Privacy Policy
1. Who we are
This policy explains how VALQEN LTD (“Valqen”, “we”, “us”) collects and uses personal data when you visit valqen.co.uk, contact us, or become a client of our outsourced finance management services.
- Legal entity: VALQEN LTD, registered in England and Wales
- Company number: 17422650
- Registered office: 10 Lower Thames Street, London, England, EC3R 6AF
- Email: [email protected]
- Phone: +44 7418 392657
For personal data about enquirers, clients and their contacts, Valqen is the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For personal data contained in our clients’ financial records, we act as a processor on the client’s behalf — see section 3.
2. Personal data we collect
When you contact us
If you write to us, call us, or use the enquiry form on this site, we receive the details you choose to give: your name, email address, phone number, company name and the content of your message. The enquiry form does not send data to a server — it opens your own email app with a pre-filled message, and we receive it only when you send that email.
When you become a client
- Contact and business data: name, email, phone, job title, company name, company registration number and VAT number where applicable.
- Contract and billing data: engagement terms, invoices and payment records.
- Customer due diligence data: identity documents and information about directors and beneficial owners, collected to meet anti-money-laundering requirements.
- Correspondence and meeting notes relating to the engagement.
When you visit the website
The site itself does not use analytics, advertising tools or tracking cookies. Our hosting provider and the font service described in section 9 receive standard technical data such as your IP address and browser type when the page loads.
3. Client data we process as a processor
To deliver our services we are given access to clients’ accounting systems, bank statements and other financial records. These contain personal data about third parties — for example the client’s employees (including payroll and salary data), suppliers, contractors and customers.
For this data the client is the controller and Valqen is the processor. We work under a written data processing agreement that meets Article 28 of the UK GDPR. Under that agreement we:
- process the data only on the client’s documented instructions;
- ensure everyone with access is bound by confidentiality;
- use sub-processors only with the client’s prior authorisation;
- apply appropriate technical and organisational security measures;
- help the client respond to data subject requests and meet its own obligations;
- notify the client without undue delay of any personal data breach;
- return or delete the data at the end of the engagement, as the client chooses, unless the law requires us to keep it.
If you are an employee, supplier or customer of one of our clients and want to exercise your data protection rights, please contact that client directly. We will support them in responding.
Client financial data is available only to the people working on that engagement. It is never used for our marketing and is not passed to third parties except where the contract or the law requires.
4. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Replying to enquiries and preparing a proposal | Steps taken at your request before entering a contract; legitimate interests in responding to business enquiries |
| Delivering the services and managing the engagement | Performance of a contract |
| Invoicing, accounting and tax records | Legal obligation |
| Customer due diligence and anti-money-laundering checks | Legal obligation |
| Keeping our systems and client data secure | Legitimate interests |
| Establishing or defending legal claims | Legitimate interests |
| Occasional updates about our services to business contacts | Consent, or legitimate interests for existing clients, with an opt-out in every message |
Where we rely on legitimate interests, we have balanced them against your rights and you can object at any time (see section 10). Data collected for due diligence is used only for that purpose.
5. Who we share data with
We do not sell personal data. We share it only as needed with:
- IT and software providers that host our email, files and working tools, acting as our processors;
- providers of accounting and reporting software used on client engagements, where the client has authorised them;
- the client’s own accountant, auditor, bank or investors, when the client instructs us to share materials with them;
- identity verification providers used for customer due diligence;
- our professional advisers, such as lawyers and insurers, under duties of confidentiality;
- HMRC, regulators, law enforcement or courts, where the law requires it.
6. International transfers
We aim to store data in the UK or the European Economic Area. Some service providers may process data in other countries, including the United States. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards needed. Client data is transferred outside the UK only with the client’s authorisation. You can ask us for details of these safeguards.
7. How long we keep data
- Enquiries that do not lead to an engagement: up to 12 months after our last contact.
- Client contract, correspondence and billing records: 6 years after the end of the engagement, in line with UK limitation periods and tax rules.
- Customer due diligence records: 5 years after the business relationship ends, as required by the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and not used for any other purpose.
- Client financial data processed on the client’s behalf: returned or deleted at the end of the engagement, as the client instructs.
8. Security
Access to data is limited to the people who need it for a specific engagement. We use individual accounts with multi-factor authentication, encrypted storage and transfer, least-privilege access to client systems, and we remove our access when an engagement ends. Staff and contractors are bound by confidentiality. If a personal data breach occurs we will assess it promptly, notify the ICO where required, and inform affected clients and individuals where the law requires.
9. Cookies and website data
This website does not set cookies and does not use analytics or advertising trackers, so no cookie banner is shown. Web fonts are loaded from Google Fonts; when the page loads, your browser connects to Google’s servers, which receive your IP address and browser details. Google may process this data outside the UK. The enquiry form does not store anything in your browser or on our server.
10. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data where there is no reason to keep it;
- restriction of processing in certain circumstances;
- data portability for data you provided to us, processed by automated means on the basis of contract or consent;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where we rely on it.
To exercise any right, email [email protected]. We may need to confirm your identity. We respond within one month, which may be extended by two further months for complex requests. Some rights are limited by law — for example, we must keep due diligence records for the required period.
11. Withdrawing consent
Where we rely on your consent, you can withdraw it at any time by emailing [email protected] or using the unsubscribe link in any update we send. Withdrawal does not affect processing carried out before it.
12. Complaints
If you have a concern, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority: ico.org.uk, telephone 0303 123 1113.
13. Children
Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children through this website.
14. Changes to this policy
We may update this policy when our services, suppliers or legal requirements change. The current version is always on this page, with the date of the last update at the top. Significant changes will be communicated to clients directly.
15. Contact us
VALQEN LTD, 10 Lower Thames Street, London, England, EC3R 6AF
Email: [email protected]
Phone: +44 7418 392657