Our Commitment to You
We process client information only for agreed service purposes and under documented instructions. The applicable controls, systems and transfer safeguards are confirmed during onboarding and recorded in the engagement documents.
1. Governance & Regulatory Framework
This policy describes how Rowville Consulting protects the confidentiality, integrity, and availability of client data. It applies to all employees, contractors, and third parties processing data on our behalf.
1.1 Primary Regulatory Alignment
Our operations are structured to comply with the data protection frameworks of our primary client jurisdictions:
| Jurisdiction | Key Legislation | Our Status |
|---|---|---|
| United Kingdom | UK GDPR, Data Protection Act 2018 | Contractual obligations agreed per engagement |
| Ireland / EEA | EU GDPR, Irish Data Protection Act 2018 | Contractual obligations agreed per engagement |
| Botswana (delivery location) | Applicable Botswana data-protection law | Local processing and security obligations |
1.2 International Data Transfers
Botswana is not currently covered by a UK or EU adequacy decision. Where a restricted transfer applies, the parties document an appropriate safeguard and complete the relevant assessment before processing begins.
- UK transfers: The UK International Data Transfer Agreement or EU Standard Contractual Clauses with the UK Addendum may be used where appropriate, supported by a transfer risk assessment.
- Ireland / EEA transfers: EU Standard Contractual Clauses may be used where appropriate, supported by the required transfer assessment.
- Supplementary measures: Technical and organisational controls are selected according to the data, systems, access model and risks of the engagement.
2. Minimum Security Baseline
Rowville maintains the following controls as a baseline before any client engagement begins. Additional controls may be agreed depending on the sensitivity and scope of the work.
| Control Area | Baseline Requirement |
|---|---|
| Authentication | Multi-factor authentication on all Rowville-managed business accounts |
| User Accounts | Unique user accounts for each team member; no shared credentials |
| Device Security | Screen-lock and device-password requirements on all Rowville-issued devices |
| Confidentiality | Signed confidentiality agreements for all personnel with client access |
| Access Lifecycle | Access removed promptly following reassignment or departure; periodic access reviews |
| Data Storage | Restricted local downloads; client data stored only in approved, access-controlled systems |
| File Transfer | Approved file-transfer channels; no client data sent via uncontrolled email |
| Incident Escalation | Documented escalation procedure; all suspected incidents reported to the responsible lead |
3. Core Security Principles & Controls
Our security approach is informed by recognised good practice. Rowville does not claim independent ISO 27001 certification unless a current certificate is expressly identified.
3.1 Data Protection by Design & Default
- Minimisation: We only collect and process data essential for delivering our contracted accounting services.
- Approved systems: Client data is handled through the systems and locations agreed for the engagement.
- Access control: Role-based access and multi-factor authentication are used where supported and required by the agreed control schedule.
3.2 Technical & Organisational Measures
- Cloud platforms: The selected providers, processing locations and relevant provider certifications are disclosed during due diligence.
- Endpoints: Device, encryption and endpoint-protection requirements are documented for personnel assigned to the engagement.
- Local storage: Restrictions on downloads, removable media and local copies are agreed with the client.
- Personnel: Assigned personnel sign confidentiality obligations and receive role-appropriate data-handling guidance.
4. Data Handling, Retention & Your Rights
4.1 The Data We Process
As your finance partner, we may process: Company financial records, management accounts, payroll data, tax information, and employee details (as necessary for reporting). We act as a Data Processor under your instructions for this data.
4.2 Data Retention
We retain client data only as long as necessary for the service, to meet statutory obligations (e.g., HMRC/Revenue requirements), or as specified in our contract. Secure deletion is performed thereafter.
4.3 Upholding Your Data Subject Rights
We fully support your rights under GDPR. Requests concerning data we process on your behalf (Right to Access, Erasure, etc.) will be handled promptly and in coordination with you, the Data Controller.
5. Incident Response & Breach Notification
We have a formal incident response plan to identify, contain, and resolve security events.
- Identification & containment: Suspected incidents are escalated, investigated and contained under the documented response procedure.
- Assessment: Rowville assesses the affected systems, data, individuals and likely impact.
- Client notification: The affected client is notified without undue delay and within any shorter contractual period. The controller remains responsible for its regulatory reporting decisions.
- Remediation: Action taken to prevent recurrence.
6. Audit, Review & Continuous Improvement
This policy is not static. It is reviewed annually or following significant regulatory changes.
- Control Reviews: Periodic reviews of documented controls, access and engagement requirements.
- Third-Party Reviews: Willingness to participate in client-led security assessments (subject to agreement).
- Policy Updates: Clients will be informed of material changes to this policy.
Request Our Full Data Processing Agreement
For a complete view of our contractual commitments, technical measures, and third-party sub-processors, please request our formal Data Processing Agreement (DPA).
Email for DPA General Questions
Privacy and Data Protection Contact: compliance@rowvilleconsulting.co.bw
