Privacy Policy
Last updated · 21 August 2026
This Privacy Policy explains how ClientLoop handles personal data when you visit clientloop.digital, use the application at app.clientloop.digital, administer a ClientLoop workspace, or use a client portal to provide information to a business.
Summary. ClientLoop is a business-to-business platform for collecting documents, form responses, messages and approvals. For information placed in a Customer’s workspace, the Customer normally acts as controller and ClientLoop acts as its processor. ClientLoop acts as controller for its own account administration, billing, security, support, service analytics and marketing. We do not sell personal data.
1. Who we are
ClientLoop is a trading name of Pleesys Technology Limited, a company registered in England and Wales under company number 17350856, whose registered office is at 11 Rosemary Court, York, England, YO1 9UQ (“ClientLoop”, “we”, “us” or “our”).
For privacy enquiries or requests:
- Email: info@clientloop.digital
- Post: Pleesys Technology Limited, 11 Rosemary Court, York, England, YO1 9UQ
We have not appointed a statutory Data Protection Officer. Our contact for data-protection matters can be reached using the details above.
2. Who this policy covers
This policy covers:
- Customers: businesses and professionals that create or pay for a ClientLoop workspace;
- Team Members: people authorised by a Customer to administer or use its workspace;
- Clients: people invited by a Customer to upload documents, complete forms, exchange messages or acknowledge information;
- website visitors and prospective Customers; and
- people who contact us for support, sales or other enquiries.
ClientLoop is intended for business use and is not directed at children.
3. When ClientLoop is controller and processor
3.1 ClientLoop as controller
We act as controller when we determine why and how personal data is used, including for:
- account registration, authentication and workspace administration;
- subscription billing and account management;
- service security, abuse prevention, diagnostics and audit records;
- support and operational communications;
- our own website analytics and product measurement; and
- our own sales and marketing.
3.2 ClientLoop as processor
We generally act as processor for personal data that a Customer or its Clients place inside a workspace (“Workspace Content”), including uploaded files, form answers, client records, messages, notes and associated metadata. The Customer controls what it requests, who it invites, why the information is collected, how long it should be kept and which integrations receive it.
We process Workspace Content on the Customer’s documented instructions, including instructions given through its configuration and use of the Service, and under the data-processing terms incorporated into our Terms & Conditions.
If you are a Client and want to access, correct, restrict or delete Workspace Content, contact the business that invited you. We will assist that business where required.
4. Personal data we process
The exact information depends on how the Service is configured and used.
4.1 Account and Team Member data
We may process:
- name, email address, profile image and workspace role;
- password hash and email-verification status;
- authentication method, session information and security events;
- two-factor authentication preference, an encrypted authenticator secret where enabled, and hashed recovery credentials;
- legal acceptance evidence, including the Terms and Privacy Policy versions presented, acceptance timestamp, account identifier, IP address, browser information and integrity-verification data;
- workspace memberships, invitations, status and permissions;
- time zone, notification and service preferences; and
- support correspondence.
We do not store passwords in readable form.
4.2 Customer and workspace data
We may process:
- business or trading name;
- workspace name, subdomain and custom domain;
- logo, favicon, colours, fonts and other brand assets;
- sender names and email configuration;
- subscription plan, usage, storage and seat information;
- Stripe customer and subscription identifiers and payment status;
- integration settings, encrypted integration credentials and API-key metadata;
- webhook configuration, event payloads, delivery status, responses and errors; and
- where an API request supplies an idempotency key, a stored copy of the resulting response so that a repeated request returns the same result.
Payment-card details are entered with and processed by Stripe. The ClientLoop application does not store full card numbers.
4.3 Client and Workspace Content
Customers decide what they collect. The Service supports:
- client name, email address, telephone number, company and status;
- tags, notes, colours, external references, source information and arbitrary metadata;
- request titles, descriptions, instructions, categories, priorities, due dates and review notes;
- files and documents, including their contents, filenames, sizes, types, storage identifiers and upload timestamps;
- structured and free-text form answers;
- typed-name signature fields;
- client and Team Member messages, file comments, internal notes and saved replies;
- acknowledgements, approvals, rejections and change requests; and
- scheduled workflow and reminder information.
Because Customers can design forms and upload arbitrary business documents, Workspace Content may include postal addresses, identity documents, financial information, business information, employment information, legal records or other information not represented by a dedicated field in our database.
4.4 Special-category and criminal-offence data
Workspace Content may include health information or other special-category data under Article 9 UK GDPR or EU GDPR, or criminal-offence data under Article 10, if a Customer chooses to collect it.
ClientLoop does not require Customers to collect these categories. The Customer is responsible for identifying an appropriate lawful basis and, where applicable, an Article 9 condition, compliance with rules for criminal-offence data, appropriate transparency information and any sector-specific duties.
4.5 Technical, activity and security data
When the Service is accessed, we and our infrastructure providers may process:
- IP address, request headers, browser and device information;
- timestamps, pages or routes accessed and performance information;
- login, authentication, rate-limit and security events;
- actions performed in a workspace and identifiers of the relevant actor and record;
- file-access and download activity; and
- error, diagnostic and delivery logs.
Selected activity records expressly include IP addresses. IP addresses, email addresses or internal identifiers may also be used temporarily as rate-limit keys.
4.6 Integration data
When a Customer enables an integration, we may process:
- Slack: a customer-provided webhook address and notifications containing request, client, deadline, status, filename and workspace-link information;
- Asana: an access token, project identifiers, request and client details, due dates, status and related task activity;
- Calendly: an access token and signing key, attendee name and email, event type, meeting name, time and Calendly identifiers;
- customer webhooks: the endpoint, signing secret, selected event payloads, responses and delivery logs; and
- information returned by those services that is needed to operate or diagnose the connection.
Customers control whether these connections are enabled.
5. How and why we use personal data
Where ClientLoop acts as controller, we use personal data as follows:
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create, authenticate and administer accounts | Account, membership and authentication data | Performance of a contract |
| Record and demonstrate acceptance of our legal terms | Account identifier, policy versions, timestamp, IP address, browser and integrity data | Performance of a contract; legitimate interests |
| Provide subscriptions and manage billing | Account, plan, usage and Stripe identifiers | Performance of a contract; legal obligation |
| Send essential invitations, reminders, security and service messages | Names, email addresses, request and account information | Performance of a contract; legitimate interests |
| Provide support and resolve incidents | Account, correspondence, logs and relevant Workspace Content supplied for support | Performance of a contract; legitimate interests |
| Protect the Service, prevent abuse and enforce our terms | Authentication, usage, IP, activity and security data | Legitimate interests; legal obligation |
| Measure and improve reliability and usability | Technical, performance and usage data | Legitimate interests; consent where required for the relevant technology |
| Send our own marketing | Contact details and preferences | Consent or legitimate interests where permitted |
| Establish, exercise or defend legal claims and meet legal obligations | Account, billing, audit and correspondence data | Legal obligation; legitimate interests |
Our legitimate interests include operating a secure and commercially viable service, preventing fraud, diagnosing faults and improving the Service. We consider the effect on individuals before relying on this basis.
Where ClientLoop acts as processor, the Customer determines the lawful basis for the processing.
6. How we obtain personal data
We receive personal data:
- directly from Customers, Team Members, Clients and website visitors;
- from another Team Member who creates an account invitation or client record;
- from Stripe in connection with subscription billing;
- from Resend in connection with email delivery;
- from Calendly, Asana, Slack or another customer-enabled integration;
- from browsers, devices and infrastructure when the Service is accessed; and
- from public website content when a Customer asks the branding tool to analyse a website it identifies.
7. Who receives personal data
We do not sell personal data or disclose it for third-party behavioural advertising.
7.1 Service providers
The following services are used or supported by the current implementation. A provider processes personal data only when the relevant feature is deployed, configured or used.
| Provider or category | Purpose | When used |
|---|---|---|
| Vercel | Hosting for the application at app.clientloop.digital and workspace subdomains, private Blob file storage, custom domains, and usage and performance measurement | Core Service; measurement components are present in the application |
| Cloudflare | Hosting and content delivery for the marketing website at clientloop.digital, and marketing-site analytics | Core for the marketing website; analytics only after consent |
| Neon | Core application database (PostgreSQL) | Core Service |
| Stripe | ClientLoop subscription billing and customer billing portal | When a paid subscription or billing portal is used |
| Resend | Transactional email delivery | When the Service sends email |
| Upstash | Rate limiting and custom-domain cache/mapping | When configured for the application |
| Cloudmersive | Malware scanning of uploaded files | Only when malware scanning is configured |
| PostHog EU | Marketing-site analytics | Only after analytics consent |
| Tawk.to | In-application support chat | Only where the support-chat integration is configured |
We also use professional advisers and other suppliers where reasonably necessary to operate the business, subject to appropriate confidentiality and data-protection obligations.
Further details of relevant processing locations and safeguards are available from info@clientloop.digital. Customers may also ask to receive notice of material new subprocessors.
7.2 Customer-controlled recipients
Slack, Asana, Calendly and customer-configured webhook destinations are connected at the Customer’s choice. When enabled, relevant Workspace Content is sent to the Customer’s account or chosen endpoint on its instruction. Those recipients operate under their own terms and privacy arrangements. Disconnecting an integration stops future transmissions but does not retrieve or delete information already received by the third party.
Customers must assess whether a destination is suitable before connecting it, restrict payloads to what is necessary and protect credentials and signing secrets.
7.3 Other disclosures
We may also disclose personal data:
- to a Customer that controls the relevant Workspace Content;
- to competent authorities, regulators or courts where required by law;
- to protect the rights, safety or security of ClientLoop, our users or others;
- to professional advisers under duties of confidentiality; or
- to a purchaser, investor or successor in connection with a corporate transaction, subject to appropriate safeguards.
If we receive an intellectual-property complaint, we may share the notice, supporting evidence and complainant contact details with the affected Customer or uploader, professional advisers, insurers or competent authorities where reasonably necessary to investigate, resolve or defend the complaint.
8. International transfers
The application, its database and uploaded files are hosted in the United Kingdom: application compute runs in London, the database is hosted in London, and file storage is located in London.
Some providers or their support operations may nonetheless process data outside the United Kingdom or European Economic Area. Where restricted transfers are made, we use an available lawful mechanism as applicable, such as an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where appropriate.
Customer-controlled integrations may transfer information to locations selected by the Customer. The Customer is responsible for assessing and documenting those transfers where it acts as controller.
9. Security
Measures implemented in the Service include:
- TLS/HTTPS for data in transit;
- logical separation of each Customer’s workspace data, enforced by tenant-scoped access controls throughout the application, together with an automated check that monitors database queries for a missing workspace filter;
- tenant-scoped access controls and role-based permissions;
- restriction of production and administrative access to a limited number of authorised personnel on a need-to-know basis;
- passwords stored as bcrypt hashes;
- optional time-based one-time-password or email-code two-factor authentication;
- encrypted storage of authenticator secrets and supported third-party credentials;
- private file storage and authenticated file streaming;
- random, hashed and time-limited client magic links;
- signed client sessions and temporary file links;
- file size, extension, content-type and executable-signature checks;
- optional specialist malware scanning before an upload is accepted and made available;
- API-key hashing, key revocation, rate limiting and idempotency controls;
- signed outbound webhooks and verification of supported inbound webhook signatures;
- HTTPS restrictions and protections against access to private networks for website analysis;
- security headers, audit records and file-access logging; and
- production configuration checks for important secrets and service dependencies.
Files uploaded through the direct-upload flow may first enter private temporary Blob storage so that server-side validation and, where enabled, malware scanning can take place. A rejected file is not made available through ClientLoop and deletion is attempted.
No security system or malware scanner can detect every threat. Customers and Clients remain responsible for using appropriate endpoint protection and for checking files before opening them.
The application encrypts selected security and integration secrets. We do not describe all Workspace Content as being application-level encrypted at rest. Infrastructure providers may apply their own storage-level protections under their services and contracts.
10. Personal data breaches and incident response
No provider can guarantee that security measures will never be defeated. If an actual or suspected security incident occurs, we operate an incident-response process designed to detect, contain, assess, remediate and document it and to preserve relevant evidence.
Where ClientLoop acts as controller and a personal-data breach is likely to result in a risk to individuals, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 UK GDPR (or the equivalent obligation under the EU GDPR where it applies). Where a breach is likely to result in a high risk to affected individuals, we will also inform those individuals without undue delay.
Where ClientLoop acts as processor, we will notify the affected Customer without undue delay after becoming aware of a personal-data breach affecting its Workspace Content and will provide information reasonably available to us to help the Customer meet its own notification obligations. Responsibility for assessing the breach and notifying regulators and individuals in respect of Customer-controlled Workspace Content rests with the Customer as controller.
Notifications may be provided in phases as information becomes available. Providing a notification is a compliance step and is not an admission of fault or liability.
To contain an incident we may, among other measures, rotate or revoke credentials and API keys, invalidate sessions and magic links, suspend accounts, endpoints, integrations or features, block traffic or restrict access while we investigate.
If, despite the separation measures described in Section 9, an incident affects data belonging to more than one Customer, each affected Customer will be notified as described above and the incident will be handled for each Customer’s data under that Customer’s instructions and applicable law.
If you believe you have found a security vulnerability or suspect unauthorised access, report it promptly to info@clientloop.digital.
11. Retention and deletion
We keep personal data only for as long as reasonably necessary for the relevant purpose, subject to Customer instructions and legal obligations.
- Accounts and workspace administration: normally retained while the account or workspace is active and afterwards only as needed for legal, security, billing, dispute-resolution or operational purposes.
- Workspace Content: retained while the workspace is active unless the Customer deletes it or instructs us otherwise. The application does not currently apply a general age-based deletion rule to all completed requests and files.
- Activity records: certain workspace activity logs are automatically purged using the retention period associated with the Customer’s Plan. The current application configuration uses 90 days for Free, 365 days for Pro and no automatic age-based activity-log purge for Enterprise. These periods apply to covered activity logs, not to all Workspace Content. If a paid subscription lapses, is cancelled or is not renewed, the period associated with the Free Plan applies. Following a Plan downgrade, purging is deferred for a grace period of 60 days.
- Billing and business records: retained for the period required by applicable tax, accounting and company law.
- Integration and delivery logs: retained while needed to operate, secure and troubleshoot the relevant feature, subject to deletion and legal requirements.
- Operational records: webhook delivery records (including the event payload sent and the response received), in-app notifications, and stored API idempotency results are retained for the life of the workspace and are removed when the workspace is deleted.
- Legal acceptance and contract evidence: retained for the life of the agreement and afterwards for the period reasonably required to demonstrate the agreement and establish, exercise or defend legal claims. These records are kept even if the related account is later deleted.
- Records of discontinued features: historical records associated with features that have been withdrawn (including former payment-request records) are retained where required for tax, accounting, dispute-resolution or other legal purposes.
- Marketing consent: retained until withdrawn or the recorded choice expires under the consent mechanism.
A Customer can delete an individual client record or a workspace. The application removes the relevant database records and attempts to delete associated stored files. These actions are intended to be irreversible from the application, but residual copies may remain temporarily in provider recovery systems or where an external deletion attempt fails. We may retain limited information where required by law or necessary to establish, exercise or defend legal claims.
A Customer can delete an individual client record directly in the application, which removes that person’s record together with their requests, files and form responses.
Deletion of a ClientLoop user account (an account owner or Team Member) is currently handled as a support request: email info@clientloop.digital from the account’s address and we will verify the request and action it within the timescales that apply to erasure requests, subject to the retention exceptions described in this Section. Removing a Team Member from a workspace ends their access to that workspace but does not by itself delete their user account.
Customers should export information they require before deleting records, ending their subscription or requesting termination. ClientLoop does not promise a complete post-termination export window unless separately agreed in writing.
12. Cookies, local storage and analytics
We use:
- strictly necessary cookies and storage for authentication, client portal sessions, security and remembering privacy choices;
- PostHog EU and Cloudflare Web Analytics on the marketing website only after the visitor grants analytics consent through the cookie banner; and
- Vercel Analytics and Speed Insights in the application for service usage and performance measurement.
The marketing-site choice is stored in local storage for up to 365 days. PostHog may set first-party cookies when analytics is enabled. Withdrawing consent through the Cookies control stops future consent-based marketing-site analytics and removes the PostHog cookies targeted by the consent tool.
Vercel’s application measurement components may process technical request, page and performance information. We do not use these tools for third-party advertising. Where consent is legally required for a measurement technology, we will request it before using that technology.
Browser settings can also block or delete cookies, although blocking necessary cookies may prevent parts of the Service from working.
A full list of the cookies and similar technologies we use, their purposes, durations and how to control them is set out in our Cookie Policy.
13. Your data-protection rights
Depending on the circumstances, you may have rights to:
- be informed about processing;
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests or for direct marketing;
- receive certain data in a portable format;
- withdraw consent without affecting earlier lawful processing; and
- complain to a supervisory authority.
To exercise a right concerning data for which ClientLoop is controller, email info@clientloop.digital. We may verify your identity and may apply lawful exceptions. We normally respond within one month, subject to any permitted extension.
For Workspace Content controlled by a Customer, contact the Customer first. We will assist it as required by our processor obligations.
In the UK, you may complain to the Information Commissioner’s Office at ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in your country of residence, place of work or the place of the alleged infringement. We would appreciate the opportunity to address your concern first, but this does not affect your right to complain.
14. US state privacy disclosures
This section provides additional information for residents of US states with comprehensive privacy laws (including California, Virginia, Colorado, Connecticut, Texas and Utah), to the extent those laws apply to our processing. Terms such as “personal information”, “sell”, “share” and “sensitive personal information” have the meanings given in the applicable state law.
14.1 What we collect and why
In the preceding 12 months we have collected the categories of personal information described in Section 4, which correspond broadly to: identifiers (name, email address, IP address, account identifiers); commercial information (subscription, plan and billing records); internet or other electronic network activity (usage, log, device and security information); professional or employment-related information (business name, workspace role); and sensitive personal information limited to account log-in credentials, which are stored only in hashed or encrypted form and used solely to authenticate you. The sources are described in Section 6, the purposes in Section 5 and the categories of recipients in Section 7.
14.2 No sale or sharing
We do not sell personal information and we do not share personal information for cross-context behavioural advertising, and we have not done either in the preceding 12 months. We do not use or disclose sensitive personal information for purposes other than those permitted for providing the Service, so no “right to limit” choice is required. Because there is no sale or sharing, there is no opt-out to exercise; our marketing-site analytics additionally run only after opt-in consent and respect the browser Do Not Track signal.
We do not knowingly sell or share the personal information of anyone under 16.
14.3 Your rights
Depending on your state, you may have the right to know or access the personal information we hold about you, obtain a portable copy, correct inaccuracies, delete it, and not receive discriminatory treatment for exercising these rights. Submit a request to info@clientloop.digital. We will verify the request using information associated with your account or prior dealings with us, and may ask for further information where necessary. An authorised agent may submit a request on your behalf with evidence of authority; we may still verify directly with you.
If we decline a request, we will explain why. Where your state provides a right of appeal, you may appeal by replying to our decision, and we will respond within the statutory period. If the appeal is unsuccessful, you may contact your state Attorney General.
14.4 Workspace Content
For personal information inside a Customer’s workspace, we act as a service provider or processor on the Customer’s behalf. If your relationship is with a business that uses ClientLoop, direct requests about that information to the business; we will assist it as our contract requires.
15. Marketing choices
You can unsubscribe from our marketing emails using the link in the message or by contacting us. Essential account, security, billing and service messages are not marketing and may continue while you use the Service.
We do not use Workspace Content to advertise to Clients.
16. Automated decisions and artificial intelligence
The current Service does not use artificial intelligence to make decisions about individuals and does not carry out solely automated decision-making that produces legal or similarly significant effects.
If we introduce an AI-assisted feature or materially change this position, we will update this policy and provide any additional information or controls required by law before the relevant processing begins.
17. Children
The Service is intended for businesses and people aged 18 or over. We do not knowingly create accounts for children. A Customer must not use ClientLoop to collect children’s data unless it has assessed the legal requirements and configured appropriate notices, permissions and safeguards.
18. Changes to this policy
We may update this policy to reflect changes to the Service, law or our providers. We will update the date above and take reasonable steps to notify Customers of material changes. Each published version of this policy is assigned an immutable version identifier; the version presented at registration is recorded as part of the acceptance evidence described in Section 4.1, and a material change may require renewed acknowledgement in the application.
19. Contact
Questions, requests or complaints:
- info@clientloop.digital
- Pleesys Technology Limited, company number 17350856
- 11 Rosemary Court, York, England, YO1 9UQ
This policy should be read with our Terms & Conditions, including the data-processing terms that apply where ClientLoop acts as a processor.