LEGAL POLICIES

GDPR Compliance

Prexision is committed to protecting personal data and to processing it lawfully, fairly and transparently. This page explains how we handle personal data in line with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

01. Who we are

For this policy, the data controller is Prexision Co. ("Prexision", "we"), a managed finance ecosystem that deploys dedicated accounting, FP&A and tax teams to client engagements.

02. Scope

This policy covers personal data we process about website visitors, clients and their representatives, and finance professionals who apply to or work with us. Where we process data inside a client's systems, we act as a processor and the client is the controller (see section 5).

03. Data we collect

Depending on your relationship with us, we may collect:

  • Identity & contact — name, job title, business email, phone, company.
  • Engagement data — your requirements, scope, transaction volume and complexity, term, and correspondence.
  • Candidate data — CVs, work history, qualifications and assessment results.
  • Client financial data — accounting, FP&A and tax records processed to deliver an engagement (usually as a processor).
  • Technical data — IP address, device and browser details, and site analytics.

Please don't send special-category data (such as health data) unless we request it and have a lawful basis.

04. How and why we use it

We process data only where we have a lawful basis:

  • Provide and scope our services — contract or pre-contract steps.
  • Recruit finance professionals — legitimate interests, and consent where required.
  • Send guides and newsletters — consent, withdrawable at any time.
  • Operate, secure and improve our site — legitimate interests.
  • Meet legal obligations — legal obligation.

Where we rely on legitimate interests, we weigh them against your rights, and you may object (section 10).

05. Controller and processor

For our own business data — enquiries, marketing, recruitment and administration — Prexision is the controller. When our team processes personal data inside a client's finance records, Prexision is a processor and the client is the controller, under a written Data Processing Agreement (DPA) available on request via our Contact Us page.

06. How we share data

We never sell personal data. We share it only as needed with: our assigned finance team and leads; vetted service providers (sub-processors) for hosting, email, analytics and CRM, under data-protection contracts; professional advisers such as auditors, lawyers and insurers; and authorities where required by law. A current sub-processor list is available on request.

07. International transfers

Where we transfer personal data outside the EEA or the UK, we apply appropriate safeguards — such as the Standard Contractual Clauses (with the UK Addendum where relevant), or transfers to countries with an adequacy decision. Details are available on request.

08. Data retention

We keep personal data only as long as necessary for the purposes above, including legal, accounting and reporting requirements. Engagement records are kept for the engagement and a defined period afterwards; marketing data until you unsubscribe. When no longer needed, data is securely deleted or anonymised.

09. Security

We use technical and organisational measures appropriate to the risk — including access controls, encryption in transit, secure hosting, monitoring, staff confidentiality and data-protection training, and vendor due diligence. No system is completely secure, but we work continuously to protect your data.

10. Your rights

Subject to conditions in the law, you have the right to:

Access
Get confirmation we process your data, and a copy of it.