Menu
- Services
- AML checks
- HMRC & Companies House admin
- Penalty appeals
- MTD-ready reporting
- SA100, CT600 & CGT preparation
- Bank reconciliations & payroll prep
- Client onboarding
- Client inquiry support
- Billing administration
- All services
- Virtual assistant for accountants
- Company
- How it works
- About
- Blogs & Resources
- Contact
Privacy Policy
How Virtual Service Assists collects, uses and protects personal data, for visitors to this website, people who contact us and the UK accounting practices we work for. Last updated: 8 October 2026.
This policy at a glance
| Whose data | Our role | Why we use it | Lawful basis (UK GDPR) |
|---|---|---|---|
| Website visitors | Controller | Running the site; measuring visits if you agree to analytics cookies | Legitimate interests (site operation); consent (analytics) |
| People who enquire through the form, email or phone | Controller | Replying to you and discussing a possible engagement | Legitimate interests; steps before entering into a contract |
| Contacts at practices we work with | Controller | Managing the engagement, communication and invoicing | Contract; legitimate interests |
| A practice's own clients and staff | Processor | Carrying out the work the practice instructs us to do | The practice decides and is responsible for the lawful basis |
Who we are
Virtual Service Assists is the trading name of ASAH-ADU VIRTUAL SOLUTIONS, a business based in Ghana. We provide outsourced admin and compliance support to UK accounting and tax practices. In this policy, "we", "us" and "our" mean ASAH-ADU VIRTUAL SOLUTIONS trading as Virtual Service Assists.
- Registered business details: business registration number BN828460626; registered address Pantang Hospital Avenue, GA East, Accra, Ghana (Digital Address GE-006-9895).
- Email: info@virtualserviceassists.com
- Phone: +233 24 410 8277 (Monday to Friday, GMT)
- Post: Pantang Hospital Avenue, GA East, Accra, Ghana (GE-006-9895)
Our two roles: controller and processor
When we are the controller
We decide how and why personal data is used, and are responsible for it, when it concerns:
- people who visit virtualserviceassists.com;
- people who contact us through the website form, by email, by phone or on LinkedIn;
- our business contacts at the practices we work with or talk to (partners, managers and staff).
Most of this policy is about that data.
When we are a processor
When a UK practice engages us, we handle personal data about the practice's own clients and team (for example names, contact details, identity documents for AML checks, payroll and tax records) only on the practice's documented instructions. In that situation the practice is the controller. Our obligations are set out in the data processing terms of the practice's services agreement with us, and the practice's own privacy notice explains to its clients how their data is used.
If you are a client of a practice we support and want to exercise your data protection rights, please contact the practice first. If you contact us, we will pass your request to the practice promptly and help it respond.
As a processor we work inside the practice's own systems using logins the practice issues, so the practice controls that access and can withdraw it at any time. We do not use a practice's client data for our own purposes.
What personal data we collect
Contact form
The form on our contact page asks for:
- your full name;
- your work email address;
- your firm or practice name;
- a message about what you need help with.
Form submissions are sent to our email inbox and may also be kept in our website system.
Emails, calls and meetings
If you email, call or meet us (including on Microsoft Teams or Zoom), we keep a record of the correspondence and any notes we make, along with your contact details and job role.
Practice contacts during an engagement
For practices we work with, we hold the names, job titles, work email addresses and phone numbers of the people we deal with, plus billing details needed to invoice the practice.
Website usage data
Our web host keeps standard server logs (such as IP address, browser type and pages requested) to keep the site running and secure. Our website is hosted by Namecheap (EasyWP).
If you accept analytics cookies, we use Google Analytics 4 to see how visitors use the site: pages viewed, approximate location (country or city level), device and browser type, and how you arrived. Google Analytics does not run unless you consent. See our Cookie Policy.
What we do not collect
We do not ask website visitors for special category data (such as health information), and we do not sell personal data or use it for automated decision-making that has legal or similarly significant effects on you.
Why we use it and our lawful bases
Under the UK GDPR we must have a lawful basis for each use of personal data where we are the controller.
- Legitimate interests. Replying to enquiries, keeping business records, running and securing the website, and staying in touch with business contacts about our services. Our interest is in running and promoting a B2B service; we have considered your interests and believe this use is expected and proportionate. You can object at any time.
- Contract. Where we are entering into, or performing, a services agreement with a practice, we use the contact and billing details needed to deliver the work and invoice for it.
- Consent. Analytics cookies and Google Analytics 4 only run if you agree. You can withdraw consent at any time, which does not affect processing before you withdrew it.
- Legal obligation. We keep financial and tax records where the law requires us to.
If we want to send marketing emails to individuals, we will do so only where the law allows, and every message will include a simple way to opt out.
Who we share it with
We share personal data only where needed, with:
- service providers that help us run the business, such as our website host, email provider and Google (for analytics, if you consent) These include Namecheap (website hosting) and Google (analytics, only with your consent).;
- professional advisers such as lawyers and accountants, under a duty of confidentiality;
- authorities or regulators where the law requires it.
Data we handle as a processor is shared only as the practice instructs.
International transfers
Our team is based in Ghana, so personal data we receive from the UK is accessed and handled in Ghana. Some of our service providers may also store data in other countries, including the United States.
The UK government has not made adequacy regulations for Ghana, so a transfer of personal data from the UK to us in Ghana is a "restricted transfer" under the UK GDPR. These transfers must be covered by an appropriate safeguard. The safeguards the ICO recognises for this include the UK International Data Transfer Agreement (IDTA) and the International Data Transfer Addendum to the EU standard contractual clauses, used together with a check (now called the "data protection test" following the Data (Use and Access) Act 2025) that the standard of protection is not materially lower than in the UK. Source: ICO, guidance on international transfers and standard data protection clauses.
For practices that engage us, the transfer safeguard is included in, or attached to, the services agreement.
You can ask us for more information about the safeguards we use by emailing info@virtualserviceassists.com.
Ghana's Data Protection Act
As a business established in Ghana we also comply with Ghana's Data Protection Act, 2012 (Act 843), which is overseen by the Data Protection Commission.
How long we keep it
We keep personal data only for as long as we need it. Our retention periods are below.
| Data | How long we keep it |
|---|---|
| Contact form submissions and enquiry emails that do not lead to an engagement | 12 months from last contact |
| Contact details and correspondence with practices we work with | The length of the engagement plus 6 years |
| Invoices and financial records | 6 years, or longer where the law requires |
| Google Analytics data | 14 months |
| Practice client data we handle as a processor | As set out in the practice's services agreement. At the end of an engagement we return or delete it as the practice instructs, and the practice withdraws our system access. |
How we protect it
- We access practice systems through secure connections, using logins issued by the practice so it controls and can revoke access.
- We follow GDPR-conscious handling procedures for client information, and we keep the work inside the practice's own software wherever possible.
- We run dual-fibre internet and backup power so work continues during outages.
No method of sending data over the internet is completely secure. If a personal data breach affects data we process for a practice, we will tell that practice without undue delay so it can meet its own obligations.
Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of data that is wrong or incomplete;
- erasure of your data in certain circumstances;
- restrict how we use your data in certain circumstances;
- object to our use of your data based on legitimate interests, and to direct marketing at any time;
- data portability, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time where we rely on it, for example for analytics cookies.
Some rights have conditions or exceptions. Ghana's Data Protection Act gives you similar rights.
How to exercise them
Email info@virtualserviceassists.com with the subject line "Data protection request" and tell us what you are asking for. We may need to confirm your identity before acting. We will normally respond within one month, which can be extended by up to two further months for complex requests, in which case we will tell you why. There is usually no fee.
If your request concerns data we hold for a practice as its processor, we will pass it to that practice, as explained above.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at info@virtualserviceassists.com. We will acknowledge your complaint within 30 days, look into it and tell you the outcome, as UK data protection law has required since 19 June 2026. Source: ICO, "New data protection complaints law now in force".
You can also complain to a regulator:
- in the UK, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint;
- in Ghana, the Data Protection Commission: dpc.gov.gh.
Cookies
We use cookies that the website needs to work and, only with your consent, Google Analytics cookies. Our Cookie Policy lists them and explains how to change your choice.
Other websites
Our site links to other websites, such as LinkedIn, GOV.UK and the ICO. Their privacy practices are their own, so please read their privacy notices.
Changes to this policy
We review this policy from time to time and will post any changes on this page with a new "last updated" date. If a change materially affects how we use data you have given us, we will tell you directly where we can.
Contact us
For any question about this policy or your personal data, contact ASAH-ADU VIRTUAL SOLUTIONS trading as Virtual Service Assists:
- Email: info@virtualserviceassists.com
- Phone: +233 24 410 8277 (Monday to Friday, GMT)
- Post: Pantang Hospital Avenue, GA East, Accra, Ghana (GE-006-9895)
Last updated: 8 October 2026.
Outsourced compliance and practice administration for UK accounting and tax firms, worked on UK hours inside the software you already use.
- GMT working hours
- GDPR-conscious handling
- B2B supplier, no payroll
Get in touch
- info@virtualserviceassists.com
- Phone
- +233 24 410 8277
- Hours
- Monday to Friday, on GMT
- Based in
- Pantang Hospital Avenue, GA East, Accra, Ghana
© 2026 Virtual Service Assists, the trading name of ASAH-ADU VIRTUAL SOLUTIONS. Business registration BN828460626.