Legal

Privacy Policy

Last updated: 30 July 2026

Gibney Technology Enterprises Limited ("ClientCollect", "we", "us", "our") is committed to protecting personal data. This Privacy Policy explains how we handle personal data when you visit clientcollect.com, create an account, or use the ClientCollect service (the "Service"). Handling personal data carefully is the core of what our product does.

1. Who we are

ClientCollect is operated by Gibney Technology Enterprises Limited, a company registered in Ireland (company number 674150), with its registered office at [registered address]. For any privacy question, contact us at privacy@clientcollect.com.

2. Two roles: controller and processor

ClientCollect handles personal data in two distinct capacities:

  • As a data controller — for the personal data of our customers and their team members (the people who sign up for and administer a ClientCollect account) and visitors to our website. This Privacy Policy governs that data.
  • As a data processor — for the documents, responses and other information that our customers' own clients upload into the Service. There, our customer (the firm) is the controller and decides how that data is used; we only process it on their instructions. That relationship is governed by our Data Processing Agreement, not this Policy. If you are a client of a firm that uses ClientCollect and have a question about your documents, please contact that firm directly.

3. Personal data we collect (as controller)

  • Account and profile data — name, email address, firm name, role and profile details you provide. We use passwordless sign-in, so we do not store passwords.
  • Billing data — where you subscribe, billing contact details and subscription records. Card payments are handled by our payment processor; we do not store full card numbers.
  • Usage and technical data — log data, IP address, device and browser information, and actions taken in the Service, used to operate, secure and improve it.
  • Communications — messages you send us (support, sales) and your preferences.
  • Cookies — see Section 7.

4. How we use personal data, and our legal bases

Purpose Legal basis (GDPR Article 6)
Provide, operate and maintain the Service Performance of a contract
Authenticate you and secure accounts Contract; legitimate interests
Bill and manage subscriptions Contract; legal obligation
Send service and transactional messages Performance of a contract
Improve, troubleshoot and develop features Legitimate interests
Marketing communications, where relevant Consent, or legitimate interests where permitted
Comply with legal obligations Legal obligation

Where we rely on legitimate interests, we weigh those interests against your rights and only proceed where appropriate.

5. AI features

The Service includes an optional AI assistant ("Colette"). When you use it, the content you submit is sent to our AI sub-processor(s) to generate a response. We do not permit our AI providers to use your data to train their models. The current list of sub-processors is in our Data Processing Agreement.

6. Sharing and sub-processors

We do not sell personal data. We share it only with:

  • Service providers / sub-processors who help us run the Service (hosting, storage, email delivery, payments, AI). They act on our instructions under contract; the current list is in our DPA.
  • Legal and safety — where required by law, court order, or to protect rights and safety.
  • Business transfers — in connection with a merger, acquisition or sale of assets, subject to this Policy.

7. Cookies

We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, where applicable, limited analytics. We ask for consent for any non-essential cookies, and you can control cookies through your browser settings.

8. International transfers

We are based in the EU and prefer EU/EEA data hosting. Where personal data is transferred outside the EEA (for example, to a sub-processor), we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9. Retention

We keep account and personal data while your account is active and as needed to provide the Service, then for a limited period afterwards to meet legal, accounting and dispute-resolution requirements, after which it is deleted or anonymised. Data we process on a customer's behalf is retained and deleted per our agreement with that customer — see the DPA.

10. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, audit logging and least-privilege access. No system is perfectly secure, but security is central to how we build. A summary of our measures is in Annex 2 of the DPA.

11. Your rights

Under the GDPR you have the right to access your data; to have it rectified or erased; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To exercise any of these, contact privacy@clientcollect.com. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.

If you are a client of a firm that uses ClientCollect, please exercise these rights with that firm (the controller of your documents); we will assist them as their processor.

12. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.

13. Changes

We may update this Policy from time to time. We will post the updated version here and change the "Last updated" date; we will notify you of material changes as appropriate.

14. Contact

Gibney Technology Enterprises Limited, [registered address]. Privacy queries: privacy@clientcollect.com.