Trust

Security & Compliance

The safeguards behind our website and client portal — and how you can verify them.

Encrypted in transit

256-bit TLS encryption

Every connection between your browser and our servers is encrypted with Transport Layer Security (TLS) using strong, modern ciphers.

All pages on this website and the client portal are served exclusively over HTTPS. Data you submit — contact enquiries, sign-in credentials, uploaded documents — is encrypted in transit so it cannot be read or tampered with while travelling across the internet.

We enforce TLS 1.2 or higher and use HSTS (HTTP Strict Transport Security) so browsers always connect over a secure channel and refuse insecure fallbacks.

TLS protects data while it is being sent. It does not by itself protect data once it has been stored — see UK GDPR and UK/EU hosting below for how stored data is safeguarded.

Data handled lawfully

UK GDPR compliance

We process personal data in line with the UK GDPR and the Data Protection Act 2018, as a data controller for client information.

Beck Hill Ltd (Company Number 14127398) is registered as the data controller for the personal data we hold. Our full approach is set out in our Privacy & Cookie Policy.

We only collect the data we need to deliver your accountancy services and meet legal duties such as AML supervision and HMRC/Companies House retention. Client records are kept for at least six years after an engagement ends, and non-engagement enquiries are deleted within 24 months.

You can exercise your data rights — access, correction, erasure where no legal retention duty applies, restriction and portability — by emailing us, and you have the right to complain to the Information Commissioner's Office (ico.org.uk).

Portal sign-in

Two-factor authentication

The client portal supports two-factor authentication (2FA), adding a second check beyond your password when you sign in.

Two-factor authentication (2FA) is available on the client portal. When enabled, signing in requires both your password and a time-based one-time code from an authenticator app such as Google Authenticator or Authy.

This means that even if a password were ever guessed or leaked, an attacker would still need the second factor to reach your account. We strongly recommend every client turns 2FA on from the Security page inside the portal.

2FA applies to portal sign-ins only. It does not change how the public marketing pages work, which do not require an account.

Secure data centres

UK / EU hosting

Our website, portal and databases are hosted on infrastructure located within the UK and EU, so client data does not leave European jurisdictions.

The Beck Hill website, secure client portal and the databases that store client information run on hosting providers with data centres in the United Kingdom and European Union. This keeps personal data within jurisdictions covered by UK and EU data protection law.

Hosting includes physical and environmental security at the data centres, monitored networks, and regular backups. Access to production systems is restricted to authorised personnel and logged for audit.

We do not store client data in jurisdictions outside the UK/EU. If a subprocessor change ever required this, we would assess the impact and apply suitable safeguards before proceeding.