Privacy notice

Last updated: 9 October 2026

Klarifile is in development and is not yet available to customers. This notice describes how we will handle personal data once the service is live, and how we handle the data of people who contact us in the meantime. It will be updated before launch.

Who we are

Klarifile is operated by Giulio Rossi, United Kingdom. For the purposes of UK data protection law we are the controller of the personal data described here.

Contact: info@klarifile.com. We have not appointed a Data Protection Officer because we are not required to; the contact address above reaches the person responsible.

What we collect, and why

What Why Legal basis
Your account details: email address, password (stored only as a hash), optional phone number and two-factor seed To authenticate you and secure your account Contract
Your business details: business name, VAT number, address To produce valid invoices and quotes in your name Contract
Your customers' details: name, email, phone, address, payment terms So you can quote, invoice and send reminders to your own customers. We act on your instructions for this data Contract
Financial records: quotes, invoices, credit notes, payments, bank transactions, supplier invoices, receipts To provide the bookkeeping service, and to meet HMRC record-keeping obligations Contract, and legal obligation
Uploaded documents and generated PDFs To store and deliver your business documents Contract
Communication logs: what was sent, to whom, when, and whether it was delivered So you can see what your customers received, and to avoid duplicate reminders Contract
Security audit log: who did what, when, and from which IP address To detect and investigate unauthorised access Legitimate interests

Features that are not live yet

Two features described on this site are still in development, and we do not process the following data until they are launched and you choose to enable them:

  • Voice commands. If enabled, we would process audio and its text transcription in order to carry out the action you asked for. Transcripts would be retained for 90 days and then deleted. Because voice can incidentally capture sensitive information, a Data Protection Impact Assessment will be completed before this feature is offered to anyone.
  • WhatsApp delivery. If enabled, messages would be sent via Twilio's WhatsApp Business service.

Neither is active. If either is launched, this notice will be updated first, and voice will require your explicit opt-in.

What we do not do

  • We do not sell your data, or your customers' data.
  • We do not run advertising, and we do not build advertising profiles.
  • We do not use tracking cookies. This website sets no cookies and loads no third-party scripts, fonts or analytics.
  • We do not use your data to train machine learning models.
  • We do not make automated decisions with legal or similarly significant effect. Payment matching suggests allocations, but a person confirms them.

Who we share data with

We use a small number of sub-processors, each under a written data processing agreement:

Provider Purpose Location
Neon Database hosting United Kingdom (eu-west-2)
Railway Application hosting United States / EU regions
Amazon Web Services (SES) Transactional email delivery United States (sending region us-east-1)
Amazon Web Services (S3) Document and attachment storage EU or US region, configurable
Cloudflare DNS, and routing inbound receipt emails United States
GitHub Source code storage. Contains no customer data United States

If you use the reminder feature, emails to your customers are sent through Amazon SES. Your customers' addresses are shared with SES for the sole purpose of delivery.

International transfers

Several sub-processors are based in the United States. Where personal data leaves the UK we rely on the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, incorporated into each provider's data processing terms. The database itself is hosted in the UK (eu-west-2).

How long we keep data

Data Retention
Financial records: invoices, quotes, payments, receipts Life of the account plus 7 years, to meet HMRC record-keeping requirements
Customer records Life of the account plus 7 years
Communication logs 7 years
Account and authentication data Life of the account, plus 90 days after deletion to prevent account resurrection
Security audit log Retained while the service operates; reviewed periodically
Voice transcripts (not yet live) 90 days, then deleted

Your rights

Under UK GDPR you have the right to:

  • Access — ask what we hold about you and receive a copy
  • Rectification — correct inaccurate data. Most records can be edited by you directly in the app
  • Erasure — ask us to delete your data, subject to the HMRC retention requirement above, which is a legal obligation that overrides erasure for financial records
  • Restriction — ask us to stop processing while a dispute is resolved
  • Data portability — receive your data in a machine-readable format. Export is a planned feature
  • Object — object to processing based on legitimate interests, including reminder emails to your customers

How to exercise them: email info@klarifile.com from the address on your account. We will respond within one calendar month. Self-service export and deletion are planned but not yet built, so requests are currently handled by us directly. We may ask you to confirm your identity before releasing anything.

These rights are free to exercise. We will only charge, or refuse, where a request is manifestly unfounded or excessive.

Security

  • All traffic is encrypted in transit with TLS
  • Data is encrypted at rest by our hosting providers
  • Every record is scoped to your business, and the application enforces that separation on every request. Database-level row-level security is being added as a second, independent layer
  • Passwords are hashed with bcrypt. We never store passwords in plain text, and we cannot read them
  • Credentials are held in a managed secret store, never in source code. Automated scanning blocks any commit containing a secret
  • Access to production systems is limited, logged, and requires multi-factor authentication

If a breach occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.

Cookies

This website sets no cookies and loads no third-party resources. The application itself uses strictly necessary storage to keep you signed in on your device. There is no advertising or analytics tracking.

Changes to this notice

We will update this page when our processing changes, and revise the date at the top. Material changes will be announced to account holders by email before they take effect.

Complaints

If you are unhappy with how we have handled your data, please contact us first at info@klarifile.com.

You also have the right to complain to the Information Commissioner's Office at any time:

  • Web: ico.org.uk/make-a-complaint
  • Telephone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF