top of page

PRIVACY POLICY 

Form My Company – a trading name of IBA Limited

Last updated: 1 September 2026

​

1. About this Privacy Policy

​

Form My Company is committed to protecting your privacy and handling your personal information lawfully, fairly, securely and transparently.

This Privacy Policy explains:

  • what personal information we collect;

  • how and why we use it;

  • the lawful bases on which we process it;

  • who we may share it with;

  • how long we retain it;

  • how we protect it;

  • whether it may be transferred outside the United Kingdom; and

  • your rights under UK data-protection law.

This Policy applies when you:

  • visit www.formmycompany.co.uk;

  • create an online account;

  • contact us;

  • request a quotation;

  • purchase or use our services;

  • act as a director, shareholder, member, partner, person with significant control or beneficial owner in connection with a customer order;

  • use one of our registered-office, service-address or virtual-office services;

  • receive marketing communications from us; or

  • otherwise interact with Form My Company.

​

2. Who we are

​

Form My Company is a trading name of IBA Limited, a private limited company registered in Scotland under company number SC660379.

​

For the purposes of applicable UK data-protection law, IBA Limited is normally the controller of personal information described in this Policy.

​

Our contact details are:

​

IBA Limited
Trading as Form My Company
9A Tinto Place
Edinburgh
EH6 5GD
United Kingdom

​

Email: info@formmycompany.co.uk
Telephone: 0131 322 1309
Website: www.formmycompany.co.uk
Opening hours: Monday to Friday, 9:00 a.m.–5:00 p.m. UK time
VAT registration number: 371 8646 69
AML registration number: XNML00000150818

​

Questions, requests and complaints concerning your personal information may be sent to the email or postal address above.

​

3. Data-protection laws

​

We process personal information in accordance with applicable UK data-protection and privacy legislation, including:

​

  • the UK General Data Protection Regulation;

  • the Data Protection Act 2018;

  • the Data (Use and Access) Act 2025;

  • the Privacy and Electronic Communications Regulations 2003, as amended; and

  • other applicable legislation governing privacy, electronic communications, identity verification, corporate services and anti-money laundering.

​

This Policy does not create rights beyond those provided by applicable law.

​

4. Personal information we collect

​

The information we collect depends on your relationship with us and the services you request.

​

4.1 Identity information

​

We may collect:

​

  • full name;

  • title;

  • previous names;

  • date of birth;

  • place of birth;

  • nationality;

  • citizenship;

  • country of residence;

  • occupation;

  • gender, where required for a lawful purpose;

  • signature;

  • Companies House personal code or identity-verification details;

  • customer or account reference number; and

  • copies or details of identity documents.

​

Identity documents may include passports, driving licences, national identity cards, residence permits and other official documents.

​

4.2 Contact information

​

We may collect:

​

  • residential address;

  • previous addresses;

  • business address;

  • correspondence address;

  • service address;

  • registered-office address;

  • email address;

  • telephone number;

  • social-media or messaging contact details; and

  • communication preferences.

​

4.3 Company and business information

​

We may collect:

​

  • company or proposed company name;

  • company number;

  • jurisdiction of incorporation;

  • business activities and SIC codes;

  • registered-office details;

  • details of directors and company secretaries;

  • shareholder and shareholding details;

  • member or partner details;

  • person with significant control information;

  • beneficial-ownership and control information;

  • statutory-register information;

  • filing history;

  • tax and VAT information;

  • payroll and employee information where relevant;

  • financial-year and accounting-reference dates;

  • licences and regulatory information; and

  • other information needed to provide company-formation, secretarial, accounting or administrative services.

​

Some company information may already be publicly available through Companies House or another official register.​​

4.4 Financial and transaction information

​

We may collect:

​

  • billing address;

  • payment status;

  • transaction amount;

  • payment method;

  • invoice and receipt information;

  • refund information;

  • bank-account details where required;

  • accounting and bookkeeping records;

  • source-of-funds information;

  • source-of-wealth information; and

  • transaction history.

​

Payment-card information may be collected and processed directly by our payment provider. We may not receive or retain complete payment-card details.

​

4.5 AML, KYC and compliance information

​

We may collect:

​

  • identity-verification results;

  • proof of address;

  • source-of-funds and source-of-wealth evidence;

  • beneficial-ownership information;

  • sanctions and politically exposed person screening results;

  • fraud-risk indicators;

  • adverse-media screening results;

  • risk assessments;

  • information concerning the intended nature and purpose of a business relationship;

  • information about expected business activities and transactions;

  • copies of supporting documents;

  • records of compliance reviews; and

  • information required by Companies House, HMRC, our AML supervisor or another competent authority.

​

Where required and lawful, compliance information may include information relating to criminal allegations, offences, convictions, sanctions or suspected financial crime.

​

We process this type of information only where we have a lawful basis and any additional condition required by the Data Protection Act 2018.

​

4.6 Service and account information

​

We may collect:

​

  • username and account details;

  • services purchased;

  • order history;

  • application information;

  • account settings;

  • uploaded documents;

  • customer-support records;

  • mail-handling and forwarding instructions;

  • scanned mail;

  • renewal information;

  • complaints;

  • refund and cancellation requests; and

  • records concerning the performance of our services.

​

4.7 Communications

​

We may retain:

​

  • emails;

  • telephone notes or recordings where lawful and notified;

  • website enquiries;

  • live-chat conversations;

  • messages;

  • complaint correspondence;

  • customer-service requests;

  • feedback and survey responses; and

  • records of instructions and approvals.

​

4.8 Technical and website information

​

When you use our website, we may collect:

​

  • IP address;

  • browser type and version;

  • device type;

  • operating system;

  • time-zone and approximate location;

  • pages visited;

  • referring website;

  • links selected;

  • dates and times of visits;

  • account log-in activity;

  • session information;

  • cookie identifiers;

  • security and fraud-prevention information; and

  • information about how you interact with our website.

​

4.9 Marketing information

​

We may collect:

​

  • marketing preferences;

  • consent records;

  • unsubscribe requests;

  • email engagement information;

  • campaign interaction information;

  • services that may interest you; and

  • records of when and how consent was obtained or withdrawn.

​

5. How we collect personal information

​

We may collect personal information:

​

5.1 Directly from you

​

This includes information provided when you:

​

  • complete a website form;

  • create an account;

  • place an order;

  • upload documents;

  • contact us by email, telephone, post, live chat or social media;

  • request customer support;

  • complete identity verification;

  • use our address or mail-handling services;

  • subscribe to marketing;

  • make a complaint; or

  • otherwise communicate with us.

​

5.2 From a customer or authorised representative

​

A customer may provide information about directors, shareholders, members, partners, persons with significant control, beneficial owners, employees or other persons connected with an order.

​

If you provide another person’s information, you confirm that you have lawful authority to do so and, where required, that you have provided that person with this Privacy Policy.

​

5.3 From public sources

​

We may obtain information from:

​

  • Companies House;

  • HMRC and other government bodies;

  • electoral or official registers where lawful;

  • court and insolvency records;

  • professional and regulatory registers;

  • company websites;

  • publicly available online sources; and

  • sanctions, politically exposed person and adverse-media databases.

​

5.4 From service providers and other third parties

​

We may receive information from:

​

  • identity-verification providers;

  • fraud-prevention agencies;

  • credit-reference agencies where lawful;

  • payment providers;

  • banks and financial institutions;

  • professional advisers;

  • accountants and bookkeeping providers;

  • address and mail-handling providers;

  • website, analytics and security providers;

  • business partners and referral partners; and

  • regulators or law-enforcement authorities.

​

6. Purposes and lawful bases

​

We only process personal information where we have a lawful basis.

​

Depending on the circumstances, we may rely on one or more of the following bases.

​

6.1 Performance of a contract

​

We process personal information where necessary to:

​

  • provide a quotation;

  • accept and administer an order;

  • form a company;

  • prepare or submit a filing;

  • provide company-secretarial services;

  • provide registered-office, service-address or virtual-office services;

  • process and forward mail;

  • prepare documents;

  • manage an account;

  • process payments and refunds;

  • communicate about an order;

  • provide customer support; and

  • otherwise perform a contract with you.

​

This basis also applies where processing is necessary to take steps at your request before entering into a contract.

​

6.2 Legal obligation

​

We process information where necessary to comply with legal and regulatory obligations, including:

​

  • identity-verification requirements;

  • anti-money laundering and counter-terrorist financing obligations;

  • sanctions compliance;

  • fraud prevention;

  • tax and accounting obligations;

  • record-keeping requirements;

  • Companies House requirements;

  • responding to court orders or lawful requests;

  • reporting suspected criminal or unlawful conduct; and

  • responding to data-protection rights and complaints.

​

Where a legal obligation prevents us from deleting or disclosing certain information, that obligation will take priority.

​

6.3 Legitimate interests

​

We may process information where necessary for our legitimate interests or those of another person, provided those interests are not overridden by your rights and freedoms.

​

Our legitimate interests may include:

​

  • operating and improving our business;

  • managing customer relationships;

  • protecting our systems, website, staff and customers;

  • preventing and investigating fraud or misuse;

  • maintaining accurate records;

  • enforcing contractual rights;

  • recovering unpaid fees;

  • handling legal claims;

  • monitoring service quality;

  • understanding how our website and services are used;

  • carrying out proportionate business-to-business marketing;

  • maintaining network and information security; and

  • conducting internal administration, reporting and audits.

​

Where we rely on legitimate interests, we consider the necessity and proportionality of the processing and its potential effect on you.

​

6.4 Consent

​

We may rely on your consent for:

​

  • optional cookies and similar technologies;

  • certain electronic marketing communications;

  • collecting or using information for an optional purpose explained when consent is requested; and

  • any other processing where consent is the appropriate lawful basis.

​

You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

​

6.5 Legal claims and substantial public interest

​

Where applicable, we may process information necessary to:

​

  • establish, exercise or defend legal claims;

  • prevent or detect unlawful acts;

  • protect the public against dishonesty;

  • meet regulatory requirements;

  • prevent fraud;

  • comply with anti-money laundering obligations; or

  • fulfil another substantial-public-interest condition recognised by law.

​

7. If you do not provide information

​

Certain information is required to enter into or perform a contract or to comply with legal obligations.

If you do not provide requested information, we may be unable to:

​

  • verify your identity;

  • accept or continue an order;

  • form your company;

  • submit a filing;

  • provide an address service;

  • process or forward mail;

  • provide accounting or compliance services;

  • process a payment or refund; or

  • continue the business relationship.

​

We may also be required to suspend or terminate services.

​

8. Identity verification and compliance screening

​

We may use electronic systems and specialist providers to verify identities, documents, addresses, beneficial ownership and other information.

Checks may include:

​

  • document-authenticity checks;

  • facial comparison or liveness checks where lawful;

  • address verification;

  • sanctions screening;

  • politically exposed person screening;

  • fraud screening;

  • adverse-media screening; and

  • comparison with public or commercial databases.

​

The results may be used to determine whether we can accept or continue a customer relationship.

​

We may be unable to explain certain compliance decisions where doing so is prohibited by anti-money laundering, sanctions, fraud-prevention or other legislation.

​

9. Companies House and public information

​

When you instruct us to form a company or submit a filing, information may be disclosed to Companies House and placed on the public register.

Depending on the filing, public information may include:

​

  • company name and number;

  • registered-office address;

  • director and secretary details;

  • service addresses;

  • month and year of birth;

  • nationality;

  • occupation;

  • shareholder information;

  • share-capital information;

  • person with significant control information; and

  • filed documents.

​

Companies House determines what information is published and how long it remains available.

​

Information on the public register may remain permanently accessible, even after a company is dissolved or a person ceases to be involved.

You should not provide a residential address for public use unless it is necessary and you understand the consequences. Where eligible, you may purchase or use an appropriate service address.

​

We are not responsible for Companies House’s independent processing of information after it has been submitted.

​

10. Sharing personal information

​

We do not sell personal information.

​

We may share information where necessary with:

​

10.1 Government and regulatory bodies

​

These may include:

​

  • Companies House;

  • HMRC;

  • our AML supervisor;

  • law-enforcement agencies;

  • the National Crime Agency;

  • courts and tribunals;

  • tax authorities;

  • local authorities; and

  • other competent regulators or public bodies.

​

10.2 Service providers

​

These may include providers of:

​

  • website hosting and e-commerce services;

  • cloud storage;

  • customer-relationship management systems;

  • email and communications;

  • identity verification;

  • sanctions and fraud screening;

  • payment processing;

  • accounting and bookkeeping software;

  • document generation and electronic signatures;

  • postal, courier and mail-handling services;

  • IT support;

  • cybersecurity;

  • analytics;

  • marketing tools; and

  • professional advice.

​

Service providers may process information only for agreed purposes and subject to appropriate contractual and security requirements.

​

10.3 Professional advisers

​

We may share information with solicitors, accountants, auditors, insurers, consultants and other professional advisers where necessary.

​

10.4 Banks and business partners

​

Where you request or agree to an introduction, we may share relevant information with banks, payment providers, insurers, finance providers or other business partners.

​

Those organisations may act as independent controllers and provide their own privacy information.

​

10.5 Business transfers

​

If IBA Limited or part of its business is sold, transferred, merged, reorganised or acquired, relevant information may be disclosed to prospective purchasers, advisers and the new owner, subject to appropriate confidentiality and data-protection safeguards.

​

11. Payment information

​

Payments may be processed by independent payment providers.

​

Payment providers may collect:

​

  • cardholder name;

  • billing address;

  • card details;

  • bank information;

  • device information;

  • transaction information; and

  • fraud-prevention information.

​

We generally receive confirmation of payment, transaction references and limited billing details rather than complete payment-card information.

​

Payment providers may act as independent controllers for some processing. Their privacy notices will apply to their use of personal information.

​

12. International transfers

​

Some service providers or their technical systems may be located outside the United Kingdom. This may result in personal information being transferred to or accessed from another country.

​

Where required, we will use an appropriate transfer safeguard, such as:

​

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to approved standard contractual clauses;

  • another legally recognised transfer mechanism; or

  • a permitted statutory exception.

​

Where required, we will also assess whether the destination and safeguards provide appropriate protection.

​

You may contact us for further information about the safeguards used for relevant international transfers.

​

13. Data retention

​

We retain personal information only for as long as reasonably necessary for the relevant purpose, including legal, regulatory, tax, accounting, fraud-prevention and dispute-resolution requirements.


Typical retention periods include:

​

Information

​

AML, KYC, identity-verification and transaction records

Customer orders, contracts, invoices and payment records

Company-formation and Companies House filing records

Accounting, tax, VAT and payroll information

Registered-office, service-address and mail-handling records

Customer-support and complaint correspondence

Unsuccessful enquiries and quotations

​

Marketing records

​

Cookie and consent records

​

Security logs

​

Legal-dispute information

Typical retention period

​

At least 5 years after the business relationship ends or an occasional transaction is completed, unless a longer period is required or permitted

Normally 6 years after the relevant financial year or end of the contractual relationship

Normally 6 years after completion or the end of the customer relationship

For the period required by applicable tax, accounting and employment law, normally at least 6 years where relevant

​

Normally for the duration of the service and up to 6 years afterwards, subject to legal and compliance requirements

​

Normally up to 6 years after resolution, depending on the nature of the matter

​

Normally up to 24 months after the last meaningful contact

​

Until you unsubscribe or object, plus a limited suppression record to ensure your preference is respected

For the duration stated in our cookie information or as reasonably necessary to demonstrate consent

For a limited period appropriate to cybersecurity, fraud prevention and incident investigation

Until the dispute is resolved and any applicable limitation or retention period expires

​​

We may retain information for longer where:

​

  • required by law or a regulator;

  • necessary for legal proceedings;

  • necessary to prevent or investigate fraud;

  • requested by law enforcement;

  • necessary to enforce or defend legal rights; or

  • another lawful reason applies.

​

When information is no longer required, we will securely delete, anonymise or destroy it.

​

14. Data security

​

We use appropriate technical and organisational measures designed to protect personal information against:

​

  • unauthorised access;

  • unlawful processing;

  • accidental loss;

  • alteration;

  • disclosure;

  • destruction; and

  • misuse.

​

Measures may include:

​

  • access controls;

  • password and authentication requirements;

  • encryption where appropriate;

  • secure hosting and storage;

  • staff confidentiality obligations;

  • staff training;

  • malware and network protection;

  • backups;

  • logging and monitoring;

  • supplier due diligence;

  • data-processing agreements;

  • incident-response procedures; and

  • regular review of security arrangements.

​

No online system is completely secure. You are responsible for protecting your passwords and account credentials and for notifying us promptly if you suspect unauthorised access.

​

15. Personal data breaches

​

If a personal data breach occurs, we will assess and respond to it in accordance with applicable law.

​

Where required, we will notify the Information Commissioner’s Office and affected individuals within the applicable legal time limits.

​

Notification to individuals will depend on the likelihood and severity of risk to their rights and freedoms.

​

16. Cookies and similar technologies

​

Our website uses cookies and similar storage or access technologies.

These technologies may include:

​

  • cookies;

  • pixels;

  • tags;

  • scripts;

  • local storage;

  • session storage;

  • device identifiers; and

  • similar technologies.

​

We may use the following categories:

​

16.1 Strictly necessary cookies

​

These are required for core website functions such as:

​

  • website security;

  • network management;

  • shopping-basket functions;

  • payment processing;

  • account access;

  • fraud prevention; and

  • remembering privacy preferences.

​

Where a legal exemption applies, these cookies may be used without consent.

​

16.2 Functional cookies

​

These help remember choices and provide enhanced features. Where required by law, we will request consent before using them.

​

16.3 Analytics cookies

​

These help us understand website traffic, performance and user interaction.

​

We will request consent before using non-essential analytics cookies where consent is required.

​

16.4 Advertising and marketing cookies

​

These may be used to measure campaigns, personalise advertising or track activity across websites.

​

We will not use non-essential advertising or marketing cookies unless the required consent has been obtained.

​

You can accept, reject or manage non-essential cookies using our cookie controls. Withdrawing consent will not affect the lawfulness of earlier processing.

​

Blocking certain cookies may affect website functionality.

​

More detailed information should be provided in our separate Cookie Policy and cookie-preference tool.

​

17. Direct marketing

​

We may send information about our services where:

  • you have provided valid consent;

  • applicable electronic-marketing rules permit us to contact you;

  • we have an appropriate legitimate interest for non-electronic or business-to-business marketing; or

  • another lawful basis applies.

​

You can opt out at any time by:

  • using the unsubscribe link in a marketing email;

  • adjusting your account or cookie preferences;

  • emailing info@formmycompany.co.uk; or

  • telephoning 0131 322 1309.

​

We may retain a limited suppression record after you unsubscribe so that we do not contact you again for the relevant marketing purpose.

Service messages concerning active orders, legal obligations, security, renewals or important account information are not marketing and may still be sent where necessary.

​

18. Automated decision-making and profiling

​

We may use automated tools to support:

  • identity verification;

  • fraud prevention;

  • sanctions screening;

  • risk assessment;

  • website security; and

  • service personalisation.

​

These systems may generate risk indicators or recommendations.

​

We do not ordinarily make decisions producing legal or similarly significant effects solely through automated processing without appropriate lawful grounds and safeguards.

​

Where applicable, safeguards may include:

​

  • informing you about the processing;

  • allowing you to provide additional information;

  • human review;

  • allowing you to challenge a decision; and

  • explaining the principal reasons where legally permitted.

​

Certain information may be withheld where disclosure would prejudice fraud prevention, anti-money laundering obligations, security or another legal requirement.

​

19. Your data-protection rights

​

Depending on the circumstances and applicable exemptions, you may have the following rights:

​

19.1 Right to be informed

​

You have the right to receive clear information about how your personal information is collected and used.

​

19.2 Right of access

​

You may request confirmation that we process your information and obtain a copy of the personal information we hold about you.

​

We are required to carry out reasonable and proportionate searches when responding to an access request.

​

19.3 Right to rectification

​

You may ask us to correct inaccurate information or complete incomplete information.

​

19.4 Right to erasure

​

You may ask us to delete personal information in certain circumstances.

​

This right is not absolute. We may retain information where necessary to comply with AML, tax, accounting, legal, regulatory or claims-related obligations.

​

19.5 Right to restrict processing

​

You may ask us to restrict the use of your information in certain circumstances.

​

19.6 Right to data portability

​

Where processing is based on consent or contract and carried out by automated means, you may have the right to receive information you provided in a structured, commonly used and machine-readable format or ask us to transmit it to another controller where technically feasible.

​

19.7 Right to object

​

You may object to processing based on legitimate interests.

​

We may continue processing if we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or if processing is needed for legal claims.

​

You have an absolute right to object to the use of your personal information for direct marketing.

​​

19.8 Rights relating to automated decisions

​

Where applicable, you may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.

​

19.9 Right to withdraw consent

​

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal will not affect processing that was lawful before consent was withdrawn.

​

20. Exercising your rights

​

To exercise a data-protection right, contact:

​

Email: info@formmycompany.co.uk

​

Post:

​

IBA Limited
9A Tinto Place
Edinburgh
EH6 5GD
United Kingdom

​

Please explain which right you wish to exercise and provide enough information for us to identify the relevant records.

​

We may request reasonable proof of identity before responding. This is intended to protect personal information from unauthorised disclosure.

You will not normally be charged a fee. We may charge a reasonable fee or refuse to act where permitted by law if a request is manifestly unfounded or excessive.

​

We will respond within the applicable legal time limit. This is normally one month, although the period may be extended where permitted for complex or multiple requests. If an extension applies, we will inform you.

​

Some rights may be restricted by legal exemptions, AML requirements, third-party rights, legal professional privilege or the need to prevent or detect crime.

​

21. Data-protection complaints

​

If you are concerned about how we have handled personal information, please contact us:

​

Email: info@formmycompany.co.uk
Telephone: 0131 322 1309

​

Post:

​

IBA Limited
9A Tinto Place
Edinburgh
EH6 5GD
United Kingdom

​

Please include:

​

  • your name and contact details;

  • a description of your concern;

  • the personal information or processing involved;

  • relevant dates and correspondence; and

  • the outcome you are seeking.

​

We will:

​

  • provide a way for you to submit a complaint;

  • acknowledge receipt within 30 days;

  • investigate and take appropriate steps without undue delay;

  • keep you informed where appropriate; and

  • communicate the outcome without undue delay.

​

You may also complain to the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching the regulator.

​

Information about making a complaint is available at www.ico.org.uk.

​

22. Information about other people

​

If you provide information about another person, including a director, shareholder, member, partner, beneficial owner, employee or person with significant control, you must ensure that:

​

  • you are authorised to provide it;

  • the information is accurate;

  • the disclosure is lawful; and

  • the person receives this Privacy Policy where required.

​

We may contact that person directly to verify their identity, obtain consent where necessary or provide privacy information.

​

23. Children

​

Our services are intended for adults and businesses. They are not directed at children under 18.

​

We do not knowingly allow a person under 18 to place an order or form a contractual customer relationship.

​

Information about a child may occasionally be processed where lawfully required in connection with company ownership, beneficial ownership, trusts, estates or another legitimate corporate matter. In such cases, we will apply appropriate safeguards and consider the child’s rights and interests.

​

24. Third-party websites

​

Our website may contain links to third-party websites, platforms and services.

​

Those organisations may collect and use information under their own privacy policies. We do not control and are not responsible for their independent privacy practices.

​

You should review the privacy information of any third-party website before providing personal information.

​

25. Changes to this Privacy Policy

​

We may update this Privacy Policy to reflect changes in:

​

  • law or regulation;

  • regulatory guidance;

  • our services;

  • technology;

  • data-processing activities; or

  • business operations.

​

The current version will be published on our website with its effective date.

​

Where a change materially affects how we use personal information, we will provide additional notice where required.

​

26. Contact us

​

Form My Company is a trading name of IBA Limited.

​

IBA Limited is registered in Scotland under company number SC660379.

​

Registered office:

​

IBA Limited
9A Tinto Place
Edinburgh
EH6 5GD
United Kingdom

​

Email: info@formmycompany.co.uk
Telephone: 0131 322 1309
Website: www.formmycompany.co.uk
VAT registration number: 371 8646 69
AML registration number: XNML00000150818

bottom of page