Privacy Policy
Last updated: 5 August 2026
[BRACKETED] placeholder (legal entity, registered address, governing law, contact addresses).This policy explains how [Legal Entity Name](“ClientReady”, “we”) handles personal data. It covers our markets including the UK and EEA, Australia, New Zealand, and India, and is written to align with the UK GDPR and EU GDPR, the Australian Privacy Act, the New Zealand Privacy Act 2020, and India’s Digital Personal Data Protection Act 2023.
1. Our two roles
- Controller — for the personal data of our customers: account holders and the team members they invite (name, email, login and billing details, usage).
- Processor — for the personal data that you, our customer, collect from your own end-clients and their site visitors through what you build with us (for example, booking or contact-form entries). For that data you are the controller and decide why and how it is processed; we process it on your instructions to run the service. If our standard data-processing terms apply to you, they form part of your agreement with us.
2. What we collect
| Category | Examples |
|---|---|
| Account | Name, email, hashed password, workspace and team membership, plan. |
| Content you provide | Prompts, briefs, uploaded assets, generated sites and their versions. |
| Client review data | Comments and feedback left on a shared preview, and any name a reviewer enters. |
| End-client submissions | Data collected through the sites you build (processed on your behalf, as controller = you). |
| Billing | Handled by our payment processor; we receive limited data such as the last four digits and billing status, not full card numbers. |
| Usage & device | Log data, IP address, approximate location, and cookies needed to keep you signed in and to secure the service. |
Voice input.Voice-to-text is performed by your own browser’s built-in speech recognition. Depending on your browser, audio may be processed by your browser or operating-system vendor under their terms. ClientReady does not receive or store your audio — only the transcribed text you choose to submit.
3. How we use personal data
- To provide, secure, and support the service and generate the output you request.
- To process payments and manage subscriptions.
- To communicate with you about your account, security, and material changes.
- To detect, prevent, and investigate abuse, fraud, and violations of our Terms.
- To meet legal obligations.
We do not sell personal data, and we do not use your content or your clients’ data to train AI models.
4. AI processing
To generate and refine sites, the prompts and relevant content you submit are sent to our AI provider (Anthropic) for processing and returned to you. This is necessary to perform the service. Our AI provider processes this data as our subprocessor and, under our agreement, does not use it to train its models.
5. Legal bases (UK/EU GDPR)
- Contract — to provide the service you sign up for.
- Legitimate interests — to secure, maintain, and improve the service and prevent abuse, balanced against your rights.
- Legal obligation — for tax, accounting, and compliance.
- Consent — where required (for example, certain communications); you may withdraw it at any time.
6. Subprocessors
We use a small number of vetted providers to run the service. Current subprocessors:
| Provider | Purpose |
|---|---|
| Anthropic | AI generation of sites and content. |
| Fly.io | Application compute and hosting of generated sites. |
| Supabase | Database and file storage. |
| Vercel | Front-end delivery of the app. |
| [Stripe / Razorpay] | Payment processing (region-dependent). |
We will keep this list current and give notice of material changes as required.
7. International transfers
Our providers may process data outside your country, including in the United States. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses and equivalent mechanisms under the applicable laws listed above.
8. Retention
We keep personal data for as long as your account is active and as needed to provide the service, then delete or anonymise it in the ordinary course, unless a longer period is required by law (for example, tax records). You can delete workspace content at any time, and end-client data you control can be removed on request.
9. Security
We use industry-standard measures including encryption in transit, hashed passwords, access controls, and tenant isolation so one workspace cannot access another’s data. No system is perfectly secure, but we work to protect your data and to notify you of a breach as required by law.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights for data we control, contact [privacy@yourdomain]. We provide tooling in the app to locate and erase personal records on request (for example, to satisfy a GDPR or NZ/AU/DPDP deletion request).
If you are an end-client or site visitor whose data was collected through a site an agency built with ClientReady, that agency is the controller of your data — please contact them. We will assist them in responding to your request.
You also have the right to complain to a supervisory authority (for example, the UK ICO, an EU data protection authority, the OAIC in Australia, the New Zealand Privacy Commissioner, or India’s Data Protection Board).
11. Children
The service is not directed to children, and you must not use it to knowingly collect data from children without a lawful basis and appropriate consent.
12. Cookies
We use strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising cookies. Where required, any non-essential cookies are used only with your consent.
13. Changes
We may update this policy and will post the new version here with a revised date, giving notice of material changes.
14. Contact
Data controller: [Legal Entity Name], [Registered Address]. Privacy contact: [privacy@yourdomain]. [If you appoint a Data Protection Officer or an EU/UK representative, name them here.]