Legal

Privacy policy

Last updated 7 September 2026.

1. Who we are

Linx Automate is a trading name of Linx Accounting Services Limited, a company registered in England and Wales, company number 11742116, with its registered office at 124-128 City Road, London EC1V 2NX, United Kingdom.

Linx Accounting Services Limited is the data controller for the information described in this policy. We are registered with the Information Commissioner’s Office under reference ZC094764, and licensed and regulated by the Association of Chartered Certified Accountants, licence number 4859891.

For any question about this policy, or to exercise any of the rights in section 8, contact us at info@linxaccounting.com.

2. What this policy covers

This policy covers the linxautomate.com website and enquiries made to Linx Automate. Linx Accounting Services Limited also operates as Linx Accounting and as Linx Tax Defence, each with its own website and its own privacy policy describing the processing carried out under that brand. Those policies do not contradict this one; they describe different activities.

3. What we collect, and when

When you visit this website

There is no contact form, no analytics package and no advertising script running on this site unless you have actively agreed to one.

Our hosting provider, Cloudflare, processes technical information such as your IP address, browser type and the pages requested in order to serve the site and protect it from attack. This is done on our behalf and is necessary for the site to function at all.

If you agree to advertising cookies through the banner, we load the LinkedIn Insight Tag. It allows us to see whether visits arriving from our LinkedIn advertising go on to make an enquiry, and it sets cookies in your browser. It does not load, and no such cookie is set, unless you choose “Accept advertising cookies”. You can withdraw that agreement at any time using the control in the footer.

When you contact us

If you email, telephone, message us on WhatsApp, or connect with us on LinkedIn, we hold what you choose to tell us: typically your name, your contact details, the organisation you work for, and a description of the process or problem you want help with.

We ask you not to send financial records, personal data about your staff or customers, or system credentials with an initial enquiry. We do not need them at that stage and would rather not hold data we have no reason to hold.

If you respond to one of our advertisements

If you submit a lead form within LinkedIn, LinkedIn passes us the details you confirmed on that form. Those details are recorded in our customer relationship management system, HubSpot, so that an enquiry is not lost and so that we can see which advertising produces genuine conversations rather than clicks.

If you become a client

An engagement brings further processing: the identification evidence we are required to obtain under anti-money-laundering law, the records needed to perform the work, and any system access agreed in writing for that purpose. What access is needed, what it is used for and how long it lasts is agreed before any of it is granted. Client processing is governed by our engagement terms as well as this policy.

4. Why we use it, and our lawful basis

What we doLawful basis
Serve and secure this websiteLegitimate interests — operating a website that works and is not abused
Respond to your enquiry and discuss whether we can helpLegitimate interests, and steps taken at your request before entering a contract
Record enquiries in our CRM so they are not lostLegitimate interests — running the practice competently
Measure which advertising leads to genuine enquiriesConsent, given through the cookie banner and withdrawable at any time
Carry out client work once engagedPerformance of our contract with you
Anti-money-laundering identification and record keepingLegal obligation
Keep records for professional, tax and insurance purposesLegal obligation, and legitimate interests in defending claims

5. Who we share it with

We do not sell personal information and we do not share it for anyone else’s marketing. We use the following processors:

  • Cloudflare — hosts this website and delivers its pages.
  • Microsoft — provides our email and document systems, so correspondence with us is stored there.
  • HubSpot — our customer relationship management system, where enquiries and the correspondence trail are recorded.
  • LinkedIn — where you submit a lead form in response to an advertisement, LinkedIn processes that submission before passing it to us. If you have consented to advertising cookies, LinkedIn also receives the measurement data described in section 3.
  • Meta Platforms — if you choose to contact us on WhatsApp, Meta processes that conversation under its own terms as the operator of the service.

We may also disclose information to our professional indemnity insurers, our regulator, our own professional advisers, or a law enforcement or regulatory body where we are required or permitted by law to do so.

6. Transfers outside the UK

Several of the providers above are based in, or operate infrastructure in, the United States and elsewhere. Where personal information is transferred outside the UK, that transfer is covered by UK adequacy regulations, the UK addendum to the EU standard contractual clauses, or another mechanism permitted by the UK GDPR, as set out in our agreements with those providers.

7. How long we keep it

  • Enquiries that do not become engagements — up to 24 months from our last contact, after which they are deleted. Ask us sooner and we will delete them sooner.
  • Client records — for at least six years after the engagement ends, reflecting our professional, tax and limitation obligations.
  • Anti-money-laundering records — five years from the end of the business relationship, as the Money Laundering Regulations 2017 require.
  • System access granted for a project — revoked at the end of the engagement, or sooner where the work no longer needs it.
  • Website and advertising measurement data — retained by the relevant provider under its own published retention periods.

8. Your rights

Under the UK GDPR you have the right to:

  • ask what personal information we hold about you, and receive a copy;
  • have inaccurate information corrected;
  • ask us to delete information, where we are not required to keep it by law or by our professional obligations;
  • object to, or ask us to restrict, processing based on legitimate interests;
  • withdraw consent at any time where consent is the basis — which for this site means advertising cookies, withdrawable through the footer control;
  • receive certain information in a portable format.

To exercise any of these, email info@linxaccounting.com. We will respond within one month.

If you are unhappy with how we have handled your information you may complain to the Information Commissioner’s Office at ico.org.uk, or by telephone on 0303 123 1113. We would rather you raised it with us first.

9. Security

Access to enquiry and client information is limited to those who need it. Systems are protected by multi-factor authentication, this website is served only over HTTPS, and access granted to a client’s systems for a project is read-only where read-only is sufficient, time-limited, and revoked when the work ends.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you where the law requires it.

10. Cookies

What is set, by whom and why is described in our cookie policy.

11. Changes to this policy

Where we change how we handle personal information, this page is updated before the change takes effect and the date at the top is revised. Material changes affecting people we already hold information about will be notified directly.