Privacy Policy
Last updated: February 2025
1.Data Controller
Carclaimer Ltd (“we”, “us”, “our”) is the data controller responsible for your personal data. We are registered with the Information Commissioner's Office (ICO) under registration number [TBD].
Contact: Data Protection Officer, Carclaimer Ltd
Email: support@carclaimer.co.uk
2.What Data We Collect
We collect the following categories of personal data:
- Identity Data: Name, title, date of birth
- Contact Data: Email address, phone number, postal address
- Vehicle Data: Registration number, make, model, year
- Financial Data: Information about your car finance agreements obtained via soft credit check
- Technical Data: IP address, browser type, device information
- Consent Records: Timestamps and records of your consent
- Identity Documents: Driving licence or passport images for verification
3.Lawful Basis for Processing
We process your personal data on the following legal bases:
- Consent (Article 6(1)(a) UK GDPR): For running credit checks, sharing data with partner firms, and marketing communications
- Legitimate Interests (Article 6(1)(f)): For operating our service, improving our website, and preventing fraud
- Contract (Article 6(1)(b)): To perform the services you have requested
- Legal Obligation (Article 6(1)(c)): To comply with regulatory requirements
4.Who We Share Your Data With
We may share your personal data with:
- Credit Reference Agencies: To perform soft credit checks (this does not affect your credit score)
- FCA-Authorised Partner Firms: If you have eligible agreements and choose to proceed with a claim
- Our Service Providers: Including hosting (Supabase/Cloudflare), email (Resend), and SMS (Twilio) providers who process data on our behalf
We never sell your personal data to third parties for marketing purposes.
5.Data Retention
- Eligible leads: Retained for the duration of the claims process plus 6 years
- Non-eligible checks: Personal data deleted within 30 days. Anonymised statistical data retained
- Contact form submissions: 2 years
- Cookie data: As per our Cookie Policy
6.Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data (“right to be forgotten”)
- Restrict Processing: Limit how we use your data
- Data Portability: Receive your data in a structured format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time for consent-based processing
To exercise any of these rights, email support@carclaimer.co.uk. We will respond within 30 days.
7.Data Security
We implement appropriate technical and organisational measures to protect your data, including: 256-bit SSL/TLS encryption in transit, encryption at rest, access controls, regular security reviews, and staff training.
8.International Transfers
Our primary data processing occurs within the UK/EEA. Where data is transferred outside the UK/EEA (e.g., to service providers), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.
9.Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
10.Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We recommend reviewing this page periodically.