ClientCut

ClientCut

Privacy Policy

Last updated: 28 July 2026

1. Who We Are

ClientCut is operated by H3llo H3llo Ltd, registered in England and Wales under company number 16704188. Our registered office is 27 Wolseley Gardens, Newcastle Upon Tyne, United Kingdom, NE2 1HR. We act as controller for ClientCut account, billing, security and support data. For client, project and media data that a subscribing business controls, ClientCut generally processes that data on the business's instructions, subject to the feature and actual use.

Contact: darius@h3lloh3llo.co.uk

2. Data We Collect

We collect the following categories of personal data:

Account Information

  • Name, email address, business name
  • Password (stored as a secure hash, never in plain text)
  • Billing information (processed by Stripe; we do not store card details)

Client Data You Store

  • Your clients' names, emails, phone numbers, addresses
  • Project details, proposals, contracts, invoices
  • Notes, communications, and file attachments

Usage Data

  • Feature usage statistics and interaction data
  • Log data (IP address, browser type, access times)
  • Device information and approximate location (country level)

Safety and Rights Reports

  • The reported ClientCut page, category and description
  • Your email address if you choose to provide it
  • A one-way hash of the source IP address and limited browser information for abuse prevention and evidence

3. How We Use Your Data

We process your data for the following purposes and legal bases:

PurposeLegal Basis
Providing and maintaining the ServiceContract performance
Processing payments and subscriptionsContract performance
AI-assisted content generationContract performance
Sending service-related communicationsLegitimate interest
Improving and developing the ServiceLegitimate interest
Preventing fraud and ensuring securityLegitimate interest
Complying with legal obligationsLegal obligation
Assessing safety, rights and content-handling reportsLegal obligation and legitimate interests in protecting people and the Service

4. AI and Your Data

ClientCut uses third-party AI services (such as OpenAI) to power AI-assisted features. When you use AI features:

  • Relevant context from your account (client names, project details) may be sent to the AI provider to generate responses.
  • We minimise the data sent and only include what is necessary for the feature.
  • AI providers process data according to their own privacy policies and data processing agreements.
  • ClientCut does not use customer content to develop or train its own general-purpose AI models. Provider handling is governed by the settings, terms and data-processing arrangements that apply to the service we use.

5. Data Sharing

We share your data with the following categories of recipients:

  • Supabase — Database hosting and authentication (EU/US)
  • Stripe — Payment processing (US, with EU data protection)
  • Railway — Application hosting (US)
  • Netlify — Frontend hosting (US)
  • OpenAI — AI content generation (US, with DPA)
  • Google — OAuth sign-in and Gmail integration (when authorised by you)
  • Resend — Transactional email delivery (US)

We do not sell your personal data to third parties. We only share data as necessary to provide the Service or comply with legal obligations.

6. International Data Transfers

Some of our service providers are located outside the UK. Where we transfer data internationally, we use an applicable lawful transfer mechanism, which may include UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses, together with supplementary safeguards where appropriate.

7. Data Retention

We retain your data as follows:

  • Active accounts: Data is retained for as long as your account is active.
  • After cancellation: We normally begin deleting or anonymising service data after the account closes. Some information may remain for a limited period in backups or be retained where required for tax, fraud prevention, dispute resolution, legal claims or other legal obligations.
  • Billing and tax records: Normally retained for six years from the end of the relevant company financial year, or longer where a tax enquiry or another legal requirement applies.
  • Security and service logs: Retained only for the period needed to investigate incidents, operate the Service and establish or defend legal claims, using shorter periods where the risk and purpose allow.
  • Safety and rights reports: Retained for as long as needed to assess and resolve the report, meet applicable reporting and record-keeping duties, protect people, and establish, exercise or defend legal claims. Access is restricted and retention is reviewed.

A report may contain special-category or criminal-offence information. Where it does, we process that information only where an additional condition under data-protection law applies, such as substantial public interest or the establishment, exercise or defence of legal claims.

8. Your Rights (UK GDPR)

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you may have the following rights, depending on the circumstances and lawful basis:

  • Right of access — Request a copy of your personal data.
  • Right to rectification — Request correction of inaccurate data.
  • Right to erasure — Request deletion of your personal data.
  • Right to restrict processing — Request limitation of how we use your data.
  • Right to data portability — Request your data in a structured, machine-readable format.
  • Right to object — Object to processing based on legitimate interests.
  • Rights related to automated decision-making — We do not make solely automated decisions that have legal effects on you.

To exercise any of these rights, contact us at darius@h3lloh3llo.co.uk. We will normally respond within one month, subject to the extensions and exceptions allowed by law.

9. Security

We take the security of your data seriously and implement appropriate technical and organisational measures, including encryption at rest and in transit, row-level security for tenant data isolation, regular security audits, and secure credential storage. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

10. Cookies

We use the following cookies:

  • Essential cookies: Required for authentication and security (CSRF tokens, session management). These cannot be disabled.
  • Functional cookies: Remember your preferences and settings.

We do not use advertising or tracking cookies. We do not use Google Analytics or similar third-party analytics services.

11. Children

ClientCut accounts are not intended for people under 18. A business user may upload lawful project material that depicts or concerns children—for example, wedding or family-event footage. That user is responsible for having an appropriate legal basis, permissions and safeguards for the material. If you believe children's data has been uploaded unlawfully, use our content reporting form.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The “Last updated” date at the top indicates when this policy was last revised.

13. Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

ico.org.uk/make-a-complaint

14. Contact Us

For any privacy-related questions or requests: darius@h3lloh3llo.co.uk

H3llo H3llo Ltd
United Kingdom

Terms of ServiceSign Up