Marketing that will not put your practising certificate at risk
You are regulated. We are not going to be the reason a client complains, a body writes to you, or a review gets pulled. Here is exactly how we operate, in enough detail that your compliance partner can read it and be satisfied.
Reviews and testimonials
Review gating — asking clients how they feel first and only sending the happy ones to Google — is the single most common thing agencies do that would embarrass a regulated firm. It breaches Google’s policies, it falls foul of the CMA’s rules on fake and misleading reviews, and under the Digital Markets, Competition and Consumers Act it is now directly enforceable. We do not do it, and we will not do it if asked.
Every client of yours gets the same request at the same trigger point. Nobody is filtered. Requests carry no incentive, no discount and no suggestion of what to write. Where a client writes something negative, we draft a reply for your approval — we never attempt to have it removed unless it breaches Google’s content policy on genuinely prohibited grounds, in which case we tell you what we are reporting and why.
Professional advertising rules
Different bodies impose different constraints on how a practice may describe itself. We build to the strictest reading, then relax only where your own compliance lead confirms it is fine.
Claims and results
Everything we publish about your firm has to be defensible. That means no invented statistics, no “award-winning” without the award, no “Ireland’s leading” anything, and no client outcome quoted without written permission and a source we can produce.
It applies to us too. Every figure on our own site — the 4.9 rating, the 300+ businesses, the screenshots on our results page — comes from a live dashboard or a public profile, and we will show you the source on request. Where a case study describes an outcome, the practice has read and approved the wording.
Data protection
For enquiries that come through your website, your practice is the data controller and Webnua is the processor. We act only on your documented instructions, and we do not use your prospect or client data for our own purposes — not for analytics, not to train anything, and never to market to your list.
In practice that means enquiry forms collect the minimum needed to respond, consent language is written plainly rather than buried, records are retained for as long as you specify, and a subject access or erasure request can be actioned by your account lead within the statutory window. Because prospective clients of an accountancy practice frequently disclose financial detail unprompted, enquiry content is treated as confidential by default and is visible only to the people working your account.
Sub-processors and the DPA
We sign a Data Processing Agreement with every client before go-live, incorporating Standard Contractual Clauses where any transfer outside the EEA arises. The current sub-processor list is below and we give thirty days’ notice of any addition, so you have time to object.
Ask your account lead, or email privacy@webnua.com, for a countersigned DPA and the current sub-processor register.
Security and uptime
Because the site runs on our platform rather than on hosting you have to maintain, patching, certificates and backups are ours to get right rather than something that quietly lapses.
Accessibility
Sites are built to WCAG 2.2 AA as standard: colour contrast that passes, every control reachable by keyboard, proper heading structure, labelled form fields, alternative text on meaningful images, and text that reflows without loss of content at 200% zoom.
This is not only a legal consideration. A meaningful share of the people looking for an accountant are over sixty, and a page that is hard to read on a phone loses them to the firm whose page is not.
What we ask of you
Three things, none of them onerous, all of which keep both of us safe.
