Saltar al contenido principal

Esta página aún no está disponible en Español. Está leyendo la versión en inglés.

Legal

Confidentiality

What we do with what you tell us. Last updated September 2026.

The commitment

Everything you give us in the course of an engagement is confidential. We use it to perform the work you hired us for and for nothing else, unless you tell us in writing that we may, or the law requires it of us.

This is not only a policy. As a firm preparing tax returns we are a financial institution under the Gramm-Leach-Bliley Act, and separately bound by Internal Revenue Code section 7216, which makes the unauthorised use or disclosure of return information a criminal matter rather than a contractual one.

What counts as confidential

Your financial records, tax returns and the information in them; documents you upload; what your own business credit file says, as you gave it to us; the advice and reports we prepare for you; your plans, contracts and commercial arrangements; and the fact and nature of our engagement itself.

Who inside the firm sees it

Access is limited to the people performing your work. Staff authenticate with multi-factor authentication, permissions follow least privilege, access is reviewed periodically, and every material action against a client file is logged with who did it and when.

Who outside the firm sees it

Nobody, unless one of the following applies:

  • You have authorised it in writing. For tax return information this means a separate section 7216 consent that names the recipient and the purpose, is never a condition of your tax work, and expires after one year unless renewed.
  • A service provider needs it to deliver the service — a payment processor, a secure storage provider, an e-signature provider. Each is bound by a written contract requiring equivalent safeguards, and each receives the minimum necessary.
  • The law or a professional obligation requires disclosure — a valid subpoena, a court order, or a regulatory examination. Where we are permitted to tell you first, we will.

What we will never do

We do not sell personal or business data. We do not share client information with advertising platforms. We do not use your tax return information to decide what else to sell you without the specific written consent described above, and our systems enforce that in software rather than by policy — the marketing and recommendation engines cannot read return data unless a live consent exists for that client and that purpose.

Client data is not used to train third-party artificial intelligence models. Tax returns are never passed to a language model. One thing is, and only if you choose it: if you paste the text of your own business credit report to save yourself typing it, that text is sent to a third-party model to be read. Bank and routing numbers, card numbers, tax identification numbers, email addresses, telephone numbers and any bare run of nine or more digits are removed before it leaves. What comes back is a suggestion with the line of your report it came from attached; nothing is used until you confirm it, and you can skip the whole step and type the figures instead. We keep a record of what was sent, when, how much of it and what was stripped out — it holds no report text and no figure read from one. Where automated analysis is used anywhere else, identifiers are minimised or masked first.

How it is protected

Encryption in transit and at rest. Documents uploaded through an encrypted portal with malware scanning and expiring links; we do not accept tax documents by email. A written information security programme with a named individual accountable for it, as the FTC Safeguards Rule requires. An incident response plan, and notification to you and to regulators within the periods the law sets if a breach affects your information.

How long we keep it

For the period professional and legal obligations require, then securely destroyed. Those obligations can override a deletion request; where that is the case we will tell you which records are affected and why.

If you are giving us someone else's information

Where you provide information about employees, owners or guarantors, you confirm you are entitled to share it with us for the purpose of the engagement. Consumer credit reports on a guarantor are pulled only with that individual's written authorisation.

Questions about any of this go to the contact on the Contact page. See also Privacy and Disclosures.