01Why this statement exists
Handing your books to an outside firm means handing over the most sensitive records your business holds — bank positions, payroll, margins, Taxpayer Identification Numbers, and every filing you have made to a revenue authority. Asking how that will be protected is a reasonable question, and one most accounting firms answer vaguely or not at all.
This statement sets out the controls we apply to client data. It is written to be read by a business owner, not a security auditor. It supplements our Privacy Policy, which explains the legal basis on which we process data; this page explains how we safeguard it in practice.
02What this covers
Every category of client information we handle under an engagement, including: books of account, ledgers, and supporting documents; bank statements and payment-processor exports; payroll registers and statutory contribution records; Taxpayer Identification Numbers and equivalent foreign identifiers; filed and draft tax returns; correspondence with the BIR and other authorities; identification documents collected for client due diligence; and management accounts and forecasts prepared for advisory engagements.
03Who can see your data
Least privilege. Access is granted by engagement, not by seniority. A staff member assigned to your bookkeeping does not thereby gain access to another client's audit file, and staff not assigned to your engagement have no access to your records.
Client segregation. Each client's records are held in a separate workspace. We do not commingle client files, and we do not use one client's data to inform work for another.
Access review. Access rights are reviewed when an engagement ends, when a staff member changes role, and immediately on departure.
Confidentiality obligations. Everyone with access — employees, contractors, and any specialist we co-engage — is bound by written confidentiality obligations, and, for professional staff, by the ethical requirements of the accountancy profession, which survive the end of the engagement.
04Separation from our other business
Briah Creatives is a separate marketing business under common ownership. Common ownership does not mean shared data. Client information held by Chensed Solutions is not disclosed to Briah Creatives, and vice versa, without the client's express written consent. If we think one business could help a client of the other, we will ask you first — we will not move your information across on our own initiative.
05Technical safeguards
- Encryption in transit. This website and our client-facing systems are served over HTTPS/TLS. Documents are exchanged through encrypted channels, not as unprotected attachments on open networks.
- Encryption at rest. Client records are held in cloud accounting and storage platforms that encrypt data at rest as standard.
- Multi-factor authentication. MFA is required on the accounts that hold or reach client data, including email, cloud storage, and accounting platforms.
- Device controls. Devices used for client work are password-protected, kept current with security updates, and run endpoint protection.
- Backups. Client records are backed up so that data can be restored following accidental deletion, hardware failure, or ransomware.
- Vendor selection. We favour established platforms with published security practices and independent assurance over cheaper tools with none.
06Providers we rely on
Delivering cloud-based accounting requires third-party platforms — accounting software, document storage, email, and payroll tools. We select providers that offer encryption, access logging, and contractual commitments on data handling, and we bind them to process data only on our instructions.
A current list of the providers used on your engagement is available on request. Where an engagement requires a formal data processing agreement — common for clients subject to GDPR — we will enter into one.
07The human layer
Most breaches in professional services begin with a person, not a firewall. We address that directly:
- Staff are trained to recognise phishing and social-engineering attempts, including requests that appear to come from a client or a partner.
- Payment-detail changes are verified out-of-band. If you email us asking to change bank details, we will call you on a number we already hold before acting. We ask that you apply the same rule to any such request appearing to come from us.
- Client matters are not discussed in public settings or over unsecured consumer messaging where records are being exchanged.
- Access to client data from shared or public computers is not permitted.
08What we will never ask you for
Knowing what a legitimate request looks like is one of the strongest protections you have.
- We will never ask for your online banking password, PIN, or one-time passcode. If we need read access to bank data, it is arranged through your bank's or accounting platform's authorised feed — never by sharing credentials.
- We will never ask you to send funds to an account other than the one on our issued invoice, and we will never notify a change of bank details by email alone.
- We will never ask for your eFPS or revenue-authority portal password over email or chat.
If you receive a request of this kind appearing to come from us, do not act on it. Call us on (082) 227-5745 and tell us.
09Retention and destruction
We keep client records for the statutory preservation period applicable to the engagement — in the Philippines, ten years from the day following the filing deadline for the relevant return, under Section 235 of the National Internal Revenue Code and BIR regulations, with comparable periods in the other jurisdictions we serve.
When an engagement ends, we return or make available the records you are entitled to receive, and retain what we are legally required to keep. When retention obligations expire, records are securely destroyed — electronic data deleted from live systems and backups on the ordinary backup cycle, and paper shredded.
10If something goes wrong
No firm can promise a breach will never happen. What we can commit to is how we will respond.
- Contain — revoke affected access and isolate affected systems immediately.
- Assess — establish what data was involved, whose, and what the likely consequences are.
- Notify you — promptly, with what we know, what it means for you, and what we are doing. We would rather tell you early with incomplete information than late with a tidy account.
- Notify regulators — where the breach is notifiable, we report to the National Privacy Commission within the period required by the Data Privacy Act and its IRR, and, where GDPR applies, to the relevant supervisory authority within 72 hours of becoming aware.
- Remediate — fix the cause and record what changed, so the same route is closed.
11What we ask of you
Security is shared. It helps materially if you: send documents through the channel we agree at onboarding rather than whatever is convenient; keep MFA switched on for your own email and accounting platform; tell us promptly when a staff member with access to your finance systems leaves; and call us to verify anything that looks unusual, however small.
12Questions
Ask us anything about how your data is handled
If you are evaluating us and your own policy requires a security review, tell us what you need and we will answer specifically rather than pointing you back at this page.
Email admin@chensedsolutions.com or call (082) 227-5745, Monday to Friday, 8:00am–5:00pm PHT.