Privacy Policy

Last updated: June 2026

1. Introduction

Welcome to ClearFact (“we”, “our”, or “us”), a trading name of Creobyte Ltd, a company registered in England and Wales under company number 17228907, with a registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

We are registered with the Information Commissioner’s Office (ICO) under registration number ZC167266.

This Privacy Policy explains how we collect, use, store, and protect personal data when you use our CRM and Client Portal software at clearfact.co.uk.

2. The Data We Collect

We process two distinct categories of personal data:

Adviser Data , information about you, our customer:

  • Name, firm name, email address, phone number
  • Billing and payment information (processed via Stripe , we never store full card details)
  • Account usage and activity data
  • Support correspondence

Client Data , information uploaded by you or your clients into the platform:

  • Identity documents, proof of address, financial records
  • Fact-find responses and mortgage/financial case data
  • Electronic signatures and document packs
  • SMS and email communication logs

We act as a Data Processor for Client Data. You, the adviser, remain the Data Controller and are solely responsible for the lawful basis on which you collect and process your clients’ personal data.

3. How We Use Your Data

We use Adviser Data to:

  • Provide, operate, maintain, and improve the ClearFact platform
  • Process subscription payments via Stripe
  • Send transactional system emails via Resend
  • Send SMS notifications on your behalf
  • Provide customer support
  • Monitor platform performance and security via PostHog analytics (aggregated, anonymised)

We use Client Data solely to:

  • Provide the CRM and client portal functionality you have subscribed to
  • Store and retrieve documents and fact-finds on your instruction
  • We do not analyse, share, sell, or use Client Data for any purpose beyond service delivery

4. Data Storage and Security

All personal data processed by ClearFact is stored exclusively on servers located within the United Kingdom:

  • Application servers: Vultr (London region)
  • File and document storage: Amazon Web Services (AWS London , eu-west-2)

Security measures include:

  • AES-256 encryption at rest for all stored data
  • TLS 1.2+ encryption in transit
  • Strict role-based access controls
  • Immutable audit trails on all data access events
  • Regular security testing and vulnerability assessments

5. Sub-processors

We use the following third-party sub-processors to deliver our service. Each is bound by data processing agreements and GDPR-compliant terms:

Sub-processor Purpose Location
Amazon Web Services (AWS) Document and file storage UK (eu-west-2)
Vultr Application hosting UK (London)
Stripe Payment processing UK/EU
Resend Transactional email delivery EU
The SMS Works SMS notifications UK

A full and up-to-date sub-processor list is maintained at clearfact.co.uk/sub-processors.

6. Cookies and Analytics

We use the following technologies on our marketing website (clearfact.co.uk):

  • PostHog , product analytics (anonymised, aggregated usage data only). No personal identifiers are transmitted.
  • Google Tag Manager , used to manage analytics tags on the marketing site only. Not used within the application portal.
  • Essential cookies , required for authentication and session management within the application.

You can manage cookie preferences via the cookie consent banner on our marketing site. See our Cookie Policy for full details.

7. Data Retention

  • Adviser Data is retained for the duration of your subscription plus 12 months following cancellation, after which it is permanently deleted.
  • Client Data is retained according to your own retention settings within the platform. You may delete client records at any time via the portal. Upon account cancellation, all Client Data is permanently deleted within 30 days.
  • Backup data is retained for a maximum of 30 days in encrypted backups before permanent deletion.

8. Your Legal Rights

Under UK GDPR you have the right to:

  • Access , request a copy of the personal data we hold about you
  • Rectification , request correction of inaccurate data
  • Erasure , request deletion of your personal data
  • Restriction , request we limit processing of your data
  • Portability , receive your data in a structured, machine-readable format
  • Object , object to processing based on legitimate interests

For Client Data, your clients must direct data rights requests to you as the Data Controller. You can action deletion requests directly within the ClearFact portal.

To exercise your rights as an adviser, contact us at [email protected].

9. Data Breaches

In the event of a personal data breach, we will notify the ICO within 72 hours where required under UK GDPR Article 33, and will notify affected Data Controllers (advisers) promptly to enable them to fulfil their own notification obligations.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by displaying a notice within the platform. Continued use of the service after changes take effect constitutes acceptance of the updated policy.

11. Contact Us

Creobyte Ltd (trading as ClearFact)

71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

Company number: 17228907

ICO registration: ZC167266

Email: [email protected]