Privacy Notice
Last updated: June 2026
PRIVACY SUMMARY
Rory Williams Limited (trading as Rory Williams Chartered Accountants) is committed to protecting your personal information by processing it responsibly and safeguarding it using appropriate technical, administrative and physical security measures.
This privacy notice explains what information we gather about you, what we use that information for, who we share it with, how long we keep it, and what your rights are. It also explains how we use cookies and similar technologies on our website.
If you have any questions about this notice or how we handle your personal data, please contact us using the details in section 13.
CONTENTS
1. Who we are and how to contact us
2. Who this privacy notice applies to and what it covers
3. Links to third party websites
4. What information we collect
5. Information provided by or about third parties
6. How we use information about you
7. The legal grounds we use for processing personal data
8. Cookies and tracking technologies
9. Sharing your personal data
10. Transferring your personal data outside Ireland
11. Protection of your personal data
12. How long we keep your information for
13. Your rights
14. Sending you marketing information
15. Right to complain
16. Changes to this privacy notice
PRIVACY NOTICE
In this notice, "Data Protection Legislation" means the EU General Data Protection Regulation 2016/679 (GDPR), the Irish Data Protection Act 2018, and all other applicable legislation relating to privacy or data protection as may be in force from time to time.
1. WHO WE ARE AND HOW TO CONTACT US
1.1 The data controller responsible for your personal data is:
Rory Williams Limited
Trading as Rory Williams Chartered Accountants
20 Harcourt Street
Dublin 2
D02 H364
Ireland
Registered in Ireland: Company Number 629179
Director : Rory Williams
1.2 Our Data Protection contact is:
Rory Williams
Email:
Phone: 01 255 2400
You can contact our Data Protection contact with any questions, concerns or requests relating to your personal data.
2. WHO THIS PRIVACY NOTICE APPLIES TO AND WHAT IT COVERS
2.1 This privacy notice applies to all individuals whose personal data we process, including:
(a) existing and prospective clients and their employees, officers and beneficial owners;
(b) visitors to our website at rwca.ie; and
(c) any other individuals whose personal data we receive in connection with the operation of our business.
2.2 We are committed to protecting your personal data and processing it in an open and transparent manner in compliance with our obligations under Data Protection Legislation.
2.3 When we refer to "our Website" or "this Website" we mean the webpages located at rwca.ie and any subpages thereof.
2.4 In this privacy notice your information is sometimes called "personal data". References to "processing" include collecting, recording, storing, using, sharing, transferring and deleting personal data.
3. LINKS TO THIRD PARTY WEBSITES
3.1 Our Website may include links to third party websites which are not governed by this privacy notice. We are not responsible for the privacy practices of those websites and encourage you to review the privacy notices on each of those websites before disclosing any personal data.
4. WHAT INFORMATION WE COLLECT
4.1 We may collect, record and use information about you in physical and electronic form and will hold, use and otherwise process that data in accordance with Data Protection Legislation and as set out in this notice.
4.2 We may collect or obtain personal data about you:
(a) because you provide it to us directly (for example, via a form on our Website, by email, by telephone or at a meeting);
(b) because other people give it to us (for example, your employer, adviser or a third party service provider we use to help operate our business); or
(c) because it is publicly available or because we observe or infer it from the way you interact with us or our Website (for example, through the use of cookies and analytics tools — see section 8 below).
4.3 The personal data we may collect or obtain includes:
(a) identity data: your name, gender, age and date of birth;
(b) contact data: postal address, email address and telephone number;
(c) country of residence;
(d) lifestyle and social circumstances (for example, pastimes, marital status and dependants);
(e) employment and education details (for example, organisation, job title and education history);
(f) Government identifiers (for example, Personal Public Service Number (PPSN), passport number, driver's licence number);
(g) financial and tax-related information (for example, income, investments, tax residency and bank details);
(h) technical data: IP address, browser type and language,access times, pages visited, referring URLs; and
(i) usage data: details of how you use our Website, products and services.
4.4 We may also collect special categories of personal data where relevant to the services we provide, including:
(a) dietary requirements (for example, where we provide lunch during a meeting);
(b) health information (for example, to make reasonable accommodations at our office or events); and
(c) information about racial or ethnic origin, where relevant to a specific service or engagement.
We will only process special categories of data where we have a lawful basis to do so under Article 9 GDPR - see section 7.2 below.
4.5 If you fail to provide us with personal data that we require, or you object to our processing it, we may be unable to process your instructions or to provide all or some of our services to you.
5. INFORMATION PROVIDED BY OR ABOUT THIRD PARTIES
5.1 Where a client or other third party provides us with personal data about you, we take steps to ensure that they have complied with applicable data protection law before doing so (including, where necessary, having given you appropriate notice and obtained any required consent).
5.2 Where you provide us with personal data about third parties (such as a spouse, financial dependant, joint account holder or beneficiary), by providing that information you confirm that you have obtained any necessary consent from those individuals, or are otherwise permitted to share their information with us.
6. HOW WE USE INFORMATION ABOUT YOU
6.1 To provide our services
We use your personal data to provide accountancy, tax, audit and related advisory services to you and our clients.
This includes:
(a) providing advice, completing tax returns and conducting audits or similar activities;
(b) conducting due diligence and know-your-client checks;
(c) corresponding with you, your employer, advisers, third-party service providers or competent authorities in connection with those services; and
(d) managing our client relationships and engagements.
6.2 For the operation of our business
We may also use your personal data for:
(a) compliance with applicable legal, regulatory or professional requirements (including anti-money laundering obligations);
(b) responding to requests and communications from competent authorities;
(c) client account administration and onboarding;
(d) financial accounting, invoicing and risk analysis;
(e) sending you insights, updates, reports or details of our services that we think may be of interest to you (see section 14 on marketing);
(f) inviting you to events, seminars or briefings;
(g) recruitment and business development (for example, using client testimonials in promotional materials, with the individual's permission); and
(h) protecting our rights and those of our clients.
6.3 For our Website
In connection with your use of our Website, we may use your personal data to:
(a) manage, maintain and improve our Website;
(b) personalise your experience on our Website;
(c) manage and respond to enquiries submitted through our Website; and
(d) conduct analytics to understand how visitors use our Website (subject to your cookie preferences — see section 8).
6.4 Use of personal data collected via our website
In addition to the general uses of personal data described above, we collect and use personal data via our website (rwca.ie) in the following circumstances:
6.4.1 Contact forms and enquiries
When you contact us using a form on our website, we may collect:
your name
email address
telephone number (if provided)
subject and message content
Purpose:
to respond to your enquiry
to communicate with you
to follow up where appropriate
Legal basis: The legal bases for this processing are set out in Section 6.1, in particular:
legitimate interests in responding to enquiries and managing communications; and
where relevant, taking steps at your request prior to entering into a contract
Retention: Personal data submitted via website enquiries is retained in accordance with the retention periods set out in Section 12.2.
6.4.2 Payments
Where you make a payment using links or facilities provided on our website:
payments are processed by third-party providers (such as Stripe or GoCardless)
those providers may process your personal data in accordance with their own privacy policies and terms
We do not store full payment card or bank account details on our website systems.
Purpose:
to process payments
to administer our client relationships and billing
Legal basis: The legal bases for this processing are set out in Section 6.1, in particular:
performance of a contract; and
legitimate interests in administering payments and managing our business
6.4.3 Further information
Further details of how we process personal data in connection with:
cookies and similar technologies are set out in Section 8;
marketing communications are set out in Section 14; and
sharing of personal data with third parties is set out in Section 9.
7. THE LEGAL GROUNDS WE USE FOR PROCESSING PERSONAL DATA
7.1 We are required by law to identify the legal basis on which we process your personal data. We rely on one or more of the following:
(a) Consent (Article 6(1)(a) GDPR): where you have explicitly agreed to us processing your data for a specific purpose, such as receiving our marketing communications or placing non-essential cookies on your device. You may withdraw consent at any time — this will not affect the lawfulness of any processing carried out before withdrawal.
(b) Contract (Article 6(1)(b) GDPR): where processing is necessary to perform our agreement with you or to take steps before entering into an agreement with you.
(c) Legal obligation (Article 6(1)(c) GDPR): where processing is necessary to comply with a legal or regulatory obligation, such as anti-money laundering requirements, tax obligations or responding to regulatory enquiries.
(d) Legitimate interests (Article 6(1)(f) GDPR): where processing is necessary for our legitimate business interests (or those of a third party), provided those interests are not overridden by your rights and interests. Our legitimate interests include:
(i) providing and managing our services;
(ii) preventing fraud and protecting our business;
(iii) ensuring complaints are investigated;
(iv) evaluating and improving our services; and
(v) keeping clients and contacts informed about relevant developments and services.
7.2 Where we process special categories of personal data (section 4.4), we do so on one of the following additional grounds:
(a) explicit consent (Article 9(2)(a) GDPR);
(b) legal obligation relating to employment, social security or social protection law (Article 9(2)(b) GDPR);
(c) the data has been manifestly made public by you (Article 9(2)(e) GDPR); or
(d) the processing is necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f) GDPR).
7.3 Please note that even where you withdraw consent, it may still be lawful for us to continue processing your personal data if another legal basis applies.
8. COOKIES AND TRACKING TECHNOLOGIES
8.1 See Cookie Policy
9. SHARING YOUR PERSONAL DATA
9.1 We may share your personal data with the following categories of recipients where necessary for the purposes described in section 6:
(a) Professional advisers and service providers: third parties that provide services to us, including IT and software providers, cloud hosting providers, payment processors and professional advisers (such as lawyers and consultants);
(b) Regulatory and competent authorities: courts, tribunals, the Revenue Commissioners, the Office of the Data Protection Commission, An Garda Síochána and other bodies that regulate our profession, where we are required or permitted by law to do so;
(c) Your employer and their advisers, or your own advisers, where relevant to the services we provide;
(d) Successor entities: any purchaser of our business or assets following a restructure, sale or acquisition, provided that any such entity uses your personal data only for the same purposes for which it was originally collected; and
(e) Credit reference agencies and fraud prevention organisations: where relevant to our risk management and due diligence obligations.
9.2 The third-party technology providers we currently use to operate our Website and business include:
Provider & Purpose
Google -(Analytics / Website analytics, tag management & Tag Manager) and advertising measurement
Cookiebot - Cookie consent management
Calendly - Online appointment scheduling
Sprig / UserLeap - User research and experience analytics (connected to Calendly scheduling)
YouTube (Google) - Embedded video content
Stripe - Payment processing
Go Cardless - Payment processing
Cloudflare- Website security and performance
Each of these providers processes personal data as a data processor on our behalf, or as an independent data controller, and has its own privacy policy. We encourage you to review their privacy policies if you wish to understand how they process your data.
9.3 We do not sell your personal data to third parties.
9.4 We do not share your personal data with third parties for their own marketing purposes.
10. TRANSFERRING YOUR PERSONAL DATA OUTSIDE IRELAND
10.1 Some of our third-party service providers are based outside Ireland and the European Economic Area (EEA). Where we transfer your personal data outside the EEA, we ensure that appropriate safeguards are in place to protect it to the standard required under GDPR. These safeguards may include:
(a) transfers to countries that have been granted an adequacy decision by the European Commission, confirming that they provide an equivalent level of data protection to the EEA;
(b) for transfers to the United States: reliance on the EU-US Data Privacy Framework (DPF), where the recipient is certified under the DPF (this applies to providers such as Google, Stripe and Calendly);
(c) execution of EU Standard Contractual Clauses (SCCs) approved by the European Commission with the recipient; or
(d) your explicit consent to the transfer, where required and appropriate.
10.2 You may request further information about the specific safeguards we have put in place for international transfers by contacting us using the details in section 1.2.
10.3 We may share non-personal, de-identified or aggregated information with third parties for data analytics, research or promotional purposes. Such information cannot reasonably be used to identify you.
11. PROTECTION OF YOUR PERSONAL DATA
11.1 We implement a range of physical, technical and organisational security measures to protect your personal data against unauthorised access, loss, destruction or alteration. These measures include:
(a) staff training and awareness on data protection obligations;
(b) access controls restricting personal data to those who need it;
(c) technical security measures including firewalls, encryption and anti-virus software; and
(d) physical security measures at our premises.
11.2 Whilst we take appropriate steps to protect your personal data once received, the transmission of data over the internet (including by email) is never entirely secure. We cannot guarantee the security of data in transit.
12. HOW LONG WE KEEP YOUR INFORMATION FOR
12.1 We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law or regulation. We regularly review our files to check that data is accurate, up to date and still required.
12.2 The table below sets out our standard retention periods. This table is illustrative and there may be occasions where longer retention is required - for example, where data is relevant to ongoing litigation, a regulatory investigation, or a professional indemnity claim that arises after the standard period has expired.
Category of data | Retention period
Client files and correspondence | 7 years from end of engagement (or longer if required by ICAI or by law)
Tax records and supporting documents | 6 years from end of relevant tax year (per TCA 1997 s.886)
AML/KYC records | 5 years from end of business relationship (per CJA 2010)
Accounting records | 6 years (Companies Act 2014 s.282)
Employee records | 7 years from termination of employment
Website enquiry | 2 years from last contact contact form data (or until matter resolved)
Cookie consent records | 1 year from consent given
Marketing preference or records | Until consent is withdrawn or 3 years from last interaction, whichever is sooner
12.3 When personal data is no longer required, it will be securely deleted or anonymised in accordance with our data retention procedures.
13. YOUR RIGHTS
13.1 Under Data Protection Legislation you have the following rights in relation to your personal data:
(a) Right of access: to obtain confirmation that we are processing your personal data and to receive a copy of it.
(b) Right to rectification: to ask us to correct personal data that is inaccurate or incomplete.
(c) Right to erasure ("right to be forgotten"): to ask us to delete your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent (and no other legal basis applies), or where we have processed it unlawfully.
(d) Right to restriction: to ask us to restrict our processing of your personal data in certain circumstances (for example, while the accuracy of data is disputed).
(e) Right to data portability: to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where processing is based on consent or a contract.
(f) Right to object: to object to our processing of your personal data where we rely on legitimate interests as the legal basis, or where we process it for direct marketing purposes.
(g) Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal. To withdraw cookie consent, use the cookie settings link in the footer of our Website.
13.2 To exercise any of these rights, please contact our Data Protection contact using the details set out in section 1.2. Requests should be in writing (email is acceptable) and we will respond within one month of receipt, or notify you if we require an extension.
13.3 We will not charge a fee to respond to your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline the request.
13.4 Please keep us informed if your personal data changes so that we can ensure we hold accurate and up-to-date information about you.
14. SENDING YOU MARKETING INFORMATION
14.1 From time to time we may use your contact information to send you information about our services, news and updates that we believe may be of interest to you, by email or other electronic means.
14.2 We will only do this where we have your consent to do so, or where we have a legitimate interest in doing so (for example, where you are an existing client and the communication relates to services similar to those we have already provided to you), subject always to your right to opt out.
14.3 You may opt out of receiving marketing communications from us at any time by:
(a) clicking the unsubscribe link in any marketing email we send you; or
(b) contacting us at
14.4 We will action your opt-out request promptly and in any event within 30 days.
14.5 Opting out of marketing will not affect the processing of personal data that is necessary to provide our services to you.
14.6 We do not share your personal data with third parties for their own marketing purposes.
15. RIGHT TO COMPLAIN
15.1 If you wish to raise a concern about how we have handled your personal data, please contact us in the first instance using the details in section 1.2. We will investigate your concern and respond within one month.
15.2 If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Data Protection Commission (DPC):
Data Protection Commission
6 Pembroke Road
Dublin D02 X963
Ireland
Website: www.dataprotection.ie
Phone: +353 (0)1 765 01 00
16. CHANGES TO THIS PRIVACY NOTICE
16.1 We may update this privacy notice from time to time to reflect changes in our practices, technology, legal requirements or for other operational reasons.
16.2 When we make changes, we will update the "Last updated" date at the top of this page. We encourage you to review this notice periodically.
16.3 Where changes are material, we will take reasonable steps to bring them to your attention — for example, by a prominent notice on our Website or by email.
Rory Williams Chartered Accountants
20 Harcourt Street, Dublin 2.
