About Multiplier Holdings
Multiplier is a technology company that owns professional services firms and builds custom AI technology across them.
Multiplier portfolio companies provide professional services to clients across accounting, finance, tax and advisory.
We use client information and work products, which may contain personal data, to provide our services. We may also use this information to develop, train and evaluate our AI tools that help our professionals deliver more accurate, efficient and useful services. Our revenue comes from the professional services we provide to clients. We do not sell personal data.
This policy explains what personal data we collect as controllers, how it is used, who it is shared with, and the rights available to you.
Summary of how we use your data
- Multiplier Holdings and its portfolio companies (also referred to as “Multiplier”, "we" or "us"), use your personal data to perform contractual and legal obligations, in particular to provide you or the organisation you represent with professional services such as tax, accounting and advisory services.
- We share the data with our portfolio companies, regulators and authorities, and our third-party service providers. Due to the global nature of our business, your personal data may be transferred outside the country of your residence, in particular outside of the UK/EEA. Where these locations do not provide an appropriate level of data protection, we ensure appropriate safeguards are in place.
What does this notice cover?
We are committed to making our privacy practices transparent and fair. This policy describes how Multiplier Holdings and its portfolio companies will process your data, when you use our websites and services such as our Multiplier Apps (“Apps”) and professional services, in particular when we provide you tax, accounting and advisory services as an individual or as an organisation, or if you represent such client.
We may also process personal data on behalf of our clients, e.g. if we provide our corporate client with payroll services or with our App services, we process data of their users, employees and other individuals whose data are in the materials we obtain as data processors. If that is the case, our client is the data controller responsible for providing you with appropriate notice, and this notice does not apply to you.
The notice also describes your data protection rights, including the right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “What are your rights and how to exercise them” section.
Content
1. Personal data we may collect about you
2. How do we use your personal data, and what is the legal basis for this use?
3. How do we use cookies and similar technologies?
4. How we share your personal data
5. Where we transfer your personal data
6. What are your rights and how to exercise them
7. How long we retain your personal data
8. Data security
9. Updates to this privacy notice
10. Contact us
1. Personal data we may collect about you
We collect and process personal data about you when you interact with us and our websites, and when you purchase services from us. This includes:
| Category |
Details |
| Identity Data |
Data that enables us to identify and verify you such as name, title, job role, identifiers (such as passport/ID number, insurance number, login) (hashed) passwords, name of the company (your business/employer), country of residence, anti-money laundering and electronic identity verification information. |
| Contact Data |
Data enabling us to contact you such as (private or processional) email address, telephone number, postal address. |
| Demographic Data |
Data such as date of birth, marital status, spouse and dependents, occupation, city of residence. |
| Service-related Data |
Details of any services you have received from us such as company records, tax and accounting documentation, R&D tax credit details, or payroll and employment-related data, pensions, salaries, real estate, information from competent authorities, information required to prepare relevant tax and accounting documentation. |
| Financial Data |
Financial and banking information such as bank account details, payment records, amount on invoices, tax identifiers, credit card details. |
| Marketing Data |
Your marketing preferences for receiving e.g. updates, newsletters, event invitations, including any consents you have given us. |
| Technical Data |
Information related to the browser or device you use to access our website such as IP address, operating system, browser version, locale and language settings used, the cookies and similar technologies used on such device, and the activity (clicks and other interactions) on our websites. |
| Correspondence Data |
Our correspondence and communications with you, including complaints, opinions and enquiries you make to us. |
We may process special categories of data in limited circumstances, such as when it is necessary to perform our legal or regulatory obligations and processing is necessary for reasons of substantial public interest, on the basis of EU or Member State law (e.g. PEP status for AML purpose) (“Special Category Data”).
It is important that the personal data we hold about you is accurate and current. Should your personal data change, please notify us of any changes of which we need to be made aware by contacting us, using the contact details below.
We collect personal data directly from you when you: (i) request a proposal from us in respect of the services we provide, (ii) engage us to provide our services and also during the provision of those services, (iv) contact us by phone, email, post, or through our website forms;
Indirectly we may obtain most categories of your data from:
- your organisation
- your spouse, partner or authorised representative
- our portfolio companies
- public authorities (e.g. tax authorities)
- publicly available sources (e.g. public registers)
- business partners, other professional advisers or service providers, and using tools and channels commonly used to connect between companies and individuals to explore potential business and employment opportunities, such as LinkedIn we may receive your contact and professional details (e.g., your name, company, position, contact details and professional experience, preferences and interests)
- event organisers if you participate in an event or webinar that we sponsor
- electronic identity verification providers
- other third parties (for example banks, pension providers or investment managers) where authorised by you.
We may also obtain your data automatically through cookies and similar technologies when you browse our websites.
2. How do we use your personal data, and what is the legal basis for this use?
We will only use your personal data for the purposes and legal bases set out below:
| Purpose |
Legal Basis |
|
We will collect, use and store your Identity Data, Contact Data and
Technical Data to register and create an account on our website,
particularly in the App, and to provide you with related services.
We will collect, use and store your Identity Data, Contact Data,
Financial Data and Service-Related Data to provide you with our
professional services such as tax, accounting or advisory services.
We will communicate with you in relation to the services via general
or personalised service-related messages (such as purchase
confirmations or system maintenance notices, notices about changes
to our services) or to organise meetings with you.
In providing our services, we use new technologies such as machine
learning and generative artificial intelligence, which assist us in
providing services, in particular with document processing, data
extraction and analysis, and the generation of drafts and summaries;
however, outputs are reviewed by a qualified staff member.
|
It is necessary for us to process your personal data to perform our
contract with you, or to take steps at your request prior to
entering into a contract with you.
We have a legitimate interest in providing services to our clients,
including collecting customer feedback.
|
|
We will collect and use your Identity Data, Contact Data and
Financial Data to verify your identity.
|
We have a legitimate interest in ensuring the security of our services
and data.
|
|
We will collect, use and store your Identity Data, Contact Data and
Correspondence Data to manage our relationship with you (e.g.,
respond to your non-services related enquiries, seek your customer
feedback).
|
We have a legitimate interest in managing our business and providing
services to our clients, including collecting customer feedback.
|
|
We will use, store and share your All Data Categories to perform our
legal, regulatory and professional obligations, and to comply with
internal policies and procedures and codes of conduct.
|
We have legal obligations under relevant laws such as tax and
accounting laws, AML laws, data protection laws. The processing is
necessary for reasons of substantial public interest, on the basis of
EU or Member State law.
|
|
We will also use, store and share All Data Categories to pursue
potential legal claims or defend ourselves against potential legal,
regulatory or professional claims.
|
We have a legitimate interest in ensuring internal compliance,
reporting to professional bodies or authorities and to pursue or
defend against claims.
|
|
We will collect and analyse your All Data Categories to monitor
customer accounts to prevent, investigate and/or report misuse of our
services, fraud, terrorism, misrepresentation, security incidents or
crime, in accordance with applicable law.
|
We have a legal obligation under relevant criminal, tax and
cybersecurity laws.
We have a legitimate interest in preventing and detecting fraud,
or other wrongdoing.
UK only: where it is necessary to process personal data to prevent,
detect, or investigate a crime, we rely on our recognised legitimate
interests.
|
|
We will collect and use Identity Data, Contact Data, Marketing Data,
Service-Related Data and Technical Data to send you direct marketing
in relation to our relevant products and services, or other products
and services provided by us, our portfolio companies.
|
Depending on the country, it may be:
Your consent. Whenever we ask for your consent, we will explain why
and how we will use your data, so your consent can be informed.
We have a legitimate interest in promoting our services to our
clients.
|
|
We will collect and use your Identity Data, Contact Data, Technical
Data, Marketing Data and Service-Related Data to send you personalised
adverts for our relevant services or other services provided by us,
our portfolio companies and carefully selected partners.
|
Your consent when we rely on cookies. Whenever we ask for your
consent, we will explain why and how we will use your data, so that
you can give your consent in full knowledge of the facts.
|
|
We will collect, analyse and store Identity Data, Contact Data,
Service-Related Data and Technical Data to manage and operate and
customise our websites and services, including carrying out data
analytics to keep them updated and relevant, to improve our business,
your user experience and to inform our marketing strategy.
|
Your consent when we rely on cookies. Whenever we ask for your
consent, we will explain why and how we will use your data, so your
consent can be informed.
We have a legitimate interest in operating our services and
improving their operation (when we do not use cookies for such
processing).
|
|
We will collect and store Identity Data and Financial Data to
facilitate, process payment for services and maintain financial
records.
|
It is necessary for us to process your personal data to perform our
contract with you.
We have a legal obligation under relevant tax and accounting laws.
|
|
We will collect, use and analyze your Identity Data, Contact Data,
Service-Related, Technical Data and Financial Data to improve and
develop our services, and the technology and tools we use to provide
them, in particular to develop, train, test and improve, where needed,
the artificial intelligence or machine learning models we use to
deliver and enhance our services (for instance, for document
extraction, error detection, drafting, quality assurance etc) and
improving the technology we use to provide and improve our services.
|
We have a legitimate interest in developing and improving our services.
|
Where we process personal data on the basis of a legitimate interest, then – as required by data protection law we carry out a documented balancing test weighing our interests against the potential impact on individuals. In the UK, we do not need to conduct this test for ‘recognised legitimate interests’. You can request more information about this balancing test by using the contact details at the end of the notice.
3. How do we use cookies and similar technologies?
When you visit our websites or interact with us, we may use tools to store data on your devices or access data already stored on such devices, such as cookies, web beacons, pixels, tags, plug-ins, or, in the case of the app, software development kits (SDKs) or other similar technologies (collectively, “cookies”). We use cookies in accordance with the applicable legal requirements. For more information, please see our cookie policy on our website.
4. How we share your personal data
We may share your data with the following categories of recipients:
| Personal Data Category |
Category of Recipient |
Why? |
| All Data Categories |
Our portfolio companies |
To operate our business, including IT, technical and engineering
support.
To improve and develop the services, technology and tools that
portfolio companies use to provide their services, and, in
particular, we may share data with Multiplier Holdings for
developing, training, testing and improving the proprietary
artificial intelligence and machine learning models that portfolio
companies use to deliver and enhance their services. For more
information click here.
As part of international engagements, where professional expertise
from other portfolio companies is required or desirable to provide
our services.
|
|
Varies by provider — All Data Categories for infrastructure providers;
additionally Identity, Contact, Service-related, Financial,
Correspondence, Marketing and Special Category Data where relevant
for service-specific providers such as AI systems, CRM and email
platforms
|
Technology and service providers (IT, cloud, hosting, cybersecurity,
AI systems, CRM, email, marketing, analytics, session recording,
administration services)
|
To host, maintain and secure our App; to deliver, analyse and improve
our services; to manage client communications and marketing
activities.
|
|
Identity, Contact, Demographic, Service-related, Financial,
Correspondence, and Special Category where relevant
|
Professional delivery partners (subcontractors, consultants, KYC and
identity verification providers, financial services providers,
appointed alternates)
|
We employ other companies and individuals to deliver professional
services under the same professional and ethical obligations, to
verify identity and comply with AML obligations, to process payments,
among others.
|
|
Identity, Contact, Demographic, Service-related, Financial,
Correspondence, Special Category where relevant.
|
Regulators and authorities, third parties you require us to
correspond with
|
Where it is necessary to administer the relationship between us
(for example, to submit your tax return to the relevant tax
authorities in the jurisdictions where you are filing)
Sometimes you ask us to correspond with certain entities for your
convenience, for example finance providers, pension providers
(including auto-enrolment), investment brokers, new advisors.
|
|
Identity, Contact, Service-related, Financial, Correspondence.
Special Category only where a specific matter requires it.
|
Insurers (incl. professional indemnity insurers), auditors, external
quality reviewers, business, legal, financial and compliance advisors
|
To ensure compliance of our business with the provisions of law and
with industry requirements.
|
|
Identity, Contact, Demographic, Service-related, Financial,
Correspondence, Technical (for cybercrime matters), Special Category
where legally required.
|
Regulators and competent authorities (including police and law
enforcement agencies), courts, tribunals and professional bodies
|
To perform our legal and regulatory obligations, comply with a
subpoena, search warrant or court order, comply with codes of
conduct of professional bodies, or prevent, investigate and/or
report misuse of our services, fraud, terrorism, misrepresentation,
security incidents or crime, in accordance with applicable law.
Such disclosure or access may occur with or without notice to you,
if we have a good faith belief that we are legally compelled to do
so, or that disclosure is appropriate in connection with efforts to
investigate, prevent, or take action regarding actual or suspected
illegal activity, fraud, or other wrongdoing.
|
| All Data Categories |
Prospective Buyer/Seller or entities related to selling and
restructuring of business
|
If the business is sold, integrated with another business or
restructured, your details may be disclosed to our advisors and any
prospective purchaser’s adviser and will be passed to the new owners
of the business.
|
We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality, security standards and obligations.
5. Where we transfer your personal data
Personal data that we collect from you may be transferred to and stored at a destination outside your place of residence, including outside the EEA/UK. Due to the global nature of our business, your personal data will be disclosed to our portfolio companies, based on an intragroup data processing agreement, in Hong Kong, the USA and Singapore. We may also share personal data to other portfolio companies as part of international engagements, and where required or desirable to meet our legal and regulatory obligations around the world.
All our personal data transfers are compliant with applicable data protection laws. The agreements we have in place with our portfolio companies and with our third-party service providers include appropriate safeguards to ensure that data flows are safe and that individuals can exercise their data protection rights. These include standard contractual clauses approved by the EU Commission, or other arrangements, as applicable in specific countries, and other safeguards as may be appropriate. We may also transfer data to countries with an adequate level of personal data protection based on decisions adopted by competent authorities, such as the adequacy decisions adopted by the European Commission or approved in accordance with the UK GDPR.
See a list of countries for which the European Commission has issued an adequacy decision here.
A list of countries approved in accordance with the UK GDPR is available here (The UK approach to international data transfers - GOV.UK).
A copy of the relevant mechanism can be obtained for your review on request by using the contact details below.
6. What are your rights and how to exercise them
You have the following rights:
| Right |
Summary |
| The right of access |
Enables you to receive a copy of your personal data
|
| The right to rectification |
Enables you to correct any inaccurate or incomplete personal data we
hold about you
|
| The right to erasure |
Enables you to ask us to delete your personal data in certain
circumstances
|
| The right to restrict processing |
Enables you to ask us to halt the processing of your personal data
in certain circumstances
|
| The right to object |
Enables you to object to us processing your personal data on the basis
of our legitimate interests (or those of a third party), including
processing for direct marketing purposes or profiling for purposes
of direct marketing, or where we are performing a task in the public
interest. Your objection will be upheld, and we will cease processing
your personal data, unless the processing is based on compelling
legitimate grounds or is needed for the exercise or defence of legal
claims that may be brought by or against us.
|
| The right to data portability |
Enables you to request us to transmit personal data that you have
provided to us to a third party without hindrance, or to give you a
copy of the data so that you can transmit it to a third party, where
technically feasible.
|
|
[FRANCE ONLY] The right to instruct us regarding the use of your
personal data after your death
|
[FRANCE ONLY] Enables you to instruct us on the processing
(retention, deletion, and disclosure) of your personal data after
your death. You can change or revoke such instructions at any time.
|
|
The right to complain to the data controller (available only in the
UK)
|
Enables you to complain whenever you believe that we handled your
personal data in a manner infringing data protection legislation.
We acknowledge complaints within 30 days.
|
These rights may be limited, for example, if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
If you wish to exercise any of these rights, please contact us at the contact details set out below.
We may need to request specific information from you to help us confirm your identity.
Wherever we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. We may, however, have other legal grounds for processing your data for other purposes, such as those set out above.
In some cases, we may send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt out of direct marketing or profiling at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below.
We do not make solely automated decisions that produce legal or similarly significant effects on individuals without human review.
If you have unresolved concerns, you have the right to make a complaint to the data protection authority in the country that you reside in or, the country of your place of work or the country where the alleged infringement took place.
A list of authorities in the EEA can be found here: https://www.edpb.europa.eu/about-edpb/our-members_en
In the UK, this will be the Information Commissioner; details can be found here: Make a complaint | ICO
For information on how to exercise your right to do this, please see contact details below.
Providing data necessary to perform our contractual and legal obligations (such as Identity Data, Contact Data, Financial Data and Service-related Data) is mandatory. If you refuse to provide us with this information when requested, we will not be able to provide you our services (perform our contractual obligations) or perform our legal obligations.
Provision of all other data is optional and does not affect our provision of services to you.
7. How long we retain your personal data
While provisions of law may vary between jurisdictions, we have taken reasonable steps to ensure that your personal data are treated by our portfolio companies and service providers in a secure and lawful manner.
We retain personal data for as long as we have a relationship with you and for a period after our relationship has ended. We will store your personal data for no longer than is necessary for the performance of our obligations (e.g., in the UK this is seven years after engagement ends (minimum statutory period)) or for achieving the purposes for which the data were collected, or as may be permitted under applicable law. If we have a contract with you, your personal data will be retained for the duration of your contract and for an appropriate duration after it terminates in your country, to protect us from any legal claim.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm resulting from unauthorised use or disclosure; the purposes for which we originally collected and processed the data, the lawful grounds on which we based our processing and whether we can achieve those purposes by other means, and the applicable legal requirements and the requirements of our business and the services provided. Unless otherwise required by applicable law, we will remove personal data from our systems and records or take appropriate steps to properly anonymise them at the end of the retention period.
Where we process personal data for marketing purposes or with your consent, we process the data until you withdraw the consent. We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in the future.
8. Data security
To protect your personal data held with us and our service providers, we use appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption, secure servers, and restricted access to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those who have a business need to know.
We are not responsible for the privacy practices of third-party sites to which our sites contain links.
9. Updates to this privacy notice
We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal data.
The controller of your personal data is Multiplier Holdings and portfolio companies listed here: https://www.multiplierholdings.com/portfolio.
If you have questions about this notice or wish to contact us for any reason in relation to our personal data processing, please contact us at info@multiplierholdings.com.