This Privacy Notice applies to all personal information collected by Crowned Bookkeepers Pty Ltd, Crowned Bookkeepers Ltd, and Crowned Bookkeepers LLC (we, us, or our) when you visit our website located at www.crowned-group.com (Website) or engage with us through our online forms or social media accounts.
1. What Personal Information We Collect
We collect personal information you voluntarily provide when you express interest in obtaining information about our Services. The Personal Information which we collect and hold about you may include:
- Name, Title, Contact Details, including phone number and email address
- Business/mailing address
- Information about your business activities
- Information about your family members
- Financial Records or Financial Information
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable: (a) whether the information or opinion is accurate or not; and (b) whether the information or opinion is recorded in a material form or not. If the information does not disclose your identity or enable your identity to be ascertained, it will, in most cases, not be classified as “Personal Information” and will not be subject to this privacy policy.
Sensitive Information can include information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record, or health information. Sensitive Information will be used by us only for the purpose for which it was obtained, with your consent or where required or authorised by law.
We automatically collect certain information when you visit, use, or navigate our website. This information does not reveal your specific identity but may include device and usage information such as your IP address, location, and referring URL. We primarily use this information for internal analytics and reporting.
Where we collect personal information indirectly (for example, from a client organisation providing us with their employees’ or customers’ details for bookkeeping purposes, from publicly available business registers, or from cookies and analytics providers as described in Section 11), we obtain it from those specific sources rather than from you directly.
We do not knowingly collect personal information from or market to children under 18 years of age.
2. How We Collect It
- Directly: Onboarding forms, emails, registrations
- Indirectly: cookies, log files, third-party integrations
3. Why We Collect It (Purpose of Use)
We collect Personal Information to provide you with the best service experience possible, and to keep in touch with you about developments in our business. This may sometimes include:
- Processing your information to provide you with the requested service.
- Processing your information to respond to your inquiries and solve any potential issues you might have.
- Processing your information to send you details about our products and services, changes to our terms and policies, and other similar information.
- Processing your information if you choose to use any of our offerings that require communication with a third-party partner.
- Processing your information when necessary to save or protect an individual’s vital interests.
- Processing your information for marketing purposes, for example, when you opted in to receive our regular Newsletter or Blog post. Our direct marketing material will include a simple means by which you can request not to receive further communications of this nature, such as an unsubscribe or opt-out link.
- Processing your information to carry out client due diligence, identity verification, and ongoing monitoring as required under anti-money laundering law (in the UK, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017), and to comply with our obligations as a supervised business under those regulations.
- Processing your information to prepare, maintain, and retain accounting and bookkeeping records on behalf of our clients, and to meet statutory record-keeping obligations (for example, HMRC requirements for UK clients — see Section 12).
4. Our Role: Controller and Processor
Depending on the service, Crowned Bookkeepers may act either as a data controller or as a data processor:
- As a controller — where we decide the purposes and means of processing your personal information, for example when you enquire about our services, subscribe to our newsletter, or where we handle our own client and supplier records. This Privacy Notice applies in full to that processing.
- As a processor — where a client engages us to provide bookkeeping, payroll, or accounting services and, in doing so, we process personal information about that client’s own employees, customers, or suppliers on the client’s behalf and instructions. In that situation, the client remains the controller of that data, is responsible for providing its own privacy notice to the individuals concerned, and our processing is governed by a separate data processing agreement (or equivalent contractual terms) with the client, in addition to this notice.
If you are unsure whether Crowned Bookkeepers is acting as controller or processor in relation to your information, please contact us using the details in Section 15.
5. Legal Bases for Processing
The table below sets out, for each jurisdiction in which we operate, the framework we rely on to process your Personal Information and, for the UK, how our purposes map to specific legal bases.
| Region | Framework and Legal Bases |
| Australia | Crowned Bookkeepers Pty Ltd is committed to protecting your privacy and complying with the Privacy Act 1988 and the Australian Privacy Principles (APPs). We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification, or disclosure. The Australian Privacy Principles permit you to obtain access to the Personal Information we hold about you in certain circumstances (APP 12); and allow you to correct inaccurate Personal Information subject to certain exceptions (APP 13). |
| United Kingdom | Crowned Bookkeepers Ltd is committed to how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We rely on the following legal bases, depending on the purpose: • Consent — for direct marketing communications such as our newsletter, where you can withdraw consent at any time. • Contract — to provide our bookkeeping and accounting services to you or the business you represent. • Legal obligation — to comply with obligations such as HMRC record-keeping requirements and the Money Laundering Regulations 2017. • Vital interests — where necessary to protect someone’s life. • Legitimate interests — for general business administration, website analytics, and fraud prevention, where these interests are not overridden by your own interests or fundamental rights. Where we rely on legitimate interests, we carry out a balancing assessment and can provide details of it on request. |
| United States (Texas) | Crowned Bookkeepers LLC is committed to protecting your privacy and handling your personal information responsibly and in compliance with U.S. privacy standards and applicable Texas law. If you are a resident of Texas, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent. We have not disclosed, sold, or shared any personal information to third parties in the preceding 12 months, and we will not share or sell personal information in the future. |
6. Cross-Border Transfers
Crowned Bookkeepers is part of an international group of Companies that operates in Australia, the United Kingdom, and the United States. We may, from time to time, share your Personal Information with our business partners and/or subsidiaries located in any of these locations.
Where we transfer personal information from the UK to a country outside the UK that does not have UK adequacy regulations in place, we do so on the basis of an appropriate safeguard recognised under UK GDPR, in particular: the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses; or, where applicable, reliance on the UK Extension to the EU-U.S. Data Privacy Framework (“UK-US Data Bridge”) for transfers to the United States. You may request a copy of the relevant safeguard from Charlene Simpson (charlene@crowned-group.com) using the details in Section 15.
You acknowledge and consent to your Personal Information being transferred to, and processed in, another jurisdiction, not necessarily that of your country of residence. Although Crowned Bookkeepers will take reasonable steps to ensure that the recipient does not breach international privacy guidelines in relation to your information, the recipient country may not offer the same level of data protection as your home jurisdiction. In the event of mishandling or a breach of your personal information in another jurisdiction than your own, legal remedies under your home jurisdiction may not be available to you.
7. Who We Share Your Information With
In providing our services, we may share personal information with the following categories of recipients:
- Cloud-based accounting and bookkeeping software providers used to deliver our services, for example QuickBooks Online, Xero, HubSpot CRM, and Dropbox/OneDrive
- IT hosting, backup, and cloud storage providers
- Professional advisers (auditors, lawyers, tax agents) where reasonably necessary
- Regulatory and supervisory bodies, including HMRC and our anti-money laundering supervisory body (IAB (International Association of Bookkeepers)), where required by law
- Our group entities and business partners as described in Section 6
8. Your Legal Rights
| Region | Rights You Can Exercise |
| Australia | Right to access your Personal Information (APP 12) and to correct inaccurate Personal Information, subject to certain exceptions (APP 13). |
| United Kingdom | Under UK GDPR, you have the right to: • Be informed about how your personal information is used • Access the personal information we hold about you • Request rectification of inaccurate or incomplete information • Request erasure of your personal information in certain circumstances • Request restriction of processing in certain circumstances • Object to processing, including for direct marketing purposes • Request data portability, where processing is based on consent or contract and carried out by automated means • Withdraw consent at any time, where processing is based on consent • Complain directly to us first (Section 15) before referring your complaint to the ICO — a statutory requirement since 19 June 2026 under the Data (Use and Access) Act 2025 • Lodge a complaint with the Information Commissioner’s Office (ICO) — see Section 15 |
| United States (Texas) | Right to request access to and details about the personal information we maintain about you, correct inaccuracies, obtain a copy, delete your personal information, and withdraw consent. We have not disclosed, sold, or shared personal information to third parties in the preceding 12 months, and will not do so in future. |
9. Automated Decision-Making and Profiling
We do not use your personal information to make decisions about you based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you. If this changes, we will update this notice and, where required, seek your consent.
10. How We Protect Your Personal Data
We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% safe. Although we will do our best to protect your personal information, transmission of personal information to and from our services is at your own risk; you should only access the services within a secure environment.
Given the volume of financial records we handle, this includes access controls that limit staff access to client financial data on a need-to-know basis, encryption of data in transit and at rest where supported by our software providers, and regular review of third-party software providers’ security certifications.
11. Cookies
We may also collect cookies from your computer, which enable us to tell when you use the Website and help customise your website experience. As a general rule, however, it is not possible to identify you personally from our use of cookies. In some cases, we may use cookies to collect personal information, or information that becomes personal when combined with other information.
| Category | Purpose | Consent required (UK)? |
| Essential / strictly necessary | Required to provide the Website and its core features (e.g. security, load balancing). | No — exempt under PECR |
| Performance and functionality | Enhance performance and remember your preferences. Non-essential; some features may not work without them. | Yes |
| Analytics and customisation | Help us understand site usage and customise your experience. | Yes |
For UK and EU visitors: under the Privacy and Electronic Communications Regulations (PECR) and UK GDPR, we will ask for your consent via a cookie banner before setting any non-essential (performance, functionality, analytics, or customisation) cookies, and you can withdraw that consent at any time through our cookie preference settings, available at https://crowned-group.com/cookie-policy-uk/.
12. Data Retention
We will keep your personal information only as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law, such as tax, accounting, or other legal requirements. When we no longer require your Personal Information for the purpose for which we obtained it, we will take reasonable steps to destroy and anonymise or de-identify it.
For UK clients specifically:
- We retain bookkeeping, accounting, and tax-related records for a minimum of 6 years from the end of the relevant accounting period, in line with HMRC record-keeping requirements.
- Client due diligence and identity verification records obtained under anti-money laundering law are retained for 5 years from the end of the client relationship, in line with the Money Laundering Regulations 2017.
- General inquiry and marketing data is retained for 2 years from the date of last contact, or until you unsubscribe, whichever is sooner.
13. Children’s Privacy
We do not knowingly collect personal information from or market to children under 18 years of age.
Note for UK purposes: where we offer information society services directly to a child, UK data protection law sets the age at which a child can consent to that processing at 13. Our policy of not knowingly collecting information from anyone under 18 is a Crowned Bookkeepers group standard that is more protective than this minimum legal threshold and is applied consistently across all jurisdictions in which we operate.
14. Changes to This Policy
We may update this Privacy Notice from time to time. We encourage you to review this notice frequently to stay informed about how we protect your information.
15. Contact Details
Privacy contact (Australia): Bernice Grobler. Privacy contact (United States): Charlene Simpson. Data Protection Officer (DPO) (United Kingdom): Charlene Simpson.
UK Data Protection Officer contact: charlene@crowned-group.com / +44 7805 223 731.
ICO registration: Crowned Bookkeepers Ltd is registered with the UK Information Commissioner’s Office under registration number ZB890372. You can verify our registration on the ICO’s public register.
If you have any queries, seek access to your Personal Information, or have a complaint about our privacy practices, you can contact us at info@crowned-group.com.
If you believe your personal information has been misused and you would like to make a formal complaint or seek further information, please take note of the following privacy and data protection agencies:
- US — Financial data misuse: consumerfinance.gov/complaint
- US — General data misuse: reportfraud.ftc.gov
- US — State-specific privacy issues: naag.org/find-my-ag
- UK — Information Commissioner’s Office: ico.org.uk/make-a-complaint/data-protection-complaints
- AU — Office of the Australian Information Commissioner: oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us
