Privacy Policy
Last Updated: January 1, 2025
KohariGonzalez Oneyear&Brown, CPAs & Advisors ("KGOB," "we," "us," or "our") is committed to protecting the privacy and confidentiality of our clients' personal and financial information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you engage our professional services or visit our website.
As a licensed CPA firm in North Carolina, we are bound by professional ethical standards and federal and state regulations governing the confidentiality of client information. This policy is designed to comply with the North Carolina State Board of CPA Examiners rules (21 NCAC 08N), the AICPA Code of Professional Conduct, the Gramm-Leach-Bliley Act (GLBA), FTC Safeguards Rule, IRS Publication 4557, and North Carolina data breach notification laws (N.C. Gen. Stat. § 75-65).
Contact Information
Office Address
2740 East WT Harris Blvd, Suite 240
Charlotte, NC 28213
Phone
1-844-499-3355
relief@kgob.com
Privacy Officer
privacy@kgob.com
1. Information We Collect
Personal Identification Information
- Full legal name, date of birth, and Social Security Number (SSN)
- Employer Identification Number (EIN) for businesses
- Driver's license or state identification number
- Passport information (if applicable)
- Contact information (address, phone, email)
Financial Information
- Bank account and routing numbers
- Income statements (W-2s, 1099s, K-1s)
- Investment and brokerage account information
- Real estate records and mortgage information
- Business financial statements and records
- Credit card information (for payment processing only)
- Prior tax returns and IRS correspondence
Tax-Related Information
- IRS account transcripts and tax history
- State tax records and filings
- Deduction and credit documentation
- Estimated tax payment records
- IRS notices and correspondence
Methods of Collection
We collect information through:
- Direct submission from clients (in-person, mail, email, secure portal)
- Third-party sources with your authorization (IRS, state agencies, financial institutions)
- Website forms and secure client portals
- Phone conversations and video consultations
2. How We Use Your Information
Primary Uses
- Preparing and filing federal and state tax returns
- Conducting IRS Peace-of-Mind Reviews and transcript analysis
- Providing tax planning and advisory services
- Representing clients before the IRS and state tax authorities
- Preparing financial statements and accounting reports
- Responding to IRS notices and correspondence
Administrative Uses
- Client billing and payment processing
- Scheduling appointments and managing engagements
- Communicating about your services and deliverables
- Quality assurance and peer review compliance
- Maintaining required professional records
3. Confidentiality Commitment
In accordance with 21 NCAC 08N .0205 and the AICPA Code of Professional Conduct Section 1.700, we shall not disclose any confidential information obtained in the course of a professional engagement except with the consent of the client.
Limited Exceptions to Confidentiality
We may disclose your information without your consent only in the following narrowly defined circumstances:
- Court Order or Subpoena: When legally compelled by a valid court order or subpoena. We will notify you before disclosure when legally permitted.
- IRS or State Tax Authority Inquiries: When required to respond to official tax authority requests as part of your tax representation.
- NC Board of CPA Examiners Investigation: In connection with enforcement actions by the North Carolina State Board of CPA Examiners.
- Professional Standards Compliance: As required by AICPA peer review or quality control standards (without identifying confidential client information).
- Legal Requirements: When disclosure is mandated by federal or state law.
- Client Authorization: When you have provided explicit written consent for disclosure.
4. Information Security Safeguards
We maintain a comprehensive Written Information Security Plan (WISP) in compliance with the FTC Safeguards Rule (16 C.F.R. Part 314) and IRS Publication 4557. Our security measures include:
Administrative Safeguards
- • Designated Security Officer
- • Employee confidentiality agreements
- • Annual security training
- • Background checks
- • Access termination procedures
Technical Safeguards
- • AES-256 encryption (data at rest)
- • TLS 1.2+ encryption (transmission)
- • Multi-factor authentication
- • Firewall & intrusion detection
- • Regular security updates
Physical Safeguards
- • Locked file storage
- • Restricted office access
- • Cross-cut shredding
- • Visitor log procedures
- • Secure document destruction
5. Data Retention
We retain your information in accordance with professional standards and legal requirements:
- Tax-related records: Minimum 7 years from the date of filing or the date the tax was due, whichever is later.
- Engagement files: Minimum 5 years after completion of the engagement.
- IRS representation records: Retained for the longer of 7 years or until all matters are resolved.
- Client-provided original documents: Returned to you upon completion of services or upon request.
Upon expiration of the retention period, records are securely destroyed using cross-cut shredding for paper documents and certified data wiping for electronic files.
6. Your Rights
You have the following rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Correction: You may request correction of any inaccurate information.
- Right to Your Records: You may request return of client-provided records at any time (per 21 NCAC 08N .0305).
- Right to Portability: You may request your information in a transferable format.
- Right to Deletion: You may request deletion of your information, subject to our legal retention requirements.
To exercise any of these rights, please contact our Privacy Officer at privacy@kgob.com or call 1-844-499-3355. We will respond to all requests within 30 days.
7. Data Breach Notification
In compliance with the North Carolina Identity Theft Protection Act (N.C. Gen. Stat. § 75-65), if we discover unauthorized access to your personal information that creates a material risk of harm, we will:
- Notify you within 45 days of discovering the breach
- Describe the types of information involved
- Explain the steps we are taking to address the breach
- Provide recommended steps for your protection
- Offer credit monitoring services when appropriate
- Notify the North Carolina Attorney General as required by law
8. Third-Party Service Providers
We may share your information with carefully selected service providers who assist us in delivering services, including:
- Tax preparation software providers
- Secure cloud hosting and backup services
- Electronic filing services (IRS-authorized e-file providers)
- Secure document portal services
- Payment processing services
All service providers are required to maintain substantially similar security standards and have executed data processing agreements that protect your information. We retain the right to audit our service providers for compliance.
9. Regulatory Compliance
This Privacy Policy complies with:
- 21 NCAC 08N – North Carolina Administrative Code Professional Ethics and Conduct
- AICPA Code of Professional Conduct – Section 1.700 Confidential Client Information Rule
- Gramm-Leach-Bliley Act (GLBA) – 15 U.S.C. § 6801-6809
- FTC Safeguards Rule – 16 C.F.R. Part 314
- IRS Publication 4557 – Safeguarding Taxpayer Data
- N.C. Gen. Stat. § 75-65 – North Carolina Data Breach Notification Law
10. Filing Complaints
If you have concerns about our privacy practices, you may contact:
Our Privacy Officer
Email: privacy@kgob.com
Phone: 1-844-499-3355
NC Board of CPA Examiners
1101 Oberlin Road, Suite 104
Raleigh, NC 27605
Phone: (919) 733-4222
NC Attorney General
Consumer Protection Division
Website: ncdoj.gov
Federal Trade Commission
Website: ftc.gov/complaint
11. Policy Updates
We review and update this Privacy Policy at least annually. Material changes will be communicated to clients within 30 days of the effective date. The "Last Updated" date at the top of this policy indicates when it was most recently revised. Continued use of our services after changes become effective constitutes acceptance of the revised policy.
This firm is licensed by the North Carolina State Board of CPA Examiners pursuant to N.C. General Statutes Chapter 93.
© 2025 KohariGonzalez Oneyear&Brown, CPAs & Advisors. All rights reserved.
