Legal

Privacy Policy

Last updated

We collect only what we need to run Clientwharf, and we never sell personal data.

1. Who we are

Clientwharf is operated by Goohoost Ltd, trading as Clientwharf, a private limited company registered in England and Wales under company number 17040971, with its registered office at First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom (“we”, “us”). This policy explains how we handle personal data when you visit clientwharf.com, create an account, subscribe, or contact us.

For privacy questions or to exercise your rights, email privacy@clientwharf.com or write to Goohoost Ltd, First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.

2. When we are controller and when we are processor

We are the controller for personal data we decide how to use: website visitors, account holders and team members, billing and subscription records, support and contact messages, abuse reports, and security logs.

We are a processor for the content our customers put into their workspaces, including files, comments, approvals, requests and documents, and the names and email addresses of the client contacts they invite. Our customer (the freelancer or agency) is the controller of that data and decides what is shared and with whom. Our Data Processing Addendum governs that processing. If you are a client contact and want to exercise your rights over that data, please contact the business that invited you; we will help them respond.

We may also process limited data about client contacts as a controller where needed to keep the Service secure, prevent abuse, and comply with law (for example, sign-in records and security logs).

3. Personal data we collect, why, and our legal basis

The legal bases below come from the EU and UK General Data Protection Regulation (GDPR): performance of a contract, our legitimate interests, compliance with a legal obligation, and consent.

Personal data categories, purposes and legal bases
DataWhat it includesWhy we use itLegal basis
Account dataName, email address, password (stored only as a secure hash), two-factor settings, workspace memberships and roles, notification preferences.To create and run your account and workspace, sign you in, and send service emails such as sign-in links and notifications.Contract
Workspace settingsWorkspace name, logo, brand color and portal settings you choose.To provide the branded portals you configure.Contract
Subscription and billing recordsPlan, billing interval, subscription status and dates, Paddle customer, subscription and transaction IDs, amounts and currency, refund records. We do not receive or store your full card details.To give you the features you paid for, show your billing status, handle plan changes and refunds, and keep business records.Contract; legal obligation (accounting and tax records)
Security and usage logsIP address, browser user agent, sign-in sessions, timestamps, rate-limit counters and audit events for sensitive actions.To keep accounts and workspaces secure, detect and prevent abuse and fraud, investigate incidents, and keep the Service working.Legitimate interests (security and abuse prevention)
Support and contact messagesYour name, email address, the content of your message and our replies; IP address for contact-form submissions.To answer your questions and improve our help content.Legitimate interests; contract where it concerns your account
Abuse and copyright reportsReporter name, email, organization, the reported content, declarations and signature, IP address.To review and act on reports and counter-notices, and to keep records of what we did.Legal obligation; legitimate interests (keeping the Service safe and lawful)
Website analyticsAggregated page views with URL, referrer, country, browser, operating system and device type, via Vercel Web Analytics. It does not use cookies and does not identify individual visitors.To understand which pages are useful and improve the website.Legitimate interests
Customer ContentFiles, comments, updates, approvals, requests, documents and client contact details that customers add to their workspaces.To provide the Service to the customer who controls it.Processed on the customer's behalf under the DPA

We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to make automated decisions that have legal or similarly significant effects on you. We do not send marketing newsletters; if we start, we will ask for your consent where the law requires it, and you will be able to unsubscribe at any time.

If you do not give us the data needed to create an account (such as an email address), we cannot provide the Service to you.

4. Who receives personal data

We share personal data only as needed for the purposes above:

  • Paddle, as Merchant of Record. Paddle.com sells our subscriptions as a reseller. When you buy, Paddle collects your payment details, billing address and tax information directly, as an independent controller under its own Privacy Notice (opens in a new tab). Paddle shares order and subscription details with us so we can give you access.
  • Service providers (subprocessors) that host, store and deliver the Service for us, under written contracts that require them to protect the data and use it only on our instructions. They are listed below and on our subprocessors page.
  • Professional advisers such as lawyers and accountants, under a duty of confidentiality.
  • Authorities and others where required by law, for example to respond to a valid legal request, or where necessary to protect the rights, safety or property of our users, the public or us.
  • A successor business if we are involved in a merger, acquisition or sale of assets, subject to this policy. We will tell you before your data becomes subject to a different privacy policy.
  • Your workspace and clients. Information you add to a workspace is visible to the team members and client contacts who have access to it, as you decide.
Subprocessors used by Clientwharf
SubprocessorPurposeLocationPrivacy policy
Paddle.com Market Ltd (and affiliates)Merchant of Record: checkout, payments, invoicing, sales tax, refundsUnited Kingdom / United StatesPrivacy policy of Paddle.com Market Ltd (and affiliates) (opens in a new tab)
Vercel Inc.Application hosting and content deliveryUnited States (functions in us-east-1)Privacy policy of Vercel Inc. (opens in a new tab)
Neon Inc. (Databricks)Managed PostgreSQL databaseUnited States (AWS us-east-1)Privacy policy of Neon Inc. (Databricks) (opens in a new tab)
Cloudflare, Inc.File storage (R2), DNS, email routing, network securityUnited States / global networkPrivacy policy of Cloudflare, Inc. (opens in a new tab)
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited States (AWS us-east-1)Privacy policy of Resend (Plus Five Five, Inc.) (opens in a new tab)

5. How long we keep data

Retention periods
DataRetention
Account data and Customer ContentWhile your account or workspace exists. After a trial or subscription ends, the workspace is kept read-only for at least 30 days; we email the owner at least 14 days before deleting it. When you delete a workspace or account, data is removed from live systems within 30 days.
BackupsOur database provider keeps rolling point-in-time backups. Deleted data expires from them within a further 30 days.
Subscription and billing recordsSix years after the end of the financial year they relate to, as UK company and tax law requires, even after your account is deleted.
Security logs and audit eventsUp to 12 months, longer only if needed to investigate a specific incident.
Sign-in sessionsUntil you sign out, or 30 days after your last activity.
Support, contact and abuse-report recordsUp to 3 years after the matter is closed, so we can handle follow-ups and repeat issues.
Data exportsExport files are available to download for 7 days and then deleted.
Website analyticsAggregated only; Vercel discards visitor session identifiers after 24 hours.

We may keep data longer if the law requires it or to establish, exercise or defend legal claims.

6. Your rights

Depending on where you live, and in particular under the EU and UK GDPR, you have the right to:

  • access the personal data we hold about you and get a copy;
  • rectification of inaccurate or incomplete data;
  • erasure of your data (“right to be forgotten”) in certain circumstances;
  • restriction of processing in certain circumstances;
  • data portability: receiving data you gave us in a structured, machine-readable format, or having it sent to another provider;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time where we rely on consent, without affecting processing that took place before; and
  • complain to a supervisory authority, in particular in the country where you live or work or where you believe an infringement took place. Our lead authority is the UK Information Commissioner’s Office (ico.org.uk (opens in a new tab)), because Goohoost Ltd is established in the United Kingdom. We would appreciate the chance to address your concern first.

To exercise a right, email privacy@clientwharf.com. We may need to verify your identity first. We respond within one month of receiving your request. If a request is complex or we receive many, we may extend this by up to two further months, and we will tell you why within the first month. Exercising your rights is free unless a request is clearly unfounded or excessive.

You can also update most account details yourself in the app, and workspace owners can export all workspace data at any time.

7. International transfers

Clientwharf is hosted in the United States, and our subprocessors may process data in the United States and other countries. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards:

  • an adequacy decision, including the EU–US Data Privacy Framework and its UK and Swiss extensions where the recipient is certified; or
  • the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant, plus additional measures where needed.

You can ask for more information about these safeguards, or a copy of the relevant clauses, at privacy@clientwharf.com.

8. How we protect data

We take appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access, including:

  • encryption in transit (TLS) on every connection, and encryption at rest by our storage and database providers;
  • workspace (tenant) isolation enforced in our data layer, so one customer cannot reach another customer’s data;
  • files kept in a private storage bucket and downloaded only through signed, short-lived links;
  • passwords stored only as secure hashes, optional two-factor authentication, email verification and rate-limited sign-in;
  • audit logging of sensitive actions and access to production systems limited to people who need it.

No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify you and the relevant authorities as the law requires. More detail is on our security page. To report a vulnerability, email security@clientwharf.com.

9. Cookies

We use only essential cookies, needed to sign you in and remember your active workspace. Our website analytics do not use cookies. When you open Paddle’s checkout, Paddle may set its own cookies under its own policy. Details are in our Cookie Policy.

10. Children

Clientwharf is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@clientwharf.com and we will delete it.

11. Notice for US residents

We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that would give you a right to limit it. Where US state privacy laws give you rights to know, access, correct or delete your personal information, you can exercise them by emailing privacy@clientwharf.com. We will not discriminate against you for doing so.

12. Changes to this policy

We may update this policy to reflect changes in the Service, our providers or the law. The “Last updated” date at the top shows when it last changed. If a change is material, we will email account holders before it takes effect.