Last updated: 21 August 2026
Privacy Policy
This privacy notice explains how Invi (“we”, “us” or “our”) collects, uses, stores and protects personal information.
It applies to people who:
visit or contact us through our website;
make an enquiry about our services;
become or are clients of Invi;
work for or are connected with one of our clients; or
have personal information included within records that we process as part of providing bookkeeping services.
Who we are
Invi is a bookkeeping practice providing bookkeeping and related services to businesses in the UK.
For data protection purposes, we will usually be the data controller for personal information we collect about our clients, prospective clients and other people we deal with directly.
There may also be circumstances where we process personal information contained within a client’s business records on their behalf.
You can contact us about the use of your personal information at:
Email: hello@inviaccounts.co.uk
Address: Unit 7, Henley’s Business Park, Abbotskerswell, Newton Abbot, TQ12 5NF
What information we collect
The information we collect depends on our relationship with you and the services we are providing.
It may include:
your name and contact details;
your business name and business contact information;
information you provide when contacting us or making an enquiry;
accounting and bookkeeping records;
invoices, bills, receipts and supporting documents;
bank transactions, account balances and payment information;
information about customers, suppliers, employees and other individuals contained within your accounting records;
tax, VAT and other financial information;
correspondence between you and us;
information required to administer our engagement and provide our services;
information about company directors, partners, trustees, persons with significant control and beneficial owners;
identity documents and information required for anti-money laundering checks;
information obtained through identity, sanctions, PEP and other compliance checks; and
technical information generated when you use our website, such as your IP address, browser, device information and information about how the website is used.
Some of the information we process for anti-money laundering and identity-verification purposes may be particularly sensitive. This can include photographs and identity-document information, biometric information used for identity verification, information relating to politically exposed persons, sanctions and adverse-media screening and, where relevant, information relating to criminal convictions or offences.
We only collect information that is reasonably necessary for the purpose for which it is being used.
How we obtain your information
We may receive personal information:
directly from you;
from somebody authorised to act on behalf of your business;
from your accountant, tax adviser or another professional adviser;
from accounting, bookkeeping and financial systems you give us access to;
from banks and open-banking services that you choose to connect;
from Companies House, HMRC and other official or publicly available sources;
through identity-verification and anti-money laundering services;
from previous accountants or bookkeepers where you have authorised a handover;
through our website; and
through correspondence and documents you send to us.
When providing bookkeeping services, we may also receive information relating to your customers, suppliers, employees and other people from the records you provide to us.
How we use your information
We may use personal information to:
respond to enquiries;
provide quotations and discuss the services you require;
take steps to enter into an engagement with you;
provide bookkeeping and related professional services;
maintain and review accounting records;
reconcile accounts and investigate discrepancies;
prepare and submit VAT returns or other submissions where this forms part of our agreed services;
communicate with you about your bookkeeping and our work;
administer our relationship with you;
issue invoices and collect payment for our services;
carry out identity verification and anti-money laundering checks;
comply with legal, regulatory and professional obligations;
maintain records of the work we have carried out;
investigate or defend complaints, disputes or legal claims;
protect our systems, devices and information;
maintain business continuity and backups;
improve our website and services; and
send information about our services where permitted by law.
Our lawful bases for using your information
The lawful basis we rely on depends on why we are using the information.
Contract
We may process information where it is necessary to enter into or perform our contract with you.
For example, we need to process your business and financial information in order to provide bookkeeping services.
Legal obligation
We may process information because we are required to do so by law.
This includes information required to comply with anti-money laundering legislation and other legal or regulatory obligations.
Legitimate interests
We may process information where it is necessary for our legitimate business interests and those interests are not overridden by your rights.
This may include:
administering and protecting our business;
maintaining appropriate professional records;
communicating with business contacts;
protecting our systems;
obtaining professional advice;
handling complaints or legal claims; and
improving our services.
Consent
In some circumstances we may rely on your consent.
Where we do, you may withdraw that consent at any time.
Information we need from you
Some information is required so that we can provide our services or meet our legal and regulatory obligations.
Where information is required for these purposes, you may need to provide it to us before we can begin or continue acting for you.
If you do not provide information that we reasonably require, we may be unable to start work, complete particular services or continue providing services to you.
Anti-money laundering and identity checks
As a regulated bookkeeping practice, we are required to carry out customer due diligence and other checks designed to prevent money laundering and financial crime.
This may require us to obtain and verify information about clients, directors, partners, trustees, beneficial owners and other relevant individuals.
We use Xama to help us carry out anti-money laundering, identity-verification, risk-assessment, PEP, sanctions and related compliance checks.
Depending on the checks required, this may involve processing identity documents, photographs, biometric verification information and information obtained from official registers and specialist screening databases.
We may be legally prevented from telling you about certain disclosures or investigations connected with anti-money laundering legislation.
The systems and service providers we use
We use specialist software and service providers to help us operate Invi and provide our services.
Not every service listed below will be used for every client.
Depending on the work we carry out for you, personal information may be processed using the following services.
Xero
We use Xero as our accounting and bookkeeping platform.
Information held in Xero may include transactions, bank information, invoices, bills, receipts, customer and supplier information and other information forming part of your accounting records.
Engager
We use Engager for practice management and client administration.
This may include client contact information, engagement records, correspondence, service information, deadlines, documents and other information needed to manage our relationship with you.
Xama
We use Xama for anti-money laundering compliance, client due diligence, identity verification, client risk assessment, PEP and sanctions screening and related regulatory checks.
Xenon Connect
We may use Xenon Connect to analyse bookkeeping information, identify potential issues or inconsistencies within accounting records and assist with bookkeeping review and quality control.
Xenon may obtain information from connected bookkeeping platforms such as Xero.
Streem Connect
We may use Streem Connect where additional access to banking information is required.
With your authorisation, Streem Connect can use open-banking services to obtain read-only information such as bank transactions, statements and account balances. It may also be used to verify banking data or assist with reconciliation.
MoveMyBooks
We may use MoveMyBooks when accounting or bookkeeping records need to be transferred between accounting systems.
This can involve providing the service with copies of accounting records for the purpose of carrying out the migration.
Apron
We use Apron for the collection and processing of bookkeeping documents such as supplier invoices, bills and receipts.
Information contained within those documents may therefore be processed through Apron as part of providing our bookkeeping services.
Adfin
We use Adfin for billing, payment collection and related payment administration.
Depending on how you choose to pay us, Adfin and the regulated payment providers used through its service may process information including your name, contact details, invoice information, payment information and relevant bank or transaction details.
Microsoft 365 and OneDrive
We use Microsoft 365, including Outlook and OneDrive, for business email, communications, document storage and day-to-day administration.
Emails, attachments and documents you send to us may therefore be stored within Microsoft 365.
Dropsuite
We use Dropsuite to provide backup of our Microsoft 365 environment.
This means information contained within Microsoft 365, including emails and documents stored within it, may also be held within backup systems provided by Dropsuite.
Hostinger
Our website is hosted by Hostinger.
Hostinger may process technical information associated with visits to the website and information passing through the website infrastructure, including server logs and IP addresses.
Google Analytics
We use Google Analytics to help us understand how visitors use our website.
Where your consent is required, Google Analytics will only be activated after you have made the appropriate choice through our cookie consent system.
Analytics information may include information about pages visited, approximate location, device and browser information and how visitors interact with the website.
More information about our use of cookies and analytics can be found in our Cookie Policy.
ZOOC IT
We use ZOOC IT to provide IT support, maintenance and technical assistance.
In order to diagnose or resolve technical problems, authorised IT support personnel may occasionally require access to our devices or systems and could therefore have incidental access to personal information held within them.
Access is limited to what is necessary to provide IT support and is subject to appropriate confidentiality and security requirements.
Other organisations we may share information with
In addition to the service providers above, there are circumstances where we may need or be permitted to share information with other organisations.
These may include:
AAT
AAT is our professional body.
We may be required to provide information to AAT in connection with our professional obligations, regulatory supervision, practice monitoring, complaints, investigations or anti-money laundering supervision.
HM Revenue & Customs
Where you have authorised us to make submissions or communicate with HMRC as part of our services, relevant information may be provided to HM Revenue & Customs.
We may also be required to provide information to HMRC where required by law.
Your other professional advisers
Where appropriate and with the necessary authority, we may exchange information with your accountant, tax adviser or another professional adviser involved in your affairs.
This may include providing bookkeeping records and supporting information as part of an accountant or year-end handover.
Professional advisers and insurers
We may disclose information to our professional indemnity insurers, legal advisers or other professional advisers where necessary to obtain advice, handle a complaint or establish, exercise or defend a legal claim.
Regulators, law enforcement and other authorities
We may disclose information to regulators, law-enforcement agencies, courts or other authorities where we are legally required or permitted to do so.
This can include disclosures required under anti-money laundering and financial-crime legislation.
We do not sell personal information to third parties.
Service providers and data protection responsibilities
Many of the services we use process information on our behalf under contractual data-protection arrangements.
In some circumstances, particularly where regulated payment services, open-banking services, identity-verification services or other independently regulated activities are involved, a provider may also act as a separate data controller for some of the information it processes.
These providers have their own privacy notices explaining how they use information when acting in that capacity.
International transfers
Some of the technology providers we use operate internationally and may store, process or make information accessible from countries outside the United Kingdom.
Where our use of a service involves a restricted transfer of personal information outside the UK, we take steps to ensure an appropriate transfer mechanism is in place as required by UK data protection law.
Depending on the circumstances, this may include:
a country covered by UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to approved standard contractual clauses; or
another safeguard permitted by UK data protection legislation.
You can contact us if you would like further information about the safeguards applying to a particular service provider.
How long we keep your information
We only keep personal information for as long as it is reasonably required for the purpose for which it was collected and to meet our legal, regulatory and professional obligations.
As a general policy:
client engagement, bookkeeping and professional records will normally be retained for seven years after our relationship with you ends;
anti-money laundering and client due diligence records will normally be retained for five years after the end of the business relationship, unless we are required or permitted to retain them for longer;
information relating to an enquiry that does not result in you becoming a client will normally be retained for up to 24 months after our last contact; and
information collected through website analytics will be retained in accordance with the retention settings applied to our analytics services and our Cookie Policy.
Some information may need to be retained for longer where this is necessary because of a complaint, investigation, professional obligation, legal claim or another legal or regulatory requirement.
Where we process personal information solely on behalf of a client, arrangements for the return or deletion of that information may also be governed by our agreement with that client.
Information that no longer needs to be retained will be securely deleted or anonymised where appropriate.
Keeping your information secure
We take appropriate technical and organisational measures to protect the information entrusted to us.
These include measures such as:
password and access controls;
multi-factor authentication where available;
device and account security;
secure cloud services;
appropriate backups;
restricted access to client information; and
the use of reputable professional software providers.
Although no electronic system can be guaranteed to be completely secure, we take reasonable precautions to protect personal information against loss, misuse, unauthorised access, disclosure or alteration.
Automated decision-making
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
We may use software to analyse information, identify potential bookkeeping issues, carry out screening or assist with compliance checks, but relevant decisions remain subject to human review.
Your data protection rights
Depending on the circumstances and the lawful basis we rely on, you may have the right to:
ask us for a copy of the personal information we hold about you;
ask us to correct inaccurate or incomplete information;
ask us to delete information;
ask us to restrict how information is used;
receive certain information in a portable format;
withdraw consent where processing is based on consent; and
complain about the way your information has been handled.
These rights are not absolute.
For example, we may be required to retain particular information to comply with our legal or regulatory obligations even if you ask us to delete it.
To exercise your rights, please contact us using the details at the beginning of this notice.
Your right to object
Where we process your personal information on the basis of our legitimate interests, you have the right to object to that processing in certain circumstances.
You also have the right to object at any time to the use of your personal information for direct marketing.
If you object, we will consider your request and stop the relevant processing where required by data protection law.
Complaints
If you have concerns about how we have handled your personal information, please contact us first so that we have an opportunity to investigate.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator.
Information about your rights and how to make a complaint is available at ico.org.uk.
Cookies
Our website uses cookies and similar technologies.
Some cookies are necessary for the website to operate correctly. Others, including analytics cookies, may only be used where you have given the appropriate consent.
You can change your cookie preferences through the cookie controls available on our website.
Further information about the cookies we use is available in our Cookie Policy.
Links to other websites
Our website may contain links to websites operated by other organisations.
Those organisations are responsible for their own privacy practices and we recommend reading their privacy information when visiting their websites.
Changes to this privacy notice
We may update this privacy notice from time to time, including when:
the services we provide change;
we introduce or stop using a software provider;
our legal or regulatory obligations change; or
our data-processing practices change.
The latest version will always be published on our website, with the date of the most recent update shown at the top of this page.







