Privacy Policy
Effective: July 16, 2026 · Last Updated: July 16, 2026
1. Information We Collect
A. Information You Provide to Us
Identifiers: name, mailing address, email address, telephone number, date of birth, marital status, dependents.
Government identifiers: Social Security Number (SSN), Individual Taxpayer Identification Number (ITIN), Employer Identification Number (EIN), driver's license or state ID, passport, tax ID numbers of related entities.
Financial information: bank account numbers, brokerage account numbers, investment holdings, real estate holdings, income from all sources, retirement accounts, expenses, deductions, credits, loans, prior tax returns, W-2s, 1099s, K-1s, and any documents necessary to prepare your tax returns or maintain your books.
Business information: entity type, ownership structure, governance documents, contracts, payroll records, vendor and customer information.
Employment and demographic information where relevant to your engagement (e.g., dependent care credits, retirement planning).
Court, trust, and estate information: beneficiary details, court filings, fiduciary accounting records, trust instruments, probate documents.
Communications: emails, phone messages, portal messages, notes from meetings, and any information you voluntarily share.
B. Information Collected Automatically When You Visit Our Website
IP address, browser type, device identifiers, operating system, referring URL, pages visited, and access times.
Cookies and similar tracking technologies (see Section 8 below).
If you submit our Contact form, we receive the information you enter.
C. Information From Third Parties
From your representatives: bookkeepers, attorneys, financial advisors, brokers, insurance agents, or family members you authorize.
From tax authorities: IRS, Franchise Tax Board (FTB), state and local tax agencies, when acting on your behalf under a properly executed Power of Attorney (IRS Form 2848 or state equivalents).
From service providers: Intuit ProConnect, QuickBooks Online, Bill.com, ADP, Egnyte, Microsoft, and similar platforms we use to deliver services.
From publicly available sources: Secretary of State filings, county assessor records, credit bureaus (only with your consent).
2. How We Use Your Information
We use your information only for legitimate business purposes:
To prepare federal, state, and local tax returns and related filings.
To provide bookkeeping, accounting, payroll, bill-pay, court accounting, trust accounting, business management, and advisory services.
To communicate with you about your engagement, deadlines, deliverables, and questions.
To respond to tax authority notices, audits, and examinations on your behalf.
To bill you and collect fees for services.
To comply with our legal, regulatory, professional, and ethical obligations (including IRS Circular 230, AICPA standards, and applicable state accountancy rules).
To detect, prevent, and address fraud, security incidents, and unauthorized access.
To improve our website and internal processes.
With your consent, for any other purpose disclosed to you at the time of collection.
We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes.
3. How We Disclose Your Information
We disclose your information only in the following circumstances:
To provide services: to sub-contractors, professional staff, and full-time contractors bound by written confidentiality agreements consistent with California Business & Professions Code §5063.3 (which limits when a CPA may disclose client information to third parties).
With your written consent: where §5063.3 requires it (e.g., disclosure to a lender, third-party financial advisor, or family member not authorized under a Power of Attorney).
To tax authorities: the IRS, FTB, and other tax agencies, only as required to represent you or file returns you have authorized.
To service providers: cloud-based software vendors (Intuit ProConnect, QuickBooks Online, Egnyte, Microsoft, Bill.com, ADP, and similar) under contracts requiring them to protect your information and use it only to provide services to us.
To comply with legal process: in response to a valid subpoena, court order, or government request, and only as permitted or required by law. We will notify you if legally permitted.
To protect rights and safety: to protect our firm, our clients, or the public from harm, fraud, or illegal activity.
In a business transition: if Laléa & Black is party to a merger, acquisition, or asset sale, information may be transferred to the successor entity subject to this Privacy Policy.
We never disclose your Social Security Number, tax return, or financial information to unrelated third parties without your written consent, except as required by law or professional standards.
4. Federal Law Compliance
A. Gramm-Leach-Bliley Act (GLBA) & FTC Safeguards Rule
As a "financial institution" under the GLBA (15 U.S.C. §6801 et seq.), we maintain a written Information Security Program designed to:
Ensure the security and confidentiality of client information.
Protect against anticipated threats or hazards.
Protect against unauthorized access or use that could harm any client.
Our program includes: designated Qualified Individual oversight, risk assessments, access controls (including multi-factor authentication), encryption of client data in transit and at rest, secure disposal, employee training, oversight of service providers, and incident response procedures — consistent with the FTC's revised Safeguards Rule (16 C.F.R. Part 314).
B. IRS Publication 4557 & Written Information Security Plan (WISP)
We maintain a Written Information Security Plan (WISP) as required for federal tax return preparers under IRS Publication 4557 and Publication 5708.
C. IRC §7216
Under Internal Revenue Code §7216 and Treasury Regulation §301.7216-3, we will not disclose or use any information you provide to us in connection with the preparation of your tax return for any purpose other than preparing the return, without your prior written consent.
D. IRC §6713
We understand that the unauthorized disclosure or use of tax return information is prohibited and subject to civil and criminal penalties.
E. Federal Trade Commission Act §5
We do not engage in unfair or deceptive practices with respect to your personal information.
5. State Law Compliance (California & Others)
A. California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA)
If you are a California resident, you have the following rights, subject to certain exceptions (including the GLBA exemption for personal information collected, processed, sold, or disclosed pursuant to the GLBA):
Right to Know: request the categories and specific pieces of personal information we have collected about you.
Right to Delete: request deletion of your personal information, subject to legal and professional record-retention requirements.
Right to Correct: request correction of inaccurate personal information.
Right to Opt Out of Sale or Sharing: we do not sell or share personal information as those terms are defined by the CPRA, but you may still submit a request.
Right to Limit Use of Sensitive Personal Information: you may direct us to limit our use of sensitive personal information to purposes specified in the CPRA.
Right to Non-Discrimination: we will not discriminate against you for exercising any CCPA/CPRA right.
Right to Data Portability: where technically feasible.
Important: Much of the information we collect from tax and accounting clients is exempt from the CCPA/CPRA because it is subject to the Gramm-Leach-Bliley Act (Cal. Civ. Code §1798.145(e)). However, we still honor your rights with respect to non-GLBA information.
To exercise your rights, contact us at privacy@laleablack.com or (310) 271-5749. We will verify your identity before responding (typically by matching two data points already on file). We will respond within 45 days as required by law.
You may also designate an authorized agent to make requests on your behalf. Written authorization required.
B. California Business & Professions Code §5063.3
As a California CPA firm, we may not disclose confidential client information to any third party without your written consent, except as expressly permitted by §5063.3 (e.g., in response to a subpoena, professional practice review, or ethics investigation).
C. Shine the Light Law (Cal. Civ. Code §1798.83)
California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.
D. California Online Privacy Protection Act (CalOPPA)
This Privacy Policy is our notice under CalOPPA. We honor "Do Not Track" browser signals by not tracking users across third-party websites for behavioral advertising purposes.
E. Other State Laws
If you reside in Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, or Virginia, similar rights may apply under your state's comprehensive privacy law. Contact us at privacy@laleablack.com to exercise those rights. Most comprehensive state privacy laws contain a GLBA exemption similar to California's.
F. New York SHIELD Act
We maintain reasonable administrative, technical, and physical safeguards for the personal information of New York residents.
G. State Data Breach Notification Laws
If a breach of security involving your personal information occurs, we will notify you and any applicable state attorney general in the manner and timeframe required by the relevant state law (all 50 states have breach notification statutes).
6. Data Security
We implement industry-standard administrative, technical, and physical safeguards to protect your information, including:
Encryption of data in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
Multi-factor authentication (MFA) on all client-data systems.
Role-based access controls; personnel access only information necessary to perform their duties.
Secure client portals for document exchange; we do not accept sensitive personal information via unencrypted email.
Regular security assessments, penetration testing, and vendor due diligence.
Employee training on privacy and information security, including annual refreshers.
Incident response and breach notification procedures compliant with federal and state law.
Despite these measures, no system is 100% secure. If you believe your interaction with us is no longer secure or your information has been compromised, contact us immediately at privacy@laleablack.com.
7. Data Retention
We retain your information for as long as necessary to provide services and to comply with our legal, professional, regulatory, and tax obligations:
Tax returns and supporting documents: minimum 7 years (some indefinitely for real estate basis, retirement basis, and gift tax records).
Bookkeeping records: minimum 7 years from the last date of service.
Engagement letters and client correspondence: minimum 7 years from the end of the engagement.
Court and trust accounting records: as required by the applicable court or state law (typically longer than 7 years).
Website logs and analytics data: typically 24 months.
When retention is no longer required, we securely destroy paper records (cross-shredding) and permanently delete or anonymize electronic records.
8. Cookies & Website Analytics
Our website uses cookies and similar technologies for:
Strictly necessary cookies: required to operate the site (e.g., session cookies).
Analytics cookies: to understand how visitors use our site (e.g., Squarespace built-in analytics, Google Analytics if enabled).
Functional cookies: to remember preferences.
You can control cookies through your browser settings. Blocking some cookies may impair site functionality. We honor Global Privacy Control (GPC) signals as opt-outs of sale/sharing under CCPA/CPRA.
9. Children's Privacy
Our website and services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have inadvertently collected such information, we will delete it promptly. Parents or guardians who believe we have collected information from a child may contact us at privacy@laleablack.com.
If you are a parent or guardian engaging us to prepare a tax return for a minor (e.g., a "kiddie tax" return), we collect the minor's information from you under COPPA's parental-consent exception.
10. Third-Party Links
Our website may contain links to third-party websites (e.g., IRS, FTB, professional resources). We are not responsible for the privacy practices of those sites. Please review their privacy policies before providing information.
11. International Users
Our services are directed to clients in the United States. If you access our website from outside the U.S., you understand your information will be transferred to, stored, and processed in the United States. We do not knowingly collect information from EU or UK residents; if the GDPR or UK GDPR applies to your relationship with us, additional rights may exist — contact us to discuss.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top will reflect the most recent revision. Material changes will be communicated to active clients via email. Your continued engagement with us after the effective date constitutes acceptance of the revised Policy.
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise any of your rights, or believe your information has been mishandled, contact us at:
Laléa & Black, LLP Attn: Privacy Officer 256 South Robertson Blvd, Suite 206 Beverly Hills, CA 90211
Email: info@laleablack.com Phone: (866) 222-6060 Ext 101 Fax: (310) 295-2247
For complaints, California residents may also contact the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General (oag.ca.gov). Residents of other states may contact their state Attorney General's office. All U.S. residents may file a complaint with the Federal Trade Commission (ftc.gov/complaint).
This Privacy Policy is intended to comply with applicable U.S. federal and state privacy and data protection laws. It is not intended as legal advice. For interpretation of your specific rights or obligations, consult legal counsel.