Privacy Policy

Last Updated: September 30, 2026

About Multiplier Holdings

Multiplier is a technology company that owns professional services firms and builds custom AI technology across them.

Multiplier portfolio companies provide professional services to clients across accounting, finance, tax and advisory.

We use client information and work products, which may contain personal data, to provide our services. We may also use this information to develop, train and evaluate our AI tools that help our professionals deliver more accurate, efficient and useful services. Our revenue comes from the professional services we provide to clients. We do not sell personal data.

This policy explains what personal data we collect as controllers, how it is used, who it is shared with, and the rights available to you.

Summary of how we use your data
  • Multiplier Holdings and its portfolio companies (also referred to as “Multiplier”, "we" or "us"), use your personal data to perform contractual and legal obligations, in particular to provide you or the organisation you represent with professional services such as tax, accounting and advisory services.
  • We share the data with our portfolio companies, regulators and authorities, and our third-party service providers. Due to the global nature of our business, your personal data may be transferred outside the country of your residence, in particular outside of the UK/EEA. Where these locations do not provide an appropriate level of data protection, we ensure appropriate safeguards are in place.

What does this notice cover?

We are committed to making our privacy practices transparent and fair. This policy describes how Multiplier Holdings and its portfolio companies will process your data, when you use our websites and services such as our Multiplier Apps (“Apps”) and professional services, in particular when we provide you tax, accounting and advisory services as an individual or as an organisation, or if you represent such client.

We may also process personal data on behalf of our clients, e.g. if we provide our corporate client with payroll services or with our App services, we process data of their users, employees and other individuals whose data are in the materials we obtain as data processors. If that is the case, our client is the data controller responsible for providing you with appropriate notice, and this notice does not apply to you.

The notice also describes your data protection rights, including the right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “What are your rights and how to exercise them” section.

Content

1.  Personal data we may collect about you

2.  How do we use your personal data, and what is the legal basis for this use?

3.  How do we use cookies and similar technologies?

4.  How we share your personal data

5.  Where we transfer your personal data

6.  What are your rights and how to exercise them

7.  How long we retain your personal data

8.  Data security

9.  Updates to this privacy notice

10. Contact us

1.  Personal data we may collect about you

We collect and process personal data about you when you interact with us and our websites, and when you purchase services from us.  This includes:

Category Details
Identity Data Data that enables us to identify and verify you such as name, title, job role, identifiers (such as passport/ID number, insurance number, login) (hashed) passwords, name of the company (your business/employer), country of residence, anti-money laundering and electronic identity verification information.
Contact Data Data enabling us to contact you such as (private or processional) email address, telephone number, postal address.
Demographic Data Data such as date of birth, marital status, spouse and dependents, occupation, city of residence.
Service-related Data Details of any services you have received from us such as company records, tax and accounting documentation, R&D tax credit details, or payroll and employment-related data, pensions, salaries, real estate, information from competent authorities, information required to prepare relevant tax and accounting documentation.
Financial Data Financial and banking information such as bank account details, payment records, amount on invoices, tax identifiers, credit card details.
Marketing Data Your marketing preferences for receiving e.g. updates, newsletters, event invitations, including any consents you have given us.
Technical Data Information related to the browser or device you use to access our website such as IP address, operating system, browser version, locale and language settings used, the cookies and similar technologies used on such device, and the activity (clicks and other interactions) on our websites.
Correspondence Data Our correspondence and communications with you, including complaints, opinions and enquiries you make to us.

We may process special categories of data in limited circumstances, such as when it is necessary to perform our legal or regulatory obligations and processing is necessary for reasons of substantial public interest, on the basis of EU or Member State law (e.g. PEP status for AML purpose) (“Special Category Data”).

It is important that the personal data we hold about you is accurate and current. Should your personal data change, please notify us of any changes of which we need to be made aware by contacting us, using the contact details below.

We collect personal data directly from you when you: (i) request a proposal from us in respect of the services we provide, (ii) engage us to provide our services and also during the provision of those services, (iv) contact us by phone, email, post, or through our website forms;

Indirectly we may obtain most categories of your data from:

  • your organisation
  • your spouse, partner or authorised representative
  • our portfolio companies
  • public authorities (e.g. tax authorities)
  • publicly available sources (e.g. public registers)
  • business partners, other professional advisers or service providers, and using tools and channels commonly used to connect between companies and individuals to explore potential business and employment opportunities, such as LinkedIn we may receive your contact and professional details (e.g., your name, company, position, contact details and professional experience, preferences and interests)
  • event organisers if you participate in an event or webinar that we sponsor
  • electronic identity verification providers
  • other third parties (for example banks, pension providers or investment managers) where authorised by you.

We may also obtain your data automatically through cookies and similar technologies when you browse our websites.

2. How do we use your personal data, and what is the legal basis for this use?

We will only use your personal data for the purposes and legal bases set out below:

Purpose Legal Basis

We will collect, use and store your Identity Data, Contact Data and Technical Data to register and create an account on our website, particularly in the App, and to provide you with related services.

We will collect, use and store your Identity Data, Contact Data, Financial Data and Service-Related Data to provide you with our professional services such as tax, accounting or advisory services.

We will communicate with you in relation to the services via general or personalised service-related messages (such as purchase confirmations or system maintenance notices, notices about changes to our services) or to organise meetings with you.

In providing our services, we use new technologies such as machine learning and generative artificial intelligence, which assist us in providing services, in particular with document processing, data extraction and analysis, and the generation of drafts and summaries; however, outputs are reviewed by a qualified staff member.

It is necessary for us to process your personal data to perform our contract with you, or to take steps at your request prior to entering into a contract with you.

We have a legitimate interest in providing services to our clients, including collecting customer feedback.

We will collect and use your Identity Data, Contact Data and Financial Data to verify your identity. We have a legitimate interest in ensuring the security of our services and data.
We will collect, use and store your Identity Data, Contact Data and Correspondence Data to manage our relationship with you (e.g., respond to your non-services related enquiries, seek your customer feedback). We have a legitimate interest in managing our business and providing services to our clients, including collecting customer feedback.
We will use, store and share your All Data Categories to perform our legal, regulatory and professional obligations, and to comply with internal policies and procedures and codes of conduct. We have legal obligations under relevant laws such as tax and accounting laws, AML laws, data protection laws. The processing is necessary for reasons of substantial public interest, on the basis of EU or Member State law.
We will also use, store and share All Data Categories to pursue potential legal claims or defend ourselves against potential legal, regulatory or professional claims. We have a legitimate interest in ensuring internal compliance, reporting to professional bodies or authorities and to pursue or defend against claims.
We will collect and analyse your All Data Categories to monitor customer accounts to prevent, investigate and/or report misuse of our services, fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law.

We have a legal obligation under relevant criminal, tax and cybersecurity laws.

We have a legitimate interest in preventing and detecting fraud, or other wrongdoing.

UK only: where it is necessary to process personal data to prevent, detect, or investigate a crime, we rely on our recognised legitimate interests.

We will collect and use Identity Data, Contact Data, Marketing Data, Service-Related Data and Technical Data to send you direct marketing in relation to our relevant products and services, or other products and services provided by us, our portfolio companies.

Depending on the country, it may be:

Your consent. Whenever we ask for your consent, we will explain why and how we will use your data, so your consent can be informed.

We have a legitimate interest in promoting our services to our clients.

We will collect and use your Identity Data, Contact Data, Technical Data, Marketing Data and Service-Related Data to send you personalised adverts for our relevant services or other services provided by us, our portfolio companies and carefully selected partners. Your consent when we rely on cookies. Whenever we ask for your consent, we will explain why and how we will use your data, so that you can give your consent in full knowledge of the facts.
We will collect, analyse and store Identity Data, Contact Data, Service-Related Data and Technical Data to manage and operate and customise our websites and services, including carrying out data analytics to keep them updated and relevant, to improve our business, your user experience and to inform our marketing strategy.

Your consent when we rely on cookies. Whenever we ask for your consent, we will explain why and how we will use your data, so your consent can be informed.

We have a legitimate interest in operating our services and improving their operation (when we do not use cookies for such processing).

We will collect and store Identity Data and Financial Data to facilitate, process payment for services and maintain financial records.

It is necessary for us to process your personal data to perform our contract with you.

We have a legal obligation under relevant tax and accounting laws.

We will collect, use and analyze your Identity Data, Contact Data, Service-Related, Technical Data and Financial Data to improve and develop our services, and the technology and tools we use to provide them, in particular to develop, train, test and improve, where needed, the artificial intelligence or machine learning models we use to deliver and enhance our services (for instance, for document extraction, error detection, drafting, quality assurance etc) and improving the technology we use to provide and improve our services. We have a legitimate interest in developing and improving our services.

Where we process personal data on the basis of a legitimate interest, then – as required by data protection law we carry out a documented balancing test weighing our interests against the potential impact on individuals. In the UK, we do not need to conduct this test for ‘recognised legitimate interests’. You can request more information about this balancing test by using the contact details at the end of the notice.

3. How do we use cookies and similar technologies?

When you visit our websites or interact with us, we may use tools to store data on your devices or access data already stored on such devices, such as cookies, web beacons, pixels, tags, plug-ins, or, in the case of the app, software development kits (SDKs) or other similar technologies (collectively, “cookies”). We use cookies in accordance with the applicable legal requirements. For more information, please see our cookie policy on our website.

4. How we share your personal data

We may share your data with the following categories of recipients:

Personal Data Category Category of Recipient Why?
All Data Categories Our portfolio companies

To operate our business, including IT, technical and engineering support.

To improve and develop the services, technology and tools that portfolio companies use to provide their services, and, in particular, we may share data with Multiplier Holdings for developing, training, testing and improving the proprietary artificial intelligence and machine learning models that portfolio companies use to deliver and enhance their services. For more information click here.

As part of international engagements, where professional expertise from other portfolio companies is required or desirable to provide our services.

Varies by provider — All Data Categories for infrastructure providers; additionally Identity, Contact, Service-related, Financial, Correspondence, Marketing and Special Category Data where relevant for service-specific providers such as AI systems, CRM and email platforms Technology and service providers (IT, cloud, hosting, cybersecurity, AI systems, CRM, email, marketing, analytics, session recording, administration services) To host, maintain and secure our App; to deliver, analyse and improve our services; to manage client communications and marketing activities.
Identity, Contact, Demographic, Service-related, Financial, Correspondence, and Special Category where relevant Professional delivery partners (subcontractors, consultants, KYC and identity verification providers, financial services providers, appointed alternates) We employ other companies and individuals to deliver professional services under the same professional and ethical obligations, to verify identity and comply with AML obligations, to process payments, among others.
Identity, Contact, Demographic, Service-related, Financial, Correspondence, Special Category where relevant. Regulators and authorities, third parties you require us to correspond with

Where it is necessary to administer the relationship between us (for example, to submit your tax return to the relevant tax authorities in the jurisdictions where you are filing)

Sometimes you ask us to correspond with certain entities for your convenience, for example finance providers, pension providers (including auto-enrolment), investment brokers, new advisors.

Identity, Contact, Service-related, Financial, Correspondence. Special Category only where a specific matter requires it. Insurers (incl. professional indemnity insurers), auditors, external quality reviewers, business, legal, financial and compliance advisors To ensure compliance of our business with the provisions of law and with industry requirements.
Identity, Contact, Demographic, Service-related, Financial, Correspondence, Technical (for cybercrime matters), Special Category where legally required. Regulators and competent authorities (including police and law enforcement agencies), courts, tribunals and professional bodies

To perform our legal and regulatory obligations, comply with a subpoena, search warrant or court order, comply with codes of conduct of professional bodies, or prevent, investigate and/or report misuse of our services, fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law.

Such disclosure or access may occur with or without notice to you, if we have a good faith belief that we are legally compelled to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.

All Data Categories Prospective Buyer/Seller or entities related to selling and restructuring of business If the business is sold, integrated with another business or restructured, your details may be disclosed to our advisors and any prospective purchaser’s adviser and will be passed to the new owners of the business.

We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality, security standards and obligations.

5. Where we transfer your personal data

Personal data that we collect from you may be transferred to and stored at a destination outside your place of residence, including outside the EEA/UK. Due to the global nature of our business, your personal data will be disclosed to our portfolio companies, based on an intragroup data processing agreement, in Hong Kong, the USA and Singapore. We may also share personal data to other portfolio companies as part of international engagements, and where required or desirable to meet our legal and regulatory obligations around the world.

All our personal data transfers are compliant with applicable data protection laws. The agreements we have in place with our portfolio companies and with our third-party service providers include appropriate safeguards to ensure that data flows are safe and that individuals can exercise their data protection rights. These include standard contractual clauses approved by the EU Commission, or other arrangements, as applicable in specific countries, and other safeguards as may be appropriate. We may also transfer data to countries with an adequate level of personal data protection based on decisions adopted by competent authorities, such as the adequacy decisions adopted by the European Commission or approved in accordance with the UK GDPR.

See a list of countries for which the European Commission has issued an adequacy decision here.

A list of countries approved in accordance with the UK GDPR is available here (The UK approach to international data transfers - GOV.UK).

A copy of the relevant mechanism can be obtained for your review on request by using the contact details below.

6. What are your rights and how to exercise them

You have the following rights:

Right Summary
The right of access Enables you to receive a copy of your personal data
The right to rectification Enables you to correct any inaccurate or incomplete personal data we hold about you
The right to erasure Enables you to ask us to delete your personal data in certain circumstances
The right to restrict processing Enables you to ask us to halt the processing of your personal data in certain circumstances
The right to object Enables you to object to us processing your personal data on the basis of our legitimate interests (or those of a third party), including processing for direct marketing purposes or profiling for purposes of direct marketing, or where we are performing a task in the public interest. Your objection will be upheld, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for the exercise or defence of legal claims that may be brought by or against us.
The right to data portability Enables you to request us to transmit personal data that you have provided to us to a third party without hindrance, or to give you a copy of the data so that you can transmit it to a third party, where technically feasible.
[FRANCE ONLY] The right to instruct us regarding the use of your personal data after your death [FRANCE ONLY] Enables you to instruct us on the processing (retention, deletion, and disclosure) of your personal data after your death. You can change or revoke such instructions at any time.
The right to complain to the data controller (available only in the UK) Enables you to complain whenever you believe that we handled your personal data in a manner infringing data protection legislation. We acknowledge complaints within 30 days.

These rights may be limited, for example, if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.

If you wish to exercise any of these rights, please contact us at the contact details set out below.

We may need to request specific information from you to help us confirm your identity.

Wherever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. We may, however, have other legal grounds for processing your data for other purposes, such as those set out above.

In some cases, we may send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt out of direct marketing or profiling at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below.

We do not make solely automated decisions that produce legal or similarly significant effects on individuals without human review.

If you have unresolved concerns, you have the right to make a complaint to the data protection authority in the country that you reside in or, the country of your place of work or the country where the alleged infringement took place.

A list of authorities in the EEA can be found here: https://www.edpb.europa.eu/about-edpb/our-members_en

In the UK, this will be the Information Commissioner; details can be found here: Make a complaint | ICO

For information on how to exercise your right to do this, please see contact details below.

Providing data necessary to perform our contractual and legal obligations (such as Identity Data, Contact Data, Financial Data and Service-related Data) is mandatory. If you refuse to provide us with this information when requested, we will not be able to provide you our services (perform our contractual obligations) or perform our legal obligations.

Provision of all other data is optional and does not affect our provision of services to you.

7. How long we retain your personal data

While provisions of law may vary between jurisdictions, we have taken reasonable steps to ensure that your personal data are treated by our portfolio companies and service providers in a secure and lawful manner.

We retain personal data for as long as we have a relationship with you and for a period after our relationship has ended. We will store your personal data for no longer than is necessary for the performance of our obligations (e.g., in the UK this is seven years after engagement ends (minimum statutory period)) or for achieving the purposes for which the data were collected, or as may be permitted under applicable law. If we have a contract with you, your personal data will be retained for the duration of your contract and for an appropriate duration after it terminates in your country, to protect us from any legal claim.

To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm resulting from unauthorised use or disclosure; the purposes for which we originally collected and processed the data, the lawful grounds on which we based our processing and whether we can achieve those purposes by other means, and the applicable legal requirements and the requirements of our business and the services provided. Unless otherwise required by applicable law, we will remove personal data from our systems and records or take appropriate steps to properly anonymise them at the end of the retention period.

Where we process personal data for marketing purposes or with your consent, we process the data until you withdraw the consent. We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in the future.

8. Data security

To protect your personal data held with us and our service providers, we use appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, secure servers, and restricted access to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those who have a business need to know.

We are not responsible for the privacy practices of third-party sites to which our sites contain links.

9. Updates to this privacy notice

We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal data.

10. Contact us

The controller of your personal data is Multiplier Holdings and portfolio companies listed here: https://www.multiplierholdings.com/portfolio.

If you have questions about this notice or wish to contact us for any reason in relation to our personal data processing, please contact us at info@multiplierholdings.com.