Last updated: 5 June 2026
This notice explains describes how the RSM Entities collect and process your personal data when downloading and using the myRSM. It should be read alongside the RSM UK Entities Privacy Policy, which provides further detail on how we handle personal data.
Purpose of the app
The myRSM is a secure platform used to facilitate the exchange of information and documents between you and RSM.
This notice relates only to the data collected and processed through the operation of the app itself. Any personal data or documents submitted or accessed through the app will be processed separately in accordance with:
- your client engagement letter or other agreement (if any) with us, and
- the relevant privacy notice
What data we collect through the app
When you use the app, we may collect:
- Account and identity data
such as your name, email address, and login activity - Technical and device data
such as your device type, operating system, app version, IP address, and approximate location - Usage and audit data
such as actions taken within the app and security logs associated with your account - Diagnostic and performance data
such as crash reports and device information (for example memory, storage, and other technical metrics) to help us maintain and improve the app - Authentication data
including login attempts, multi factor authentication, and session activity
Some of this data is collected automatically when you use the app. Depending on how you use the app, some of this data may be associated with your account or device.
How we use your data
We use this data to:
- Provide secure access to the app
- Authenticate users and protect against unauthorised access
- Monitor, maintain, and improve the app
- Meet our legal and regulatory obligations
Legal basis for processing
We rely on the following legal bases when processing your personal data through the app:
- Performance of a contract
where processing is necessary to provide access to the app and deliver services in line with your engagement with RSM - Legitimate interests
where processing is necessary to ensure the security, integrity, and ongoing operation of the app, including authentication, session management, monitoring, and system improvement - Legal obligations
where processing is required to comply with applicable laws and regulatory requirements
Third party services
We use trusted service providers to support the operation of the app, including identity, authentication, security and diagnostic services. These providers process personal data on our behalf under appropriate contractual and security controls. We do not use personal data collected through the app to track you across third party apps, websites, or services for advertising purposes.
Security and your responsibilities
We use appropriate security measures including:
- Multi factor authentication and biometric access (where enabled)
- Session management and inactivity timeouts
- Restricted access to systems and monitoring of activity
- Encryption in transit
You are responsible for maintaining the security of your device. This includes:
- Keeping your device protected with a passcode or biometric lock
- Ensuring your device software is kept up to date
- Preventing unauthorised access to your device
If your device is lost, stolen, shared, or compromised, or if you have any concerns about unauthorised access, you should contact your usual RSM contact as soon as possible so that access can be restricted or revoked. If you dispose of or sell your device, you are responsible for removing the app and ensuring any associated data is no longer accessible.
Important information about downloaded documents
If you choose to download documents from the myRSM app, these may be stored on your device or in your personal cloud storage outside of the app environment. Once downloaded, RSM cannot control how those documents are stored or secured. You are responsible for ensuring that any downloaded information is kept secure.
Data transfer
To the extent that the processing of personal data involves the transfer of such data to a territory that does not provide an adequate level of protection, we shall implement appropriate safeguards in accordance with applicable data protection legislation.
You may request details of any safeguards implemented from our Data Privacy Officer at: lee.mcgirr@rsmuk.com
Data storage and retention
We retain data only for as long as necessary to operate, secure, and improve the app, and in line with our wider retention policies.
Further details are available in the relevant RSM privacy policy for you.
Your rights
You have a number of rights in relation to your personal data, including:
- The right to request access to the personal data we hold about you
- The right to request correction of inaccurate or incomplete data
- The right to request deletion of your personal data in certain circumstances; if the app enables you to create an account, you may also request deletion of that account and associated app data, subject to any data we are required or permitted to retain for legal, regulatory, security, fraud prevention, or legitimate business purposes
- The right to restrict or object to processing, where applicable
- The right to data portability, allowing you to obtain and reuse your data
- The right to withdraw consent, where processing is based on consent
To exercise your rights or ask questions, contact: data.protection@rsmuk.com
We may need to verify your identity before responding to your request.
More information
For full details on how we use personal data, including how data is processed once submitted to RSM as part of our services, please see the relevant privacy notice.