Privacy policy.

Privacy Policy

Effective Date: August 2026.

‍ ‍

1. Who we are

This Privacy Policy explains how we collect, use, store and protect personal information when you interact with Third FD or use our services.

Third FD is a trading name of Freepaper Ltd, a company registered in England and Wales under company number 13832942.

Registered office:
31 Market Place
Chippenham
SN15 3HP

Privacy contact:ben@thirdfd.com

Freepaper Ltd is the data controller for personal information that we process for our own business purposes, including providing our services, managing client relationships, complying with our legal and regulatory obligations and operating our business.

Where we process personal information on behalf of a client as part of a particular service, our role may instead be that of a data processor. The applicable responsibilities will depend on the nature of the service and the arrangements with the client.

‍ ‍

2. Personal information we collect

‍The information we collect depends on how you interact with us and the services we provide.

This may include:

  • your name and contact details;

  • your job title and organisation;

  • business and company information;

  • information provided when you enquire about our services;

  • information contained in correspondence and communications with us;

  • financial and accounting information required to provide our services;

  • information contained in accounting records, invoices, expenses and other financial documents;

  • information relating to employees, directors, trustees, contractors or other individuals where this information is contained in records provided to us by a client;

  • information required to carry out identity and anti-money laundering checks;

  • information relating to beneficial ownership and business structure;

  • information relating to our contractual and commercial relationship with you;

  • information relating to invoices and payments;

  • information about your preferences, including marketing preferences; and

  • technical information relating to your use of our website, including information collected through cookies and similar technologies.

‍We may also process information that you provide to us about other people. If you provide us with personal information relating to another individual, you should ensure that you are authorised to provide that information and, where appropriate, that the individual has been informed that their information is being shared with us.

‍ Some information contained within accounting, payroll or other business records may constitute special category personal data or criminal offence data. Where this occurs, we will only process such information where there is an appropriate legal basis and, where required, an applicable additional condition under data protection law.

3. Where we obtain personal information

‍ We may obtain personal information:

  • directly from you;

  • from your organisation or from individuals authorised to act on its behalf;

  • from prospective or existing clients;

  • from information and documents provided to us in connection with our services;

  • from third-party service providers where necessary to provide our services;

  • from publicly available sources, where appropriate;

  • as part of our anti-money laundering and identity verification checks; and

  • automatically when you use our website, subject to our cookie and tracking arrangements.

‍ ‍

‍ ‍4. How we use personal information

‍ ‍We use personal information where necessary to:

  • ‍ provide bookkeeping, accounting, management accounting, financial planning and fractional finance services;

  • manage and administer our client relationships;

  • communicate with clients and prospective clients;

  • prepare proposals and engagement documentation;

  • administer contracts and provide services;

  • prepare invoices and manage payments;

  • maintain appropriate accounting and business records;

  • prepare and administer payments on behalf of clients in accordance with their instructions and approval procedures;

  • comply with legal, regulatory and professional obligations;

  • carry out customer due diligence, identity verification and anti-money laundering checks;

  • protect our business, systems and information from fraud, misuse and security threats;

  • manage our website and understand how visitors use it;

  • improve our services and business processes;

  • respond to enquiries and requests;

  • establish, exercise or defend legal claims; and

  • send relevant marketing communications where permitted by law.

‍We will not use personal information for purposes that are incompatible with the purposes described in this Privacy Policy unless we are permitted or required to do so by law.

5. Our lawful bases for processing

‍Data protection law requires us to have a lawful basis for processing personal information. Depending on the circumstances, we rely on one or more of the following lawful bases:

Purpose - Typical lawful basis

  1. Providing our services and managing our contractual relationship - Performance of a contract

  2. Taking steps at your request before entering into a contract - Steps necessary to enter into a contract

  3. Managing communications and our client relationships - Contract and/or legitimate interests

  4. Maintaining appropriate business and financial records - Legal obligation and/or legitimate interests

  5. Carrying out anti-money laundering and identity checks - Legal obligation

  6. Protecting our systems, information and business - Legitimate interests and/or legal obligation

  7. Responding to enquiries and developing prospective client relationships - Legitimate interests and/or steps necessary to enter into a contract

  8. Website analytics and similar technologies - See our Cookies and Website Analytics section below

  9. Direct marketing - Consent or legitimate interests, where permitted by law

  10. Establishing, exercising or defending legal claims - Legitimate interests and/or legal obligation

‍ ‍

Where we rely on legitimate interests, we will consider whether those interests are appropriate and whether they are overridden by the rights and interests of the individual concerned.

6. Anti-money laundering and identity checks

‍As an accountancy and financial services business, we are required to comply with applicable anti-money laundering and related regulatory requirements.

‍ This may require us to collect and process information such as:

  • identity documents;

  • dates of birth;

  • residential addresses;

  • information about directors, trustees and beneficial owners;

  • information about ownership and control of organisations;

  • risk assessments;

  • information obtained during customer due diligence; and

  • records of our anti-money laundering checks and decisions

We process this information to comply with our legal and regulatory obligations and to help prevent money laundering, terrorist financing and related financial crime.

We may be required to retain records relating to customer due diligence for five years from the end of a business relationship or completion of a transaction, as applicable.

‍ ‍

7. Sharing personal information

‍We do not sell or rent personal information. We may share personal information where necessary with trusted third parties and service providers that support our business or help us provide our services.

These may include:

  • accounting and financial software providers, including Xero;

  • email, document storage and collaboration providers, including Microsoft 365;

  • client relationship, workflow and project management software providers, including Karbon;

  • specialist payroll providers where payroll services are outsourced;

  • specialist payment and banking platforms, including Telleroo, to prepare and initiate payments on behalf of clients. Payments are subject to the client's instructions and authorisation procedures. Telleroo may process personal information relating to payees and payment transactions in accordance with the applicable contractual and data protection arrangements;

  • IT, cybersecurity and technical support providers;

  • professional advisers, insurers and other business service providers;

  • banks and financial institutions where necessary;

  • government bodies, regulators and law enforcement agencies where required or permitted by law; and

  • other service providers where necessary to provide the services requested by you.

Where appropriate, we require service providers that process personal information on our behalf to enter into appropriate contractual arrangements and to implement suitable security measures.

Where payroll services are outsourced to a specialist payroll bureau, the relevant client will be informed that the service is being provided by a third party.

‍ ‍

8. International transfers

‍ Some of the technology and service providers we use may process personal information outside the United Kingdom.

‍ Where personal information is transferred outside the UK, we will ensure that the transfer is permitted under applicable data protection law and that appropriate safeguards are in place where required.

‍ This may include relying on UK adequacy regulations or appropriate contractual safeguards, depending on the circumstances.

‍ We do not state that all personal information is stored exclusively in the UK because this depends on the services and providers we use.

‍ ‍

‍ ‍9. Generative artificial intelligence

‍ We may use generative artificial intelligence tools to assist with certain administrative, analytical, research, drafting and other business activities. We currently use generative AI tools including ChatGPT and Claude.

‍Our policy is that identifiable client personal information should not be entered into these tools. Where information derived from client work is used with a generative AI tool, we take steps to anonymise or pseudonymise the information so that individuals are not identifiable.

‍We recognise that simply removing a person's name does not necessarily make information anonymous. Information may remain personal data if an individual could reasonably be identified from the remaining information.

‍We therefore take care when preparing information for use with generative AI tools and aim to remove or generalise or pseudonymise identifying information wherever appropriate.

‍We do not intentionally use generative AI tools to make solely automated decisions about individuals that produce legal or similarly significant effects.

‍ We keep our use of technology and generative AI under review and may update this Privacy Policy if our use changes materially.

‍ ‍

‍ ‍10. How long we keep personal information

‍We retain personal information only for as long as it is necessary for the purposes for which it was collected, including where necessary to meet legal, accounting, tax, regulatory and professional obligations or to establish, exercise or defend legal claims.

As a general guide:

  • client accounting and financial records will normally be retained for six years, or longer where required or justified by applicable legal, regulatory or professional requirements;

  • records relating to our contractual relationship with clients will normally be retained for six years after the end of the relationship;

  • anti-money laundering and customer due diligence records will normally be retained for five years from the end of the business relationship or completion of the relevant transaction, as applicable;

  • information relating to unsuccessful prospective client enquiries will normally be retained for 12 months, unless there is a reason to retain it for longer;

  • marketing information will be retained for as long as necessary for the relevant marketing purpose and in accordance with applicable marketing and data protection requirements; and

  • website analytics and cookie information will be retained in accordance with the configuration and retention settings of the relevant technologies.

These are general retention periods. Specific information may be retained for a longer period where this is necessary to comply with a legal or regulatory requirement or to establish, exercise or defend legal claims.

‍ We periodically review information that we hold and delete or anonymise information when it is no longer required.

‍ ‍11. Cookies and website analytics

‍Our website uses cookies and similar technologies to operate the website, understand how visitors use it and improve our website and services.

‍We use Google Analytics to collect statistical information about how visitors use our website. Google Analytics is only activated where permitted under applicable law and, where consent is required, only after you have given consent through our cookie banner.

‍Our cookie banner allows you to:

  • accept or reject non-essential cookies;

  • manage your cookie preferences; and

  • change or withdraw your preferences at any time.

‍For more information about the cookies and similar technologies used on our website, and to manage your preferences, please use the cookie settings available on our website.

‍ ‍

‍ ‍12. Marketing

‍We may contact existing and prospective clients or business contacts about our services where permitted by applicable law.

‍Where we process personal information for direct marketing, we will comply with applicable data protection and electronic marketing laws, including the Privacy and Electronic Communications Regulations (PECR).

‍You have the right to object to the use of your personal information for direct marketing at any time.

‍You can opt out of marketing communications by contacting us at ben@thirdfd.com or by using any unsubscribe facility provided in a marketing communication.

‍If you object to direct marketing, we will stop using your personal information for that purpose, subject to any limited circumstances where we are legally required to retain information for another purpose.

‍ ‍

‍ ‍13. Information security

‍We take reasonable and appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

‍These measures include appropriate access controls, secure systems and services, confidentiality arrangements and measures designed to protect the security of our information and technology environment.

‍No method of transmitting or storing information is completely secure. However, we take reasonable steps to protect the personal information entrusted to us.

‍ ‍

‍ ‍14. Your data protection rights

‍Depending on the circumstances, you may have rights under UK data protection law including:

  • the right to be informed about how your personal information is used;

  • the right to access personal information we hold about you;

  • the right to have inaccurate personal information corrected;

  • the right to have personal information erased in certain circumstances;

  • the right to restrict processing in certain circumstances;

  • the right to data portability in certain circumstances;

  • the right to object to certain processing, including direct marketing; and

  • the right to withdraw consent where we rely on consent as our lawful basis.

‍ These rights are subject to certain exceptions and are not all absolute.

‍ To exercise your rights, please contact ben@thirdfd.com. We may need to verify your identity before responding to your request.

‍ We will normally respond to valid data protection requests without undue delay and within the applicable statutory time limit.

‍ ‍15. Complaints

‍If you have concerns about how we have handled your personal information, please contact us first at: ben@thirdfd.com

‍ We will try to resolve your concern.

‍You also have the right to complain to the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.

‍Information about making a complaint is available on the ICO's website.

‍ ‍

16. Changes to this Privacy Policy

‍We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal or regulatory requirements, or how we process personal information.

‍The latest version will be published on our website with the date of the most recent update.

Last updated: August 2026

‍ ‍

Contact

‍If you have any questions about this Privacy Policy or how Third FD handles personal information, please contact:

Freepaper Ltd trading as Third FD
31 Market Place
Chippenham
SN15 3HP

Email:ben@thirdfd.com

‍ ‍

‍ ‍