Privacy Policy
Last updated: June 2026
1. Introduction
Welcome to ClearFact (“we”, “our”, or “us”), a trading name of Creobyte Ltd, a company registered in England and Wales under company number 17228907, with a registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
We are registered with the Information Commissioner’s Office (ICO) under registration number ZC167266.
This Privacy Policy explains how we collect, use, store, and protect personal data when you use our CRM and Client Portal software at clearfact.co.uk.
2. The Data We Collect
We process two distinct categories of personal data:
Adviser Data , information about you, our customer:
- Name, firm name, email address, phone number
- Billing and payment information (processed via Stripe , we never store full card details)
- Account usage and activity data
- Support correspondence
Client Data , information uploaded by you or your clients into the platform:
- Identity documents, proof of address, financial records
- Fact-find responses and mortgage/financial case data
- Electronic signatures and document packs
- SMS and email communication logs
We act as a Data Processor for Client Data. You, the adviser, remain the Data Controller and are solely responsible for the lawful basis on which you collect and process your clients’ personal data.
3. How We Use Your Data
We use Adviser Data to:
- Provide, operate, maintain, and improve the ClearFact platform
- Process subscription payments via Stripe
- Send transactional system emails via Resend
- Send SMS notifications on your behalf
- Provide customer support
- Monitor platform performance and security via PostHog analytics (aggregated, anonymised)
We use Client Data solely to:
- Provide the CRM and client portal functionality you have subscribed to
- Store and retrieve documents and fact-finds on your instruction
- We do not analyse, share, sell, or use Client Data for any purpose beyond service delivery
4. Data Storage and Security
All personal data processed by ClearFact is stored exclusively on servers located within the United Kingdom:
- Application servers: Vultr (London region)
- File and document storage: Amazon Web Services (AWS London , eu-west-2)
Security measures include:
- AES-256 encryption at rest for all stored data
- TLS 1.2+ encryption in transit
- Strict role-based access controls
- Immutable audit trails on all data access events
- Regular security testing and vulnerability assessments
5. Sub-processors
We use the following third-party sub-processors to deliver our service. Each is bound by data processing agreements and GDPR-compliant terms:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Document and file storage | UK (eu-west-2) |
| Vultr | Application hosting | UK (London) |
| Stripe | Payment processing | UK/EU |
| Resend | Transactional email delivery | EU |
| The SMS Works | SMS notifications | UK |
A full and up-to-date sub-processor list is maintained at clearfact.co.uk/sub-processors.
6. Cookies and Analytics
We use the following technologies on our marketing website (clearfact.co.uk):
- PostHog , product analytics (anonymised, aggregated usage data only). No personal identifiers are transmitted.
- Google Tag Manager , used to manage analytics tags on the marketing site only. Not used within the application portal.
- Essential cookies , required for authentication and session management within the application.
You can manage cookie preferences via the cookie consent banner on our marketing site. See our Cookie Policy for full details.
7. Data Retention
- Adviser Data is retained for the duration of your subscription plus 12 months following cancellation, after which it is permanently deleted.
- Client Data is retained according to your own retention settings within the platform. You may delete client records at any time via the portal. Upon account cancellation, all Client Data is permanently deleted within 30 days.
- Backup data is retained for a maximum of 30 days in encrypted backups before permanent deletion.
8. Your Legal Rights
Under UK GDPR you have the right to:
- Access , request a copy of the personal data we hold about you
- Rectification , request correction of inaccurate data
- Erasure , request deletion of your personal data
- Restriction , request we limit processing of your data
- Portability , receive your data in a structured, machine-readable format
- Object , object to processing based on legitimate interests
For Client Data, your clients must direct data rights requests to you as the Data Controller. You can action deletion requests directly within the ClearFact portal.
To exercise your rights as an adviser, contact us at [email protected].
9. Data Breaches
In the event of a personal data breach, we will notify the ICO within 72 hours where required under UK GDPR Article 33, and will notify affected Data Controllers (advisers) promptly to enable them to fulfil their own notification obligations.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by displaying a notice within the platform. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
Creobyte Ltd (trading as ClearFact)
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company number: 17228907
ICO registration: ZC167266
Email: [email protected]