing your information to us. Where we act purely on a client’s documented instructions in relation to their employee records, we act as a processor for that element of the work.
HMRC requires that claims are supported by records sufficiently detailed to allow it to check the figures in a return or claim, and claims may be subject to enquiry for a considerable period after submission. We therefore retain claim files and their supporting evidence for the periods described in section 18.
Where an HMRC enquiry, compliance check, alternative dispute resolution process, appeal or tribunal proceeding arises, we will process the personal information necessary to represent our client and to establish, exercise or defend legal claims.
9. Telephone calls, video meetings and recordings
We may record telephone calls, video meetings and other communications with us.
We do this for the following purposes:
training, coaching and quality assurance;
maintaining accurate and complete records of instructions, discussions and information provided to us;
supporting the delivery of our professional services, including ensuring nothing material discussed is missed when a claim is prepared;
maintaining an evidential record of the information provided in connection with a client’s claim, enquiry or other engagement;
resolving queries, complaints and disputes;
protecting the safety and security of our staff and clients; and
preventing and detecting crime.
Our lawful basis. We rely on our legitimate interests in the accuracy, quality and defensibility of our professional work, and — where a recording is necessary to deliver the service you or your company has engaged us for — on performance of a contract. We do not rely on consent for these recordings, and this Notice, together with the notification given at or before the start of a recorded call or meeting, is how we make you aware of them.
How you will know. Where practicable we give a short notification at the beginning of a recorded telephone call or video meeting, and video conferencing platforms we use will typically display a recording indicator. This Notice provides the full explanation.
If you would prefer not to be recorded. Please tell us at the start of the call or meeting, or contact us in advance. We will consider your request and, where we can reasonably do so, we will either stop the recording, delete it, or make written notes instead. You also have the right to object to processing based on legitimate interests, as described in section 19. In some circumstances we may need to continue recording — for example where a recording is necessary to establish or defend a legal claim — and if so we will explain why.
Access and retention. Recordings, transcripts and automatically generated summaries are held securely with access limited to those who need it. They are retained for the periods described in section 18: a shorter defined period for routine calls, and for the life of the relevant file where a recording forms a material part of a client or claim record.
We will not record a call or meeting for a purpose incompatible with those set out above, and we do not sell recordings or share them for third-party marketing purposes.
10. The PSS Academy, webinars, training and events
Where we operate the PSS Academy or run webinars, seminars, conferences, workshops, training sessions or other educational activities, whether online or in person, we process personal information in order to:
register you and administer your place, including any account, membership or log-in;
communicate with you about the session, including joining instructions, reminders, changes and follow-ups;
deliver the content and, where applicable, assess participation, issue certificates and maintain participation or certification records;
record sessions, as described below;
respond to questions submitted before, during or after a session;
collect and act on feedback;
make our educational content and future sessions better; and
where you have agreed, or where we may lawfully do so on the basis of legitimate interests for business contacts, send you related content and marketing.
Recording of sessions. Webinars, training sessions and events may be recorded, and recordings may be made available afterwards to attendees or more widely, including on our website or social channels. Recordings normally capture presenters and any audio, video or chat contributions made by participants. We will tell you when a session is being recorded. If you attend and do not wish to appear in a recording, you can keep your camera and microphone off and avoid submitting content to public chat, and you may contact us about any content you have already contributed.
Lawful bases. We rely on performance of a contract where you have registered for a paid or contractual programme, consent where you have opted in to optional communications, and legitimate interests in delivering, recording, improving and promoting our educational activities and in maintaining accurate participation records.
Third-party platforms. Registration, delivery and recording may be handled by third-party webinar, event, learning and video platforms acting as our processors. Those platforms may set cookies or similar technologies on their own pages; where they do, their own notices will apply to that activity.
11. Business-to-business marketing and business development
We market our services primarily to businesses. How the law applies depends on the type of contact.
What we send
We may use identity, contact, business, profile, interaction, technical and usage information to identify businesses likely to benefit from our services and to send you information about R&D tax relief, legislative and HMRC developments, our services, the PSS Academy, events and other content we consider relevant to your role.
Corporate subscribers
Where you are a contact at a limited company, limited liability partnership or other corporate body, PECR permits us to send business-to-business marketing emails and to make marketing calls without prior consent, provided we identify ourselves, give you a means of objecting and respect any objection you make. In these cases we rely on our legitimate interests in promoting our services to businesses. We assess the balance between those interests and your rights, and we limit our marketing to content relevant to your business role.
Before making marketing calls we screen our lists against both the Telephone Preference Service (TPS) and the Corporate Telephone Preference Service (CTPS), and against our own do-not-call records.
When we make a marketing call we say who is calling, display our telephone number or a valid alternative contact number, and we do not call anyone who has told us they do not want our calls, whether or not they are registered with the TPS or CTPS. When we send marketing email we never disguise or conceal our identity, and we always provide a valid address to which you can send an opt-out request.
Sole traders, partnerships and individuals
Where you are a sole trader, an individual, or a member of a partnership that is not an LLP, PECR treats you in the same way as a consumer for electronic marketing. In those cases we will only send you marketing emails or texts where you have consented, or where the “soft opt-in” applies — that is, where we obtained your details in the course of a sale or negotiations for a sale of our services, we are marketing our own similar services, and we gave you a simple means of opting out at the time and in every message since. Marketing calls are screened against the TPS and CTPS and against our own suppression records, as above.
Referrals
Where a third party such as an accountant or introducer has provided your details, we will make clear in our first communication where we obtained them. Where the law requires your consent for that referral, we expect the referrer to have obtained it.
Advertising and audience matching
We may use advertising, analytics and audience-matching services to show our content to relevant business audiences and to measure how our advertising performs.
Where this involves cookies or similar technologies on our website, we act on the basis of your consent as recorded through our cookie consent tool and in accordance with our Cookie Policy.
Where we share contact identifiers — such as a hashed business email address — with an advertising platform in order to build or exclude an audience, we do so on the basis of our legitimate interests in business-to-business marketing where you are a contact at a corporate body, and on the basis of your consent where you are a sole trader, an individual or a member of a partnership that is not an LLP. You can object at any time using the details in section 20, and we will remove you from the audiences we control. Some of these platforms act as independent or joint controllers in relation to their own use of the information; their own privacy notices apply to that use.
Email tracking
When we send you a marketing email we may include a small image or tracked links that tell us whether the message was opened and which links were clicked, so that we can understand what is useful and improve what we send. Where your consent is required for this, we ask for it at the point you sign up. You can withdraw it at any time using our preference centre or by contacting us, and you can also prevent it by setting your email client not to load remote images.
Your control
You can ask us to stop sending you marketing at any time. See section 20.
We do not sell your personal information. Other than the audience-matching described above, we do not share it with third parties for their own direct marketing purposes.
12. Automated processing and profiling
We use limited automated processing to make our services and communications more relevant and efficient. This includes:
scoring and segmenting business contacts in our CRM according to engagement, sector, size and likely relevance of our services;
automated eligibility indications produced by our online eligibility checker based on the answers you provide;
automated allocation of enquiries and workflow tasks; and
automated measurement of email and website engagement.
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. An output from our eligibility checker is an indicative guide only. It is not advice and it is not a final decision. Every engagement, and every conclusion about whether a claim is viable, involves review and judgement by a member of our team.
If we introduce solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, we will update this Notice, explain the logic involved and the likely consequences, and apply the safeguards required by Articles 22A to 22D of the UK GDPR (as amended by the Data (Use and Access) Act 2025). Those safeguards include telling you that such a decision has been made, giving you the opportunity to make representations, to obtain human intervention and to contest the decision. Where such a decision would be based wholly or partly on special category information, we would only make it with your explicit consent or where it is necessary for a contract with you and a Schedule 1 condition applies.
Where we use artificial intelligence or machine learning tools — for example to transcribe or summarise meetings, to draft or check documents, or to assist with research — outputs are reviewed by our people before being relied upon, and we assess such tools before use to ensure that personal information is handled appropriately and is not used to train third-party public models without an appropriate basis and safeguards.
13. Cookies, analytics, advertising and similar technologies
Our website and online tools use cookies, tags, pixels, web beacons, local storage, software development kits, server logs and similar technologies.
Strictly necessary technologies are used to make our website work, to keep it secure and to remember your cookie choices. These do not require your consent.
Data protection law also now exempts certain low-risk statistical and appearance-related technologies from the consent requirement where clear information and a free means of objecting are given. As a matter of policy we go further than the law requires: apart from strictly necessary technologies, we set nothing without your consent.
All other technologies — including analytics, performance, functionality, personalisation, advertising and social media technologies — are used only where you have given your consent through our cookie consent tool.
You can change or withdraw your preferences at any time using the cookie preferences control on our website, and you can also control cookies through your browser settings. Blocking all cookies, including strictly necessary ones, may prevent parts of our website from working.
Because the technologies operating on a website change over time, the definitive and current list of the cookies and similar technologies we use, their purposes, providers and durations is maintained in our cookie consent tool, which you can open at any time from our website. Our Cookie Policy at /cookies explains the categories, what they collect and how to control them.
Third-party links. Our website and communications may include links to third-party websites, plug-ins and applications. Following those links or enabling those connections may allow third parties to collect or share information about you. We do not control third-party websites and are not responsible for their privacy notices. We encourage you to read the privacy notice of every website you visit.
14. Who we share your personal information with
We share personal information only where there is a proper basis for doing so. The categories of recipient are:
Our people. Employees, contractors and consultants who need access to carry out their role, subject to confidentiality obligations and access controls.
Service providers acting as our processors. We use third parties to provide the technology and services we need to operate. The categories include: customer relationship management and client relationship platforms; cloud hosting, infrastructure and storage; email and communications services; document management and collaboration platforms; video conferencing and meeting platforms; telephony and call handling systems; transcription, note-taking and productivity tools; accounting, bookkeeping and financial systems; payment processing; website hosting, development, maintenance and support; analytics and measurement; advertising and marketing platforms; marketing automation and email delivery; webinar, event and learning platforms; e-signature services; identity verification, anti-money laundering and fraud prevention services; cybersecurity, monitoring, backup and disaster recovery providers; archiving and secure destruction services; and IT support.
We use a central CRM environment together with cloud document management, communications and accounting systems as the core of our data architecture. We name particular providers where doing so materially helps you understand what happens to your information, and we can tell you which providers are used for a particular activity if you ask.
Processors act on our documented instructions under written contracts that meet the requirements of Article 28 of the UK GDPR, and may not use your personal information for their own purposes.
Some advertising, social media and audience-matching platforms act as independent controllers or joint controllers in relation to their own use of information rather than as our processors. Where that is the case, their own privacy notices govern that use, and we will tell you which platforms this applies to on request.
Your professional advisers and representatives. Your accountant, tax adviser, bookkeeper, payroll provider, solicitor or other adviser, where you or your company have asked or authorised us to deal with them, or where doing so is necessary to deliver our services.
Introducers and referral partners. Where an introducer has referred you to us, we may confirm the status of the introduction and share limited information necessary to administer the referral arrangement. We do not share your information with introducers for their own marketing purposes without a lawful basis.
HMRC, regulators and public authorities. As described in section 15.
Our own professional advisers and insurers. Lawyers, accountants, auditors, tax advisers, insurance brokers and professional indemnity insurers, who may act as controllers in their own right in relation to the information they receive.
Banks, payment providers and credit reference or debt recovery agencies, in connection with payments and the recovery of sums owed.
Parties to a corporate transaction. Prospective buyers, sellers, investors or merger partners and their advisers, in connection with due diligence, and any new owner of the business or the relevant part of it. Where this happens, the new owner may use your personal information in the same way as set out in this Notice, and we will tell you if a change of controller occurs.
Anyone else where you ask us to, or where we are permitted or required by law to disclose.
15. HMRC, regulators and public authorities
Delivering our services necessarily involves dealing with HM Revenue & Customs. Where we act as your company’s agent, we submit claims, returns, notifications, additional information forms and correspondence to HMRC, and we respond to HMRC enquiries, compliance checks and information notices. This will involve disclosing personal information about the individuals connected with a claim, including the competent professionals and staff whose activities support it.
We may also disclose personal information to:
other government departments, regulators and public authorities where they have a lawful right to it;
law enforcement agencies, where required or permitted by law;
courts and tribunals, and parties to legal proceedings, where required by rules of court, a court order or the establishment, exercise or defence of legal claims; and
professional bodies, where we are subject to their rules.
HMRC, regulators and public authorities act as independent data controllers in relation to the information they receive from us. Their own privacy notices govern what they do with it. HMRC’s privacy notice is published at gov.uk.
Where we receive a request for personal information from a public authority, we satisfy ourselves that there is a lawful basis for disclosure and we disclose only what is necessary. Where we are legally able to tell you about such a request, we will.
16. International transfers
We prefer to keep personal information within the United Kingdom or the European Economic Area. However, some of our service providers, and some of our clients’ and partners’ organisations, operate internationally or use infrastructure, support functions or group companies outside the UK. This means your personal information may be transferred to, stored in or accessed from countries outside the UK.
Where we transfer personal information out of the UK, we ensure a similar degree of protection by relying on one of the following:
a transfer to a country, territory or sector that the UK government has determined provides an adequate level of protection, including under the UK Extension to the EU-US Data Privacy Framework where the recipient is certified;
the International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment (the “data protection test” — an assessment that protection for the information will not be materially lower than under UK law); or
another lawful transfer mechanism or exception permitted by Chapter V of the UK GDPR, including where the transfer is necessary for the establishment, exercise or defence of legal claims.
We also apply supplementary technical and organisational measures where our transfer risk assessment indicates they are needed.
You can obtain a copy of the safeguards we rely on for a specific transfer — for example the relevant IDTA or Addendum, with commercially confidential terms redacted — by contacting us using the details in section 25.
17. How we keep your personal information secure
We have put in place appropriate technical and organisational measures designed to protect personal information from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include, as appropriate to the risk:
access controls, role-based permissions and the principle of least privilege;
multi-factor authentication on business systems;
encryption of information in transit and, where appropriate, at rest;
managed and monitored endpoints, anti-malware and patching;
secure, resilient cloud infrastructure with backup and recovery arrangements;
network and email security controls, including filtering and threat protection;
logging and monitoring of access to systems containing personal information;
secure disposal of paper and electronic records;
confidentiality obligations in employment and supplier contracts;
staff training and awareness on data protection and information security;
due diligence and written contracts with processors; and
documented policies, including an information security policy and a personal data breach procedure.
We limit access to your personal information to those employees, contractors, agents and third parties who have a business need to know. They process it only on our instructions and are subject to a duty of confidentiality.
We have procedures in place to deal with any suspected personal data breach. Where a breach is likely to result in a risk to your rights and freedoms we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it where we are required to do so, and where a breach is likely to result in a high risk to your rights and freedoms we will also notify you without undue delay.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. Please take care when sending sensitive information to us by email, and contact us if you would prefer to use a secure alternative.
18. How long we keep your personal information
We keep personal information only for as long as necessary for the purposes for which it was collected, including to satisfy legal, tax, accounting, regulatory, professional indemnity insurance and reporting requirements, and to establish, exercise or defend legal claims.
To decide the appropriate period we consider the amount, nature and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether those purposes can be achieved by other means, and applicable legal, regulatory and professional requirements.
We maintain an internal retention schedule that sets out the periods applying to each category of record. The current framework is summarised below.
Client engagement and R&D claim files, including technical and financial evidence
Approach to retention: Retained for the period reasonably necessary to provide the services and to comply with tax, accounting, legal, regulatory and professional obligations, to respond to HMRC enquiries, compliance checks or proceedings, to establish, exercise or defend legal claims, and to satisfy professional indemnity insurance requirements. Our baseline is 6 years from the end of the accounting period to which the claim relates, or the end of the engagement, whichever is later, extended where an open or anticipated enquiry, dispute, claim or insurance requirement makes a longer period necessary
Financial and accounting records
Approach to retention: Normally a minimum of 6 years from the end of the financial year concerned, in line with statutory requirements, subject to applicable exceptions
HMRC enquiry, alternative dispute resolution and litigation files
Approach to retention: Retained through the conclusion of the matter plus an appropriate subsequent period reflecting professional, insurance and legal limitation periods
Prospect and enquiry records where no engagement follows
Approach to retention: Reviewed periodically and deleted or anonymised where there is no longer a reasonable business development purpose
Business-to-business marketing contact records
Approach to retention: Retained while there is a live legitimate business development purpose, subject to periodic review, refresh and cleansing
Marketing opt-outs and objections
Approach to retention: Suppression information retained for as long as necessary so that we can continue to honour your choice. This information is kept because you have opted out, not in spite of it
Recordings of calls and video meetings, and their transcripts and automatically generated summaries
Approach to retention: 12 months from the date of the call or meeting. Where a recording forms a material part of a client or claim file, it is moved into that file and follows the retention period for that file
PSS Academy, webinar, event and training records
Approach to retention: Retained for a period appropriate to the membership, training or event relationship and your marketing preferences
Website analytics data
Approach to retention: 14 months from collection, unless a shorter period is configured with the provider
Cookie consent records
Approach to retention: 6 months, after which we ask for your choices again
Client due diligence, identity verification and anti-money laundering and sanctions screening records, where these apply
Approach to retention: 5 years from the end of the business relationship, after which we are required to delete them unless we must keep them for legal proceedings or by law
Supplier, contractor, introducer and partner records
Approach to retention: Retained for the duration of the contract plus an appropriate legal and accounting retention period
Records of data protection rights requests and how we handled them
Approach to retention: 3 years from closure, to evidence our compliance
Complaints
Approach to retention: 6 years from closure, reflecting professional indemnity insurance and limitation requirements
In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use that information indefinitely without further notice to you.
In some circumstances you can ask us to delete your personal information. See section 19. Please note that the right to erasure is not absolute: we may need to retain information to comply with a legal obligation, or for the establishment, exercise or defence of legal claims. Where that applies, we will explain it to you and, where possible, restrict our use of the information to those purposes only.
You can request a copy of our retention schedule by contacting us.
19. Your rights
Under data protection law you have the following rights. Some apply only in certain circumstances.
Right to be informed — to be told how we use your personal information. This Notice, together with any additional notice we give you, is how we do that.
Right of access — to receive confirmation of whether we process your personal information and, if so, a copy of it and certain supplementary information. This is commonly known as a subject access request.
Right to rectification — to have inaccurate personal information corrected and incomplete information completed. We may need to verify the accuracy of new information you provide.
Right to erasure — to ask us to delete personal information where there is no good reason for us to continue processing it, where you have successfully objected to processing, where we have processed it unlawfully, or where we are legally required to erase it. This right is not absolute and does not apply where we need the information to comply with a legal obligation or to establish, exercise or defend legal claims.
Right to restrict processing — to ask us to suspend processing where you contest the accuracy of the information, where our use is unlawful but you do not want it erased, where we no longer need it but you need it for legal claims, or where you have objected and we are verifying whether our legitimate grounds override yours.
Right to object — to object to processing based on our legitimate interests where something about your particular situation makes you want to object. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or we need to process the information for legal claims. You have an absolute right to object to processing for direct marketing purposes, and we will always stop when you exercise it.
Right to data portability — to receive personal information you provided to us in a structured, commonly used, machine-readable format, or to have it transmitted to another controller. This applies only where our processing is based on consent or on a contract with you, and is carried out by automated means.
Right to withdraw consent — where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it. If you withdraw consent we may be unable to provide certain services, and we will tell you if that is the case.
Rights in relation to automated decision-making — see section 12.
Right to complain — see section 21.
How to exercise your rights
Contact us using the details in section 25. Please tell us clearly which right you wish to exercise and give us enough information to locate your records.
No fee, usually. You will not have to pay a fee to exercise your rights. We may charge a reasonable fee, or refuse to act, if a request is manifestly unfounded or excessive, particularly if it is repetitive.
Verifying your identity. We may need to ask for specific information to confirm your identity and your right to access the information. This is a security measure to ensure personal information is not disclosed to anyone with no right to receive it. We may also contact you for further information to help us respond more quickly.
Searches. When you ask for a copy of your information we carry out a reasonable and proportionate search for the information covered by your request.
Time limits. We aim to respond to all legitimate requests within one month. If your request is complex, or you have made a number of requests, it may take us longer, in which case we may extend the period by up to two further months, and we will tell you within one month and explain why. Where we need to confirm your identity, or to ask you to clarify a very broad request, the one-month period does not begin, or is paused, until we receive what we have asked for.
Information about others. Our records, particularly claim files, often contain information about more than one person and information that is confidential to our clients or subject to legal professional privilege. Where we cannot disclose information without adversely affecting the rights of others, or where an exemption applies, we will tell you and explain, so far as we are able.
20. How to stop marketing
You can ask us to stop sending you marketing communications at any time by:
clicking the unsubscribe link in any marketing email we send you;
using any preference centre we provide;
telling the person you are speaking to on a call; or
emailing us at [privacy@pss-tax.co.uk] or info@pss-tax.co.uk with the word “unsubscribe” or a clear statement of what you want to stop.
We will action your request promptly and in any event without undue delay.
Please note:
Opting out of marketing does not stop us sending you service communications that are necessary for a contract or engagement — for example claim updates, HMRC correspondence, invoices, engagement letters and changes to our terms or this Notice.
To honour your opt-out we need to keep a record of it on a suppression list. That is why we retain minimal information about you after you unsubscribe.
Where marketing was sent to a corporate email address on the basis of legitimate interests, your objection is absolute and we will stop.
21. Complaints and the Information Commissioner’s Office
If you are unhappy with how we have handled your personal information, or with how we have dealt with a request you have made, you can complain to us by emailing [privacy@pss-tax.co.uk] or by writing to the Data Privacy Manager at our correspondence address.
We will acknowledge your complaint within 30 days of receiving it and respond without undue delay, in line with our obligations under the UK GDPR as amended by the Data (Use and Access) Act 2025. We take complaints seriously and would welcome the opportunity to put things right.
You also have the right to complain at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:
Website: ico.org.uk/make-a-complaint
Helpline: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the chance to deal with your concerns before you approach the ICO.
22. Keeping your information accurate
It is important that the personal information we hold about you is accurate and current. Please let us know if your personal or business details change during your relationship with us, so that we can update our records.
23. Future technologies and changes to how we work
We may introduce new technologies, platforms, tools and methods of delivering our services from time to time. Where these involve the processing of personal information, we will assess that processing in accordance with applicable data protection law — including, where required, by carrying out a data protection impact assessment — and we will update this Privacy Notice or provide additional information where appropriate.
24. Changes to this Privacy Notice
We keep this Privacy Notice under review and will update it when our processing changes or when the law requires. The date at the top of this Notice shows when it was last updated.
Where changes are significant, we will take reasonable steps to bring them to your attention, for example by a notice on our website or by contacting you directly. Previous versions can be obtained by contacting us.
25. Contacting us
For any question about this Privacy Notice, about how we handle personal information, or to exercise any of your rights:
Data Privacy Manager
Perfect Support Services Limited
3 Parsonage Chambers, Manchester, M3 2HV
Email: [privacy@pss-tax.co.uk]
General email: info@pss-tax.co.uk
Telephone: 0161 358 0820
Registered office: 35 Ruddlesway, Windsor, Berkshire, SL4 5SF. Registered in England and Wales, company number 06200085.
26. Glossary of lawful bases
Performance of a contract means processing your personal information where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract.
Legitimate interests means the interests of our business in conducting and managing it so that we can provide the best service and the most secure experience. Before relying on this basis we consider and balance any potential impact on you, both positive and negative, and your rights. We do not use your personal information for activities where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted by law. You can obtain further information about how we assess our legitimate interests in respect of a specific activity by contacting us.
Compliance with a legal obligation means processing your personal information where it is necessary for compliance with a legal or regulatory obligation to which we are subject.
Consent means a freely given, specific, informed and unambiguous indication of your wishes by which you signify agreement, by a statement or clear affirmative action, to the processing of your personal information.