1. Who we are

This website is operated by Higginson James ("we", "us", "our"), Higginson James Limited, company number 09776382, of Belvedere, Debden Road, Newport, Essex, CB11 3RU, United Kingdom.

We are the data controller for the personal information described in this policy. This policy explains how we collect, use, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any questions about this policy or how we handle your data, contact us at:

  • Email: info@higginsonjames.com
  • Post: Belvedere, Debden Road, Newport, Essex, CB11 3RU, United Kingdom
  • ICO Registration number: ZC029724

2. The information we collect

We collect different information depending on how you interact with the site:

When you contact us or subscribe. If you use our contact form, email us, or sign up to any newsletter, we collect your name, email address, phone number (if given), and the content of your message.

When you book an appointment. Our booking system collects your name, email address, phone number, and the appointment detail you provide when you schedule a meeting with us.

When you become a client and use our document portal. To provide our services we may ask you to upload documents through a secure client portal or via email. This can include financial records, tax documents, bank statements, and because we are legally required to verify client identity before acting for you; proof of identity and proof of address (for example, a passport, driving licence, or utility bill) as part of our client due diligence and anti-money laundering (AML) obligations.

As part of our AML and client due diligence checks. As a firm regulated for anti-money laundering purposes, we're required to check client identity and assess risk before and during a client relationship. This may include screening against sanctions lists and Politically Exposed Persons (PEP) lists, checking international due-diligence databases, and, where necessary, sharing information with fraud prevention agencies to verify identity and prevent financial crime. This applies to clients and prospective clients, not to general visitors to the website.

When you browse the site. We use Cloudflare Web Analytics to understand how visitors use the site. This runs from a JavaScript snippet loaded on each page, and is a privacy-first analytics tool: it does not use cookies or any persistent client-side identifiers, and it does not track you across other websites. It measures aggregated metrics such as page views, referrers, approximate location (derived from IP address, which is not stored), device/browser type, and how long pages take to load. Because no cookies or unique identifiers are used, individual visitors cannot be identified from this data. See the Cookies section below for more detail.

We do not knowingly collect any special category data (such as health information) through the website itself, beyond what you may choose to include in a message or document you send us.

3. How we use your information

We use the information we collect to:

  • respond to enquiries sent through the contact form or by email;
  • provide accounting, tax, and advisory services to clients, including preparing and filing returns and correspondence with HMRC on your behalf where authorised;
  • carry out client identity verification and due diligence as required by UK anti-money laundering law;
  • schedule and manage appointments;
  • send service-related communications (for example, reminders about deadlines or documents we need from you);
  • send marketing communications, but only where you've opted in, and you can unsubscribe at any time;
  • maintain the security of the website and diagnose technical issues;
  • meet our own legal, regulatory, and professional obligations, including record-keeping requirements set by HMRC and registered professional bodies including the Association of Chartered Certified Accountants (ACCA) and The Association of Accounting Technicians (AAT).

4. Our legal basis for processing

Under UK GDPR, we rely on the following legal bases:

  • Contract: to provide services you've engaged us for, such as preparing your accounts or tax return.
  • Legal obligation: to comply with AML/client due diligence rules, HMRC record-keeping requirements, and other regulatory duties.
  • Consent: for optional marketing communications, and for any non-essential cookies (you can withdraw consent at any time).
  • Legitimate interests: to respond to general enquiries, keep the website secure, understand how the site is used through privacy-preserving analytics, and improve our services, balanced against your right to privacy.

5. Who we share your information with

We don't sell your personal data. We share it only where necessary, with:

  • Service providers who process data on our behalf, under contract and only for the purposes we specify. This currently includes Cloudflare (website hosting, security, and web analytics), GoDaddy Inc (domain registration and email), our email provider Microsoft Inc., and any newsletter tools we use.
  • HMRC and other regulators, where we are authorised to act on your behalf or where we are legally required to report information.
  • Our professional body (ACCA & AAT), where required for regulatory or compliance purposes.
  • Professional advisers (such as our own solicitors or insurers), where necessary.
  • Law enforcement or other authorities, where we're legally required to disclose information, including under money laundering reporting obligations.
  • Fraud prevention agencies, as part of our AML and client due diligence checks, they use this to help prevent fraud and money laundering and to verify identities, and may in turn enable law enforcement agencies to access and use this information to detect, investigate, and prevent crime.
  • Anyone to whom we transfer our rights and/or obligations under this policy.
  • A successor to our business, in the event of a restructure, sale, or acquisition of Higginson James Limited, subject always to confidentiality obligations.

If we, or a fraud prevention agency, determine that a client or prospective client poses a fraud or money laundering risk, we may decline to provide the services requested or may stop providing existing services. A record of this may be retained by fraud prevention agencies in line with their own retention practices, and may result in other organisations also declining to provide services, financing, or employment.

Some of our service providers may store or process data outside the UK/EEA. Where that happens, we ensure appropriate safeguards are in place (such as the UK's international data transfer addendum or standard contractual clauses).

6. How long we keep your information

  • Client records (accounts, tax documents, correspondence): we retain these for at least seven years from the end of the relevant tax/accounting year, in line with HMRC & Companies House (incl. ACSP) record-keeping requirements.
  • AML/identity verification records: retained for seven years after the end of our business relationship with you, as required by the Money Laundering Regulations.
  • General enquiries (contact form messages that don't lead to a client relationship): retained for 12 months, then deleted.
  • Marketing/newsletter data: retained until you unsubscribe or withdraw consent.
  • Website analytics data: Cloudflare Web Analytics data is aggregated and not tied to identifiable individuals; Cloudflare's own retention for this data is set by Cloudflare and can change.

7. Cookies and similar technologies

We keep this to the minimum. When you first visit the site, a banner lets you choose between two categories:

Necessary: a small piece of local storage on your device that remembers your cookie choice itself, so we don't ask again every visit. This isn't a tracking cookie and can't be switched off, since without it, we'd have nowhere to remember your preference.

Analytics: if you say yes, we use Cloudflare Web Analytics to see aggregate figures like which pages are visited and how often. It's built to run without cookies and without tracking individuals across websites, and Cloudflare doesn't sell this data or use it for advertising. If you say no, it simply doesn't run.

We don't currently use any advertising or marketing cookies. You can change your choice at any time using the "Cookie Preferences" link in the footer of any page.

You can control or delete cookies through your browser settings at any time; doing so may affect how parts of the site function.

8. Who we share data with (relevant to this site)

We use Formspree to process contact form submissions and deliver them to us by email, and Cloudflare to host the website and, if you consent, to provide the analytics described above. Both may process data outside the UK/EEA as part of how their infrastructure works; we only use providers who commit to appropriate safeguards for that.

9. Your rights

Under UK GDPR, you have the right to:

  • ask for a copy of the personal data we hold about you (right of access);
  • ask us to correct inaccurate or incomplete data (right to rectification);
  • ask us to delete your data, where we're not required to keep it for legal reasons such as HMRC record-keeping (right to erasure);
  • ask us to restrict how we use your data in certain circumstances;
  • object to processing based on legitimate interests, including direct marketing;
  • ask for your data in a portable format, where technically feasible;
  • withdraw consent at any time, where we rely on consent (this won't affect processing already carried out).

To exercise any of these rights, contact us at info@higginsonjames.com. We'll respond within one month, as required by law.

If you're unhappy with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We'd appreciate the chance to resolve any concern directly first.

10. Security

We use appropriate technical and organisational measures to protect your information, including encryption in transit, access controls, and secure hosting through Cloudflare. Once our client document portal is built, this policy will be updated to describe the specific security measures protecting it. In the meantime, any documents shared with us are handled through secure, access-controlled channels.

No method of transmission or storage is completely secure, so while we take reasonable steps to protect your data, we can't guarantee absolute security.

11. Children

Our services are intended for adults engaging accounting, financial, tax and maritime services. We don't knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time, for example when we add new tools to the site or our practices change. We'll post the updated version here with a new "last updated" date. For significant changes, we may notify clients directly.

13. Contact us

If you have questions about this policy or how we handle your personal information, please contact:

Higginson James Limited
Address: Belvedere, Debden Road, Newport, Essex, CB11 3RU, United Kingdom
Email: info@higginsonjames.com