AdvisorDraft
/Privacy Policy

Legal Document

Privacy Policy

Last updated: February 2026

CaseFlow Automation Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the IFA Letter Generator service (the "Service").

CaseFlow Automation Ltd is the data controller for personal data relating to your user account and your use of the Service. For any personal data about your own clients that you choose to process through the Service, you remain the data controller and we act as your data processor in line with our contract and data processing terms.

We are registered with the Information Commissioner's Office (ICO) under registration number ZC013423.

1. Information We Collect

Personal information you provide

  • Name and email address
  • Company name and business contact details
  • Account credentials and profile information
  • Content you submit through the Service (meeting notes, case details, and generated letters you choose to save)

You should avoid entering unnecessary personal data about third parties into the Service. Where possible, we encourage you to redact or anonymise meeting notes before upload.

Usage data

  • IP address and browser type
  • Pages visited and features used
  • Date and time of access
  • Device and technical information
  • Log data relating to security and performance

Documents and PDFs

Where you upload or open a PDF or Word document within the Service, the document is processed in your browser using a local processing library. The original file does not leave your device; only extracted text is sent securely to our backend for analysis and letter generation. We do not store or further process the original file itself.

2. How We Use Your Information

We use the information we collect for the following purposes and lawful bases under UK GDPR:

  • To provide, operate, and maintain the Service, including AI-assisted drafting and letter generation (performance of a contract).
  • To manage your account, billing, and customer support (performance of a contract / legitimate interests).
  • To improve and personalise your experience, including troubleshooting, analytics, and feature development (legitimate interests).
  • To communicate with you about updates, security alerts, and administrative matters (performance of a contract / legitimate interests).
  • To ensure security, prevent fraud and misuse, and protect our rights (legitimate interests / legal obligations).
  • To comply with legal and regulatory obligations (legal obligation).

We do not use your data to train AI models.

Our AI provider processes text we send to it to generate responses and does not use that text to train or improve its models.

A PII masking gateway is active. User inputs are processed by a browser-side redaction layer that detects and replaces common personal identifiers (client names, addresses, NI numbers, postcodes, email addresses, phone numbers, dates of birth, and account references) using pattern-based rules before being transmitted to AI providers. Original values are reinjected into extraction results after processing.

3. Data Sharing and Disclosure

We do not sell your personal information.

We may share your information with:

  • Cloud infrastructure providers (hosting, database, authentication). subject to data processing agreements and UK/EU data residency requirements.
  • AI model providers. Receiving only PII-masked text via our active masking gateway, never original documents or unmasked personal data.
  • Professional advisers (legal, accounting) where necessary for compliance or dispute resolution.
  • Law enforcement or regulatory bodies where required by law.

4. Data Retention

We retain personal data only for as long as necessary for the purposes described:

  • Account data is retained while your account is active and for a reasonable period afterwards.
  • Meeting note text is processed transiently. Raw text is deleted immediately after AI extraction. Only structured fields (template type, fund names) are stored.
  • Generated letters are retained in accordance with your firm's retention settings.
  • Audit logs are retained for regulatory compliance purposes.

5. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data (subject to legal obligations).
  • Restriction: Request restriction of processing in certain circumstances.
  • Data portability: Receive your data in a structured, machine-readable format.
  • Object: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at info@caseflowautomation.co.uk. You also have the right to lodge a complaint with the ICO (ico.org.uk).

6. International Data Transfers

Your data is hosted in the UK/EU (eu-west-2, London region). Where any processing involves transfer outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions.

AI model API calls may be routed through provider infrastructure. Only PII-masked text is transmitted via our active masking gateway. Never original documents or unmasked personal data.

7. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

CaseFlow Automation Ltd

Email: info@caseflowautomation.co.uk

ICO Registration: ZC013423

···