Signed in as:
filler@godaddy.com
Signed in as:
filler@godaddy.com
Effective date: 18 August 2026
This Privacy Statement explains how BlueRoot Finance Ltd collects, uses, stores, shares, and protects personal information when you visit our website, enquire about our services, become a client, complete onboarding or anti-money-laundering checks, or receive bookkeeping, accounting, or related support. It also outlines our data management policies regarding the types of personal information we handle.
Furthermore, this statement clarifies the distinction between the information BlueRoot Finance Ltd controls for its own business and regulatory purposes, and the information it may process on a client’s instructions while delivering our services.
1. Who We Are
Legal name: BlueRoot Finance Ltd
Company number: 16770863
ICO registration: ZC011478
Website: www.bluerootfinance.co.uk
Privacy contact: eve@bluerootfinance.co.uk
BlueRoot Finance Ltd is an AAT-licensed practice providing remote bookkeeping and related accountancy support to UK small businesses, individuals, and accountancy practices.
2. Scope of This Statement
This statement applies to the BlueRoot Finance website, contact and onboarding forms, client communications, service platforms, and professional activities operated by BlueRoot Finance Ltd. It does not cover Khemi Love Ltd or its websites, books, digital products, or wellbeing services, which have a separate privacy statement.
Our services may include bank reconciliations, purchase and sales ledger work, invoice processing, supplier reconciliations, credit control, transaction processing, record maintenance, catch-up bookkeeping, ongoing monthly support, accounts preparation, and tax-return preparation where included in an agreed engagement.
3. Our Roles: Controller and Processor
As a data controller, BlueRoot Finance Ltd decides why and how personal information is used for enquiries, client acceptance, identity and AML checks, contracts, billing, professional compliance, security, service administration, legal claims, and its own business records. Our privacy compliance ensures we handle data according to applicable regulations.
As a data processor, when a client provides personal information about its customers, suppliers, employees, contractors, or other individuals for bookkeeping or accounting work, BlueRoot Finance Ltd processes that information on the client’s documented instructions. The client remains the controller for that processing, subject to the engagement letter and any data-processing terms.
In some situations, we may become an independent controller for part of the same information where the law or our professional obligations require us to make our own decisions, such as for AML compliance, regulatory reporting, fraud prevention, or the establishment or defence of legal claims.
4. Information We Collect
Identity and contact information: names, business names, job titles, addresses, email addresses, telephone numbers, dates of birth, and signatures.
Business and ownership information: company numbers, trading details, organizational structure, directors, partners, trustees, beneficial owners, officers, managers, and authorized contacts.
Client due diligence and AML information: identity documents, proof of address, nationality, ownership and control information, business activities, risk assessments, politically exposed person or sanctions screening results, source-of-funds or source-of-wealth information where required, and records of ongoing monitoring.
Financial and accounting information: bank statements, transaction records, invoices, receipts, ledgers, supplier and customer records, payroll-related records, tax information, accounting files, payment information, and supporting documents.
Engagement and service information: enquiries, proposals, engagement terms, instructions, work records, deadlines, communications, deliverables, queries, complaints, and service history.
Website and technical information: IP address, device and browser information, pages viewed, referral source, approximate location, cookie choices, security logs, and website interaction information.
Marketing information: newsletter choices, consent records, preferences, and engagement with communications.
Information about other people: personal information contained in records supplied by a client, including information about directors, employees, customers, suppliers, contractors, dependents, or beneficial owners. Clients must ensure they have authority and an appropriate lawful basis to provide this information.
5. Sensitive and Criminal-Offence Information
Financial, payroll, tax, or client records may incidentally reveal health information, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, sexual orientation, or other special-category information. AML and fraud-prevention work may also involve information about allegations, investigations, or criminal offences.
Where BlueRoot Finance Ltd is a controller, we will identify both an Article 6 lawful basis and any additional condition required under UK data-protection law. Where we act as a processor, the client controller is responsible for identifying the lawful basis and any special-category or criminal-offence condition, while we process the information only as permitted by the contract and law.
6. How We Collect Information
From you: through enquiries, meetings, email, telephone, forms, onboarding, identity checks, document uploads, accounting systems, and service communications.
From your business or advisers: including directors, employees, accountants, bookkeepers, payroll providers, banks, legal advisers, and authorized representatives.
From clients: when they provide records containing information about other individuals for us to process as part of the agreed service.
From public and official sources: such as Companies House, HMRC, public registers, professional directories, sanctions or PEP sources, and other lawful verification databases.
Automatically: through website functions, essential cookies, analytics, security monitoring, and fraud-prevention technologies, subject to cookie consent where required.
7. How We Use Information
Enquiries and engagement: to respond, scope work, issue proposals, verify authority, enter into engagement terms, and manage the client relationship.
Service delivery: to provide remote bookkeeping, ledger, reconciliation, transaction, credit-control, catch-up, accounts-preparation, tax-return, or related services within the agreed scope.
AML and client due diligence: to identify and verify clients and beneficial owners, understand the nature and purpose of the relationship, assess risk, conduct ongoing monitoring, and meet reporting or record-keeping obligations.
Administration and payment: to schedule work, communicate, issue invoices, collect payment, maintain records, and manage complaints or disputes.
Professional quality and compliance: to maintain insurance, respond to practice assurance or supervisory requirements, protect against fraud, keep systems secure, and establish, exercise or defend legal claims.
Website and marketing: to operate and improve the website and, where permitted, send useful updates, guides, or service information.
8. Lawful Bases
Contract: to take steps at your request, enter into an engagement, and deliver agreed services.
Legal obligation: to meet tax, accounting, company, AML, sanctions, court, regulatory, and professional requirements.
Legitimate interests: for proportionate business administration, relationship management, service improvement, debt recovery, security, fraud prevention, professional compliance, and legal claims after balancing your rights and interests.
Consent: for optional electronic marketing and non-essential cookies where consent is required. Consent can be withdrawn at any time.
Vital interests: in rare circumstances where processing is necessary to protect someone’s life.
We do not rely on consent where processing is required by AML law or another legal obligation.
9. Anti-Money-Laundering and Regulatory Processing
As a regulated accountancy-services provider, BlueRoot Finance Ltd maintains proportionate AML policies, controls, and procedures, including client-specific risk assessment, customer due diligence, ongoing monitoring, and record keeping. Our commitment to privacy compliance ensures we manage this information responsibly.
We may use identity-verification, sanctions, or PEP-screening providers and may request further information where the nature of a client, transaction, or business relationship requires it. We may be legally required to share information with AAT, HMRC, the National Crime Agency, law-enforcement bodies, or other competent authorities.
Where the law restricts what we may disclose, we may be unable to tell you that a report, request, or investigation exists. We will not use AML information for unrelated marketing.
10. Marketing and Cookies
We may send newsletters, bookkeeping guidance, service updates, or offers where we have the permission or lawful basis required for that communication. You can unsubscribe through the email link or by contacting eve@bluerootfinance.co.uk. We may retain a minimal suppression record so your choice is respected.
Essential cookies may support website security and core functions. Non-essential analytics, preference, or marketing technologies will be controlled through the relevant cookie banner or preference tool where consent is required. Details of providers and durations should appear in the website’s cookie notice or preference tool.
11. Who We Share Information With
Professional and regulatory bodies: AAT, HMRC, the National Crime Agency, courts, law-enforcement bodies, and other regulators or authorities where required or permitted.
Service providers: website, email, cloud storage, client-portal, identity-verification, accounting, bookkeeping, tax, payment, banking, communications, cybersecurity, and IT-support providers.
Professional advisers: insurers, legal advisers, accountants, tax specialists, and consultants where their assistance is required.
Client-authorised recipients: people or organisations you instruct us to communicate with, such as another accountant, payroll provider, bank, solicitor, or software provider.
We do not sell personal information. Processors are expected to act only for agreed purposes, protect information, and meet applicable contractual and data-protection requirements.
12. International Transfers
Some technology providers may store or access information outside the United Kingdom. Where a restricted transfer occurs, we will use an appropriate legal safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism, together with supplementary protections where appropriate.
13. Security and Confidentiality
We implement proportionate technical and organisational measures designed to protect personal information, including access controls, authentication, reputable software, secure storage and transfer methods, backups, confidentiality requirements, device security, and provider checks. Our data management policies ensure robust handling of personal data.
No system is completely secure. We assess suspected personal-data breaches and will notify affected controllers, individuals, regulators, or authorities where the law or our contracts require us to do so.
14. Retention
Enquiries that do not become clients: normally up to two years after the last meaningful contact.
Engagement, billing, and financial records: normally six years after the end of the relevant financial period or client relationship, subject to tax, accounting, insurance, or legal requirements.
AML and customer-due-diligence records: normally five years after the business relationship ends or an occasional transaction is completed, followed by deletion unless continued retention is required or permitted by law.
Client records processed on instructions: for the period set out in the engagement and data-processing terms, followed by return, deletion, or restricted backup retention as agreed and legally permitted.
Marketing records: until you unsubscribe or continued contact is no longer appropriate; suppression information may be retained to honour your choice.
Cookie and analytics information: for the duration shown in the relevant cookie notice, preference tool, or provider settings.
A legal hold, complaint, investigation, regulatory request, or active claim may require information to be kept longer. We delete, anonymise, or securely archive information when it is no longer required.
15. Your Rights
Depending on the circumstances and lawful basis, you may have rights of access, rectification, erasure, restriction, objection, and data portability, together with the right to withdraw consent where consent is used. These rights are not absolute and may be limited by legal or regulatory duties.
You have an absolute right to object to direct marketing. Where we rely on legitimate interests for another purpose, you may object based on your particular situation.
To exercise a right, email eve@bluerootfinance.co.uk. We may need to verify your identity and will normally respond within one month, subject to lawful extensions. If the information is held only on behalf of a client controller, we may refer the request to that client or assist them in responding.
16. Automated Decision-Making
We do not currently make decisions about individuals based solely on automated processing where those decisions produce legal or similarly significant effects. Screening and software may support risk or verification work, but material client-acceptance and AML decisions involve human review.
17. External Links and Third-Party Platforms
Our website or communications may link to external services that act as independent controllers. Their own privacy notices explain how they use personal information. Please review those notices before providing information.
18. Complaints
Please contact us first if you have a concern so that we can try to resolve it. Email eve@bluerootfinance.co.uk.
You may also complain to the UK Information Commissioner’s Office. Current guidance is available at https://ico.org.uk/make-a-complaint/.
19. Changes to This Statement
We may update this Privacy Statement when our services, providers, regulatory obligations, or processing activities change. The current version will be published on the BlueRoot Finance website with its effective date. Material changes will be brought to affected people’s attention where appropriate.
20. Contact Us
Data controller: BlueRoot Finance Ltd
Company number: 16770863
ICO registration: ZC011478
Email: eve@bluerootfinance.co.uk
Website: www.bluerootfinance.co.uk
Please do not send identity documents, bank records, or other highly sensitive information by ordinary email unless we have asked you to use that method. We will provide an appropriate route for information that is genuinely required.

Copyright © 2026 Khemi Love - All Rights Reserved.