1. Introduction and Scope
This Privacy Notice sets out the manner in which Provantec Limited, trading as Finsera (the Company), Processes Personal Data in connection with its website, enquiries, consultations and, where applicable, the provision of accounting, bookkeeping, tax, payroll, company secretarial, reporting and related business-support services.
Finsera is a trading name of Provantec Limited, registered in Ireland. Company No. 820186. This Notice is issued pursuant to applicable Data Protection Legislation, including Regulation (EU) 2016/679 (the GDPR) and the Data Protection Acts 1988 to 2018, as amended from time to time.
This Notice applies to Data Subjects whose Personal Data is Processed by the Company in the course of operating its website and carrying on its business, including (without limitation) website visitors, persons who submit enquiries or consultation requests, clients, authorised representatives, and individuals whose Personal Data is provided to the Company in connection with a client engagement.
This Notice does not constitute legal advice and does not confer rights additional to those arising under Applicable Law. In the event of any conflict between this Notice and Applicable Law, Applicable Law shall prevail.
2. Data Controller
For the purposes of Data Protection Legislation, the Data Controller is Provantec Limited, trading as Finsera, a company registered in Ireland under company number 820186.
The Company's contact details for the purposes of this Notice are set out in section 24. The Company has not appointed a statutory Data Protection Officer. Data protection enquiries may be directed to the contact details in section 24.
3. Definitions and Interpretation
In this Notice, unless the context otherwise requires:
- Applicable Law means all laws, statutes, regulations, codes of practice and binding guidance applicable to the Company from time to time, including Data Protection Legislation.
- Controller (or Data Controller) has the meaning given in the GDPR.
- Data Protection Legislation means the GDPR, the Data Protection Acts 1988 to 2018, the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (as amended), and any successor or implementing legislation, in each case as amended from time to time.
- Data Subject means an identified or identifiable natural person.
- Personal Data means any information relating to a Data Subject.
- Personal Data Breach (or Data Breach) has the meaning given in the GDPR.
- Processing means any operation or set of operations performed on Personal Data, whether or not by automated means.
- Processor (or Data Processor) has the meaning given in the GDPR.
- Special Categories of Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation, as provided for in Article 9 GDPR.
- Supervisory Authority means the Data Protection Commission, or such other competent supervisory authority as may apply.
Headings are for convenience only and shall not affect interpretation. References to "including" shall be construed as "including without limitation".
4. Categories of Personal Data
The categories of Personal Data Processed by the Company depend upon the nature of the Data Subject's interaction with the Company and the scope of any engagement. The Company does not necessarily Process every category described below in respect of every Data Subject.
Where relevant to the particular circumstances, the Company may Process:
- identification information, including name, title, date of birth, and identifiers contained in identity documents where collected for a lawful purpose;
- contact information, including postal address, email address and telephone number;
- business and company information, including business name, business type, position or role, company registration particulars supplied by the client, and related organisational information;
- tax, accounting and financial information, including VAT particulars, tax references supplied by the client, invoices, receipts, ledgers, management accounts, forecasts and other financial records;
- bank and payment information, where provided for the purpose of an engagement or the administration of fees;
- payroll and employment information, where the Company is engaged to provide payroll or related services;
- correspondence, enquiry details, consultation notes and other communications;
- engagement information, including the nature of services requested or provided and records necessary for the administration of the relationship;
- information contained in documents, files or records supplied by or on behalf of a client;
- information relating to individuals connected with a client, as further described in section 5; and
- technical information relating to use of the website, as further described in the Cookie Policy, to the extent such information constitutes Personal Data.
The Company does not seek to collect more Personal Data than is reasonably required for the purposes set out in this Notice.
5. Personal Data Relating to Third Parties
In the course of an engagement, a client or authorised representative may provide the Company with Personal Data relating to third parties, which may include employees, directors, shareholders, customers, suppliers, contractors, and, where relevant to the engagement, family members or dependants.
Where a client (or any person acting on its behalf) provides Personal Data relating to a third party, that client is responsible for ensuring that it is lawful and duly authorised to do so, including, where required, by providing any necessary information to the relevant Data Subject and ensuring that an appropriate lawful basis exists.
The Company Processes such Personal Data as Controller or, where Applicable Law so requires in respect of a particular Processing activity, in such other capacity as is appropriate to that activity, solely for the purposes of the relevant engagement and as otherwise described in this Notice.
6. Sources of Personal Data
Personal Data may be obtained:
- directly from the Data Subject, including via the website enquiry form, email, telephone or in person;
- from clients and authorised representatives;
- from documents, records and files supplied by or on behalf of a client;
- from public authorities or public registers, where legally permitted and necessary for the relevant purpose; and
- from Processors or other service providers engaged by the Company, to the extent necessary to operate the business or perform an engagement.
The Company does not obtain Personal Data from sources other than those which are necessary and appropriate in the circumstances. Specific third-party data sources are: limited to the Companies Registration Office and other public registers where a search or filing is required for a service you request, and otherwise to the sources listed in section 6 above.
7. Purposes of Processing
The Company Processes Personal Data for the following purposes, in each case as applicable to the particular circumstances:
- responding to enquiries and consultation requests;
- providing professional services, which may include accounting, bookkeeping, tax compliance, VAT, payroll (where engaged), preparation of accounts, management reporting, company secretarial support and business advisory services;
- client administration, communication, document management and engagement management;
- billing, invoicing and payment administration;
- compliance with legal and regulatory obligations, including, where applicable, tax, company law, anti-money laundering and client due diligence requirements;
- prevention and detection of fraud, misuse or other unlawful activity;
- website administration, information security and the maintenance of business records;
- the establishment, exercise or defence of legal claims, and the taking of professional advice; and
- such other purposes as are compatible with the foregoing and permitted by Applicable Law.
8. Lawful Bases for Processing
The Company Processes Personal Data only where a lawful basis under Article 6 GDPR applies. The applicable lawful basis depends upon the particular Processing activity and may include one or more of the following:
- performance of a contract (Article 6(1)(b)), where Processing is necessary for the performance of a contract with the Data Subject or in order to take steps at the Data Subject's request prior to entering into a contract, including the handling of an enquiry or consultation and the performance of an engagement;
- compliance with a legal obligation (Article 6(1)(c)), where Processing is necessary for compliance with a legal obligation to which the Company is subject, including, where applicable, obligations arising under tax, company, anti-money laundering and other Applicable Law;
- legitimate interests (Article 6(1)(f)), where Processing is necessary for the purposes of legitimate interests pursued by the Company or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject. Such interests may include the proper administration of the business, the security of systems and information, the keeping of records, and responding to communications;
- consent (Article 6(1)(a)), where Consent is relied upon for a specific Processing activity, in which case Consent may be withdrawn at any time without affecting the lawfulness of Processing based on Consent before its withdrawal; and
- vital interests (Article 6(1)(d)), only where Processing is necessary in order to protect the vital interests of the Data Subject or of another natural person, which the Company does not anticipate as a routine basis for Processing.
The Company does not rely on the performance of a task carried out in the public interest or in the exercise of official authority as a routine lawful basis.
A record of the lawful bases applicable to particular Processing activities is: maintained internally and mapped to the purposes in section 7, principally performance of a contract, compliance with a legal obligation, legitimate interests (where applicable), and consent where required.
9. Special Categories of Personal Data
The Company does not routinely seek to Process Special Categories of Personal Data. In the ordinary course of website use and an initial consultation enquiry, such data is not required.
If, in the context of a particular engagement, Special Categories of Personal Data are provided to the Company (including incidentally in documents supplied by a client), the Company shall Process such data only to the extent necessary for the relevant purpose and only where an Article 9 GDPR condition applies, in addition to an Article 6 lawful basis. The applicable Article 9 condition depends upon the circumstances and may include, where relevant, explicit consent, or Processing necessary for the establishment, exercise or defence of legal claims, or such other condition as Applicable Law permits.
Whether Special Categories of Personal Data are Processed in the course of particular services is: not routinely collected through the website; may arise incidentally in documents supplied during an engagement, in which case Processing is limited to what is necessary and supported by an applicable Article 9 condition.
10. Accounting, Tax, Payroll and Compliance Processing
The provision of professional accounting, tax, bookkeeping, payroll, company secretarial and related services may require the Processing of financial, tax, employment, payroll, accounting and other information necessary to perform the engagement and to comply with applicable legal, regulatory and professional obligations.
Such Processing may include the preparation and filing of returns or accounts, correspondence with competent authorities where required, the maintenance of working papers and engagement files, and the making of such records as are necessary to demonstrate compliance.
The Company Processes such Personal Data only to the extent reasonably required for the engagement and for compliance with Applicable Law. The precise scope of Processing will depend upon the services agreed with the relevant client.
11. Disclosure of Personal Data
The Company may disclose Personal Data where such disclosure is necessary for the purposes set out in this Notice or is required or permitted by Applicable Law. Recipients may include, as applicable:
- the Office of the Revenue Commissioners;
- the Companies Registration Office;
- other competent public authorities and regulatory bodies, where required or permitted by law;
- professional advisers, legal advisers and, where applicable, auditors;
- Processors and service providers engaged to support the operation of the business or the performance of services, as described in section 12; and
- other parties where disclosure is required or permitted by law, or is necessary for the establishment, exercise or defence of legal claims.
The Company does not disclose Personal Data as a matter of routine to any organisation except as necessary for the relevant purpose. Named recipients beyond the categories above are: none as a matter of routine, except where required for a particular engagement (for example Revenue, the CRO, a bank, or a payroll provider as instructed by the client).
12. Data Processors and Service Providers
The Company may engage third-party service providers to act as Processors on its behalf, where necessary to operate the website, administer the business, or provide services. Such Processors may include providers of information technology, hosting, communications, document management, accounting systems, payroll systems (where payroll services are engaged), and professional support.
Where the Company engages a Processor, it shall do so pursuant to a written contract containing the provisions required by Article 28 GDPR, and shall require the Processor to Process Personal Data only on documented instructions and to implement appropriate technical and organisational measures.
The identity of particular Processors and subprocessors is: Vercel Inc. (website hosting and delivery); FormSubmit (transmission of consultation enquiry emails to the Company); and, where the company name checker is enabled, Companies Registration Office Open Services (search queries submitted through the website tool). Additional Processors may be engaged to deliver professional services (for example accounting, payroll or document systems) and will be identified in an engagement or privacy information where appropriate.
13. International Transfers
Personal Data may, depending upon the systems and service providers used by the Company, be transferred to, or accessed from, a country outside the European Economic Area.
Where Personal Data is transferred outside the EEA, the Company shall ensure that an appropriate safeguard required by Chapter V GDPR is in place, which may include an adequacy decision of the European Commission, standard contractual clauses, or such other mechanism as Data Protection Legislation permits, together with any supplementary measures that may be required in the circumstances.
The locations in which Personal Data is hosted or otherwise Processed, and the safeguards applied, are: website and enquiry data may be processed on infrastructure operated by service providers in the United States and other countries outside the EEA; where required, transfers are supported by appropriate GDPR safeguards such as the European Commission's standard contractual clauses and supplementary measures where applicable.
14. Information Security and Confidentiality
The Company shall implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, alteration, disclosure or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risks of varying likelihood and severity for the rights and freedoms of Data Subjects.
Such measures may include, as appropriate to the circumstances:
- access controls and restricted access on a need-to-know basis;
- confidentiality obligations applicable to persons authorised to Process Personal Data;
- the use of systems and procedures intended to maintain the integrity and availability of information; and
- organisational measures directed to the secure handling of documents and communications.
The Company does not, by this Notice, make any representation as to particular encryption standards, security certifications, or the architecture of its systems. Measures in place include HTTPS for the public website, access controls and confidentiality obligations for staff, and security measures provided by hosting and other suppliers as applicable to each system.
15. Data Retention
Personal Data shall be retained only for as long as is necessary for the purposes for which it is Processed, subject to applicable statutory, regulatory, professional, accounting, tax, anti-money laundering and other legal retention requirements, and to the establishment, exercise or defence of legal claims.
Retention Periods vary according to the category of Personal Data and the purpose of Processing. Particular Retention Periods are: consultation and website enquiry records are retained for up to two years unless a client relationship continues or a longer period is required by law; client engagement records are retained for the duration of the engagement and thereafter as required by tax, accounting, anti-money laundering and professional obligations (typically at least six years, and longer where statute requires).
16. Data Deletion and Disposal
When Personal Data is no longer required for the purposes for which it was Processed, and no legal or professional obligation requires its continued retention, the Company shall, as appropriate in the circumstances, delete, destroy or anonymise such Personal Data, or shall require any Processor holding such data on the Company's behalf to do so.
The methods of deletion and disposal are: secure deletion or anonymisation on systems under the Company's control, and contractual requirements on Processors to delete or return Personal Data when it is no longer required.
17. Data Subject Rights
Subject to the conditions and exceptions provided for in Data Protection Legislation, a Data Subject may have the following rights in respect of Personal Data concerning him or her:
- the right of access;
- the right to rectification;
- the right to erasure, where the conditions in Article 17 GDPR are met, including where the Personal Data are no longer necessary for the purposes for which they were collected, subject to exceptions (including where Processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims);
- the right to restriction of Processing;
- the right to object to Processing based on legitimate interests, on grounds relating to the Data Subject's particular situation;
- the right to data portability, where Processing is based on consent or on a contract and is carried out by automated means; and
- the right to withdraw Consent, where Consent is the lawful basis, without affecting the lawfulness of Processing based on Consent before its withdrawal.
These rights are not absolute. The Company may refuse a request, in whole or in part, where Data Protection Legislation so permits or requires, including where the request is manifestly unfounded or excessive, or where an exemption applies.
18. Exercising Data Protection Rights
A request to exercise Data Subject rights may be submitted by email to info@finsera.ie, or in writing to the address set out in section 24.
The Company may require such information as is reasonably necessary to verify the identity of the person making the request and to locate the relevant Personal Data. The Company shall respond within the period required by Data Protection Legislation, subject to any lawful extension.
19. Direct Marketing
The Company does not, as at the date of this Notice, use Personal Data for unsolicited electronic direct marketing. Where the Company sends service-related communications to existing clients, these are sent in accordance with Applicable Law. A person may opt out of marketing at any time using the contact details in section 24.
Should the Company propose to send electronic marketing communications, it shall do so only in accordance with Applicable Law, including, where required, on the basis of Consent, and shall provide a means of opting out or withdrawing Consent.
21. Personal Data Breaches
The Company maintains procedures for identifying, assessing, managing and responding to a Personal Data Breach and shall, where required by Data Protection Legislation, notify the Supervisory Authority and, where applicable, affected Data Subjects, within the timeframes and in the manner prescribed by Applicable Law.
Particular internal incident-response procedures are: contain and assess the incident, record the facts, notify the Data Protection Commission within 72 hours where required, and inform affected individuals where required by law, using the contact details in section 24 as the responsible point of contact.
22. Complaints
A Data Subject who has a concern regarding the Processing of his or her Personal Data may contact the Company using the details in section 24. The Company shall consider the matter in accordance with its Complaints procedure, where applicable.
A Data Subject also has the right to lodge a complaint with the Supervisory Authority. In Ireland, the relevant Supervisory Authority is the Data Protection Commission (dataprotection.ie).
23. Changes to this Privacy Notice
The Company may amend this Notice from time to time. The version published on the website from time to time shall be the current version. Material changes may be indicated by updating the "Last updated" date appearing at the commencement of this Notice. Continued use of the website following publication of a revised Notice constitutes notice of the revised terms in respect of website use. Changes affecting an existing client engagement shall be communicated in such manner as is appropriate in the circumstances.
24. Contact Details
Finsera is a trading name of Provantec Limited, registered in Ireland. Company No. 820186.
Unit C4D, Nutgrove Office Park
Nutgrove Ave, Rathfarnham
Dublin, Ireland
D14 W6K3
Email: info@finsera.ie
Telephone: +353 1 232 5566