Skip to content

Legal

Privacy Policy

What ClientTurn does with personal data — both the data of the businesses who hold an account, and the data of the leads those businesses contact through the product.

Last updated 5 September 2026

This policy is a working draft written to reflect how the product actually operates. It is not legal advice. Before launch, the operator must have it reviewed against UK GDPR and PECR by a qualified adviser, confirm the sub-processor list, and confirm the direct-marketing wording used in customer-facing message templates.

1. Who we are and who this applies to

ClientTurn is a software service that connects a business’s Meta (Facebook and Instagram) lead ads to automated follow-up, qualification and booking.

This policy covers two different relationships:

  • Our customers. The business owners and team members who hold a ClientTurn account. For their account data we are the controller.
  • Our customers’ leads. The members of the public who submit a Meta lead form to one of our customers. For that data our customer is the controller and we are a processor acting on their instructions.

If you submitted an enquiry to a business and want your data removed, contact that business first. If you cannot reach them, write to privacy@clientturn.co.uk and we will pass the request on and assist the controller.

2. Data we hold about account holders

  • Identity and contact. Name, work email address, business name, phone number, and the role assigned to you in your workspace.
  • Authentication. Hashed credentials, session records, and security events such as sign-in attempts and password changes.
  • Billing. Plan, subscription status, invoices and payment references. Card details are handled by our payment processor and never reach our servers.
  • Configuration. Your message templates, qualification questions, sending schedules, quiet hours and integration settings.
  • Usage and support. Audit log entries for actions taken in the product, error diagnostics, and any correspondence you send us.

Our lawful bases are contract (running the service you bought), legitimate interests (securing the service, preventing abuse, improving the product) and legal obligation (accounting and tax records).

3. Data we process on behalf of our customers

When a customer connects Meta, we receive the fields their lead form collects. Typically that is a name, phone number, email address and the answers to the form’s questions, together with the campaign, ad set, ad and form the lead came from.

We then process, on the customer’s instruction:

  • the messages sent and received, including delivery status and the time of each message;
  • the answers given to the customer’s qualification questions and the outcome those answers produced;
  • opt-out and do-not-contact records, which we keep for as long as necessary specifically so that a contact is not messaged again;
  • booking records where a booking integration is connected.

We do not sell this data, do not use it to advertise to the people it describes, and do not use one customer’s lead data to benefit another customer.

4. Our customers' responsibilities

If you use ClientTurn to contact people, you are the controller for that contact. You are responsible for:

  • having a lawful basis for the messages you send, including for any reactivation of older leads;
  • the wording of your messages, including a clear and working opt-out in every direct-marketing message;
  • giving the people who contact you the privacy information UK GDPR requires;
  • responding to requests those people make about their own data.

The product enforces opt-outs, quiet hours and attempt limits, but those controls do not decide whether your campaign is lawful. That judgement is yours.

5. Who we share data with

We use a small number of sub-processors to run the service. Each is bound by a written contract and may only act on our instructions:

  • cloud database, authentication and hosting providers;
  • the SMS and WhatsApp providers used to deliver your messages;
  • Meta, for receiving lead data from your connected lead forms;
  • calendar and booking providers, where you have connected one;
  • our payment processor and our transactional email provider;
  • error monitoring and product analytics providers.

A current list of sub-processors is available on request from privacy@clientturn.co.uk. We will tell customers before adding a sub-processor that materially changes how their data is handled.

6. Where data is stored

Our primary database is hosted in the United Kingdom / European Economic Area. Some providers we rely on operate outside the UK. Where a transfer takes place, we rely on UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

7. How long we keep data

  • Account data: for the life of the account, then up to 90 days after closure to allow recovery, then deleted.
  • Lead and message data: for as long as the customer keeps it, or until they instruct deletion. On account closure it is deleted within 90 days unless the law requires otherwise.
  • Opt-out records: retained after deletion of the rest of the record, because suppressing future contact requires keeping a minimal record of the suppression.
  • Billing records: retained for six years to meet UK accounting requirements.
  • Security and audit logs: typically 12 months.

8. Security

  • Data is encrypted in transit and at rest.
  • Every tenant table is protected by row-level security, so one workspace cannot read another’s records.
  • Provider tokens and secrets are held server-side only and are never returned to a browser.
  • Administrative access is restricted, requires additional verification, and is written to an audit log.

No system is perfectly secure. If a breach affects your data we will notify you and, where required, the Information Commissioner’s Office without undue delay.

9. Your rights

Under UK GDPR you have the right to:

  • be told how your data is used and get a copy of it;
  • have inaccurate data corrected;
  • have data erased in certain circumstances;
  • restrict or object to processing;
  • data portability;
  • withdraw consent where processing relies on consent.

To exercise a right against us as controller, email privacy@clientturn.co.uk. We respond within one month. You may also complain to the Information Commissioner’s Office.

10. Cookies

Our use of cookies and similar technologies is described in the Cookie Policy. Non-essential cookies are only set after you accept them.

11. Changes and contact

We will update this policy when the service changes. Material changes are notified to account holders by email or in the product.

Privacy enquiries: privacy@clientturn.co.uk. General support: support@clientturn.co.uk.