GDPR Compliance
Prexision is committed to protecting personal data and to processing it lawfully, fairly and transparently. This page explains how we handle personal data in line with the EU General Data Protection Regulation (GDPR) and the UK GDPR.
01. Who we are
For this policy, the data controller is Prexision Co. ("Prexision", "we"), a managed finance ecosystem that deploys dedicated accounting, FP&A and tax teams to client engagements.
02. Scope
This policy covers personal data we process about website visitors, clients and their representatives, and finance professionals who apply to or work with us. Where we process data inside a client's systems, we act as a processor and the client is the controller (see section 5).
03. Data we collect
Depending on your relationship with us, we may collect:
- Identity & contact — name, job title, business email, phone, company.
- Engagement data — your requirements, scope, transaction volume and complexity, term, and correspondence.
- Candidate data — CVs, work history, qualifications and assessment results.
- Client financial data — accounting, FP&A and tax records processed to deliver an engagement (usually as a processor).
- Technical data — IP address, device and browser details, and site analytics.
Please don't send special-category data (such as health data) unless we request it and have a lawful basis.
04. How and why we use it
We process data only where we have a lawful basis:
- Provide and scope our services — contract or pre-contract steps.
- Recruit finance professionals — legitimate interests, and consent where required.
- Send guides and newsletters — consent, withdrawable at any time.
- Operate, secure and improve our site — legitimate interests.
- Meet legal obligations — legal obligation.
Where we rely on legitimate interests, we weigh them against your rights, and you may object (section 10).
05. Controller and processor
For our own business data — enquiries, marketing, recruitment and administration — Prexision is the controller. When our team processes personal data inside a client's finance records, Prexision is a processor and the client is the controller, under a written Data Processing Agreement (DPA) available on request via our Contact Us page.
07. International transfers
Where we transfer personal data outside the EEA or the UK, we apply appropriate safeguards — such as the Standard Contractual Clauses (with the UK Addendum where relevant), or transfers to countries with an adequacy decision. Details are available on request.
08. Data retention
We keep personal data only as long as necessary for the purposes above, including legal, accounting and reporting requirements. Engagement records are kept for the engagement and a defined period afterwards; marketing data until you unsubscribe. When no longer needed, data is securely deleted or anonymised.
09. Security
We use technical and organisational measures appropriate to the risk — including access controls, encryption in transit, secure hosting, monitoring, staff confidentiality and data-protection training, and vendor due diligence. No system is completely secure, but we work continuously to protect your data.
10. Your rights
Subject to conditions in the law, you have the right to: