Cleera is a trading name of Seringa Ltd (“we”, “us”, or “our”). We are committed to protecting personal data. This Privacy Policy explains how we collect, use, share, and protect information when you use our platform at cleera.co.uk, related subdomains, and embedded services. It is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy should be read alongside our Terms of Service and Cookie Policy.
1. Who We Are and Our Roles
Seringa Ltd (trading as Cleera) operates the Cleera platform. Depending on the activity, we act in different roles:
- Data controller — for personal data about people who register for Cleera accounts, visit our marketing website, contact us, or otherwise interact with Cleera directly as a customer or prospect of Cleera.
- Data processor — for personal data about your clients, leads, and introducers that you or your organisation enter into Cleera, or that is submitted through features you configure (for example client portals, introducer portals, website lead capture forms, and document ingestion). In those cases, your firm is the data controller and we process data on your instructions to provide the service.
If you submit an enquiry through a mortgage adviser's public intake form, that adviser's firm is usually the data controller for your enquiry. The form should link to their privacy policy. You may contact them first about how your enquiry is used. You may also contact us using the details at the end of this policy if you need help reaching the correct firm or have a question about Cleera's processing.
Questions about how we handle data can be sent via our contact page.
2. Who This Policy Applies To
- Advisers, org admins, and other staff who use Cleera on behalf of a firm
- Clients who use a firm's branded client portal
- Introducers who use a firm's introducer portal
- Members of the public who complete a firm's website lead capture form (hosted by Cleera or embedded on the firm's site)
- Visitors to cleera.co.uk and our marketing pages
3. Data We Collect
Information you provide directly
- Name, email address, and password when you register an account
- Company name, role, and organisation settings when setting up your firm
- Case, client, and introducer information you enter into the platform
- Documents and files you upload (including PDFs submitted for AI-assisted ingestion)
- Messages sent via our contact form or in-app messaging features
- Payment information processed via Stripe (we do not store full card numbers)
- OAuth connection details when you connect third-party integrations (for example Intelliflo Office), including tokens stored in encrypted form
Website lead capture (public enquiry forms)
When someone completes a lead capture form configured by a firm, we may collect:
- Contact and enquiry details entered in the form (for example name, email, phone, and other fields the firm chose)
- Consent selections shown on the form (including acknowledgement of the firm's privacy policy and optional marketing consent)
- A hashed IP address and submission metadata used for rate limiting and abuse prevention
- Technical data needed to operate embeds (for example referrer or origin information)
Submissions are held in a pending state until the applicant confirms their email address. Unconfirmed submissions expire automatically after 48 hours.
Information collected automatically
- Log data (IP address, browser type, pages visited, timestamps)
- Usage data collected via Google Analytics 4 and Vercel Analytics when enabled (see our Cookie Policy for when analytics load)
- Performance data via Vercel Speed Insights (anonymised)
- Authentication tokens stored as secure, HTTP-only cookies
- Bot-challenge signals when Cloudflare Turnstile is enabled on public intake forms
Property and open-data lookups
When a firm views a property report for a case, we may send property identifiers (for example postcode and address elements) to third-party and public APIs to retrieve EPC, flood, broadband, price-paid, and crime statistics. These lookups are performed to display information to authorised users of the firm and are not used for unrelated marketing.
Address lookup
When you enter a postcode into an address field anywhere on the platform — including public website lead capture forms, the client portal, and internal case and client records — we send that postcode to Ideal Postcodes to retrieve matching addresses for autocomplete. This lookup happens on our server; your browser does not contact Ideal Postcodes directly.
4. How We Use Your Data
We use personal data for the following purposes, relying on the legal bases indicated:
- To provide and manage the service — performance of a contract (for Cleera account holders) or processing on our customers' instructions (for client, lead, and introducer data)
- To process payments and manage subscriptions — performance of a contract
- To send transactional emails (account notifications, form reminders, document alerts, lead confirmation emails) — performance of a contract or our customers' instructions
- To run AI-assisted features (see Section 5) — performance of a contract or our customers' instructions; outputs are generated for review by authorised users
- To push data to integrations you connect (for example Intelliflo Office) — performance of a contract and your explicit action when you choose to send data
- To protect public forms from abuse — legitimate interests (rate limiting, honeypot, timing checks, and Turnstile where enabled)
- To respond to enquiries submitted via the contact form — legitimate interests
- To improve and maintain the platform — legitimate interests
- To comply with legal obligations — legal obligation
- To send marketing communications about Cleera (if you have opted in) — consent
5. AI-Assisted Features
Cleera offers a set of AI-assisted features built on OpenAI's API: a case chat assistant, an FCA-suitability-note drafting tool, a document checklist generator, a document analyser, and a fact-find data extractor. These features are only available where a firm's plan includes them, and each one only runs when an authorised user of that firm actively triggers it — Cleera does not run AI processing on case data in the background.
We have assessed this processing in a Data Protection Impact Assessment and put the following safeguards in place:
- Zero data retention. Every request to OpenAI is made with data retention disabled (“zero-data-retention”, or ZDR), enforced both by a setting on our OpenAI account and by an explicit parameter on every request. OpenAI does not retain data submitted through these features beyond the time needed to generate a response, and does not use it to train its models.
- Data minimisation. Before any data is sent to OpenAI, Cleera strips out National Insurance numbers, full dates of birth, full postal addresses, employer names, and itemised expenditure lines. Only the data reasonably needed for the specific feature is included.
- No special category data. Cleera does not intentionally send special category data (as defined in UK GDPR Article 9), such as health or medical information, through any AI-assisted feature.
- Human review. AI outputs are assistive drafts only. Advisers and other authorised users remain responsible for reviewing AI-generated content for accuracy before relying on it, sharing it with a client, or filing it as part of a regulatory record.
- International transfer. OpenAI processes data under a Data Processing Agreement with Seringa Ltd, using the UK International Data Transfer Agreement and Standard Contractual Clauses as the transfer mechanism for data leaving the UK.
AI conversation history is deleted from Cleera's own systems after 90 days, and AI-generated extraction drafts are deleted after 30 days, automatically, by a daily scheduled process (see Section 7, Data Retention).
6. Sharing Your Data
We do not sell personal data. We require every processor we work with to be bound by a data processing agreement or equivalent contractual data protection terms before we share personal data with them. We may share data with the following categories of recipients:
- Vercel (global infrastructure) — cloud hosting, file storage, log drains, and bot management
- Neon (London, UK) — PostgreSQL database hosting
- OpenAI (United States, zero-data-retention) — AI-assisted features described in Section 5
- Stripe (global, PCI-DSS compliant) — payment processing and subscription billing
- Brevo (EU) — transactional email delivery
- BoldSign (EU) — electronic signature services for case documents and client consent
- Cloudflare (global) — Turnstile bot protection on public intake forms, when enabled
- Ideal Postcodes (UK) — address lookup and autocomplete when a postcode is entered into an address field
- Intelliflo (UK) — when an authorised user connects their Intelliflo Office account and chooses to send case data or documents
- Public and third-party data providers — for property reports (for example UK government open-data and licensed APIs such as EPC, flood, broadband, Land Registry price paid, and police crime statistics)
- Your firm's clients and introducers — where the service requires sharing between parties you have invited to a case or portal
Where we act as processor for customer firms, we share data only to deliver the service on their instructions or as required by law. We maintain an internal register of our processors, their locations, and the status of our data protection arrangements with each of them, and review it at least annually.
7. Data Retention
We keep personal data only for as long as needed for the purpose it was collected, or as required by law. Retention periods vary by the type of data and, for customer-firm data, by our customers' own instructions and regulatory obligations:
- Mortgage and advisory casework (client and case records) — up to 7 years from case close, in line with FCA record-keeping rules (SYSC 9)
- AI chat conversation history — 90 days, then automatically deleted
- AI-generated extraction drafts — 30 days, then automatically deleted
- Uploaded case and identity documents — for the duration of the case, plus up to 7 years in line with FCA record-keeping rules
- Website lead capture submissions — unconfirmed submissions expire after 48 hours; confirmed submissions are retained as part of the relevant firm's records
- Transactional email content and delivery logs (Brevo) — deleted or anonymised within 100 days of our contract with Brevo ending; day-to-day delivery logs are retained indefinitely at low sending volumes, or on a rolling basis once an account exceeds high-volume thresholds
- Billing records (Stripe) — for as long as required for accounting, tax, and dispute-resolution purposes
- Integration tokens (for example Intelliflo OAuth credentials) — until you disconnect the integration or your account is closed
- Audit logs (who did what, and when, within the platform) — 12 months
- Data submitted to Intelliflo Office via our outbound sync — not retained by Cleera after the sync completes; retention is governed by your own Intelliflo account
When you close your Cleera account, we will delete or anonymise personal data we control within 90 days, except where we are required to retain it for longer — most commonly, case-related records kept for up to 7 years under FCA SYSC 9, or financial records kept for up to 6 years under UK tax law.
8. International Transfers
Some of our third-party providers operate outside the UK. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or adequacy decisions.
9. Your Rights
Under UK GDPR, you may have the following rights in relation to personal data we control:
- Right of access — to request a copy of the personal data we hold about you
- Right to rectification — to ask us to correct inaccurate or incomplete data
- Right to erasure — to ask us to delete your personal data in certain circumstances
- Right to restriction — to ask us to restrict processing of your data
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests
- Right to withdraw consent — where we rely on consent, you may withdraw it at any time
If your data was submitted to a firm through Cleera (for example as a client, introducer, or website lead), contact that firm first to exercise rights against the data controller. We will assist our customer firms with requests that relate to data we process on their behalf, within the scope of our agreement with them.
To exercise rights against Cleera as controller, please use our contact page. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. These include encryption in transit (TLS), hashed passwords, encrypted storage of sensitive integration tokens, access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure.
11. Cookies
We use cookies and similar technologies. For full details, please see our Cookie Policy.
12. Children
Our platform is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify account holders of material changes by email or by displaying a prominent notice on our platform. Continued use after changes take effect constitutes acceptance where applicable.
14. Contact
For any privacy-related questions or to exercise your rights against Cleera as controller, please contact:
Cleera (trading name of Seringa Ltd)
Company number: 15449830
ICO registration number: ZC184688
Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Email: our contact page