Correa Crawford & Associates
Website Privacy and Taxpayer Information Notice
Correa Crawford & Associates (“CCA,” “we,” “our,” or “us”) is committed to protecting the confidentiality, integrity, and appropriate use of personal information and tax return information entrusted to the firm. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard information in connection with our website and professional services.
1. Purpose and Scope
This Privacy Policy applies to information collected through our website, online forms, secure client portals, email, telephone, video conferences, in-person meetings, electronic signatures, document exchanges, and other interactions with CCA. It applies to website visitors, prospective clients, current and former clients, authorized representatives, beneficial owners, employees of client organizations, vendors, referral sources, and other persons whose information we receive in the course of our business.
This Policy is a website privacy notice and does not replace an engagement letter, consent required by federal tax law, authorization such as IRS Form 2848 or Form 8821, or any other agreement governing a particular professional service. Where a specific engagement letter, taxpayer consent, law, regulation, or professional obligation imposes a more protective or more specific requirement, that requirement will control.
Our services may involve U.S. federal, state, local, and cross-border tax matters. Because privacy and professional obligations can vary by service, jurisdiction, client type, and the nature of the information involved, references in this Policy to legal requirements are intended to describe the framework within which CCA operates and should not be read as a representation that every cited law applies to every client or every processing activity.
2. Information We Collect
Depending on the services requested, we may collect the following categories of information:
- Identifiers and contact information, such as name, mailing address, email address, telephone number, date of birth, taxpayer identification number, Social Security number, Individual Taxpayer Identification Number (ITIN), Employer Identification Number (EIN), passport or government-issued identification information, and signatures.
- Tax return information, including information furnished for, or derived in connection with, the preparation, review, filing, amendment, representation, planning, or analysis of a federal, state, local, or foreign tax return or tax matter.
- Financial and accounting information, including income, deductions, assets, liabilities, bank or financial account information, investment information, payroll data, books and records, financial statements, ownership information, capitalization data, and transaction records.
- Business and entity information, including formation documents, corporate records, partnership or shareholder information, beneficial ownership information, contracts, organizational charts, and information regarding related parties or affiliates.
- Immigration, residency, and cross-border information when relevant to a tax engagement, including citizenship, residency, travel, foreign asset, foreign account, and foreign entity information.
- Communications and professional records, including emails, messages, meeting notes, questionnaires, engagement documents, authorizations, correspondence with taxing authorities, and records of instructions or approvals.
- Website and device information, which may include Internet Protocol address, browser type, device type, operating system, pages viewed, referring pages, approximate location derived from IP address, cookie identifiers, and similar technical information.
We ask clients and website users not to transmit highly sensitive tax or financial records through ordinary website contact forms unless the form is specifically designed for secure transmission. When available, sensitive documents should be provided through the secure client portal or another method designated by CCA.
3. How We Collect Information
We may collect information directly from you when you contact us, request a consultation, complete a questionnaire, sign an engagement letter, upload documents, communicate with our team, make a payment, or otherwise provide information. We may also receive information from persons you authorize, including family members, employees, attorneys, financial institutions, payroll providers, bookkeepers, prior tax professionals, investment advisors, or other representatives.
Where appropriate and lawful, we may obtain information from government agencies, taxing authorities, public records, commercially available databases, or service providers used to verify identity, support compliance, prevent fraud, or perform services requested by a client.
4. How We Use Information
We use personal information and client information only for legitimate professional, operational, security, and legal purposes. Depending on the engagement, these purposes may include:
- Providing tax return preparation, tax planning, accounting, bookkeeping, payroll, entity, compliance, advisory, representation, and cross-border services.
- Establishing and administering client relationships, including conflicts checks, onboarding, engagement management, billing, collections, and client communications.
- Preparing and electronically filing returns and forms; communicating with the Internal Revenue Service, state or local taxing authorities, or other governmental bodies when authorized or permitted by law.
- Verifying identity, protecting accounts, detecting suspicious activity, preventing fraud, and maintaining information security.
- Meeting legal, regulatory, ethical, professional, insurance, record-retention, and risk-management obligations.
- Operating and improving our website, systems, client portal, internal processes, and service quality.
CCA does not sell taxpayer information or personal information. We do not use tax return information for unrelated marketing or disclose it to unrelated third parties except where the taxpayer has provided legally sufficient consent or where disclosure or use is otherwise expressly permitted by applicable law.
5. Special Protection for Tax Return Information
Tax return information is subject to special federal confidentiality restrictions. Internal Revenue Code Section 7216 generally prohibits a tax return preparer from knowingly or recklessly disclosing or using tax return information for a purpose other than preparing, or assisting in preparing, a tax return unless an exception applies or the taxpayer provides consent in the manner required by applicable Treasury Regulations. The implementing rules are principally found in Treasury Regulations Sections 301.7216-1 through 301.7216-3.
CCA treats taxpayer control over tax return information as a core confidentiality obligation. Where Section 7216 consent is required, a general website acknowledgment or acceptance of this Privacy Policy is not intended to substitute for the separate consent required by federal tax law. CCA will obtain any required consent separately and in the form and manner applicable to the proposed disclosure or use.
Unauthorized use or disclosure of tax return information may result in federal penalties. Internal Revenue Code Section 6713 provides civil penalties for certain unauthorized disclosures or uses, while Section 7216 is a criminal provision. These rules reinforce the importance of limiting access to tax return information and using it only for authorized professional purposes.
Certain disclosures or uses may be permitted without taxpayer consent under the Treasury Regulations, including specified disclosures necessary for return preparation, electronic filing, legal process, professional conflict reviews, or other activities described in the regulations. CCA evaluates such disclosures in light of the applicable rule and the circumstances of the engagement.
6. Professional Standards and Circular 230
Professionals who practice before the Internal Revenue Service may be subject to Treasury Department Circular 230, codified in 31 C.F.R. Part 10. Circular 230 establishes standards of conduct for attorneys, certified public accountants, enrolled agents, and other practitioners who represent taxpayers before the IRS, including duties relating to competence, diligence, conflicts of interest, client records, and professional responsibility.
CCA maintains professional processes intended to support the confidentiality, diligence, and responsible handling of client information required by applicable professional standards. Circular 230 is not itself a general consumer privacy statute, and this Privacy Policy does not rely on Circular 230 as the sole legal basis for CCA privacy practices. Rather, it forms part of the broader professional framework applicable to covered practitioners and engagements.
7. Information Security; GLBA and the FTC Safeguards Rule
Tax preparation firms can fall within the definition of a financial institution under the Federal Trade Commission Safeguards Rule, 16 C.F.R. Part 314, which implements information-security requirements under the Gramm-Leach-Bliley Act (GLBA) for covered financial institutions subject to FTC jurisdiction. The Safeguards Rule requires covered firms to develop, implement, and maintain an information security program appropriate to their size, complexity, activities, and the sensitivity of customer information they handle.
CCA maintains administrative, technical, and physical safeguards designed to protect customer information and other confidential information. Depending on the systems and risks involved, safeguards may include access controls, multifactor authentication, encryption, secure transmission methods, endpoint and network protections, vendor oversight, employee training, incident-response procedures, secure disposal practices, backups, and periodic review of security risks.
The Internal Revenue Service also publishes guidance for tax professionals regarding taxpayer data security, including IRS Publication 4557, Safeguarding Taxpayer Data. IRS guidance emphasizes that tax professionals should maintain a Written Information Security Plan (WISP) and implement safeguards appropriate to the information they maintain. CCA maintains information-security policies and procedures intended to address applicable requirements and guidance; however, this public Privacy Policy does not describe security controls in a level of detail that could compromise their effectiveness.
No method of transmission or storage can be guaranteed to be completely secure. Accordingly, while we use safeguards designed to reduce risk, we cannot promise absolute security. Clients are also responsible for protecting their own credentials, devices, email accounts, and access to the client portal, and should promptly notify CCA of suspected unauthorized access.
8. Client Portal, Electronic Communications, and Service Providers
CCA may use third-party technology and professional service providers to support secure document exchange, practice management, electronic signatures, tax preparation, accounting, payment processing, communications, cloud hosting, cybersecurity, analytics, and other business functions. Our client portal may be provided through Canopy or another platform selected by CCA. These providers may process information on our behalf subject to contractual, legal, technical, or confidentiality protections appropriate to the services they perform.
We seek to provide service providers only the information reasonably necessary for their role. We also consider the sensitivity of client information and the provider’s ability to protect it. Where the Safeguards Rule applies, covered financial institutions are responsible for taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to require safeguards by contract where required.
Email and ordinary text messaging may not provide the same protection as a secure client portal. Unless otherwise directed, users should avoid sending Social Security numbers, full tax returns, bank credentials, passwords, or other highly sensitive information through unencrypted email or website contact forms.
9. Disclosure of Information
CCA may disclose information in the following circumstances, subject to applicable confidentiality restrictions and any required consent or authorization:
- To the IRS, state or local tax authorities, or other governmental agencies in connection with an authorized filing, representation, response, election, application, or other professional service.
- To service providers, contractors, software platforms, cloud providers, payment processors, or professional vendors that support our operations and are subject to appropriate obligations concerning confidentiality and security.
- To attorneys, insurers, auditors, consultants, or other professional advisors when reasonably necessary to obtain advice, manage risk, address a claim, conduct a conflict review, or protect legal rights, and when permitted by applicable law.
- In response to lawful subpoenas, court orders, regulatory demands, or other legal process, or when disclosure is necessary to comply with law, protect rights or safety, or investigate suspected fraud or security incidents.
- In connection with a merger, acquisition, sale, reorganization, succession, or transfer of all or part of the practice, subject to applicable confidentiality duties and legal restrictions, including the special rules governing tax return information.
CCA does not disclose tax return information merely because a third party requests it. Where a disclosure requires taxpayer authorization or consent, CCA may require written documentation before releasing information.
10. Data Retention and Secure Disposal
CCA retains records for periods determined by applicable tax law, professional standards, engagement obligations, statutes of limitation, insurance requirements, litigation holds, business needs, and record-retention policies. Different categories of records may be retained for different periods. A request to delete information may therefore be denied or limited when retention is required or reasonably necessary for legal, professional, security, or risk-management purposes.
When records containing sensitive information are no longer required to be retained, CCA uses disposal methods intended to render the information unreadable, indecipherable, or otherwise inaccessible, consistent with applicable law and our information-security practices.
11. Texas Privacy and Data Security Requirements
CCA is based in, or conducts business in, Texas and therefore considers applicable Texas privacy and data-security requirements. The Texas Identity Theft Enforcement and Protection Act, including Texas Business & Commerce Code Chapter 521, requires covered businesses to maintain reasonable procedures to protect sensitive personal information from unlawful use or disclosure and contains requirements concerning secure disposal and notification following certain security breaches.
Texas law also contains data-breach notification obligations. Under current Texas Attorney General guidance, a breach affecting 250 or more Texas residents may trigger a reporting obligation to the Office of the Attorney General within the period specified by law, in addition to required notices to affected individuals. CCA maintains incident-response procedures intended to support assessment and notification obligations when they apply.
The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, grants certain rights to Texas consumers and imposes obligations on covered businesses that process personal data. The Act includes entity and data-level exemptions, including exemptions involving financial institutions and data governed by the Gramm-Leach-Bliley Act, and it generally exempts small businesses from many provisions subject to specific rules. Because application depends on the entity, data, and processing activity involved, CCA evaluates requests and obligations under the TDPSA in light of applicable exemptions and other governing law.
12. Your Privacy Choices and Rights
Depending on where you reside and the law applicable to the particular information, you may have rights to request access to, correction of, deletion of, or information concerning certain personal data. You may also have rights to opt out of certain processing activities or to withdraw consent where processing is based on consent. These rights are not absolute and may be limited by federal tax confidentiality rules, professional obligations, legal requirements, record-retention duties, security concerns, privileges, or exemptions under applicable law.
To submit a privacy request, contact CCA using the contact information published on our official website and clearly identify the nature of your request. We may need to verify your identity and authority before acting on a request. If you submit a request on behalf of another person, we may require documentation establishing your authority.
Nothing in this section permits a client or third party to require CCA to destroy records that we are legally or professionally required to maintain, or to obtain information protected by another person’s rights, privilege, confidentiality obligations, or applicable law.
13. Cookies, Analytics, and Website Technologies
Our website may use cookies, pixels, local storage, analytics tools, security technologies, and similar technologies to operate the site, remember preferences, understand traffic, detect abuse, improve performance, and evaluate how visitors interact with content. Some technologies may be provided by third parties. The categories of cookies used may change as our website evolves.
You can generally control cookies through your browser settings and, where available, through a website cookie preference tool. Blocking certain cookies may affect site functionality. CCA does not intend to use website analytics to obtain tax return information or to track sensitive client activity within a secure client portal for advertising purposes.
14. Cross-Border Information and International Clients
CCA serves clients whose tax and business affairs may span multiple jurisdictions. Information may therefore be received from or transmitted to persons, service providers, professional advisors, or governmental authorities located outside the United States when necessary to provide requested services and when permitted by applicable law. Cross-border matters may involve additional privacy, professional secrecy, data-localization, or transfer requirements.
Where a foreign privacy law applies to a specific engagement, CCA will address applicable requirements in light of the circumstances, the location of the individual, the nature of the service, contractual commitments, and available legal mechanisms. This Policy does not state that every foreign privacy regime applies to CCA or to every client engagement.
15. Children’s Privacy
Our website is directed to adults and business users and is not intended for children under 13. We do not knowingly solicit personal information from children through the public website. Information about a minor may nevertheless be processed when lawfully provided by a parent, guardian, or authorized client and when relevant to a tax or professional engagement, such as dependent information required for a tax return. Such information is handled as confidential client information.
16. Third-Party Websites
Our website may link to external websites, including government agencies, professional resources, software providers, financial institutions, or other third parties. A link does not mean that CCA controls or endorses the privacy, security, accuracy, or practices of that third party. Users should review the privacy notices and terms applicable to third-party sites before providing information.
17. Changes to this Privacy Policy
CCA may update this Privacy Policy from time to time to reflect changes in law, technology, business practices, services, or regulatory guidance. The updated version will be posted on our website with a revised “Last Updated” date. Material changes may be communicated in another reasonable manner when required by law or when CCA determines that additional notice is appropriate.
18. Contact Us
Questions about this Privacy Policy, our privacy practices, or a request concerning personal information may be directed to Correa Crawford & Associates through the contact information published on our official website. For security reasons, please do not include Social Security numbers, passwords, complete tax returns, or full financial account numbers in an initial privacy inquiry sent through a general website contact form.
19. Legal and Regulatory Framework Referenced in this Policy
This Policy is informed by legal and professional authorities relevant to tax professionals and information security, including, as applicable:
- Internal Revenue Code Section 7216 and Treasury Regulations Sections 301.7216-1 through 301.7216-3, concerning disclosure and use of tax return information by tax return preparers.
- Internal Revenue Code Section 6713, concerning civil penalties for certain unauthorized disclosures or uses of tax return information.
- Treasury Department Circular 230, 31 C.F.R. Part 10, governing practice before the Internal Revenue Service for covered practitioners.
- The Gramm-Leach-Bliley Act and the Federal Trade Commission Safeguards Rule, 16 C.F.R. Part 314, as applicable to covered financial institutions, including tax preparation firms within the FTC’s definition.
- IRS Publication 4557, Safeguarding Taxpayer Data, and related IRS guidance concerning Written Information Security Plans and taxpayer data protection.
- Texas Business & Commerce Code Chapter 521 and the Texas Identity Theft Enforcement and Protection Act, including applicable safeguards, disposal, and breach-notification requirements.
- The Texas Data Privacy and Security Act, to the extent applicable after consideration of statutory thresholds, exemptions, and the nature of the data involved.
The inclusion of a statute, regulation, publication, or professional standard in this section does not mean that every provision applies to every activity of CCA. Applicability depends on the facts, the services provided, the type of information involved, and the legal status of the firm or client.
Official Resources
- IRS – Section 7216 Information Center
- IRS – Office of Professional Responsibility and Circular 230
- FTC – Safeguards Rule
- FTC – Safeguards Rule: What Your Business Needs to Know
- Texas Attorney General – Texas Data Privacy and Security Act
- Texas Attorney General – Data Breach Reporting
Important: This Privacy Policy is intended for website publication and should be reviewed periodically and whenever CCA materially changes its services, technology providers, data practices, or jurisdictions served. It is not a substitute for engagement-specific consents, authorizations, or internal information-security policies.