Privacy Notice

Last updated: 1 July 2026

1. Who we are

  1. Woodstar Partners Ltd ("Woodstar Partners", "we", "us", "our") is the United Kingdom member firm of the Woodstar Partners network and is registered as auditors in the United Kingdom by the Association of Chartered Certified Accountants (ACCA). Each member firm of the network is a separate legal entity; this notice covers Woodstar Partners Ltd only. We are a private company limited by shares registered in England and Wales under company number 16852044. Our registered office is 86-90 Paul Street, London, EC2A 4NE. We are registered with the Information Commissioner's Office (ICO) as a data controller.
  2. We are the controller of the personal data described in this notice. We have not appointed a statutory data protection officer; questions about this notice and requests relating to your personal data should be sent to the person responsible for data protection, Oleksandr Vertyporokh, Director, at info@woodstarpartners.co.uk, by telephone on +44 20 7112 9389, or by post to the address above.
  3. This notice explains what personal data we collect, why and on what lawful basis we use it, who we share it with, how long we keep it, and your rights. It applies to visitors to www.woodstarpartners.co.uk (the "Site"), to our clients and prospective clients and their staff, to individuals whose personal data we see while performing audit, assurance, accounting and advisory work, and to our suppliers, contacts and job applicants.

2. Personal data we collect

  1. Depending on our relationship with you, we may collect and process the following categories of personal data:
  • Identity and contact data: name, job title, employer, postal address, email address, telephone number.
  • Client due diligence data: date of birth, nationality, copies of passports, driving licences or other identity documents, proof of address, details of beneficial ownership and source of funds, and the results of identity, sanctions and politically-exposed-person screening, collected to meet our anti-money laundering obligations.
  • Engagement data: personal data contained in the books, records, contracts, payroll, expense, banking, pension, customer, supplier and other information of our clients that we examine when carrying out audit, assurance, accounting or advisory engagements. This may include data about directors, shareholders, employees, customers, suppliers and other third parties of the client.
  • Financial data: bank account details for invoicing and payment; fee and billing history.
  • Correspondence and marketing data: the content of emails, letters, calls and meetings with you; your marketing preferences.
  • Website and technical data: IP address, browser type and version, device information, pages visited and the date and time of visits, collected through cookies and server logs as described in section 11; information you submit through the contact form.
  • Recruitment data: CVs, qualifications, employment history, references, right-to-work documents and interview notes.
  1. In the course of engagements we may incidentally see special category data (for example health information in sickness or absence records) or data about criminal convictions and offences (for example in the course of client due diligence, sanctions screening or where a matter is relevant to an audit). We do not seek such data unless it is necessary for the engagement, we process it only as described in section 4, and we do not use it for any other purpose.
  1. We obtain personal data directly from you; from the client or organisation you work for, own or deal with; from public sources such as Companies House, the Register of Statutory Auditors, the Land Registry, sanctions lists and the internet; from identity-verification and credit-reference providers; from other professional advisers, banks, regulators and counterparties; and from our website and email systems.

3. Why we use personal data and our lawful bases

  1. The UK General Data Protection Regulation ("UK GDPR") requires us to have a lawful basis for each purpose for which we process personal data. The table below sets out our main purposes and the bases we rely on.
Purpose Personal data involved Lawful basis (UK GDPR Article 6)
Responding to enquiries and providing quotes Identity, contact, correspondence Steps at your request before entering into a contract (Art 6(1)(b)); our legitimate interest in developing our business (Art 6(1)(f)).
Client acceptance, identity verification, sanctions and PEP screening, ongoing monitoring Identity, contact, client due diligence Compliance with a legal obligation (Art 6(1)(c)) under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and the Proceeds of Crime Act 2002.
Performing statutory audits and other engagements required by law Engagement data, identity, contact Compliance with a legal obligation (Art 6(1)(c)) under the Companies Act 2006 and other legislation requiring an audit; our legitimate interest in performing the engagement to the required standards (Art 6(1)(f)).
Performing non-statutory assurance, accounting and advisory engagements Engagement data, identity, contact Performance of our contract with the client (Art 6(1)(b)) and, for individuals who are not our client, our legitimate interest in performing the engagement (Art 6(1)(f)).
Complying with professional and regulatory obligations, including ACCA and FRC monitoring, quality reviews, ISQM (UK) 1 requirements and reporting to regulators Engagement data, identity, contact Compliance with a legal obligation (Art 6(1)(c)) under the Statutory Auditors and Third Country Auditors Regulations 2016 and our recognised supervisory body's rules; our legitimate interest in maintaining our registration (Art 6(1)(f)).
Invoicing, credit control, accounting and tax records Identity, contact, financial Performance of our contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)) under tax and company law.
Managing our relationship with you, including engagement letters, complaints and disputes Identity, contact, correspondence Performance of our contract (Art 6(1)(b)); legitimate interests in running our practice and establishing, exercising or defending legal claims (Art 6(1)(f)).
Sending information about our services, legislative updates and events to existing and prospective business contacts Identity, contact, marketing preferences Our legitimate interest in direct marketing (Art 6(1)(f)), which is a recognised legitimate interest under the Data (Use and Access) Act 2025; where the law requires it, your consent (Art 6(1)(a)). You may opt out at any time.
Operating, securing and improving the Site Website and technical data Our legitimate interests in running the Site securely and understanding how it is used (Art 6(1)(f)); consent for non-essential cookies (see section 11).
Recruitment Recruitment data Steps at your request before entering into a contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)) for right-to-work checks; legitimate interests in selecting suitable candidates (Art 6(1)(f)).
Preventing and detecting crime, protecting our systems and insurance and professional indemnity purposes All categories as relevant Legitimate interests (Art 6(1)(f)); legal obligation (Art 6(1)(c)); the recognised legitimate interest in detecting, investigating or preventing crime under the Data (Use and Access) Act 2025.

  1. Where we rely on legitimate interests, we have considered whether our interests are overridden by your interests, rights and freedoms and concluded that they are not, having regard to the safeguards described in this notice. You can ask us for information about our assessment using the contact details in section 1.
  2. We do not use personal data to make decisions about you based solely on automated processing, and we do not carry out profiling that produces legal or similarly significant effects.
  3. Special category and criminal offence data

4. Special category and criminal offence data

Where we process special category data or criminal offence data in the course of an engagement or client due diligence, we do so under Article 9(2)(g) or Article 10 UK GDPR together with the conditions in Schedule 1 to the Data Protection Act 2018, in particular the conditions relating to statutory and regulatory requirements, the prevention or detection of unlawful acts, protecting the public against dishonesty, and the establishment, exercise or defence of legal claims. We maintain an appropriate policy document for this processing as required by the Act.

5. Our role when we audit

  1. When we act as statutory auditor we perform an independent statutory function. Our audit working papers, including any personal data they contain, are held by us as an independent controller and not as a processor for the audited entity. We determine what information we need, how long we keep it and to whom we must disclose it under law and professional regulation. The audited entity remains the controller of its own records.
  2. For accounting, bookkeeping and payroll-type services where the client instructs us what to do with the data, we may act as processor; where that applies, the engagement letter sets out the data-processing terms required by Article 28 UK GDPR.

6. Confidentiality

All information about clients and their affairs is treated as confidential in accordance with the ACCA Code of Ethics and Conduct and our contractual obligations, whether or not it is personal data. We disclose it only as described in this notice, as required by law or regulation, or with the client's consent.

7. Who we share personal data with

  1. We may share personal data with:
  • Our regulators and professional bodies: ACCA (including its practice monitoring reviewers, who inspect audit files during compliance visits), the Financial Reporting Council, and, where relevant, the Financial Conduct Authority, the Prudential Regulation Authority and Companies House.
  • – Law enforcement and government bodies: the National Crime Agency (suspicious activity reports), HM Revenue & Customs, courts and tribunals, where we are required to do so by law.
  • – Engagement quality and file reviewers: independent engagement quality reviewers, external file reviewers and training providers engaged to meet ISQM (UK) 1 and ACCA requirements, all bound by confidentiality.
  • – Other auditors and advisers: component or group auditors, predecessor or successor auditors (professional clearance), and the client's other professional advisers, banks and counterparties where necessary for the engagement or with the client's agreement.
  • – Our service providers: providers of cloud hosting, email and document storage, audit working-paper and client-collaboration software, practice management, e-signature, identity-verification and AML screening, IT support, website hosting and analytics, and professional advisers such as lawyers, insurers and our own accountants.
  1. Our service providers act on our instructions under written contracts that require them to keep personal data secure and confidential and to use it only for the purposes we specify.

8. International transfers

We store and process personal data principally in the United Kingdom. Personal data may be transferred outside the UK where an engagement involves other firms outside the UK, and some of our service providers host data, or provide support from, the European Economic Area and the United States. Where personal data is transferred outside the UK we rely on UK adequacy regulations (including for the EEA and, for certified organisations, the UK–US Data Bridge) or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed so that the protection afforded is not materially lower than under UK law. You can ask us for details of the safeguards in place.

9. How long we keep personal data

  1. We keep personal data only for as long as we need it for the purposes set out above, including to meet legal, regulatory, professional and insurance requirements. Our standard retention periods are:
Records Retention period
Audit working papers and other engagement files 6 years from the end of the financial period to which the engagement relates (minimum 5 years under ISA (UK) 230 and ISQM (UK) 1), or longer if a claim, complaint or regulatory enquiry is open.
Client due diligence and AML records 5 years from the end of the business relationship or the completion of the occasional transaction (regulation 40, Money Laundering Regulations 2017), after which they are deleted unless we are required to keep them longer.
Engagement letters, contracts, invoices and accounting records 6 years from the end of the financial year in which the relationship ended (Companies Act 2006 and tax legislation) or, for contracts under seal, 12 years.
Enquiries that do not lead to an engagement and business-contact data Up to 2 years from our last contact with you, unless you ask us to delete it sooner.
Recruitment records for unsuccessful candidates 6 months from the end of the recruitment process.
Website server logs and analytics data Up to 13 months.

  1. When personal data is no longer needed we securely delete or anonymise it. Where deletion from backups is not immediately possible, the data is put beyond use until the backup is overwritten.

10. Security

  1. We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, including access controls, multi-factor authentication, encryption of devices and data in transit, secure client portals for exchanging documents, regular software updates and staff training. Access to personal data is limited to those who need it to carry out their role.
  2. Email is not a secure medium. We will agree a secure method for exchanging confidential client documents at the start of an engagement. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the ICO and, where required, you, in accordance with the UK GDPR.

11. Cookies and the Site

  1. The Site uses cookies and similar technologies. Strictly necessary cookies are set without consent because the Site cannot function without them. Cookies used solely to collect statistical information about use of the Site or to improve its functionality may be set on the basis permitted by the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Data (Use and Access) Act 2025, provided we give you clear information and a simple way to object; all other non-essential cookies are set only with your consent.
Cookie / tool Purpose Duration
Session and security cookies set by our hosting platform Strictly necessary: page delivery, load balancing, security and form submission. Session, or up to 12 months
Analytics tool, e.g. Google Analytics 4 / hosting-platform analytics Statistical information about how visitors use the Site, in aggregated form. You can object using the cookie controls on the Site or your browser settings. Up to 13 months

  1. You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may affect the operation of the Site. The Site may contain links to third-party websites, which have their own privacy notices; we are not responsible for them.

12. Your rights

  1. Subject to the conditions and exemptions in the UK GDPR and the Data Protection Act 2018, you have the right to:
  • request access to the personal data we hold about you and information about how we use it (we may limit our search to what is reasonable and proportionate);
  • have inaccurate personal data corrected and incomplete data completed;
  • have your personal data erased in certain circumstances;
  • restrict our processing of your personal data in certain circumstances;
  • object to processing based on legitimate interests, and object at any time to direct marketing;
  • receive personal data you have provided to us in a portable format where processing is based on consent or contract and is automated; and
  • withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal.
  1. Some of these rights are limited where we hold personal data to meet legal or professional obligations — for example, we cannot erase client due diligence records within the statutory retention period, and audit working papers must be retained under auditing standards. The exemption for personal data processed in the course of a statutory audit function may also apply. We will explain the basis for any refusal.
  2. To exercise any right, contact us using the details in section 1. We will respond within one month of receiving your request, extended by up to two further months where a request is complex or numerous, and we may ask you to verify your identity. We do not charge a fee unless a request is manifestly unfounded or excessive.

13. Complaints

  1. If you have a complaint about the way we handle your personal data, please tell us. You can complain by email to info@woodstarpartners.co.uk, by telephone on +44 20 7112 9389, or by post to the address in section 1. We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate it, and inform you of the outcome without undue delay.
  2. You also have the right to lodge a complaint at any time with the Information Commissioner's Office, the UK supervisory authority for data protection: www.ico.org.uk, telephone 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to deal with your concern first.

14. Changes to this notice

We review this notice at least annually and update it when our processing or the law changes. The current version is published on the Site with the date shown at the top. Significant changes affecting our clients will be notified through our usual channels.