Terms & Conditions
Last updated · 21 August 2026
These Terms & Conditions (“Terms”) govern access to and use of the ClientLoop website at clientloop.digital, the application at app.clientloop.digital, its client portals, API, webhooks and related services (together, the “Service”).
Summary. ClientLoop provides business software for requesting, collecting, sharing and reviewing client documents and information. Customers remain responsible for what they request, upload, send, approve and automate. The Service is not a substitute for professional judgement, independent verification, backup procedures or regulatory compliance.
1. The agreement
These Terms form a contract between:
- Pleesys Technology Limited, a company registered in England and Wales under company number 17350856, whose registered office is at 11 Rosemary Court, York, England, YO1 9UQ, trading as ClientLoop (“ClientLoop”, “we”, “us” or “our”); and
- the person or organisation accepting these Terms (“Customer”, “you” or “your”).
If you use the Service for an organisation, you confirm that you have authority to bind it. If you do not have that authority, you must not accept these Terms or administer its workspace.
These Terms incorporate our Privacy Policy, any order form we accept, the Plan information presented at purchase and the data-processing terms in Section 19. If an accepted order form expressly conflicts with these Terms, the order form prevails for that conflict.
The Service is intended for business and professional use. You must be at least 18 and able to form a binding contract. If mandatory consumer rights apply despite this business-use restriction, nothing in these Terms removes those rights.
By selecting the acceptance box during registration, creating an account, subscribing or otherwise using the Service, you agree to these Terms. You consent to contracting electronically. We may record the version of the Terms and Privacy Policy presented to you, the time of acceptance, your account identifier, IP address, browser information and a tamper-evident record of that evidence. Those records may be used to demonstrate acceptance, administer the agreement, prevent fraud and establish, exercise or defend legal claims.
2. Definitions
- “API” means the documented ClientLoop application programming interface, API keys and related developer materials.
- “Authorised User” means a Team Member whom the Customer permits to use its Workspace.
- “Client” means a person whom the Customer records or invites to a client portal.
- “Content” means files, documents, form definitions and answers, messages, comments, notes, branding, data and other material submitted to or generated through the Service by or for the Customer.
- “Customer System” means a system, application, endpoint or third-party account controlled or selected by the Customer.
- “Documentation” means the instructions and technical material we make available for the Service.
- “Integration” means a connection between the Service and a third-party service, including Slack, Asana or Calendly.
- “Plan” means the subscription tier, entitlements, quotas and fees selected by the Customer.
- “Team Member” means an owner, administrator, manager, viewer or other person associated with a Workspace.
- “Webhook” means an event notification sent by ClientLoop to a Customer System.
- “Workspace” means the Customer’s logically separated environment in the Service.
3. The Service
Depending on the Plan and current feature availability, the Service may allow a Customer to:
- manage Clients and branded client portals;
- request documents and structured information;
- build forms and reusable request resources;
- share files and request acknowledgements;
- receive private file uploads and form submissions;
- send manual or automatic reminders;
- schedule recurring or future requests;
- exchange client messages and internal notes;
- approve, reject or request changes to a request;
- search records and view activity information;
- invite Team Members and assign roles;
- use an API and Webhooks; and
- connect supported Integrations.
Feature descriptions are not a promise that every feature will be available on every Plan, in every territory or indefinitely. We may improve, replace, restrict, suspend or discontinue features. We will use reasonable efforts to give advance notice where a material change substantially removes paid functionality, unless urgent security, legal, provider or operational circumstances make notice impracticable.
ClientLoop is an information-collection and workflow tool. It is not a document-verification service, electronic identity provider, qualified electronic-signature service, records-management system, regulated archive, payment institution, professional adviser or general-purpose backup service.
4. Accounts, Workspaces and security
You must:
- provide accurate and current account information;
- keep passwords, magic links, API keys, recovery codes and integration credentials confidential;
- use appropriate role assignments and promptly remove access that is no longer required;
- maintain the security of your devices, email accounts, domains and Customer Systems;
- notify us promptly at info@clientloop.digital of suspected unauthorised access; and
- ensure every Authorised User complies with these Terms.
You are responsible for activity carried out through your Workspace, accounts and credentials, except to the extent directly caused by our breach of these Terms.
Clients use time-limited magic links that can establish a temporary portal session. A magic link currently remains valid for 72 hours and may be used more than once within that period; the portal session it creates currently lasts 12 hours. Anyone who obtains a valid link or session within those windows may be able to access the relevant client portal, because the link is not tied to a particular person, device or network. You must enter correct recipient details, warn Clients not to forward links and revoke or archive access when appropriate.
Two-factor authentication is optional. You are responsible for deciding whether to require or operationally mandate it for your Team Members.
5. Plans, fees and billing
5.1 Plans and quotas
Plans may limit Clients, Team Members, storage, file size, API calls, automation, branding or other resources. Current entitlements are displayed in the Service, pricing page or applicable order form. You must not evade or circumvent a quota or technical restriction.
5.2 Subscription billing
Paid subscriptions are billed through Stripe. By subscribing, you authorise Stripe to charge the payment method associated with your subscription for recurring fees, applicable seat charges, taxes and other agreed charges.
Unless stated otherwise at purchase:
- subscriptions renew automatically for successive billing periods until cancelled;
- fees are charged in advance;
- fees are exclusive of VAT and other applicable taxes;
- you are responsible for taxes other than taxes on our net income; and
- fees are non-refundable except where required by law or expressly stated in an order form.
Cancellation takes effect at the end of the current paid billing period. A cancellation does not refund an unused portion of that period. Following cancellation, the Workspace may lose paid features, be downgraded or be terminated.
If a charge fails or an invoice is overdue, we may retry payment, restrict paid features, downgrade or suspend access. You remain liable for accrued amounts.
5.3 Changes
We may change Plans, quotas and prices. We will provide reasonable advance notice of a price increase affecting an existing paid subscription, normally before the next renewal. Continued use after the effective date constitutes acceptance; your alternative is to cancel before renewal.
Free, trial, beta and promotional access may be limited, changed or withdrawn at any time and is provided without a continued-availability commitment.
6. Content ownership and licence
As between the parties, the Customer and its Clients retain their rights in Content. We do not acquire ownership of Workspace Content.
You grant us and our subprocessors a worldwide, non-exclusive, royalty-free licence during the relevant processing period to host, copy, store, transmit, display, transform solely for technical compatibility, scan and otherwise process Content:
- to provide, secure, maintain and support the Service;
- on your documented instructions;
- to comply with law; and
- as otherwise permitted by these Terms and our Privacy Policy.
This licence ends when the relevant Content is deleted from our systems, subject to legal retention and provider deletion or recovery cycles.
You grant us a perpetual, worldwide, irrevocable, royalty-free licence to use feedback and suggestions without restriction or payment, provided we do not identify you publicly without permission.
7. Customer responsibilities
You decide what information to collect, from whom, for what purpose and for how long. You are responsible for:
- having all rights, permissions, notices, lawful bases and, where required, consents or special-category conditions needed for Content;
- the legality, accuracy, quality and appropriateness of your requests, forms, files, messages, reminders and decisions;
- compliance with privacy, direct-marketing, confidentiality, employment, consumer, professional, financial-services, anti-money-laundering, know-your-client and sector rules that apply to you;
- ensuring that your use of typed-name signature or acknowledgement fields is legally and evidentially suitable for your purpose;
- checking the identity and authority of Clients and verifying documents, answers, signatures and approvals independently;
- configuring suitable deadlines, recipients, roles, notification settings, Integrations, Webhooks and automated workflows;
- maintaining your own copies, exports, records and recovery procedures where loss would cause harm; and
- responding to Clients and other individuals about your services and your processing of their data.
We do not verify the authenticity, completeness, legality or accuracy of Content. A status, acknowledgement, approval, typed signature, activity entry or successful delivery indicator records an event in the Service; it is not legal, financial, identity, fraud, compliance or professional verification.
You must not rely on ClientLoop as the only copy of any document or record you are required to retain.
8. Files, uploads and harmful Content
The Service accepts only supported file types and sizes. Limits may differ between portal uploads, Team Member uploads, Plans and hosting environments. We may reject, quarantine, restrict, remove or delete a file that is unsupported, malformed, unsafe, unlawful, excessive or suspected of violating these Terms.
Where malware scanning is configured, a file may first enter private temporary storage and is then scanned before it is accepted and made available through ClientLoop. Malware detection is probabilistic. It may produce false positives, miss a threat, be unavailable or change without notice.
You and your Clients remain responsible for:
- scanning and safely handling files before upload and after download;
- not uploading executables, malware, malicious scripts or weaponised documents;
- not using Content to infringe privacy, confidentiality, intellectual-property or other rights;
- ensuring Content is lawful and appropriate for its recipients; and
- keeping independent copies where required.
To the maximum extent permitted by law, we are not liable for harm caused by malicious or unlawful Content submitted by you, your Team Members, your Clients or another third party, or for the failure of a scanner to identify it.
9. Communications and reminders
The Service sends invitations, reminders, request updates and other communications using information and branding configured by the Customer. Those communications are sent on your behalf.
You must:
- have a lawful basis to contact each recipient;
- provide accurate recipient addresses and content;
- honour applicable objections and communication preferences;
- not send spam, phishing, deceptive or unlawful messages; and
- monitor failures, bounces, replies and overdue requests where relevant.
Delivery, timing and inbox placement are not guaranteed. Messages may be delayed, filtered, rejected, duplicated or unavailable because of recipient systems, provider outages, configuration or other factors outside our control.
10. Scheduled requests and workflow automation
Scheduling and automation are convenience features. You are responsible for configuring, testing, monitoring and reviewing each workflow and its outputs.
Automated actions may be delayed, duplicated, omitted, partially completed or executed with stale configuration because of timeouts, retries, provider failures, daylight-saving changes, network conditions or software faults. You must not use an automated result as the sole control for a safety-critical, legally determinative, regulated or high-risk action.
You must verify that:
- the intended recipients and request contents are correct;
- generated requests and reminders were actually created and delivered;
- duplicate or partial execution will not cause harm;
- a stopped or disconnected Integration does not leave an external workflow active; and
- appropriate human review occurs before information is relied upon.
We may pause or disable an automation that is failing, abusive, unlawful, excessive or threatening the Service.
11. API licence and restrictions
Subject to your Plan and compliance with these Terms, we grant you a revocable, non-exclusive, non-transferable, non-sublicensable licence to use the documented API solely to connect authorised Customer Systems to your Workspace for your internal business purposes.
11.1 Credentials and access
API keys are security credentials. You must:
- keep them secret and transmit them securely;
- use separate keys and least-privilege access where available;
- not embed them in public or client-side code;
- rotate or revoke them after suspected exposure;
- ensure the Team Member responsible for a key remains authorised; and
- accept responsibility for calls authenticated with your keys.
We may rotate, restrict or revoke a key to address security, misuse, membership changes, legal requirements or Plan eligibility.
11.2 Usage rules
You must not, directly or through another person:
- exceed, evade or distribute requests to circumvent rate, storage or Plan limits;
- use undocumented endpoints or interfere with API security or operation;
- scrape the website or application, use browser automation to bypass the API, or bulk-extract information except through a documented export or API operation you are authorised to use;
- access another Customer’s data or test identifiers, permissions or vulnerabilities without written authorisation;
- use the API to provide a competing, substitute, white-labelled or resold service unless an order form expressly permits it;
- copy protected Service elements, create a derivative API, reverse engineer non-public protocols, or use output to benchmark or train a competing system, except to the limited extent applicable law cannot prohibit;
- introduce malware, destructive payloads or unreasonable load;
- use the API for surveillance, unlawful profiling, discrimination or a high-risk decision without all necessary legal and human safeguards; or
- represent that an integration is endorsed by ClientLoop without permission.
We may set or change technical limits, throttle calls, require an upgrade or suspend API access. Excessive usage may be charged only where pricing or an order form provides for it.
11.3 Changes and support
The API may change. We may introduce versions, deprecate operations and withdraw undocumented behaviour. We will use reasonable efforts to give notice before a material breaking change to a supported paid API version, except for urgent security, legal or provider changes.
API availability and response times are not guaranteed. You are responsible for timeouts, retries, idempotency, validation, monitoring and compatibility testing.
12. Webhooks
Webhook delivery is provided on a reasonable-efforts basis and is not guaranteed. Events may be delayed, duplicated, delivered out of order, delivered more than once, or not delivered.
You must:
- use HTTPS endpoints;
- protect endpoint and signing-secret information;
- verify the timestamp and signature of each supported signed event;
- validate payloads and authorisation rather than trusting an event alone;
- make handlers idempotent and safe against replay and duplication;
- respond promptly and process lengthy work asynchronously;
- monitor failures and use reconciliation or polling where missing an event matters; and
- ensure a Customer System is authorised to receive all personal data included in subscribed events.
Our delivery record is operational information and not conclusive evidence that your Customer System completed its own processing. A manual retry or test can create additional deliveries. We are not responsible for actions taken by a Customer System in response to a Webhook.
13. Integrations and third-party services
An Integration is enabled and configured by the Customer. By enabling one, you instruct us to exchange the data needed to operate it with the selected third party and confirm that:
- you control or are authorised to use the connected account;
- you have assessed the third party’s terms, privacy, security and data location;
- the transmitted information is lawful, necessary and suitable for that destination; and
- you will protect and rotate access tokens, personal access tokens, webhook addresses and signing keys.
Some Integrations also send data into your Workspace. Where you connect a scheduling or similar service, information about the people it supplies — such as an attendee’s name and email address — may be used to create or update client records and to start requests automatically. You are responsible for having a lawful basis and appropriate transparency for that incoming information, and for the records it creates.
Integrations are provided on a best-efforts basis. They depend on third-party APIs, permissions, formats, quotas and policies that we do not control. An Integration may change, lose functionality, stop synchronising or be withdrawn without liability to you. We are not responsible for a third party’s service, acts, omissions, security, retention or use of information after it receives it.
Disconnecting an Integration stops future ClientLoop-initiated exchanges where technically supported. It does not delete data already sent, revoke workflows created outside ClientLoop or necessarily revoke the credential at the third-party service.
The Service also relies on hosting, storage, database, email, security, analytics and billing providers. Outages or changes affecting those providers may affect the Service.
14. Acceptable use
You must not, and must not permit a Team Member, Client, Customer System or third party to:
- use the Service unlawfully, fraudulently, deceptively, abusively or in a way that harms another person;
- collect, upload, disclose or otherwise process personal data without appropriate authority or in breach of privacy, confidentiality or professional duties;
- upload or distribute malware, ransomware, malicious macros, exploit code or material designed to damage, monitor or gain unauthorised access;
- upload Content that infringes intellectual-property, privacy, confidentiality or other rights, or is defamatory, threatening, obscene, exploitative or otherwise unlawful;
- facilitate phishing, impersonation, scams, spam, harassment or unsolicited communications;
- attempt to access another Workspace or another person’s account, link, session, file or API credential;
- probe, scan, test or circumvent security, authentication, authorisation, signed URLs, quotas, rate limits or Plan restrictions;
- scrape, crawl, index, mirror or systematically extract the Service or its non-public data without written permission;
- reverse engineer, decompile, disassemble, copy or derive source code, models, algorithms or non-public protocols, except where applicable law expressly permits and cannot be excluded;
- use unauthorised bots, scripts, headless browsers or automation against the user interface;
- benchmark, monitor availability or use the Service to build, train or improve a competing product without written permission;
- resell, sublicense, timeshare or provide access to the Service except as expressly permitted in an order form;
- remove proprietary notices or misrepresent the origin, security or capabilities of the Service;
- use the Service as a public file host, content-distribution network, general archive or unrelated backup facility;
- introduce excessive traffic or otherwise overload, degrade or disrupt the Service or its providers; or
- help another person do any of the above.
We may investigate suspected violations, preserve relevant evidence, restrict Content, contact affected parties or authorities where lawful, and suspend or terminate access.
15. Intellectual-property complaints and takedown
If you believe that Content stored or transmitted through the Service infringes copyright or another intellectual-property right, send a written notice to info@clientloop.digital containing:
- your name, organisation and contact details;
- identification of the protected work or right;
- enough information to identify and locate the allegedly infringing Content, such as the relevant Customer, Workspace, request, filename or link;
- an explanation of the alleged infringement and the basis on which you own or are authorised to enforce the right;
- a good-faith statement that the disputed use is not authorised by the rights holder, its agent or the law;
- a statement that the information in the notice is accurate; and
- your physical or electronic signature.
This process also serves as our mechanism for handling notices submitted in the style of the United States Digital Millennium Copyright Act (DMCA) and equivalent regimes in other jurisdictions.
We may request further information before acting. Where we obtain actual knowledge or a sufficiently substantiated notice of apparently unlawful Content, we may act expeditiously to restrict or disable access, remove the Content, preserve evidence, notify the affected Customer or uploader, or take another action we reasonably consider appropriate. We may provide the notice and the complainant’s contact details to the affected Customer, uploader, our advisers or a competent authority where reasonably necessary to assess or resolve the complaint.
An affected Customer or uploader may submit a written counter-notice identifying the removed Content, explaining its authority or other legal basis for use, and providing supporting evidence and contact details. We may restore access where we reasonably consider the complaint unresolved or mistaken, but we are not required to adjudicate ownership, validity, licensing or infringement disputes.
You must not submit a notice or counter-notice that is knowingly false, misleading or abusive. You are responsible for losses caused by a materially false or bad-faith submission. We may suspend or terminate repeat or serious infringers and accounts that repeatedly submit abusive complaints.
To the maximum extent permitted by law, we are not liable for a good-faith decision to restrict, preserve, remove, refuse to restore or restore Content in response to a complaint, legal obligation or apparent rights infringement. Nothing in this Section limits any right or remedy that cannot lawfully be limited.
16. Monitoring and enforcement
We do not routinely inspect Workspace Content for legality or accuracy. We may access or review limited Content where reasonably necessary to:
- provide support requested by an authorised Customer;
- investigate abuse, fraud, security incidents or technical faults;
- enforce these Terms;
- comply with law; or
- protect the Service, our users or others.
We may remove, disable or preserve Content where we reasonably believe it presents a legal, security or operational risk. We are not obliged to monitor Content or detect every violation.
17. Artificial-intelligence features
The current Service does not provide an AI-assisted decision or content-generation feature.
If we introduce an AI-assisted feature, additional feature terms may apply. Unless we expressly agree otherwise:
- output may be inaccurate, incomplete, biased, outdated or unsuitable;
- the Customer must review and verify output before using or relying on it;
- output is not professional advice or a substitute for human judgement;
- the Customer remains responsible for inputs, instructions, permissions and resulting decisions; and
- AI output must not be used as the sole basis for a legal, financial, employment, eligibility, identity, compliance or similarly significant decision.
We may require express activation or acceptance of additional privacy information before such a feature is used.
18. Confidentiality
Each party (“Recipient”) may receive confidential information from the other (“Discloser”). The Recipient will:
- use it only to perform or exercise rights under the agreement;
- protect it using at least reasonable care; and
- disclose it only to people who need it for that purpose and are bound by confidentiality obligations.
These obligations do not apply to information the Recipient can show was lawfully known without restriction, independently developed, lawfully received from another source or made public without breach.
If disclosure is legally required, the Recipient may disclose the minimum required and, where lawful, will give advance notice. These obligations continue for five years after termination, except that trade secrets and personal data remain protected for as long as they retain that character or applicable law requires.
19. Data protection and processing terms
19.1 Roles and compliance
For personal data in Workspace Content, the Customer is normally the controller and ClientLoop is the processor. Each party will comply with the data-protection law applicable to its own role.
The Customer warrants that:
- its instructions and use of the Service are lawful;
- it has provided required privacy information and established a lawful basis;
- it has an Article 9 condition or other permission where special-category data is processed;
- it has met the applicable requirements for criminal-offence data;
- the Service and selected Integrations provide an appropriate level of protection for its use case; and
- it will not instruct us to process data in breach of law.
19.2 Instructions and processing details
The subject matter, nature, purpose, duration, personal-data types and data-subject categories are described in Schedule 1. Your configuration and documented use of the Service constitute processing instructions.
We will process personal data only on documented instructions, including for transfers, unless required by applicable law. Where legally permitted, we will inform you before processing required by law. We will notify you if, in our reasonable opinion, an instruction infringes applicable data-protection law, and may suspend the affected processing while the parties address it.
Instructions outside the standard Service may require a separate agreement and reasonable fees.
19.3 Confidentiality and security
We will ensure that people authorised to process Customer personal data are subject to confidentiality obligations. We will maintain technical and organisational measures appropriate to the risk, taking into account the state of the art, implementation cost and the nature, scope, context and purposes of processing.
Security measures include the controls described in the Privacy Policy. The Customer acknowledges that no measure provides absolute security and that its configuration, endpoint security, access management and backup practices affect overall risk.
19.4 Subprocessors
You give general written authorisation for us to appoint subprocessors to provide the Service. We will:
- impose data-protection obligations on each subprocessor that provide the protection required by applicable law;
- remain responsible for the subprocessor’s performance of those obligations to the extent required by law; and
- make current subprocessor information available through the Privacy Policy or on request.
Where required by applicable law, we will give reasonable notice of a material new subprocessor. You may object within ten days on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the objection. If no reasonable alternative is available, we may allow you to terminate the materially affected paid Service without penalty as your exclusive contractual remedy for that objection.
Customer-controlled Integrations and Webhook destinations are recipients selected by the Customer, not subprocessors appointed by us to provide the core Service.
19.5 Individual rights and assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with:
- requests from individuals exercising data-protection rights;
- security obligations;
- personal-data-breach notifications;
- data-protection impact assessments; and
- prior consultation with a supervisory authority.
If we receive a request relating to Customer-controlled Workspace Content, we will normally direct the requester to the Customer and will not respond substantively unless authorised or legally required.
Assistance beyond standard Service functionality or caused by the Customer’s breach may be charged at reasonable rates.
19.6 Security incidents and personal-data breaches
We maintain an incident-response process covering detection, containment, assessment, remediation and post-incident review. To contain an actual or suspected incident we may, acting reasonably and without liability to the Customer, rotate or revoke credentials and API keys, invalidate sessions and magic links, suspend accounts, endpoints, Integrations, Webhooks or features, block traffic or restrict access while we investigate.
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data and will provide information reasonably available to help the Customer meet its notification obligations. Notification may be provided in phases as information becomes available and is not an admission of fault or liability.
The Customer is responsible for notifying regulators and affected individuals where it is the controller.
The Customer must notify us promptly at info@clientloop.digital of any actual or suspected compromise of its accounts, passwords, API keys, magic links, signing secrets, Webhook endpoints, Integrations, devices or Customer Systems, and must take its own reasonable containment steps, including rotating affected credentials and removing compromised access. As between the parties, an incident originating in credentials, endpoints, systems, recipients or configurations under the Customer’s control — including a magic link forwarded or disclosed by the Customer or a Client — is the Customer’s responsibility, except to the extent directly caused by our breach of these Terms.
19.7 Return and deletion
On termination or written instruction, we will delete or return Customer personal data as required by applicable law and the Service’s available functionality, unless law requires retention.
The Customer must retrieve required Content before deletion or termination. Deletion from active systems may be followed by deletion under provider recovery, backup or lifecycle processes. We may retain limited records necessary for billing, security, legal compliance and legal claims.
19.8 Information and audits
We will make information reasonably necessary to demonstrate compliance with these processor obligations available to the Customer, including relevant policies or third-party assurance material where available.
If that information is insufficient, the Customer may request an audit no more than once in any 12-month period, unless a regulator or substantiated breach requires more. Audits must:
- use an independent, non-competing auditor bound by confidentiality;
- take place on reasonable written notice during normal business hours;
- avoid access to another customer’s data and unreasonable disruption; and
- be at the Customer’s cost unless the audit identifies a material breach by us.
We may satisfy an audit request through questionnaires, certifications, summaries or remote evidence where reasonable.
19.9 International transfers
We will use a lawful transfer mechanism for restricted transfers made by us as processor where required. The Customer authorises transfers needed to use approved subprocessors.
The Customer is responsible for transfer assessments and safeguards relating to destinations it selects, including Customer-controlled Integrations and Webhooks.
19.10 Liability and precedence
Liability arising from these processing terms is subject to Section 26 to the maximum extent permitted by law. Nothing in these Terms limits the rights of individuals or powers of regulators under applicable data-protection law.
If this Section conflicts with another part of these Terms on processor obligations, this Section prevails for that conflict.
20. Intellectual property
The Service, Documentation, software, interfaces, design, text, graphics, trademarks and underlying technology, excluding Customer Content, are owned by ClientLoop or its licensors and protected by intellectual-property law.
Except for the limited rights expressly granted in these Terms, no rights are transferred. You must not remove notices, register confusingly similar branding or challenge our ownership based on your access to the Service.
21. Branding and custom domains
You represent that you own or are authorised to use each logo, name, domain, font and brand asset supplied to the Service. You are responsible for domain registration, DNS, email reputation and ongoing authority to use those assets.
We may reject, disconnect or suspend a domain or asset that is insecure, misconfigured, misleading, infringing, unlawful or harmful to the Service or another person.
Any website-brand analysis feature is a convenience tool. You must submit only a public HTTPS website you are authorised to analyse and must review extracted branding before use.
22. Availability, maintenance and changes
Unless an order form states a service level, we do not guarantee any uptime, response time, storage durability, email delivery time, processing time or support-resolution time.
The Service may be unavailable because of maintenance, defects, attacks, capacity, Internet conditions, force majeure or third-party providers. We may perform planned or emergency maintenance and may change architecture, providers, security controls or functionality.
Support is supplied on a commercially reasonable basis according to the Plan. We are not obliged to support Customer Systems, third-party services, unsupported browsers, modified output or use contrary to Documentation.
23. Beta, trial and free features
Beta, preview, early-access, trial and Free features:
- may be incomplete, insecure for some use cases or subject to additional limits;
- may change or be withdrawn at any time;
- are provided for evaluation or limited use;
- may not receive the same support or retention treatment as paid features; and
- must not be used for production-critical or legally required activity unless we agree otherwise in writing.
24. Warranties and disclaimers
We warrant that we will provide paid Services with reasonable care and skill.
Subject to that express warranty and to the maximum extent permitted by law, the Service is provided “as is” and “as available”. We exclude implied terms, conditions and warranties, including satisfactory quality, fitness for a particular purpose, non-infringement and uninterrupted availability, to the extent they may lawfully be excluded.
We do not warrant that:
- the Service will be uninterrupted, error-free or secure against every threat;
- Content, form answers, signatures, approvals or identities are accurate or legally effective;
- files are free from malware;
- an email, reminder, Webhook, Integration or scheduled request will be delivered or executed;
- a third-party service will remain compatible or available;
- data can always be recovered after Customer deletion, credential loss, provider failure or user error; or
- the Service will satisfy a Customer’s regulatory, retention, evidential or professional requirements.
You are responsible for evaluating whether the Service is suitable for your intended use.
25. Third-party claims and Customer indemnity
You will indemnify ClientLoop, its affiliates, officers, employees and contractors against losses, liabilities, damages, penalties, costs and reasonable legal fees arising from a third-party claim, regulatory action or investigation resulting from:
- Content or an instruction supplied by you, a Team Member, Client or Customer System;
- your breach of Sections 4, 7, 8, 10, 11, 12, 13, 14, 15 or 19;
- your unlawful collection, use, disclosure or transfer of personal data;
- infringement or misappropriation caused by your Content, branding or Customer System;
- communications sent, requests made or decisions taken through your Workspace;
- your Integration, Webhook endpoint, API client or automated workflow; or
- acts or omissions of your Team Members or Clients for which you are responsible.
You are not required to indemnify us to the extent a claim was directly caused by our breach of these Terms, negligence or wilful misconduct.
We will give reasonable notice of an indemnified claim, allow you to control its defence and settlement, and provide reasonable cooperation at your cost. You may not settle in a way that admits fault by us, imposes an obligation on us or fails to release us without our written consent.
26. Limitation of liability
Nothing in these Terms excludes or limits liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- a liability that cannot lawfully be excluded or limited; or
- your obligation to pay fees properly due.
Subject to the paragraph above, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill, reputation, business opportunity or business interruption.
Subject to the first paragraph, ClientLoop is not liable for:
- loss, corruption or disclosure of data caused by the Customer, a Client, a Customer System, an Integration or another third party, including unauthorised access resulting from compromised, shared or forwarded passwords, API keys, magic links, sessions, signing secrets or endpoints under the control of the Customer, a Team Member, a Client or a Customer System;
- Customer deletion, misconfiguration, failure to keep an independent copy, or reliance on an unverified submission or automated output;
- failure, delay, duplication or omission involving email, Webhooks, scheduled workflows or Integrations;
- suspension taken in accordance with these Terms; or
- the cost of replacement services.
Subject to the first paragraph, ClientLoop’s total aggregate liability arising from or connected with the agreement in any rolling 12-month period will not exceed the greater of:
- the fees paid or payable to ClientLoop for the Service during the 12 months preceding the first event giving rise to liability; and
- £100.
For liability arising from breach of Section 18 (Confidentiality) or Section 19 (Data protection), that aggregate cap is instead the greater of:
- two times the fees paid or payable during that 12-month period; and
- £500.
The caps apply in aggregate across contract, tort including negligence, breach of statutory duty, indemnity, misrepresentation and other causes of action. The parties agree that the fees reflect this allocation of risk.
27. Suspension
We may suspend or restrict an account, Workspace, Client, credential, file, API operation, Webhook, Integration, custom domain or other feature immediately where we reasonably believe:
- fees are overdue;
- these Terms have been breached;
- activity is unlawful, fraudulent, abusive or infringes another person’s rights;
- Content or access creates a security, privacy, legal or operational risk;
- usage is excessive or threatens the Service or a provider;
- suspension is requested by a provider or authority;
- credentials are compromised;
- an Integration or automation is malfunctioning; or
- suspension is necessary to prevent or limit harm.
Where appropriate and lawful, we will give notice and an opportunity to remedy. We may maintain suspension while investigating. We are not obliged to restore Content removed for a security or legal reason.
28. Term and termination
These Terms begin when you first accept them or use the Service and continue until terminated.
You may cancel a paid subscription through the available billing controls and may request account or Workspace termination by contacting us. You should export required information before cancellation, deletion or termination.
We may terminate:
- immediately for a material breach that cannot be remedied, unlawful activity, serious security risk, insolvency or repeated breach;
- after reasonable notice if a remediable material breach is not remedied within the notice period;
- for non-payment;
- if a provider, law or operational change makes continued provision impracticable; or
- a Free, trial or beta Service at our discretion.
On termination:
- your right to use the affected Service ends;
- outstanding fees become due;
- we may disable credentials and integrations;
- you remain responsible for activity initiated before termination; and
- Content may be deleted according to the Privacy Policy, Customer instructions, legal requirements and provider lifecycle processes.
We do not guarantee a post-termination export window unless an order form expressly provides one. Sections intended by their nature to survive, including ownership, confidentiality, data protection, disclaimers, indemnities, liability, governing law and accrued payment obligations, will survive.
29. Changes to these Terms
We may update these Terms for legal, security, operational or commercial reasons. We will update the date above and take reasonable steps to notify Customers of a material change.
Changes normally apply from the stated effective date. If a material change substantially disadvantages an existing paid Customer, it may cancel before the change takes effect. Continued use after the effective date constitutes acceptance.
Urgent changes required for law, security or provider compliance may take effect immediately.
30. Governing law and disputes
These Terms and any non-contractual dispute connected with them are governed by the laws of England and Wales.
The courts of England and Wales have exclusive jurisdiction, except to the extent mandatory law gives an individual a right to bring proceedings elsewhere.
Before commencing proceedings, each party should use reasonable efforts to resolve the dispute through good-faith discussions, except where urgent injunctive or protective relief is required.
31. General
- Assignment: You may not assign or transfer the agreement without our written consent. We may assign it to an affiliate or in connection with a merger, reorganisation, financing or sale of all or substantially all relevant assets.
- Subcontracting: We may use subcontractors and remain responsible to the extent stated in these Terms and required by law.
- Force majeure: Neither party is liable for delay or failure caused by events beyond its reasonable control, including malicious cyber attacks, denial-of-service attacks, ransomware, zero-day exploits or supply-chain compromises that could not reasonably have been prevented by the measures described in the Privacy Policy, as well as Internet, power or third-party provider failures — excluding, in every case, the Customer’s payment obligations.
- Export control and sanctions: You represent that neither you nor any Authorised User is located in, or ordinarily resident in, a country or territory subject to comprehensive UK, EU, US or UN sanctions, or named on a UK, EU, US or UN sanctions or restricted-party list. You must not use, export, re-export or provide access to the Service in breach of applicable export-control or sanctions laws, and we may suspend or terminate access where we reasonably believe continued provision would breach them.
- Notices: We may send notices to the account email or through the Service. Notices to ClientLoop must be sent to info@clientloop.digital, except where law requires another method.
- Entire agreement: These Terms, incorporated documents and accepted order forms constitute the entire agreement about the Service and replace earlier statements on the same subject. Neither party relies on a statement not set out in the agreement, without excluding liability for fraud.
- Waiver: A delay or failure to enforce a right is not a waiver.
- Severability: If a provision is unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder continues.
- No partnership or agency: The agreement does not create a partnership, joint venture, employment or agency relationship.
- Third-party rights: Except where expressly stated, no person other than the parties may enforce the agreement under the Contracts (Rights of Third Parties) Act 1999.
- Order of precedence: An accepted order form prevails over these Terms for an express conflict; these Terms prevail over Documentation and marketing material.
32. Contact
- info@clientloop.digital
- Pleesys Technology Limited, company number 17350856
- 11 Rosemary Court, York, England, YO1 9UQ
Schedule 1: Processing details
This Schedule forms part of Section 19 and describes processing in which ClientLoop acts as processor for the Customer.
It does not cover personal data that ClientLoop processes as controller — including account registration and authentication data, credentials such as password hashes, two-factor secrets and recovery codes, evidence of acceptance of these Terms and the Privacy Policy, and ClientLoop’s own subscription-billing records. That processing is described in our Privacy Policy, which also explains that acceptance evidence is retained after an account is deleted in order to establish, exercise or defend legal claims.
Subject matter
Provision of the ClientLoop document, information-request, client-portal, communication, workflow, API, Webhook, Integration, storage and support services selected and configured by the Customer.
Duration
For the term of the agreement and afterwards only for deletion, return, legal retention, security, dispute resolution and provider recovery or lifecycle processes.
Nature and purpose
Collection, recording, organisation, structuring, storage, retrieval, consultation, display, transmission, controlled sharing, validation, security scanning, communication, workflow execution, support, deletion and other processing necessary to provide and secure the Service on the Customer’s instructions.
Categories of data subjects
- Clients, prospective clients and former clients of the Customer;
- the Customer’s staff, contractors, applicants, contacts and representatives;
- Team Members and other Authorised Users;
- people identified or referred to in uploaded documents, form answers, messages, notes or metadata; and
- any other person whose data the Customer chooses to process through the Service.
Types of personal data
- identity and contact information;
- business, professional and employment information;
- financial and transaction information contained in Workspace Content;
- identity documents and verification information;
- postal addresses and contact preferences;
- request, form, response, approval and acknowledgement information;
- files, documents, images, signatures typed as names and their metadata;
- communications, comments, internal notes and support information;
- online identifiers, IP addresses, activity, audit and security information;
- client portal access tokens and session records, stored as hashes or signed values;
- records of access to shared material, including when a document was viewed or downloaded;
- external references and Customer-defined metadata;
- Calendly, Slack, Asana, Webhook and other customer-enabled Integration data; and
- any other personal data included by the Customer or a Client in Workspace Content.
Special categories
Workspace Content may include special-category data or criminal-offence data if the Customer chooses to collect or upload it. The Customer must not process such data through the Service unless it has assessed the risks, established all required legal conditions and implemented suitable safeguards.
Customer instructions
The Customer instructs ClientLoop to process the data above to provide, secure, maintain and support the configured Service; communicate with authorised recipients; operate selected subprocessors and customer-controlled destinations; and comply with the Customer’s documented settings, actions and support requests.