Legal

Privacy Policy

We believe in being completely transparent about how we handle your personal data across our outsourced bookkeeping services, payroll services UK, VAT Services, self assessment tax return work, and CT600 corporation tax engagements. This policy explains what we collect, why we collect it, and how we keep it safe under UK GDPR and ISO 27001.

Last updated: 13 June 2026UK GDPR CompliantISO 27001 Certified
01 / 13
GDPR Compliant
ISO 27001 Certified
NDA Before Every Project
ICO Registered
Data Deleted Post Project
01

Who We Are

Probal Global is a knowledge process outsourcing firm operated by Probal Consulting Group, headquartered at 305, Aakansha Complex, Gondal Road, Rajkot - 360002, Gujarat, India. We deliver outsourced bookkeeping services, payroll outsourcing services, VAT Services, self assessment tax return services, CT600 corporation tax, company secretarial services UK, and related back office accounting and bookkeeping services to practices and businesses across the United Kingdom, United States, Australia, Ireland, and beyond.

Throughout this Privacy Policy, the terms “we”, “us” and “our” refer to Probal Global and Probal Consulting Group. When we refer to “you”, we mean any individual whose personal data we collect and process, including visitors to our website, prospective and current clients, and job applicants.

This Privacy Policy explains in plain language what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have in relation to it. We are committed to handling all personal data with care, transparency, and respect.

  • Visitors to our website at probalglobal.com
  • Prospective clients who contact us or submit a free trial request
  • Current and former clients and their authorised representatives
  • Job applicants and prospective team members
  • Any other individuals whose personal data we receive in the course of our work

A note for accounting firms

If you are an accounting practice that engages us to process personal data belonging to your own clients, please pay particular attention to Section 5 of this policy, which explains our role as a data processor and the obligations we hold on your behalf.
02

Information We Collect

We collect personal data in three main ways: information you provide to us directly, information we collect automatically when you use our website, and information generated in the course of delivering our services to you.

Information you provide to us

  • Your name, job title, and the name of your practice or business
  • Your email address, telephone number, and country
  • Details of the services you are enquiring about
  • Information included in your free trial request or contact form
  • Your CV and professional details if you apply for a role with us
  • Any other information you choose to share with us in correspondence

Information we collect automatically

  • Your IP address and approximate geographic location
  • Browser type, operating system, and device type
  • Pages you visit on our website and the time you spend on them
  • How you arrived at our website (referral source or search engine)
  • Anonymised usage patterns used to improve site performance

Information from our service delivery

  • Accounting records, financial data, and client documents you share with us for processing
  • Communications between you and your dedicated account manager
  • Feedback, review notes, and quality assessment records
  • Billing and invoicing information associated with your account
03

How We Use Your Information

We use the personal data we collect only for legitimate, specific purposes. We do not use your data for automated decision making, profiling, or any purpose beyond those listed below.

  • To respond to your enquiries and arrange your free trial on bookkeeping, payroll, VAT or tax return work
  • To deliver the outsourced bookkeeping, payroll, VAT, corporation tax and self assessment services you have engaged us for
  • To communicate with you about your account, work in progress, and upcoming deadlines
  • To send you service updates, important notices, and changes to our terms
  • To improve our website, services, and internal quality processes
  • To manage billing, invoicing, and financial records associated with your account
  • To verify your identity and carry out appropriate due diligence
  • To comply with our legal and regulatory obligations
  • To consider your application if you have applied for a position with us

We will never sell, rent, or trade your personal data to any third party for commercial purposes. Where we send you marketing or newsletter content, you will always have the ability to unsubscribe.

04

Legal Basis for Processing

Under the UK General Data Protection Regulation (UK GDPR), we are required to have a valid lawful basis for every type of personal data processing we carry out. The bases we rely on are as follows:

Contractual Necessity

Where processing is necessary to deliver the services you have engaged us for, or to take steps at your request before entering into a contract with us.

Legitimate Interests

Where we have a genuine and proportionate business need, such as improving our website, sending relevant service updates, or maintaining the security of our systems.

Legal Obligation

Where we are required by law to process your personal data, for example to comply with tax regulations, anti money laundering obligations, or a court order.

Consent

Where you have given us your clear and specific consent, such as when subscribing to our newsletter, accepting optional cookies, or agreeing to receive marketing communications.

Your right to withdraw consent

Where we rely on your consent as the basis for processing, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing we carried out before the withdrawal. To withdraw consent, please contact us using the details in Section 13.
05

Client Data We Process

When you engage Probal Global for outsourced bookkeeping services, payroll outsourcing services, VAT, self assessment tax return work, or CT600 corporation tax, you will share personal data relating to your own clients with us (for example, names, addresses, National Insurance numbers, UTRs, tax reference numbers, payroll details, and financial records). In this context, our roles under UK GDPR are clearly defined.

You are

The Data Controller

You determine why and how your clients’ personal data is processed. You are responsible for having a valid legal basis to share that data with us and for maintaining records of your processing activities.

We are

The Data Processor

We process your clients’ personal data only on your documented instructions and for no other purpose. We act under your authority and in line with the data processing agreement we sign with you.

As your data processor, our obligations include the following:

  • Processing client data only as instructed by you and for no other purpose
  • Implementing appropriate technical and organisational security measures
  • Not engaging any sub processors without your prior written consent
  • Assisting you in meeting your obligations to your own clients under UK GDPR
  • Returning or securely deleting all client data at the end of the engagement
  • Notifying you without undue delay if we become aware of a personal data breach
  • Maintaining records of all processing activities carried out on your behalf
06

How We Protect Your Data

Data security is not an afterthought at Probal Global. It is embedded into every outsourced bookkeeping, payroll, VAT, and tax return engagement we handle. We operate within a comprehensive, layered security framework that is independently certified and continuously reviewed.

256 Bit AES Encryption

All data is encrypted in transit and at rest using industry standard AES 256 bit encryption.

ISO 27001 Certified

Our server infrastructure is housed in ISO 27001 certified data centres with continuous monitoring.

VPN Protected Access

All remote access to client software and files is conducted through secure, VPN protected connections.

Role Based Access

Access to client data is restricted to authorised team members only, using role based permission controls.

Multi Factor Authentication

All internal systems and client platforms require multi factor authentication for every login.

NDA Before Every Project

We sign your firm's Non Disclosure Agreement or provide our own before any work begins.

Our data security commitment

We never use personal WhatsApp, personal email accounts, or unencrypted channels to transfer any client data. All document exchange takes place through secure portals, encrypted email, or VPN protected remote access only. Every member of our team signs a comprehensive internal confidentiality agreement as a condition of their employment.
07

Data Retention

We only retain personal data for as long as is genuinely necessary for the purpose for which it was collected, or as required by law. When the retention period expires, we securely delete or destroy the data without delay.

Client accounting and financial dataDeleted or returned within 30 days of project completion or engagement end, per your written instructions
Enquiry and contact form submissionsRetained for up to 24 months from the date of last contact, then securely deleted
Website analytics and usage dataRetained for up to 12 months using anonymised data, then automatically removed
Job application data (unsuccessful)Retained for 6 months from the date of our decision, then securely deleted
Job application data (successful)Retained for the duration of employment plus any period required by applicable employment law
Financial and invoicing recordsRetained for 7 years in line with UK tax and accounting record keeping requirements

You may request deletion of your personal data at any time by contacting our data team. We will respond within 30 days. Where deletion is not legally possible due to mandatory retention obligations, we will inform you and restrict processing to the minimum necessary until deletion becomes permissible.

08

Sharing Your Information

We treat personal data with the strictest confidence and do not share it with any third party except in the following limited and clearly defined circumstances.

We may share data with

  • Technology and service providers who support our operations (secure cloud storage, accounting software platforms), under strict data processing agreements
  • Professional advisers such as legal counsel or auditors, where strictly necessary and under binding confidentiality obligations
  • Regulatory authorities or law enforcement agencies where we are legally required to disclose information by a court or regulatory body

We will never share data with

  • Marketing companies, data brokers, or advertisers
  • Competitors or other outsourcing firms
  • Any third party for commercial gain without your explicit prior written consent
  • Any party that has not agreed to appropriate data protection terms

Any service provider we engage is carefully vetted for their security standards and is required to maintain data protection standards equivalent to our own. We do not allow any service provider to use your data for their own purposes.

09

International Transfers

Our team is based in Rajkot, Gujarat, India. When you share personal data with us, that data will be transferred to and processed in India. We recognise that India does not currently hold an adequacy decision from the UK, and we take this responsibility seriously.

To ensure your personal data receives a level of protection equivalent to that required under UK GDPR, we apply the following safeguards:

  • We enter into UK approved standard contractual clauses with our clients where required
  • We apply technical and organisational security measures that meet or exceed UK GDPR standards
  • All data is processed within ISO 27001 certified and independently audited infrastructure
  • We are happy to enter into your preferred data transfer agreement before any work begins
  • We maintain a Transfer Impact Assessment that is available to clients on request

Transparency about cross border transfers

We do not treat the India based location of our team as a reason to apply lower standards. All data protection requirements, security controls, and confidentiality obligations described in this policy apply in full to every piece of data we handle, regardless of where our team members are physically located.
10

Your GDPR Rights

Under the UK GDPR, you have a number of important rights in relation to your personal data. We are committed to respecting and upholding these rights and will always respond to your requests promptly.

01

Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we are using it.

02

Right to Rectification

You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you, without undue delay.

03

Right to Erasure

You have the right to request that we delete your personal data where there is no compelling reason for us to continue holding it.

04

Right to Restriction

You have the right to ask us to restrict the processing of your personal data in certain circumstances, such as while a dispute is being resolved.

05

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine readable format and to transfer it to another organisation.

06

Right to Object

You have the right to object to our processing of your personal data where we rely on legitimate interests. We must stop processing unless we can demonstrate compelling grounds.

07

Right to Withdraw Consent

Where we process your data on the basis of your consent, you can withdraw that consent at any time without affecting the lawfulness of prior processing.

How to exercise your rights

To exercise any of the rights listed above, please contact us at info@probalglobal.com. We will acknowledge your request within 5 working days and provide a full response within 30 calendar days. If you are not satisfied with our response, you have the right to lodge a complaint directly with the Information Commissioner’s Office (ICO) in the United Kingdom.
11

Cookies and Tracking

Our website uses cookies and similar technologies to provide a better experience for visitors and to help us understand how the site is used. We are transparent about what we use and give you control over non-essential cookies.

Essential Cookies

Required

Necessary for the website to function correctly. These enable core features such as page navigation and secure form submission. They cannot be disabled.

Analytics Cookies

Help us understand how visitors interact with our website. We use Google Analytics with IP anonymisation enabled so no personally identifiable information is stored.

Preference Cookies

Remember your settings and choices so you do not need to re-enter them each time you visit. For example, your cookie consent selection is stored using a preference cookie.

We do not use advertising cookies, retargeting cookies, or any third party cookies that share your data with advertisers. You can manage your cookie preferences at any time through your browser settings. Disabling certain cookies may affect the functionality of the website.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, our legal obligations, or evolving best practice in data protection. We will always be transparent when we make changes.

  • Update the Last Updated date shown at the top of this page
  • Notify all active clients by email of any material changes before they take effect
  • Allow a minimum of 14 days before significant changes come into force
  • Keep the most recent version of this policy publicly available on this page at all times
  • Make previous versions available on request for a period of at least 12 months

We encourage you to review this page periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes take effect will constitute your acceptance of the updated policy.

If you disagree with any change to this policy and it materially affects your engagement with us, please contact our data team and we will work with you to find an appropriate resolution.

13

Contact Our Data Team

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we handle personal data, please reach out to us. We aim to respond to all privacy related enquiries within 5 working days.

Right to complain to the ICO

If you are not satisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent authority for data protection. You can contact the ICO at ico.org.uk or by telephone on 0303 123 1113. We would, however, always welcome the opportunity to address your concern directly before you contact the ICO.

Want to see our data security in action?

Start with a free trial on real bookkeeping, payroll, VAT or self assessment tax return work at no cost. We sign your NDA before anything begins.

Start Free Trial

Questions about how we handle your data? We are always here to help.

Our team is happy to walk you through our data protection practices across outsourced bookkeeping, payroll, VAT and tax return work - or sign your firm's NDA before any engagement begins.