Clearline reads your ledger, which means your customers' names, what they owe you and how they behave. That is a serious thing to hand over, so this page sets out the arrangements plainly rather than asking you to take a badge on trust. Anything here that we do not yet hold is marked as such.
Three things, and it is worth separating them because they are treated differently. The ledger you give us, which is invoice references, amounts, dates and the names of the businesses that owe you money. The correspondence that follows, which is every letter, email, text and call note on a case. And your own account details, which is who you are, who may sign in, and the authority you have set for what happens without asking you.
A free scan is different again. The ledger is analysed in memory and not stored. What we keep is a row of totals: how many invoices, how much was overdue, and what the Act puts on it. No invoice reference, no customer name, no amount against any named business. If you ask for the report by email we keep your contact details and the headline figures for six months and then delete them, unless you instruct us in the meantime.
These are the periods the system actually enforces. They are not a policy statement: a job runs on a schedule and deletes what is past its date, and the console records what it deleted.
| What | Kept for | Why that long |
|---|---|---|
| Sign-in codes | 24 hours | Long enough to use, short enough to be useless to anyone else. |
| Sessions | 30 days | Expired or idle sessions are removed, not merely invalidated. |
| Scan contact details and headline figures | 6 months | What the scan page and the privacy notice both say. |
| Scan measurement rows (totals only) | 6 months | Deleted on the same clock as the leads they sit beside. |
| Closed cases, their letters and their events | 6 years | The limitation period, so the file outlives any claim about it. |
| Receipts and remittances | 6 years | The statutory record-keeping period for the money. |
| Call recordings | As set in your account | Recording is off unless you turn it on, and the period is yours to set. |
You can ask for your data at any time and we will send it in a machine-readable form. You can ask us to delete it, and we will, subject to what we are required to keep about money we have handled and debts we have pursued on your behalf.
Every provider below has a signed data processing agreement, and none of them receives more than the part of the work it performs. This list is current; we will change it here when it changes, and a subscriber can ask to be told in advance.
| Provider | What it does | What it sees |
|---|---|---|
| Netlify | Serves the site and runs the application | Requests, and whatever a request carries |
| Supabase | The database and its backups | Everything we store, encrypted at rest |
| Postmark | Sends and receives the letters that go by email | Recipients and the content of those messages |
| Twilio | Sends the text messages, where a debtor has consented | The mobile number and the message |
| GoCardless | Collects credit control subscriptions by Direct Debit | Your own billing details, never a debtor's |
| Companies House | The register check on every debtor | A company name or number we look up |
| Cal.com | The booking calendar on one page | What you type when booking a call |
| Microsoft Clarity | Analytics on public marketing pages only, and only with consent | Nothing: it never loads on the scan, portal, payment or debtor pages |
Where we operate a client's credit control function under subscription we act as that client's processor, and they remain the controller of their own customers' data. For the recovery work and for website visitors, Clearline Ltd is the controller. The privacy notice sets out the legal bases in full.
Access is by role and every read is logged. A specialist sees the accounts they look after. A practice that introduced a client sees that client's numbers, and sees the case detail only where the client has ticked to share it, which the client can untick at any time. Nobody sees another client's ledger. The audit trail in the console names the person and the moment for every letter sent, every approval given and every figure changed, and it cannot be edited from the interface.
| What | Status |
|---|---|
| Information Commissioner's Office registration | Registered as a data controller |
| Cyber Essentials | Certified |
| Credit Services Association membership | Member, and bound by its Code |
| Professional indemnity insurance | Held |
| Cyber insurance | Held |
| Financial Conduct Authority authorisation | Not required: business-to-business debt recovery falls outside that regime and we do not collect consumer debt. If we ever do, it will be under the appropriate permission and this page will say so. |
| ISO 27001 | Not held. We are not going to imply it by listing it without a status. |
If you believe you have found a vulnerability, email security@clearline.co.uk and we will acknowledge it within one working day. Test against your own account only, do not access anybody else's data, and give us a reasonable period to fix it before you publish. We will not pursue anyone who reports in good faith and stays within those lines. Our security.txt carries the same contact in machine-readable form.
For anything about how we have handled data, privacy@clearline.co.uk. For anything about how we have behaved, the complaints procedure sets out the stages and the timescales, and you may complain to the Information Commissioner's Office at any point without going through us first.
A data processing agreement, our processor register, a copy of the Cyber Essentials certificate and insurance confirmations are all available on request from hello@clearline.co.uk, usually the same working day. If your own security questionnaire needs completing, send it and we will fill it in rather than sending you a brochure.
We will not sell or share your ledger, or anything derived from it that identifies your customers, with anyone. We will not contact a customer of yours without your written approval. We will not write to your accounting system, because the connection is read-only and cannot. And we will not buy your debt, so nothing about your customers ever becomes an asset of ours.
Send them here, or send us the questionnaire. We would rather answer it properly once than have it become a reason to put this off.