Privacy notice
What we do with personal data about you.
This notice covers the people Case Ledger Tech deals with directly: visitors to this site, people who ask for access, people who sign in to Proxy, and billing contacts. Personal data inside a customer's documents is covered by the data processing terms instead.
- Version
- 1.0
- Effective
- Not yet in force
- Operator
- Case Ledger Tech Ltd
Draft
These documents are not in force.
35 facts have still to be supplied, and they are highlighted in the text where they belong. Nothing here binds anybody until those are filled in and a solicitor has reviewed the result. The outstanding list is on the legal index.
In short.
This summary is not the agreement and has no legal effect. It is here so that somebody deciding whether to read the rest can decide.
- This website sets no cookies, runs no analytics, and makes no third-party requests.
- The access form records five fields and a timestamp. It does not record your IP address.
- We do not sell personal data, and we do not use it for advertising.
- You can ask for a copy, a correction or a deletion, and complain to the ICO.
1 Who we are
Case Ledger Tech Ltd is the controller of the personal data described in this notice. We are registered in England and Wales under number 17009166, with our registered office at registered office address, and we trade as Proxy. Our registration with the Information Commissioner's Office is ICO registration number.
For anything in this notice, including a request to exercise your rights, use the form at poweredbyproxy.co.uk/access#request. A vulnerability report goes to the same place; say in the message that it is one. We publish no email address anywhere, so the form is the only route that reaches us.
We have not appointed a Data Protection Officer, because we are not required to. Requests are handled by privacy request owner role.
This notice does not cover:
- personal data inside documents a customer sends to Proxy. We process that on the customer's instruction as their processor, under the Data Processing Terms, and the customer is the controller who has to explain it;
- sites we link to, including the API reference and the signed-in product, each of which is ours but is described where it lives.
2 What this website does, exactly
This site sets no cookies. It has no analytics, no tag manager, no advertising pixel, no embedded video and no social widget, and it makes no request to any third-party host. The fonts are served from this site rather than from a font service, so loading a page tells nobody but us that you loaded it.
The one thing stored in your browser is your light or dark theme preference, kept in localStorage. It is set only if you use the theme control, it is not personal data, it is never sent to us, and clearing your browser storage removes it.
If you submit the access request form, we record exactly the following, and nothing else:
- your name;
- your email address;
- your organisation;
- which services you ticked an interest in;
- anything you wrote in the free text field;
- the time we received it.
We do not record your IP address, your browser or your device with that submission. The form is protected against automated abuse by refusing submissions that did not come from this site and by a hidden field, neither of which collects anything about you.
Our web server and our hosting provider keep operational logs, which include IP addresses, in the ordinary way needed to run and secure a service. Those are kept for server log retention period and are not used to build a profile of anybody.
3 What we hold, why, and on what basis
Access requests and enquiries. Name, email, organisation, stated interest and message.
- Why
- to answer you, to work out whether Proxy suits what you describe, and to keep a record of the request.
- Basis
- our legitimate interests in responding to a business enquiry addressed to us. You chose to write to us, and answering is what you expected.
- Kept for
- enquiry retention period from our last exchange, unless you become a customer, in which case it moves under the row below.
Users of Proxy. Name, work email, organisation, role, authentication records, and the actor recorded against each action taken in the product.
- Why
- to give you an account, to authorise what you do, to keep the audit trail that tells a customer who did what, and to support you.
- Basis
- our legitimate interests in providing the service to the organisation that asked for it and in keeping it secure and accountable. Your employer, not you, holds the contract.
- Kept for
- the life of the account. Audit records are kept for audit record retention period after that, because an audit trail that can be shortened proves less than one that cannot.
Billing and administrative contacts. Name, email, telephone, role, and the transaction records attached to them.
- Why
- to operate the contract, raise invoices, take payment and keep accounting records.
- Basis
- performance of a contract with your organisation, and compliance with a legal obligation for the accounting records.
- Kept for
- six years from the end of the accounting period, as the Companies Act 2006 and HMRC require.
Security and operational records. Request metadata, IP addresses, credential events, and reports sent to our security address.
- Why
- to detect and investigate abuse, to diagnose faults, and to meet our obligations to customers whose data we hold.
- Basis
- our legitimate interests in keeping a service secure, and our legal obligation to apply appropriate security measures.
- Kept for
- security record retention period, or longer where a specific investigation requires it.
Marketing, if you have asked for it. Name and email.
- Why
- to send you the thing you asked us to send.
- Basis
- your consent, or our legitimate interests where you are an existing customer contact and the message concerns a service like the one you already have.
- Kept for
- until you withdraw. Every message carries an unsubscribe link, and withdrawing is free and immediate.
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and concluded that it is not, in each case above. You can ask us for that assessment, and you can object under clause 7.
4 Where we get it from
Almost all of it comes from you, or from the organisation that asked us to give you an account.
We also use business contact details from public sources such as a company website or a professional network, where we are approaching an organisation about Proxy. If that is how we reached you, you can tell us to stop and we will, and we will keep only enough to remember not to contact you again.
6 Where it is held
Personal data covered by this notice is held in controller data location.
Where a provider processes personal data outside the United Kingdom, we rely on UK adequacy regulations where they cover the country, and otherwise on the International Data Transfer Agreement, or the international data transfer addendum to the EU standard contractual clauses, together with a transfer risk assessment. Ask us through the form at poweredbyproxy.co.uk/access#request and we will tell you which applies to which provider.
A customer's own data region is a separate matter, set for their organisation before anything is stored, and covered by the Data Processing Terms.
7 Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected, and incomplete data completed;
- have data erased, where we no longer need it or where you withdraw the consent it rested on;
- restrict what we do with it while a dispute about it is resolved;
- receive data you gave us in a portable format, where the processing rests on consent or on a contract and is automated;
- object to processing that rests on legitimate interests, and to direct marketing at any time and absolutely;
- withdraw consent at any time, where consent is what we relied on. Withdrawing does not undo what was lawful before it.
To exercise any of these, use the form at poweredbyproxy.co.uk/access#request. We will respond within one month, and will tell you inside that month if a request is complex enough to need longer. There is no fee unless a request is manifestly unfounded or excessive, and we will say so and why before charging anything.
We may ask you to confirm who you are before we act, because handing somebody else's data to the wrong person is the failure these rights exist to prevent.
If your request concerns personal data inside a customer's documents, we will tell you so and, where we can identify the customer, pass the request to them. They are the controller for it; we cannot answer it for them.
8 Automated decisions
We do not make decisions about you by automated means that produce a legal effect or a similarly significant effect on you.
Proxy performs automated extraction and classification on documents for customers. Those outputs are not certified as accurate, and the customer, not Case Ledger Tech, decides what is done with them and owes you the explanation for any decision they drive.
9 Security
Transport is TLS with no plaintext fallback, and stored objects are encrypted at rest. Access to personal data inside Case Ledger Tech is limited to the people whose job needs it, and every change made in the product records a named actor.
No service is immune. If a breach is likely to result in a high risk to your rights and freedoms we will tell you without undue delay, and we will report to the Information Commissioner within 72 hours where the law requires it.
10 Complaints, and changes to this notice
If you are unhappy with how we have handled your personal data, tell us first through the form at poweredbyproxy.co.uk/access#request and we will try to put it right.
You can also complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, at ico.org.uk, or on 0303 123 1113. Complaining to us first is not a precondition.
This notice carries a version and an effective date. When it changes materially we will publish the new version here and, where we hold your address and the change affects you, tell you directly. Superseded versions are available on request.
The other documents.
All four form one agreement. This one does not stand on its own, and neither do the others.
- Terms of service
- What Proxy provides, what your organisation is responsible for, how it is paid for, how it can be suspended, and how the agreement ends. Your order form incorporates these terms at the version stated on it.
- Data processing terms
- These terms form part of the agreement and govern the personal data inside the documents your organisation sends to Proxy. You are the controller. We are your processor, and we act on your instructions.
- Acceptable use
- This policy forms part of the agreement and applies to everybody who uses Proxy through your organisation. It matters more here than on most platforms, because Sign and Communications act in your name towards people who are not your customers.