Privacy Policy

Last Updated: August 2026 

Introduction  

Sterling & Wells (“Sterling & Wells”, “we” or “us”) is a UK firm of accountants and tax advisors operating the website https://www.sterlingandwells.com/ . We provide bookkeeping, payroll, UK tax compliance, VAT, corporate structuring, Companies House identity verification, and UK business immigration services to individuals and businesses, including overseas clients expanding into the UK. Our full identity and contact details are set out in Section 1 below.  

We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (“DPA 2018”), the Data (Use and Access) Act 2025 (“DUAA 2025”), the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), and the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (“MLR 2017”), each as amended. This Notice explains what personal data we collect, why, our legal basis for using it, and your rights. 

  1. Who We Are

We are established in the United Kingdom and are the data controller for the personal data described in this Notice, save where we act as a processor on the instructions of a group affiliate (Section 9). Our group works alongside UK Property Accountants and Crane & Partners, and our client delivery is supported by our offshore team, Sterling Wells (Nepal) Private Limited (“Sterling Wells Nepal”), based in Kathmandu.  

  • Legal name: Sterling & Wells Limited  
  • Registered/company number: 11519378 (England and Wales)  
  • Registered office: Suite 809, Salisbury House 29 Finsbury Circus, London, United Kingdom, EC2M 7AQ 
  • Email: contact@sterlingandwells.com  
  • Telephone: +44 20 4526 5999  

We have appointed Jony Mainaly as the Data Protection Officer. Our Data Protection Officer can be contacted at jony@ukpa.co.uk.  Any data protection query should be directed to the contact details above.  

  1. What Personal Data We Collect

Depending on how you interact with us, we may collect:  

i. Identity and contact data 

  • Name 
  • Date of birth  
  • Nationality 
  • Address 
  • Postal address 
  • Passport or Biometric Residence Permit details.

ii. Financial and Tax data 

  • Income 
  • Expenses 
  • Bank details 
  • VAT and Self-Assessment records 
  • Unique Taxpayer Reference (UTR) 
  • National Insurance number 
  • Company accounts 
  • Payroll and pension data. 

iii. Technical data  

  • IP address 
  • Browser type  
  • Device data 
  • Cookie Identifiers 

iv. Marketing and engagement data  

  • newsletter/eBook sign-up details 
  • website usage data, and  
  • communication preferences. 

v. Corporate and company data 

  • Companies House filings 
  • Beneficial ownership  
  • Director information, for company secretarial and identity verification services. 

vi. Immigration data 

  • Visa category 
  • Sponsor licence details 
  • Right-to-work status 
  • Immigration history 
  • Criminal record/conduct information for Skilled Worker and Global Business Mobility visa applications. 
  1. How do We Collect Your Data 
  • Directly from you

When you submit a contact or enquiry form, book a “Discovery Call” or free consultation, contact us by email, telephone or WhatsApp, or download one of our eBooks, or engage us as a client. 

  • From your engagement with us

Financial, tax, payroll, VAT, corporate and immigration documents you or your business provide in the course of an engagement.  

  • From public and regulatory sources

Companies House, HMRC, and, for immigration matters, UK Visas and Immigration (UKVI)/the Home Office.  

  • From identity verification and screening checks

As part of Companies House identity verification services and our anti-money laundering obligations (Section 7), we may obtain data from identity verification and sanctions/PEP screening providers. 

  • Automatically

Through cookies, Google Tag Manager, and similar technologies when you visit sterlingandwells.com (Section 10). 

  1. Special category and criminal offence data

Article 9 UK GDPR treats certain data as special category data because it is more sensitive, such as health information or nationality-linked ethnicity data. Our immigration services sometimes require us to consider health information, such as calculating the Immigration Health Surcharge, and a client may also choose to disclose such data voluntarily. In either case, we process it only where an Article 9(2) condition and the corresponding Schedule 1 DPA 2018 condition both apply. The conditions we rely on most often are explicit consent under Article 9(2)(a), and the substantial public interest condition for employment and immigration functions under Article 9(2)(g). 

Criminal offence data is information arising from a criminal record check, or from a right-to-work or sponsor compliance check. This category is separately regulated under Article 10 UK GDPR and may only be processed where a condition in Schedule 1, Part 3 DPA 2018 is met. We typically rely on the protecting the public condition or the legal claims condition, and, where we are supporting a client’s statutory duties as a Home Office sponsor, we apply the appropriate safeguards that this type of processing requires. 

  1. What lawful reasons do we have for processing personal data
  • Contract: We rely on Article 6(1)(b) UK GDPR where processing is necessary to perform our engagement letter or terms of business with you.  
  • Legal obligation: We rely on Article 6(1)(c) UK GDPR where processing is necessary to comply with HMRC reporting duties, Companies House filing requirements, Home Office sponsor duties, or our anti-money laundering obligations under MLR 2017.  
  • Legitimate interests: We rely on Article 6(1)(f) UK GDPR where processing is necessary for our legitimate business interests, such as improving our services or marketing to existing clients, and we balance that interest against your rights. Since 5 February 2026, we may also rely on the narrower “recognised legitimate interests” basis that DUAA 2025 introduced, for limited, clearly defined purposes only. 
  • Consent: We rely on PECR and Article 6(1)(a) UK GDPR for non-essential cookies, newsletter signups, and eBook downloads. You may withdraw your consent at any time. 
  1. Why do we need personal data
  • Delivering bookkeeping, payroll, Self-Assessment, company accounts, and VAT registration, returns and e-commerce compliance services.  
  • Advising on corporate group structuring and corporate interest restriction.  
  • Providing Companies House identity verification services.  
  • Supporting Skilled Worker and Global Business Mobility visa applications, sponsor licence compliance, and related immigration advisory services. 
  • Responding to enquiries, Discovery Call bookings, and eBook requests.  
  • Meeting our anti-money laundering, tax, and company law obligations.  
  • Sending service updates and, where your consent or the PECR soft opt-in for existing clients permits it, marketing communications. 
  1. Anti-money laundering and customer due diligence

As an accountancy and tax service provider, Sterling & Wells is subject to MLR 2017 and must carry out customer due diligence (identity verification, source of funds/wealth checks, and ongoing monitoring) before and during a client relationship, under Regulations 27 to 40 MLR 2017. This includes our Companies House identity verification service, which forms part of our regulated compliance function as well as a client-facing offering. 

  1. Do we share personal data with third parties

We do not sell personal data. We may share personal data with:  

  • HMRC, Companies House, and UK Visas and Immigration/the Home Office, where required to deliver a service or comply with a legal obligation. 
  • Sterling Wells Nepal, our offshore delivery team, who process client data on our documented instructions as a data processor. 
  • FigsFlow, our affiliated engagement, proposal, and AML case-management software platform, which supports service delivery. 
  • Professional indemnity insurers, our AML supervisory body, and legal/professional advisers, where necessary. 
  • IT and cloud hosting providers, and identity verification/screening providers, under written confidentiality and security terms. 
  • Analytics and marketing platforms (e.g. Google, via Google Tag Manager), where you have consented to non-essential cookies.  

Where Sterling Wells Nepal or any other processor engages a further sub-processor, we require prior written authorisation and equivalent Article 28(3) UK GDPR obligations to be imposed on that sub-processor, consistent with Article 28(2) and (4) UK GDPR. 

  1. International data transfers 

Personal data collected within the UK and the European Economic Area (EEA) benefits from a high standard of legal protection. Not every country in the world offers the same level of safeguards, however, and it is important that you understand how we handle your data when it moves across borders. Wherever your personal data is transferred outside the UK or EEA, we take appropriate steps to ensure that it receives a level of protection that is consistent with UK data protection law. 

  1. Marketing communications

When you download an eBook, subscribe to updates or become a client, we may send you relevant service information. Existing clients may receive similar marketing by email under the soft opt-in permitted by Regulation 22 PECR. We only rely on this where we gave you a simple way to refuse at the point of collection and in every later message. For prospective clients and all other marketing, we rely on your consent. You may withdraw your consent at any time using the unsubscribe link or by contacting us directly. 

  1. How long do we retain personal data
  • Tax and accounting records 

We keep Self-Assessment records for five (5) years and ten (10) months after the end of the relevant tax year, as required by the Taxes Management Act 1970. We keep company tax records for at least six (6) years, as required by the Finance Act 1998. 

  • Anti-money laundering records 

We keep customer due diligence records for five (5) years from the end of the business relationship, as required by MLR 2017.  

  • Immigration and sponsor compliance records 

We keep these records for the period required by Home Office sponsor guidance. This is generally the duration of sponsorship plus a minimum period afterwards. 

  • Website enquiries and unconverted leads.  

We keep this data for twelve (12) months from your last contact with us.  

  • Marketing and eBook sign-up data 

We keep this data until you withdraw your consent or unsubscribe, and we review it periodically to check it remains relevant.  

  1. What are your data protection rights
  • Right of Access: You can ask for a copy of the personal data we hold about you, under Article 15 UK GDPR. 
  • Right to Rectification: You can ask us to correct inaccurate or incomplete data, under Article 16 UK GDPR. 
  • Right to Erasure: You can ask us to delete your data in certain circumstances, under Article 17 UK GDPR. This is subject to our legal retention obligations described in Section 11.  
  • Right to Restrict Processing: You can ask us to limit how we use your data while a dispute is resolved, under Article 18 UK GDPR.  
  • Right to Data Portability: You can ask to receive certain data in a portable format, under Article 20 UK GDPR. 
  • Right to Object: You can object to processing based on legitimate interests, or to direct marketing at any time, under Article 21 UK GDPR.  
  • Right relating to Automated decision-making: You have safeguards where a decision about you is made solely by automated means with legal or similarly significant effect, under Articles 22A to 22D UK GDPR as substituted by DUAA 2025. Sterling & Wells does not currently use solely automated decision-making of this kind.  
  • Right to Withdraw Consent: If we rely on your consent to process your personal data, you can withdraw that consent at any time. 
  • Right to complain to us directly: Section 164A of the DPA 2018, inserted by DUAA 2025, gives you the right to complain to us directly if you believe we have infringed UK GDPR when processing your personal data. We will acknowledge your complaint within 30 days of receipt and investigate it and communicate the outcome to you without undue delay. To exercise any of these rights, contact us using the details in Section 15. We do not charge a fee for a straightforward request and aim to respond within one month. 
  1. How do we protect personal data

In accordance with Article 5(1)(f) and Article 32 UK GDPR, we maintain technical and organisational measures appropriate to the risk, including access controls, encryption of data in transit and at rest where supported, confidentiality undertakings for staff and contractors (including at Sterling Wells Nepal), and a documented process for assessing and, where required, notifying the ICO within 72 hours (Article 33 UK GDPR) and affected individuals (Article 34 UK GDPR) of any qualifying personal data breach. 

  1. Changes to this Notice 

We may update this Notice to reflect changes in our processing activities or the law, including further DUAA 2025 provisions coming into force through 2026. Material changes will be published on this page with a revised “last updated” date.  

  1. Contact Us

If you have questions, or wish to exercise your rights, please contact:  

  • Sterling & Wells Limited 
  • Data Protection Officer: jony@ukpa.co.uk 
  • Address: Suite 809, Salisbury House, 29 Finsbury Circus, City of London, London EC2M 7AQ, United Kingdom 
  • Email: contact@sterlingandwells.com   
  • Telephone: +44 20 4526 5999  

If you are not satisfied with our response, you may contact the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113. The ICO’s address is Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.  

  • About Us
  • MTD
  • Services
  • Sectors
  • Resources
  • Contact