Rowville Consulting

Security & Data Handling

Clear information about how Rowville handles client data, controls access and supports lawful international transfers.

Contractual Safeguards
Documented Instructions
Controlled Access
Transparent Due Diligence

Our Commitment to You

We process client information only for agreed service purposes and under documented instructions. The applicable controls, systems and transfer safeguards are confirmed during onboarding and recorded in the engagement documents.

Legal Compliance We support clients in documenting the appropriate UK or EEA transfer mechanism for processing in Botswana.
Professional Duty Personnel with professional memberships remain subject to their applicable ethical duties, alongside Rowville confidentiality obligations.
Technical Security Access is limited to authorised personnel and the systems and controls agreed for the engagement.
Transparent Governance Clients can request the DPA, control schedule, subprocessor register and incident-notification commitments.

1. Governance & Regulatory Framework

This policy describes how Rowville Consulting protects the confidentiality, integrity, and availability of client data. It applies to all employees, contractors, and third parties processing data on our behalf.

1.1 Primary Regulatory Alignment

Our operations are structured to comply with the data protection frameworks of our primary client jurisdictions:

JurisdictionKey LegislationOur Status
United KingdomUK GDPR, Data Protection Act 2018Contractual obligations agreed per engagement
Ireland / EEAEU GDPR, Irish Data Protection Act 2018Contractual obligations agreed per engagement
Botswana (delivery location)Applicable Botswana data-protection lawLocal processing and security obligations

1.2 International Data Transfers

Botswana is not currently covered by a UK or EU adequacy decision. Where a restricted transfer applies, the parties document an appropriate safeguard and complete the relevant assessment before processing begins.

2. Minimum Security Baseline

Rowville maintains the following controls as a baseline before any client engagement begins. Additional controls may be agreed depending on the sensitivity and scope of the work.

Control Area Baseline Requirement
Authentication Multi-factor authentication on all Rowville-managed business accounts
User Accounts Unique user accounts for each team member; no shared credentials
Device Security Screen-lock and device-password requirements on all Rowville-issued devices
Confidentiality Signed confidentiality agreements for all personnel with client access
Access Lifecycle Access removed promptly following reassignment or departure; periodic access reviews
Data Storage Restricted local downloads; client data stored only in approved, access-controlled systems
File Transfer Approved file-transfer channels; no client data sent via uncontrolled email
Incident Escalation Documented escalation procedure; all suspected incidents reported to the responsible lead

3. Core Security Principles & Controls

Our security approach is informed by recognised good practice. Rowville does not claim independent ISO 27001 certification unless a current certificate is expressly identified.

3.1 Data Protection by Design & Default

3.2 Technical & Organisational Measures

4. Data Handling, Retention & Your Rights

4.1 The Data We Process

As your finance partner, we may process: Company financial records, management accounts, payroll data, tax information, and employee details (as necessary for reporting). We act as a Data Processor under your instructions for this data.

4.2 Data Retention

We retain client data only as long as necessary for the service, to meet statutory obligations (e.g., HMRC/Revenue requirements), or as specified in our contract. Secure deletion is performed thereafter.

4.3 Upholding Your Data Subject Rights

We fully support your rights under GDPR. Requests concerning data we process on your behalf (Right to Access, Erasure, etc.) will be handled promptly and in coordination with you, the Data Controller.

5. Incident Response & Breach Notification

We have a formal incident response plan to identify, contain, and resolve security events.

6. Audit, Review & Continuous Improvement

This policy is not static. It is reviewed annually or following significant regulatory changes.

Request Our Full Data Processing Agreement

For a complete view of our contractual commitments, technical measures, and third-party sub-processors, please request our formal Data Processing Agreement (DPA).

Email for DPA General Questions

Privacy and Data Protection Contact: compliance@rowvilleconsulting.co.bw