KleipData

Legal

Privacy Policy

Version 1.9Last updated: 30 August 2026
Contents
  1. 1. About this Privacy Policy
  2. 2. Who We Are
  3. 3. How to Contact Us About Privacy
  4. 4. Data Protection Laws
  5. 5. Important Information About KleipData
  6. 6. Our Different Data-Protection Roles
  7. 7. Information We Collect Directly
  8. 8. Website Visitor Information
  9. 9. Enquiries, Demonstrations and Prospective Customers
  10. 10. Customer Organisation Information
  11. 11. Authorised User Information
  12. 12. Developer and API Information
  13. 13. Billing and Payment Information
  14. 14. Support Information
  15. 15. Information About Individuals Appearing in KleipData
  16. 16. Sources of Service Data
  17. 17. What Service Data Is Used For
  18. 18. Access to Personal Data Is Controlled
  19. 19. Facts, Observations and Associations
  20. 20. Accuracy of Service Data
  21. 21. Correcting Information About You
  22. 22. Lawful Bases for Processing
  23. 23. Special Category and Criminal Offence Information
  24. 24. Information Obtained Indirectly
  25. 25. Information Provided by Our Customers About Other People
  26. 26. How Search Processing Works
  27. 27. Saving Search Results
  28. 28. Customer-Controlled Retention
  29. 29. Raw Provider Information
  30. 30. Audit Information
  31. 31. Why We Keep Audit Information
  32. 32. Data Retention Generally
  33. 33. Indicative Retention Categories
  34. 34. Information We Share With Customers
  35. 35. KleipData Is a Data Provider
  36. 36. Service Providers and Suppliers
  37. 37. Data Suppliers
  38. 38. Legal and Regulatory Disclosure
  39. 39. Corporate Transactions
  40. 40. International Transfers
  41. 41. Security
  42. 42. Tenant Isolation
  43. 43. API Security
  44. 44. Cookies and Similar Technologies
  45. 45. Analytics
  46. 46. Marketing Communications
  47. 47. Automated Processing, Matching and Profiling
  48. 48. Decisions About Individuals
  49. 49. Your Data Protection Rights
  50. 50. Right of Access
  51. 51. Right to Rectification
  52. 52. Right to Erasure
  53. 53. Right to Restriction
  54. 54. Right to Object
  55. 55. Data Portability
  56. 56. Rights and Customer-Controlled Data
  57. 57. Locating Search Information
  58. 58. Identity Verification for Privacy Requests
  59. 59. Requests Made on Behalf of Another Person
  60. 60. Charges for Privacy Rights Requests
  61. 61. Data Protection Complaints
  62. 62. How We Handle Data Protection Complaints
  63. 63. Complaining to the Information Commissioner’s Office
  64. 64. Data Protection by Design
  65. 65. Data Protection Impact Assessments
  66. 66. Customer Responsibilities
  67. 67. Information Exported by Customers
  68. 68. Children
  69. 69. Third-Party Websites
  70. 70. Changes to this Privacy Policy
  71. 71. Previous Versions
  72. 72. Relationship With Other KleipData Documents
  73. 73. Summary for People Whose Information Appears in KleipData
  74. 74. Contact Details

This Privacy Policy explains how Computerko Limited (operating the KleipData service) handles personal information. For a privacy request or data-protection complaint, email support@kleipdata.co.uk. It should be read alongside the Terms of Service.

1. About this Privacy Policy

KleipData respects the privacy and information rights of the people whose personal data we handle.

This Privacy Policy explains how Computerko Limited, operating the KleipData service ("KleipData", "we", "us" or "our"), collects, obtains, uses, stores, discloses and otherwise processes personal information.

This Policy applies to personal information relating to:

  • a. visitors to the KleipData website;
  • b. prospective customers and business contacts;
  • c. customers and representatives of customer organisations;
  • d. authorised users of the KleipData customer portal;
  • e. developers using the KleipData API and developer facilities;
  • f. people who contact KleipData for support;
  • g. suppliers, partners and professional contacts;
  • h. people whose personal information may appear within data made available through KleipData’s data-intelligence, search, identity, verification, address, property, corporate or related services; and
  • i. other people whose personal information we process in connection with operating KleipData.

Because KleipData provides data-intelligence services, our role under data-protection law differs depending on what we are doing.

In some circumstances we act as a controller.

In some circumstances we act as a processor for one of our customers.

In other circumstances KleipData and its customer may each act as independent controllers for their respective processing activities.

This Policy explains those distinctions.

2. Who We Are

KleipData is operated by:

Computerko Limited 27 Old Gloucester Street London WC1N 3AX United Kingdom

Company Registration Number: 11125670

Computerko Limited is registered in England and Wales.

For the processing activities in which Computerko Limited determines the purposes and means of processing, Computerko Limited is the data controller.

References to KleipData in this Policy mean Computerko Limited acting through the KleipData service.

3. How to Contact Us About Privacy

Privacy and data-protection enquiries may be sent to:

Data Protection / Privacy KleipData Computerko Limited 27 Old Gloucester Street London WC1N 3AX United Kingdom

Email: support@kleipdata.co.uk

When contacting us about your personal information, please put:

Privacy Request

or:

Data Protection Complaint

in the subject line where appropriate.

You do not have to use those words for us to recognise a valid data-protection request or complaint.

4. Data Protection Laws

We process personal information in accordance with applicable UK data-protection and privacy laws, including as applicable:

  • a. the UK General Data Protection Regulation ("UK GDPR");
  • b. the Data Protection Act 2018;
  • c. the Data (Use and Access) Act 2025;
  • d. the Privacy and Electronic Communications Regulations 2003 ("PECR"); and
  • e. other applicable legislation concerning privacy, electronic communications and processing of personal information.

These laws may be amended or replaced from time to time.

5. Important Information About KleipData

KleipData is a business and organisational data-intelligence platform.

Our Services may enable authorised customers to perform activities including:

  • a. people searches;
  • b. address searches;
  • c. current and historical address intelligence;
  • d. occupancy and address-association searches;
  • e. identity verification;
  • f. historic identity or residency verification;
  • g. KYC checks;
  • h. property intelligence;
  • i. corporate and company searches;
  • j. officer and directorship searches;
  • k. contact-data verification;
  • l. evidence and casework activities;
  • m. authorised data enrichment;
  • n. API-based searches and verification; and
  • o. other data-intelligence activities made available through KleipData.

The fact that KleipData technically provides a particular capability does not mean every customer is permitted to use it.

Customer access is subject to contractual, organisational, dataset, purpose and entitlement controls.

6. Our Different Data-Protection Roles

6.1 When KleipData is a controller

KleipData normally acts as controller for personal information used for our own purposes, including:

  • a. operating our website;
  • b. administering prospective-customer enquiries;
  • c. establishing customer relationships;
  • d. customer-account management;
  • e. billing and payments;
  • f. managing contracts;
  • g. security;
  • h. fraud prevention;
  • i. service administration;
  • j. customer support;
  • k. business communications;
  • l. maintaining our own compliance records;
  • m. maintaining appropriate audit and security information; and
  • n. sourcing, licensing, organising and making available certain Service Data where KleipData determines the purposes and means of that processing.

6.2 When KleipData acts as processor

KleipData may act as processor where a customer instructs us to process personal information solely on its behalf.

Examples may include:

  • a. Customer Content entered into a customer case;
  • b. customer notes;
  • c. customer-created case information;
  • d. information uploaded by a customer;
  • e. certain CRM or case-management integration data; and
  • f. other processing specifically covered by a Data Processing Addendum.

Where we act as processor, the relevant KleipData customer normally acts as controller and is primarily responsible for explaining its processing to the affected individuals.

6.3 Independent controllers

When KleipData lawfully supplies Service Data to a customer and that customer decides:

  • a. why to conduct a search;
  • b. whose information to search;
  • c. how to use the result;
  • d. whether to retain it;
  • e. whether it contributes to a decision; and
  • f. whether it is shared onwards,

KleipData and the customer may each act as independent controllers for their own processing.

The customer’s responsibilities do not replace ours and ours do not replace the customer’s.

7. Information We Collect Directly

We may collect personal information directly when someone:

  • a. visits our website;
  • b. completes a contact form;
  • c. requests a demonstration;
  • d. applies for access;
  • e. creates an account;
  • f. accepts an invitation to an Organisation;
  • g. uses the customer portal;
  • h. creates or administers API credentials;
  • i. subscribes to a paid Service;
  • j. communicates with our sales or support team;
  • k. enters information into the Platform;
  • l. participates in procurement or contracting;
  • m. supplies verification information;
  • n. makes a privacy request; or
  • o. otherwise communicates with KleipData.

8. Website Visitor Information

When someone visits a KleipData website, we may process information such as:

  • a. IP address;
  • b. browser type;
  • c. operating system;
  • d. device type;
  • e. approximate location derived from IP information;
  • f. pages viewed;
  • g. referring page;
  • h. date and time of access;
  • i. session information;
  • j. cookie identifiers;
  • k. consent preferences;
  • l. interaction information;
  • m. security events; and
  • n. information voluntarily submitted through forms.

We use this information for purposes including:

  • a. providing the website;
  • b. protecting website security;
  • c. detecting misuse;
  • d. maintaining performance;
  • e. understanding how the website is used;
  • f. improving content;
  • g. responding to enquiries; and
  • h. complying with legal obligations.

9. Enquiries, Demonstrations and Prospective Customers

If you contact us about KleipData, we may collect:

  • a. your name;
  • b. organisation;
  • c. job title or role;
  • d. work email address;
  • e. telephone number where provided;
  • f. enquiry type;
  • g. organisation or team size;
  • h. proposed use case;
  • i. data requirements;
  • j. integration requirements;
  • k. procurement information;
  • l. correspondence; and
  • m. other information you choose to provide.

We use this information to:

  • a. respond to your enquiry;
  • b. understand your requirements;
  • c. arrange demonstrations;
  • d. prepare quotations;
  • e. discuss procurement;
  • f. assess eligibility for KleipData Services;
  • g. communicate about commercial opportunities; and
  • h. establish a customer relationship where appropriate.

Please do not send passwords, API secret keys or other authentication credentials through general contact forms.

10. Customer Organisation Information

When an Organisation becomes a KleipData customer, we may process information including:

  • a. organisation name;
  • b. company or public-body details;
  • c. registered or business address;
  • d. billing information;
  • e. procurement information;
  • f. contractual contacts;
  • g. account administrators;
  • h. authorised signatories;
  • i. user entitlements;
  • j. Service Plan information;
  • k. enabled services;
  • l. payment status;
  • m. invoices;
  • n. contractual documents;
  • o. executed NDAs;
  • p. Data Processing Agreements;
  • q. accepted Terms;
  • r. compliance information; and
  • s. information reasonably required to establish that the Organisation is eligible to access relevant Services.

11. Authorised User Information

Authorised users may have a KleipData user account linked to one or more Organisations.

We may process:

  • a. name;
  • b. work email address;
  • c. organisation;
  • d. role;
  • e. account status;
  • f. permissions;
  • g. Organisation memberships;
  • h. login events;
  • i. authentication information;
  • j. security settings;
  • k. MFA-related configuration where applicable;
  • l. session information;
  • m. user preferences;
  • n. user-created cases;
  • o. searches conducted;
  • p. support interactions;
  • q. audit activity; and
  • r. other information required to administer the user’s access.

The Organisation is the principal commercial and security boundary within KleipData.

Users act within the Organisation’s entitlement and permissions.

12. Developer and API Information

Where a customer uses KleipData APIs, we may process:

  • a. developer name;
  • b. developer account;
  • c. Organisation;
  • d. registered API Applications;
  • e. credential identifiers;
  • f. API-key prefixes;
  • g. credential hashes;
  • h. scopes;
  • i. environment;
  • j. IP restrictions;
  • k. credential creation date;
  • l. expiry date;
  • m. revocation date;
  • n. last-used information;
  • o. API request identifiers;
  • p. API endpoints used;
  • q. Usage records;
  • r. response status;
  • s. source IP address;
  • t. timestamps;
  • u. error and diagnostic information; and
  • v. associated case or customer references where provided.

We do not need to retain a plaintext copy of API secrets after credential generation where the credential system is designed to use secure hashing.

Customers are responsible for protecting credentials after they are issued.

13. Billing and Payment Information

We may process:

  • a. billing name;
  • b. organisation;
  • c. billing address;
  • d. invoice information;
  • e. transaction amount;
  • f. payment status;
  • g. payment reference;
  • h. subscription or Service Plan information;
  • i. Usage charges;
  • j. VAT information; and
  • k. related accounting records.

Where payments are processed through a payment-service provider, KleipData may not receive complete payment-card information.

Payment providers process payment information according to their own legal obligations and privacy policies.

14. Support Information

If you contact KleipData Support, we may process:

  • a. name;
  • b. Organisation;
  • c. email address;
  • d. telephone number where provided;
  • e. customer reference;
  • f. request ID;
  • g. case or transaction reference;
  • h. affected Service;
  • i. technical diagnostic information;
  • j. correspondence;
  • k. issue descriptions;
  • l. screenshots or attachments supplied by you;
  • m. information about resolution; and
  • n. related audit information.

You should never provide us with passwords or active API secret keys through an ordinary support request.

Please provide only personal information reasonably required to diagnose the issue.

15. Information About Individuals Appearing in KleipData

This section is particularly important if you are not a KleipData customer but information about you may be available through KleipData Services.

KleipData may process personal information obtained from licensed, public, commercial, customer-provided or other lawfully accessible sources in order to provide data-intelligence Services to approved organisations.

Depending upon the Services and datasets involved, information may include:

  • a. name;
  • b. title;
  • c. date of birth or partial date of birth;
  • d. current address information;
  • e. historic address information;
  • f. postcode;
  • g. residency information;
  • h. occupancy observations;
  • i. address-linked associations;
  • j. contact information;
  • k. telephone information;
  • l. identity-verification information;
  • m. historic identity-verification information;
  • n. company directorships;
  • o. company-officer information;
  • p. corporate associations;
  • q. property information;
  • r. property ownership information where lawfully available;
  • s. electoral information where lawfully licensed and permitted;
  • t. evidence relating to an address or identity match;
  • u. dates on which information was first or last observed;
  • v. match or confidence information;
  • w. information indicating that two records may relate to the same person;
  • x. information indicating that people have been observed in association with the same address;
  • y. verification outcomes;
  • z. information produced by combining or normalising multiple lawfully obtained records; and
  • aa. other information made available through a specifically authorised dataset.

Not every category applies to every person.

Not every KleipData customer can access every category.

16. Sources of Service Data

Information available through KleipData may originate from categories of sources including:

  • a. licensed data providers;
  • b. commercial data suppliers;
  • c. data aggregators;
  • d. public registers;
  • e. public records;
  • f. official records and datasets;
  • g. corporate registries;
  • h. electoral information where lawfully available and licensed;
  • i. property and address-information sources;
  • j. telephone or contact-information sources;
  • k. identity and verification providers;
  • l. publicly accessible information;
  • m. customer-provided information;
  • n. information generated from a Customer’s authorised Search;
  • o. existing records used for matching or verification; and
  • p. other sources for which KleipData or its Suppliers have appropriate rights.

A particular Search Result may combine information from more than one source.

Where reasonably possible and legally permitted, we may provide further information about the origin of personal information in response to an appropriate individual-rights request.

We do not necessarily obtain every category of personal information directly from the individual to whom it relates.

17. What Service Data Is Used For

Depending upon the relevant Service and customer entitlement, KleipData may process Service Data to enable legitimate organisational activities such as:

  • a. identity verification;
  • b. address verification;
  • c. historic residency verification;
  • d. customer due diligence;
  • e. fraud prevention;
  • f. fraud investigation;
  • g. KYC activities;
  • h. public administration;
  • i. statutory functions;
  • j. housing and casework functions;
  • k. safeguarding where legally justified;
  • l. authorised investigations;
  • m. property research;
  • n. corporate due diligence;
  • o. business verification;
  • p. litigation or legal-claims support where lawfully authorised;
  • q. lawful debt or asset enquiries;
  • r. data-quality improvement;
  • s. authorised record enrichment;
  • t. evidence gathering;
  • u. audit and compliance;
  • v. customer onboarding;
  • w. risk-management activities; and
  • x. other lawful organisational purposes authorised under the relevant customer agreement and dataset licence.

KleipData does not authorise a customer to process personal information unlawfully merely because the Platform technically makes a Service available.

18. Access to Personal Data Is Controlled

Production access to KleipData data Services may be subject to controls including:

  • a. Organisation approval;
  • b. verification of the customer;
  • c. contractual acceptance;
  • d. execution of confidentiality arrangements;
  • e. data-protection terms;
  • f. purpose declaration;
  • g. user role;
  • h. dataset entitlement;
  • i. API scope;
  • j. Service Plan;
  • k. Usage restrictions;
  • l. compliance approval; and
  • m. other safeguards appropriate to the dataset.

An authorised user may therefore be able to access some Services while being prohibited from accessing others.

19. Facts, Observations and Associations

KleipData may receive or generate information which indicates:

  • a. a fact;
  • b. an observation;
  • c. a match;
  • d. an association;
  • e. an inference; or
  • f. a verification result.

These are not necessarily interchangeable.

For example, information showing that two people have both been observed at the same address does not automatically establish that they are:

  • a. spouses;
  • b. partners;
  • c. relatives;
  • d. financially associated; or
  • e. members of the same household.

Where appropriate, KleipData attempts to describe information according to what the available evidence supports.

20. Accuracy of Service Data

Personal information available through KleipData may originate from third-party and historical sources.

Information may therefore sometimes be:

  • a. historical;
  • b. incomplete;
  • c. inconsistent;
  • d. duplicated;
  • e. incorrectly attributed;
  • f. no longer current; or
  • g. otherwise inaccurate.

The fact that information appears within a dataset does not make it conclusive evidence of a particular fact.

KleipData takes reasonable steps appropriate to our role to maintain data quality and to represent the nature of information appropriately.

Customers are also contractually required to apply appropriate verification before relying upon information for significant purposes.

21. Correcting Information About You

If you believe information associated with you through KleipData is inaccurate, incomplete or misleading, you may contact us.

Please provide sufficient information to enable us to identify:

  • a. you;
  • b. the information concerned;
  • c. why you believe it is incorrect; and
  • d. any supporting information reasonably available.

We may need to verify your identity before disclosing or changing personal information.

Depending upon the source and our legal role, we may:

  • a. correct information we control;
  • b. annotate information as disputed;
  • c. restrict processing while an issue is investigated;
  • d. raise a correction with a Supplier;
  • e. update an internal mapping;
  • f. prevent use of an incorrect association where appropriate; or
  • g. explain why the information cannot lawfully be altered by KleipData.

Where information comes from an official source, correcting the underlying official record may need to be undertaken with the body responsible for that source.

22. Lawful Bases for Processing

We process personal information only where an appropriate lawful basis applies.

The basis depends upon the processing activity.

22.1 Contract

We may process personal information where necessary to:

  • a. enter into a contract;
  • b. administer an existing contract;
  • c. provide purchased Services;
  • d. administer authorised users;
  • e. process billing;
  • f. provide support; or
  • g. take requested steps before entering into a contract.

22.2 Legitimate interests

We may rely upon legitimate interests where appropriate for purposes such as:

  • a. operating KleipData;
  • b. securing our systems;
  • c. preventing misuse;
  • d. administering business relationships;
  • e. improving our Services;
  • f. maintaining audit information;
  • g. investigating security events;
  • h. maintaining appropriate business records;
  • i. protecting legal rights;
  • j. fraud prevention;
  • k. appropriately developing business relationships; and
  • l. certain processing involved in providing data-intelligence Services.

Where we rely upon legitimate interests, we consider:

  • a. the legitimate interest;
  • b. whether processing is necessary; and
  • c. the impact upon people’s rights and freedoms.

22.3 Recognised legitimate interests

Where the statutory conditions apply, we may rely upon a recognised legitimate interest provided for by UK data-protection law.

This basis is used only where the processing falls within the relevant statutory category.

22.4 Legal obligation

We may process personal information where required to comply with legal obligations including:

  • a. accounting;
  • b. taxation;
  • c. regulatory obligations;
  • d. court orders;
  • e. lawful requests from competent authorities; and
  • f. other applicable laws.

22.5 Consent

We may rely upon consent where appropriate, including for:

  • a. certain cookies;
  • b. certain marketing communications; or
  • c. another activity for which consent is the appropriate lawful basis.

Where processing is based on consent, consent may normally be withdrawn.

Withdrawal does not make processing carried out before withdrawal unlawful.

22.6 Other lawful bases

Where another basis provided by law applies to a particular processing activity, we may rely upon that basis.

We document the appropriate basis according to the relevant processing activity.

23. Special Category and Criminal Offence Information

KleipData does not treat the general availability of personal information as authority to process particularly sensitive information.

Where an enabled Service involves:

  • a. special category personal data; or
  • b. criminal offence data,

we will process that information only where an additional statutory condition and any other applicable requirement are satisfied.

Access may also be subject to enhanced:

  • a. contractual restrictions;
  • b. entitlement controls;
  • c. purpose requirements;
  • d. security controls; and
  • e. compliance review.

24. Information Obtained Indirectly

Much of the information used by a data-intelligence service may not be obtained directly from the person it relates to.

Where UK data-protection law requires us to provide privacy information following indirect collection, we will take reasonable steps to meet those requirements.

This Privacy Policy forms part of our transparency arrangements.

Where appropriate we may also provide privacy information through:

  • a. direct communications;
  • b. notices supplied through our data sources;
  • c. customer-facing notices;
  • d. contractual or onboarding documentation;
  • e. data-subject information pages; or
  • f. other appropriate methods.

There are circumstances in which data-protection law provides an exception from providing individual privacy information.

Where we rely upon an exception, we will do so only where the legal requirements for that exception are satisfied.

Where reliance upon a disproportionate-effort exception requires additional safeguards or an assessment of risk, we will apply those requirements as appropriate.

Publication of this Privacy Policy does not itself mean that an exception automatically applies.

25. Information Provided by Our Customers About Other People

Customers may submit personal information about third parties when they:

  • a. conduct a Search;
  • b. create a case;
  • c. perform identity verification;
  • d. submit a subject through an API;
  • e. request enrichment;
  • f. generate a report; or
  • g. use another authorised Service.

Customers are responsible for having appropriate authority and a lawful basis for submitting that information.

Where KleipData processes that information solely on the customer’s documented instructions, we may act as processor.

We may separately process limited information as controller where necessary for:

  • a. security;
  • b. fraud prevention;
  • c. billing;
  • d. compliance;
  • e. audit; or
  • f. enforcing access restrictions.

26. How Search Processing Works

A Customer Search may involve:

  • 1. information being submitted to KleipData;
  • 2. validation of the request;
  • 3. verification of the customer’s entitlement;
  • 4. communication with one or more authorised data providers;
  • 5. receipt of provider information;
  • 6. validation and normalisation;
  • 7. matching;
  • 8. application of access restrictions;
  • 9. creation of a customer-facing result;
  • 10. return of that result through the portal or API; and
  • 11. optional retention where the customer is authorised and chooses to save the result.

We aim to minimise unnecessary persistence of raw provider information.

A raw provider response does not need to become a permanent KleipData record merely because it was used to answer a Search.

27. Saving Search Results

Depending upon the Organisation’s configuration, a Search Result may be:

  • a. returned without being permanently saved;
  • b. retained temporarily;
  • c. saved to a case;
  • d. used to create an evidence snapshot;
  • e. included in a report;
  • f. exported by the customer; or
  • g. transmitted to the customer’s own system through an API.

A customer’s permission under its KleipData contract to retain information does not remove that customer’s independent obligation to have a lawful basis for continued retention.

28. Customer-Controlled Retention

Customer case information may be subject to a Customer-selected or contractually configured retention policy.

Depending upon the Service, options may include:

  • a. no persistence;
  • b. defined short-term retention;
  • c. 30-day retention;
  • d. 90-day retention;
  • e. one-year retention;
  • f. six-year retention;
  • g. case-specific retention; or
  • h. customer-managed retention.

Not every option is necessarily available under every Service Plan.

The Customer remains responsible for selecting a retention period appropriate to its lawful purpose.

29. Raw Provider Information

Our standard data-design principle is that complete raw Supplier responses should not automatically be copied into long-term audit records.

Raw provider information may be processed for the time reasonably required to:

  • a. validate it;
  • b. normalise it;
  • c. apply entitlement controls;
  • d. create the requested result;
  • e. return the result; and
  • f. create an authorised retained snapshot where requested.

There may be circumstances where information must be retained longer for:

  • a. troubleshooting;
  • b. security;
  • c. legal obligations;
  • d. Supplier reconciliation;
  • e. investigation of disputed Usage; or
  • f. another legitimate and documented reason.

30. Audit Information

KleipData maintains audit and Usage information to support accountability and security.

Audit information may include:

  • a. request ID;
  • b. Organisation;
  • c. authorised user or API Application;
  • d. Service requested;
  • e. stated purpose;
  • f. case reference;
  • g. date and time;
  • h. source IP address;
  • i. provider transaction reference;
  • j. status;
  • k. Usage units;
  • l. export event;
  • m. authentication events; and
  • n. relevant security information.

We seek to minimise personal information contained in audit records.

Audit records should not contain complete copies of every raw data-provider response merely because an underlying Search occurred.

31. Why We Keep Audit Information

Audit information may be used for:

  • a. customer accountability;
  • b. access governance;
  • c. billing;
  • d. Usage reporting;
  • e. Supplier reconciliation;
  • f. fraud monitoring;
  • g. data-security investigation;
  • h. investigation of misuse;
  • i. handling complaints;
  • j. legal compliance;
  • k. responding to individual-rights requests;
  • l. enforcing contractual restrictions; and
  • m. demonstrating when, why and by whom a Search was performed.

32. Data Retention Generally

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected or another lawful purpose.

When establishing retention periods, we consider:

  • a. the purpose of processing;
  • b. the amount of information;
  • c. sensitivity;
  • d. legal obligations;
  • e. security requirements;
  • f. contractual commitments;
  • g. Supplier licence requirements;
  • h. limitation periods;
  • i. customer configuration;
  • j. potential disputes; and
  • k. the rights and interests of affected people.

33. Indicative Retention Categories

Our retention arrangements may include the following.

Website enquiries and prospective-customer communications
Normally retained while the enquiry remains active and for an appropriate period afterwards to manage follow-up and business records.
Customer contracts
Core contractual records may be retained for the duration of the customer relationship and for an appropriate limitation and legal-record period following termination.
Financial and accounting information
Retained for the period required by applicable tax, accounting and company law.
User accounts
Operational account information is normally retained while the Account remains active.
Certain information may be retained following closure for security, audit, contractual or legal purposes.
Authentication and security records
Retained according to our security retention schedule and may be kept longer where connected to a security incident or investigation.
Support records
Retained for an appropriate period after resolution to support service continuity, accountability, dispute handling and security.
API and Usage records
Retained for billing, audit, security and Supplier-reconciliation requirements.
Search Results and case records
Retention depends upon the customer’s Service configuration, contractual terms and retention settings.
Raw provider responses
Normally treated as transient unless continued retention is necessary and justified.
Privacy requests and complaints
Retained for an appropriate period to demonstrate how the request or complaint was handled and to protect legal rights.

When information is no longer required, we may:

  • a. delete it;
  • b. anonymise it;
  • c. aggregate it; or
  • d. place it beyond ordinary use pending secure deletion from backups.

34. Information We Share With Customers

KleipData’s core service involves making authorised Service Data available to approved organisational customers.

Depending upon entitlement, those customers may include:

  • a. private-sector organisations;
  • b. public authorities;
  • c. local authorities;
  • d. charities;
  • e. regulated organisations;
  • f. professional-service organisations; and
  • g. other organisations approved to receive the relevant Service.

We do not provide unrestricted public access to production data Services.

A customer’s access to one dataset does not automatically grant access to another.

35. KleipData Is a Data Provider

We want to be clear about an important distinction.

KleipData’s business includes providing licensed data-intelligence Services to authorised organisations.

This may involve making personal information available to those customers for legitimate and authorised purposes.

Accordingly, it would be misleading for us simply to state that we "never sell or provide personal data".

However:

  • a. we do not sell customer-account credentials;
  • b. we do not sell passwords or authentication secrets;
  • c. we do not make production personal-data Services publicly accessible;
  • d. we do not sell ordinary website-visitor profiles to advertisers as part of the KleipData data-intelligence product;
  • e. access to Service Data is contractually controlled; and
  • f. disclosure must remain within our legal and Supplier rights.

36. Service Providers and Suppliers

We may share personal information with appropriate service providers where necessary to operate KleipData.

These may include:

  • a. cloud-hosting providers;
  • b. infrastructure providers;
  • c. data suppliers;
  • d. verification providers;
  • e. authentication providers;
  • f. email providers;
  • g. customer-support providers;
  • h. payment providers;
  • i. security providers;
  • j. monitoring and observability providers;
  • k. backup providers;
  • l. communications providers;
  • m. professional advisers;
  • n. accountants;
  • o. auditors;
  • p. insurers; and
  • q. legal advisers.

Such recipients receive only the information reasonably required for their role and are subject to appropriate legal or contractual obligations.

37. Data Suppliers

Providing a Search may require KleipData to communicate relevant search parameters to an authorised Supplier.

For example, a Supplier may need:

  • a. a person’s name;
  • b. address;
  • c. postcode;
  • d. date-of-birth information;
  • e. company name;
  • f. telephone information; or
  • g. another relevant search parameter

to perform the requested Search or verification.

We do not provide Suppliers with unrelated Customer information merely because a Search takes place.

38. Legal and Regulatory Disclosure

We may disclose personal information where reasonably necessary to:

  • a. comply with law;
  • b. comply with a court order;
  • c. respond to a lawful regulatory requirement;
  • d. establish or defend legal rights;
  • e. prevent or investigate crime;
  • f. protect the security of the Platform;
  • g. investigate fraud;
  • h. protect individuals from serious harm;
  • i. respond to a lawful public-authority request; or
  • j. comply with another binding legal obligation.

We review requests for information according to their legal basis and scope.

39. Corporate Transactions

If Computerko Limited or the KleipData business is:

  • a. sold;
  • b. acquired;
  • c. reorganised;
  • d. merged;
  • e. financed; or
  • f. transferred,

personal information may be disclosed to appropriate advisers, prospective purchasers, investors or successor organisations where legally permitted and subject to appropriate confidentiality safeguards.

40. International Transfers

Some Suppliers or service providers may process personal information outside the United Kingdom.

Where a transfer is a restricted transfer under UK data-protection law, we will use an appropriate lawful mechanism.

Depending upon the circumstances, this may include:

  • a. UK adequacy regulations;
  • b. the UK International Data Transfer Agreement;
  • c. the UK Addendum to approved standard contractual clauses;
  • d. binding corporate rules where applicable;
  • e. another approved appropriate safeguard;
  • f. the UK Extension to the EU-US Data Privacy Framework where the recipient is eligible; or
  • g. a statutory exception where lawfully available.

Where required, we also consider the level of protection provided in the destination country and any additional measures necessary.

41. Security

We use technical and organisational measures appropriate to the risks presented by our processing.

Measures may include:

  • a. access control;
  • b. role-based permissions;
  • c. Organisation-level data isolation;
  • d. encryption;
  • e. authentication controls;
  • f. credential hashing;
  • g. secure secrets management;
  • h. audit logging;
  • i. monitoring;
  • j. backups;
  • k. incident-management procedures;
  • l. vulnerability management;
  • m. staff confidentiality obligations;
  • n. Supplier controls; and
  • o. other appropriate security safeguards.

No internet-connected system can be guaranteed to be absolutely secure.

We therefore continually assess security according to the nature of the information and risks involved.

42. Tenant Isolation

KleipData is designed so customer organisations operate within separate organisational security boundaries.

Customer-owned records are associated with the relevant Organisation.

We use access controls intended to prevent one Organisation from accessing another Organisation’s information without lawful authorisation.

Customers are responsible for administering their own authorised users and permissions.

43. API Security

Production API credentials are associated with a Customer Organisation or registered API Application.

Customers must protect their credentials.

We may:

  • a. hash credentials;
  • b. display secret values only at creation;
  • c. permit credential rotation;
  • d. support scope restrictions;
  • e. support IP restrictions;
  • f. maintain separate test and production credentials;
  • g. revoke credentials; and
  • h. monitor API usage for suspicious activity.

We may suspend a compromised API credential where reasonably necessary to protect personal information.

44. Cookies and Similar Technologies

KleipData websites may use cookies and similar technologies.

These may include:

  • a. strictly necessary cookies;
  • b. authentication cookies;
  • c. security cookies;
  • d. preference cookies;
  • e. analytics technologies; and
  • f. other technologies described in our Cookie Policy.

Strictly necessary technologies may be used where they are required to provide a service requested by the user or maintain essential security.

Where consent is required for a cookie or similar technology, we will seek consent before using it.

Visitors can manage applicable choices through Cookie Settings where provided.

Further information is available in the KleipData Cookie Policy.

45. Analytics

Where enabled and legally permitted, we may use analytics to understand:

  • a. website performance;
  • b. navigation patterns;
  • c. feature usage;
  • d. errors;
  • e. page popularity; and
  • f. general Service performance.

Where analytics technology requires consent under PECR, it will be subject to the applicable consent mechanism.

We do not need to place complete Search Results into analytics systems to understand general website usage.

46. Marketing Communications

We may send relevant business communications where permitted by law.

The lawful basis and PECR requirements depend upon:

  • a. the recipient;
  • b. type of communication;
  • c. existing relationship; and
  • d. means of communication.

Where consent is required, we will seek consent.

Where legitimate interests may lawfully apply, we will consider the impact upon the recipient.

You may opt out of marketing communications at any time using:

  • a. the unsubscribe facility provided; or
  • b. contacting KleipData.

Opting out of marketing does not prevent us from sending necessary:

  • a. security;
  • b. contractual;
  • c. billing;
  • d. support;
  • e. legal; or
  • f. Service administration

messages.

47. Automated Processing, Matching and Profiling

KleipData may use automated processes to:

  • a. search records;
  • b. normalise data;
  • c. compare records;
  • d. identify possible matches;
  • e. calculate confidence or match indicators;
  • f. detect duplicate records;
  • g. identify address associations;
  • h. perform verification;
  • i. detect security anomalies;
  • j. enforce entitlements; and
  • k. support fraud prevention.

Such processing does not necessarily amount to a decision having legal or similarly significant effects.

48. Decisions About Individuals

KleipData primarily supplies information and verification capabilities to organisational customers.

KleipData does not ordinarily decide whether a person should:

  • a. receive housing;
  • b. receive credit;
  • c. be employed;
  • d. receive public benefits;
  • e. enter a tenancy;
  • f. receive a service;
  • g. be investigated;
  • h. be subjected to enforcement; or
  • i. otherwise experience a legal or similarly significant outcome.

Those decisions are normally made by the relevant Customer.

Customers remain responsible for complying with applicable legal requirements concerning automated decision-making and human review.

If KleipData introduces processing in which we ourselves make a solely automated decision having a legal or similarly significant effect, we will provide the additional privacy information and safeguards required by law.

49. Your Data Protection Rights

Depending upon the circumstances and applicable law, you may have rights including:

  • a. the right to be informed;
  • b. the right of access;
  • c. the right to rectification;
  • d. the right to erasure;
  • e. the right to restriction;
  • f. the right to data portability;
  • g. the right to object;
  • h. rights relating to automated decision-making and profiling;
  • i. the right to withdraw consent where processing is based on consent; and
  • j. the right to complain about processing of your personal information.

These rights are not absolute in every circumstance.

An exemption or other legal provision may affect whether a particular right applies.

50. Right of Access

You may ask whether KleipData is processing your personal information and, where applicable, request access to that information.

We may ask for information reasonably necessary to:

  • a. verify your identity;
  • b. locate the relevant information;
  • c. distinguish you from another person with a similar name; and
  • d. understand the scope of your request.

We will not require more identification information than is reasonably necessary.

51. Right to Rectification

You may ask us to correct inaccurate personal information or complete information that is incomplete.

Where the disputed information originates from a Supplier or official source, we may need to:

  • a. investigate the issue;
  • b. raise it with the relevant source;
  • c. annotate the information;
  • d. restrict its processing where appropriate; or
  • e. direct you to the body capable of correcting the underlying record.

52. Right to Erasure

In certain circumstances you may request deletion of your personal information.

The right to erasure does not apply in every situation.

We may need to retain information where processing remains necessary for purposes including:

  • a. legal obligations;
  • b. establishment, exercise or defence of legal claims;
  • c. security;
  • d. fraud prevention;
  • e. statutory functions;
  • f. public-interest requirements; or
  • g. another lawful exception.

53. Right to Restriction

You may have the right to ask us to restrict processing, including while the accuracy or legality of particular processing is investigated.

Where restriction applies, information may remain stored while its active use is limited.

54. Right to Object

Where processing is based upon legitimate interests, you may have the right to object based upon your particular situation.

We will consider the objection and determine whether:

  • a. processing should stop;
  • b. our compelling legitimate grounds justify continued processing; or
  • c. another legal basis or exception applies.

You have separate rights concerning direct marketing.

Where required by law, an objection to direct marketing will be respected.

55. Data Portability

Where the statutory conditions apply, you may have the right to receive relevant personal information in a structured, commonly used and machine-readable format or ask for it to be transmitted to another controller.

This right does not apply to every type of information held by KleipData.

56. Rights and Customer-Controlled Data

Sometimes KleipData holds information solely as processor for one of our Customers.

Where your request relates to information controlled by that Customer, we may:

  • a. tell you that the Customer is the relevant controller;
  • b. refer your request to the Customer where appropriate; or
  • c. assist the Customer in responding.

We will not use the processor/controller distinction to avoid responsibilities that legally belong to KleipData.

57. Locating Search Information

KleipData is designed to minimise unnecessary permanent storage of raw Search Results.

As a result, a Search Result previously viewed by one of our customers may not necessarily remain stored as a complete central KleipData record.

Where possible, information such as:

  • a. the customer Organisation;
  • b. approximate date of the Search;
  • c. request ID;
  • d. case reference; or
  • e. other contextual information

may assist us in locating relevant records.

We will not insist upon information that you cannot reasonably be expected to know.

58. Identity Verification for Privacy Requests

We must take reasonable steps to avoid disclosing personal information to the wrong person.

We may therefore request evidence reasonably necessary to verify identity.

The amount of verification required will depend upon:

  • a. the sensitivity of the requested information;
  • b. the risk of unauthorised disclosure;
  • c. information already available to us; and
  • d. the nature of the request.

We may use secure verification methods where appropriate.

59. Requests Made on Behalf of Another Person

You may appoint someone to act on your behalf.

We may ask for reasonable evidence showing that the representative is authorised.

Examples may include:

  • a. written authority;
  • b. legal authority;
  • c. power of attorney; or
  • d. another appropriate form of representation.

60. Charges for Privacy Rights Requests

We do not normally charge a fee for exercising data-protection rights.

We may charge a reasonable fee, or decline to act, only where applicable law permits us to do so, including in relation to requests that are manifestly unfounded or excessive.

61. Data Protection Complaints

You have the right to complain to us if you are dissatisfied with the way we process your personal information.

You may send a complaint to:

support@kleipdata.co.uk

Please use Data Protection Complaint in the subject line where convenient.

You may also contact us by post using the address in section 3.

You do not have to use a particular legal form or wording for us to recognise a data-protection complaint.

62. How We Handle Data Protection Complaints

When we receive a data-protection complaint, we will:

  • a. provide a clear means by which the complaint can be made;
  • b. acknowledge the complaint within the period required by law;
  • c. take appropriate steps to investigate;
  • d. consider relevant evidence;
  • e. keep the complainant appropriately informed where an investigation continues;
  • f. communicate the outcome without undue delay; and
  • g. explain any appropriate next steps.

Under the current statutory framework, we will acknowledge receipt of a data-protection complaint within 30 days.

Where we complete the investigation and provide the outcome within that period, a separate acknowledgement may not be necessary.

63. Complaining to the Information Commissioner’s Office

You also have the right to complain to the Information Commissioner’s Office ("ICO"), the UK’s independent data-protection regulator.

We encourage you to contact KleipData first where appropriate so that we have an opportunity to investigate and resolve the issue.

This does not affect your right to approach the ICO.

64. Data Protection by Design

We consider privacy and data protection when designing KleipData systems and Services.

Our approach may include:

  • a. data minimisation;
  • b. role-based access;
  • c. Organisation-level entitlements;
  • d. purpose recording;
  • e. dataset restrictions;
  • f. configurable retention;
  • g. separation of test and production environments;
  • h. secure API credential handling;
  • i. audit controls;
  • j. minimisation of raw-provider persistence;
  • k. use of opaque customer-facing references;
  • l. separation of case data from audit data;
  • m. access review; and
  • n. other appropriate safeguards.

65. Data Protection Impact Assessments

Where a type of processing is likely to result in a high risk to individuals, we will undertake a Data Protection Impact Assessment where required.

We may also undertake DPIAs as a matter of good practice for processing involving:

  • a. new data sources;
  • b. identity services;
  • c. large-scale matching;
  • d. systematic monitoring;
  • e. sensitive information;
  • f. high-impact data use;
  • g. significant new technology; or
  • h. reliance upon an Article 14 exception where an assessment is required.

66. Customer Responsibilities

KleipData Customers have their own responsibilities under data-protection law.

Customers may need to:

  • a. identify a lawful basis;
  • b. provide privacy information;
  • c. establish appropriate retention;
  • d. respect individual rights;
  • e. conduct DPIAs;
  • f. control user access;
  • g. verify information before significant use;
  • h. secure exported data;
  • i. manage onward sharing;
  • j. comply with rules concerning automated decision-making; and
  • k. comply with any additional statutory requirements applying to their organisation.

A customer cannot rely solely upon the fact that KleipData supplied information as proof that every subsequent use is lawful.

67. Information Exported by Customers

Customers may be permitted to export Service Data or integrate it into their own systems.

Once a customer stores information in its own:

  • a. CRM;
  • b. case-management platform;
  • c. data warehouse;
  • d. application;
  • e. document repository; or
  • f. other system,

that customer becomes responsible for the processing carried out within that system.

Deleting information from KleipData does not automatically delete information previously exported by a customer.

If your concern relates to an exported copy held by a Customer, you may need to exercise your rights with that Customer as well as with KleipData.

68. Children

KleipData is an organisational service and is not directed towards children as customers or website users.

We do not knowingly invite children to create ordinary KleipData customer Accounts.

Information relating to a child must not be searched or processed through KleipData merely out of curiosity.

Where an authorised Service legitimately involves information about a child, the customer must have a lawful and appropriate basis for that processing and comply with any enhanced protections required by law.

69. Third-Party Websites

The KleipData website may contain links to third-party websites.

Those websites have their own privacy practices.

KleipData is not responsible for a third party’s independent processing merely because we provide a link to its website.

We recommend reviewing the privacy information provided by the relevant third party.

70. Changes to this Privacy Policy

We may update this Privacy Policy where necessary to reflect:

  • a. changes in our Services;
  • b. new data sources;
  • c. new technology;
  • d. changes in law;
  • e. regulatory guidance;
  • f. changes to Suppliers;
  • g. new processing purposes; or
  • h. improvements to our privacy arrangements.

The current version and the date this Privacy Policy was last updated will be displayed on the KleipData website.

Where a change materially affects how we use personal information, we will take appropriate steps to bring the change to affected people where required by law.

71. Previous Versions

We may retain previous versions of this Privacy Policy for accountability and contractual-record purposes.

Where appropriate, previous versions may be made available on request.

72. Relationship With Other KleipData Documents

This Privacy Policy should be read alongside, where relevant:

  • a. the KleipData Terms of Service;
  • b. the KleipData Cookie Policy;
  • c. the KleipData Acceptable Use Policy;
  • d. the applicable Data Processing Addendum;
  • e. the applicable Data Use Schedule;
  • f. any Dataset-Specific Terms;
  • g. any applicable NDA; and
  • h. other privacy information presented at the point a particular Service is used.

Where KleipData acts solely as processor, the relevant Customer’s privacy notice may provide additional information concerning why that Customer processes your information.

73. Summary for People Whose Information Appears in KleipData

If you are an individual whose personal information may appear in a KleipData Service, the most important points are:

Who are we?
KleipData is operated by Computerko Limited.
What do we do?
We provide controlled data-intelligence, search and verification Services to authorised organisations.
Where may information come from?
Licensed data providers, commercial data sources, public records, public registers, official sources, customer-provided information and other lawfully accessible sources.
What may the information include?
Depending upon the Service, information such as names, addresses, historic addresses, address associations, identity information, company relationships, property information, contact information and verification results.
Who may receive it?
Authorised organisational customers who have access to the relevant KleipData Service.
Can anyone search it?
No. Production data Services are subject to customer approval, contracts, permissions and dataset entitlements.
Can a customer keep it?
Sometimes. Retention depends upon the customer’s entitlement, configuration and lawful purpose.
Does contractual permission mean indefinite storage is lawful?
No. Customers must separately comply with data-protection law.
Can information be wrong?
Historical and third-party records can sometimes be incomplete, outdated or incorrectly matched.
Can you challenge information?
Yes. You may contact KleipData if you believe personal information relating to you is inaccurate or is being processed unlawfully.
Does KleipData decide whether you receive housing, credit, employment or another benefit?
Ordinarily, no. KleipData provides information and verification capabilities. The relevant Customer normally makes those decisions.
Can you exercise data-protection rights?
Yes, subject to the applicable statutory conditions and exemptions.
How do you contact us?
Email support@kleipdata.co.uk and identify the enquiry as a privacy request or data-protection complaint where convenient.

74. Contact Details

For questions about this Privacy Policy, your personal information, an individual-rights request or a data-protection complaint:

KleipData Operated by Computerko Limited 27 Old Gloucester Street London WC1N 3AX United Kingdom

Company Registration Number: 11125670

Email: support@kleipdata.co.uk

For support relating to an existing KleipData Customer Account, the same support address may be used.

© 2026 Computerko Limited. KleipData. All rights reserved.