1. Who we are
ComplyClock Ltd is the controller for personal data used to operate customer accounts, billing, support, security and this website.
- Company number
- [LEGAL REVIEW] Insert the company registration number
- Registered office
- [LEGAL REVIEW] Insert the registered office address
- Privacy contact
- hello@complyclock.uk
- Data protection registration
- [LEGAL REVIEW] Confirm whether an ICO registration number must be published.
2. Our role when Customers add other people's data
Customers, particularly accounting practices, may add information about client companies, client contacts, staff and other individuals. For that Customer Data, the Customer normally decides why and how the data is used and acts as controller; ComplyClock acts as processor under our Data Processing Addendum.
If your data was added by a Customer, contact that Customer first to exercise your rights. We will assist the Customer as required by data protection law.
3. Personal data we collect
- Account and identity data: name, email address, authentication records, workspace membership, role and notification preferences.
- Organisation and compliance data: company names and numbers, entity profiles, tax settings, deadlines, tasks, assignments, comments and audit events.
- Documents and client-request data: files, filenames, client contact details, messages and responses uploaded through the Service.
- Billing data: plan, billing status and Stripe customer, subscription or checkout identifiers. Stripe handles payment-card details; ComplyClock does not store full card numbers.
- Communications: contact-form enquiries, support correspondence and email delivery preferences.
- Technical and security data: IP address, request and device information, timestamps, session activity, error diagnostics and security events.
- Integration and AI data: Companies House results and the prompts, selected records or outputs involved when an Authorised User deliberately invokes an OpenAI-powered feature.
The Service is not designed to require special-category personal data or criminal-offence data. Customers should not upload it unless they have assessed the need and put appropriate legal and security measures in place. [LEGAL REVIEW] Confirm whether any planned workflow intentionally requires these categories.
4. Why we use personal data and our lawful bases
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create accounts, provide workspaces, reminders and support | Account, organisation, compliance, communications | Performance of a contract; legitimate interests in serving business users |
| Manage subscriptions and payments | Account and billing data | Performance of a contract; legal obligations for financial records |
| Secure, troubleshoot and improve the Service | Technical, security and limited usage data | Legitimate interests in operating a reliable and secure service |
| Send requested service email and preference-controlled reminders | Contact details, preferences, deadline context | Performance of a contract; legitimate interests; consent where legally required |
| Meet legal, tax and regulatory duties | Account, billing, communications and audit records | Legal obligation; establishment, exercise or defence of legal claims |
[LEGAL REVIEW] Confirm each lawful basis and document any required legitimate-interest assessments and electronic-marketing position before launch.
5. Where personal data comes from
We receive data directly from account holders, invited users, client-request respondents and people who contact us; from other Authorised Users in the same workspace; from Stripe in connection with billing; and from Companies House when an Authorised User searches for or refreshes public company information.
6. Who receives personal data
Access within a workspace depends on the roles and entity permissions configured by the Customer. We also use carefully selected service providers and integrations:
- Stripe for subscription checkout, billing and payment administration.
- OpenAI for optional AI features initiated by an Authorised User.
- AWS SES for transactional email delivery.
- AWS S3 for private encrypted document storage.
- Companies House as the source of public UK company information requested through the integration.
- Honeybadger for error monitoring and operational diagnostics.
- [LEGAL REVIEW] Production hosting provider — identify the provider, contracted entity, data handled and hosting location.
More detail is available on our Sub-processors page. We may also disclose data to professional advisers, authorities or counterparties where law requires or permits it. [LEGAL REVIEW] Confirm corporate-transaction disclosure wording.
7. International transfers
Some providers may process personal data outside the United Kingdom. We will use an approved transfer mechanism where one is required.
[LEGAL REVIEW] Confirm every provider's contracted entity and processing locations, applicable UK adequacy regulations, and whether the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses is used. Complete and document the required transfer risk assessments.
8. How long we keep data
| Category | Retention position |
|---|---|
| Active account and Customer Data | Kept while needed to provide the Service. [LEGAL REVIEW] Approve the post-termination export and deletion window. |
| Uploaded documents and backups | [LEGAL REVIEW] Approve live-object, deleted-object, version and backup retention periods. |
| Billing and transaction records | [LEGAL REVIEW] Confirm the statutory accounting and tax retention period. |
| Audit, security and error records | [LEGAL REVIEW] Approve separate audit, log and incident retention periods. |
| Contact enquiries and support | [LEGAL REVIEW] Approve the enquiry and dispute retention period. |
We may retain limited information longer where required by law, to establish or defend legal claims, or where secure backup deletion occurs on a delayed cycle. Approved periods must be documented before launch.
9. How we protect data
Measures include role- and entity-based access controls, tenant-scoped queries, password hashing, HTTPS, secure session cookies, private encrypted object storage, short-lived download URLs, audit events and operational monitoring. [LEGAL REVIEW] Confirm and document the deployed backup, restoration and recovery arrangements. No internet service can guarantee absolute security.
10. Your UK data protection rights
Depending on the circumstances, you may have rights to access, rectify or erase personal data; restrict or object to processing; receive portable data; and withdraw consent without affecting earlier lawful processing. You may also have rights relating to solely automated decisions with legal or similarly significant effects.
Email hello@complyclock.uk to exercise a right. We may need to verify identity and, where a Customer controls the relevant data, refer the request to that Customer. Rights can be limited by applicable law.
[LEGAL REVIEW] Confirm whether any feature constitutes automated decision-making or profiling that requires additional Article 22 information.
11. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office (ICO) through ico.org.uk/make-a-complaint.
12. Cookies
ComplyClock currently uses strictly necessary session and CSRF-protection cookies only. They keep users signed in, preserve the selected workspace and billing flow, and protect forms against forgery.
We do not currently set analytics, advertising or cross-site tracking cookies, so there is no cookie-consent banner. If that changes, we will update this notice and introduce consent controls before setting non-essential cookies.
13. Children
The Service is intended for business compliance work and is not designed for children. [LEGAL REVIEW] Confirm the minimum permitted user age and the response process if children's data is submitted.
14. Changes and contact
We may update this notice when the Service, providers or law changes. The published “Last updated” date will change only when the notice changes. Questions can be sent to hello@complyclock.uk. [LEGAL REVIEW] Approve the process for notifying Customers of material privacy changes.