Privacy Policy
JMC Business Support Services is committed to protecting your personal data and handling it responsibly in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who I am
JMC Business Support Services is the data controller responsible for your personal data.
What information I collect
I may collect and process the following information:
- Personal details (name, address, email, phone number)
- Business information
- Financial information required for bookkeeping, payroll, and administrative services
- Information relating to direct payments (where applicable)
Lawful basis for processing
I process personal data under the following lawful bases:
- Contract – to deliver agreed services
- Legal obligation – to comply with HMRC and other regulatory requirements
- Legitimate interests – to manage and improve my services
- Consent – where required (e.g. sensitive data or marketing)
How I use your information
Your information is used to:
- Provide services
- Communicate with you
- Maintain accurate records
- Meet legal and regulatory obligations
Special category data
Where I process sensitive data (e.g. health-related information linked to direct payments), I will do so only where necessary and with appropriate safeguards, in line with UK GDPR requirements.
How your data is stored
Your data is stored securely using appropriate technical and organisational measures to protect against unauthorised access, loss, or misuse.
Data sharing
I may share your data with:
- HMRC and other regulatory bodies
- Payroll and accounting software providers
- Professional advisers (e.g. accountants)
I will only share information where necessary and will ensure appropriate safeguards are in place.
International transfers
I do not routinely transfer data outside the UK. Where this is necessary (e.g. cloud-based systems), I ensure appropriate safeguards are in place.
Data retention
I retain personal and financial data for up to 6 years in line with legal and HMRC requirements, unless a longer period is required.
Your rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure (where applicable)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (where applicable)
To exercise your rights, please contact me using the details below.
Complaints
If you are unhappy with how your data is handled, you have the right to complain to the Information Commissioner’s Office (ICO):
https://www.ico.org.uk
Contact details
