Privacy notice
Draft for service configuration. The controller is Chasely Ltd. Add its registered/business postal address and monitored privacy contact before accepting customer data.
Controller: Chasely Ltd, [insert registered/business address]. Privacy contact: [insert monitored privacy email]. Chasely Ltd decides how account and service administration data is used. For invoice and customer information uploaded by a subscriber, that subscriber is normally the controller and Chasely Ltd acts on their documented instructions as a processor.
Information we handle
Account email, business name, password verifier, verification/reset tokens, login session identifiers, account settings, subscription status, invoice and customer details, reminder text, activity records, and limited security/service logs. Passwords are not stored in readable form. Import files are previewed in your browser and should not be uploaded with invoice attachments; imported fields become service records only after confirmation.
Purposes and lawful bases
- Operate the account, authenticate you, provide the service, and manage your plan: steps needed to perform our contract.
- Protect the service, prevent abuse, and investigate incidents: legitimate interests, balanced against the rights of users and data subjects.
- Meet applicable legal obligations, including accounting and tax obligations for the operator’s own records.
- For invoice/customer data, the subscriber determines the lawful basis and gives Chasely documented instructions. Subscribers must provide required notices and ensure their use of reminder emails is lawful.
Processors and transfers
Service data is hosted using Cloudflare Workers, D1 and Email Service. Subscription checkout and recurring payment processing are handled by Stripe, which processes payment details under its own terms and privacy notice. Chasely does not receive or store full payment card details. We do not sell personal information or use advertising trackers. Publish applicable processor terms, locations, international transfer safeguards and the current subprocessor list before service launch.
Retention and deletion
Proposed retention schedule: active account records remain while the account is in use. On a verified account-closure request, active service records are deleted promptly and no later than 30 days after the request. Immediate account deletion is supported by the service API; there is no self-service deletion screen yet. A narrowly scoped recovery copy may remain only for the documented backup lifetime. Authentication sessions expire after 30 days; email verification links expire after 24 hours and password reset links after 30 minutes. Security logs should be deleted or anonymised after 90 days. Email send/bounce records should be kept for no more than 12 months. A narrowly scoped copy of business records may be retained only where a documented legal obligation or legal claim requires it, with access restricted and review dates set.
These durations are Chasely’s proposed limits, not statutory UK GDPR periods. The operator must configure and periodically verify backups, logs, and provider retention against them before claiming deletion is complete. Data is not retained just because it may be useful later. Subscribers control their customer/invoice records and should delete them when their own purpose and legal obligations end.
Your rights
Depending on the circumstances, individuals may request access, correction, erasure, restriction, portability, object to processing, or withdraw consent where consent is the basis. A subscriber’s invoice/customer records are normally managed by that subscriber as controller; contact them first. For Chasely account data, contact the operator using the privacy contact above. Individuals may complain to the UK Information Commissioner’s Office (ICO).
Security and contact
We use password hashing, expiring one-time links, secure HTTP-only session cookies, access controls and encrypted transport. No internet service can promise absolute security. Report suspected security incidents to Chasely Ltd at [insert monitored security/privacy contact]. This notice should be reviewed at least annually and when processing or providers change.
Last updated: 27 September 2026.