Close Easy Back to home
Legal

Privacy Policy

Effective 03/09/2026

Your privacy is important to us. It is our policy to respect your privacy regarding any information we may collect from you across our website, https://closeeasy.co.uk.

References in this policy to our platform include our website and any other digital mediums which enable you to access our services.

1. Who we are

We are Take On Ltd (trading as Close Easy), a company registered in England and Wales under company registration number 16216455. Our registered office address is: 4 Elm Court, Elm Grove, Berkhamsted, Hertfordshire, England, HP4 1AF. In this policy we are referred to as we or us.

We provide services to insolvency practitioners and other professionals (Advisers) that enable clients of those Advisers (Clients) to provide any required anti-money laundering documentation, and other key documentation required as part of their relevant engagement of their Adviser, to their Adviser through our platform. This information may include ‘know your client’ information (such as passport copies and other ID documents) as well as other personal data relating to the Client. Our platform also provides identity verification and anti-money laundering, politically exposed person, sanctions and adverse media screening, electronic signature of documents, and AI-assisted extraction of information from uploaded documents, AI-assisted drafting of case narrative content and voice transcription.

Our services are provided to Advisers (who make our platform available to Clients) and any information that a Client uploads to our platform is done so at the request of the relevant Adviser. We do not make any decision as to the information that is uploaded to our platform. We process that information on the Adviser’s instructions, which include making it available to the Adviser through the platform, carrying out the checks and processing described above, and operating, supporting and maintaining the platform. As such we act as a data processor for each Adviser to which we provide our services, with the Advisers being the data controllers in respect of any personal data provided by a Client.

When a Client is uploading documentation through our platform, the Client will be presented with their relevant Adviser’s terms and conditions and privacy policy. This policy will dictate how the Adviser will deal with Client’s personal information that is passed to the Adviser through our platform.

With this in mind:

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us or your Adviser in the first instance. If it is appropriate for your complaint to be dealt with by us, we will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take in response.

2. Information we collect

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous or anonymised data).

We may gather certain personal data on Advisers who are using our services (Adviser Data). We will receive this information as part of our servicing of the contract between us and the Adviser. Most of this information will relate to the Adviser’s business, and so will not be personal data. However, it is possible that some of the information may relate to individuals. We will be the data controller in respect of Adviser Data.

As mentioned above, Clients may upload personal data to our platform at the request of their relevant Adviser, so that their Adviser can provide its services to them (Client Data). The relevant Adviser decides what information to request, and how such information may be used, and we have no part in this process. We will be the Adviser’s data processor in respect of Client Data, with the Adviser being the data controller.

When a visitor (whether an Adviser or a Client) interacts with our platform we will collect certain data about the visit. This will include:

Log and device data is used to operate, secure and troubleshoot the platform. It is not always anonymised, and may be linked to a user account. It is held by our hosting, error monitoring, security logging and performance monitoring providers, which are listed in our sub-processor register, and is retained for no longer than 30 days.

Payments between a Client and their relevant Adviser cannot be made through our platform. This is a matter directly between the Adviser and the Client. We do not collect any payment processing information from Clients.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from personal data but is not considered personal data in law as this data will not directly or indirectly reveal an individual’s identity. For example, we may aggregate your Log Data to calculate the percentage of users interested in a specific platform feature. If we combine or connect Aggregated Data with personal data so that it can directly or indirectly identify an individual, then we will treat the combined data as personal data which will be used in accordance with this privacy policy.

Our identity verification feature includes facial matching against an identity document. That is biometric data used to identify an individual uniquely, and is therefore special category personal data. We process it only as a processor, on the instructions of the relevant Adviser, and it is for the Adviser to identify the condition under Article 9 of the UK GDPR that it relies on. We will not use biometric data for any purpose other than obtaining the result of the check.

Apart from that, our platform is not designed to collect special category personal data (this includes for example details about race or ethnicity, religious or philosophical beliefs and information about health). However, anti-money laundering, sanctions and adverse media screening can return results that constitute criminal offence data, and special category or criminal offence data may appear incidentally in documents uploaded by a Client. Where that happens we process it only as a processor, on the instructions of the relevant Adviser, and it is for the Adviser to identify the condition it relies on.

We also use AI-assisted features to extract information from uploaded documents, to draft case narrative content and to transcribe case history calls. These are provided through our cloud infrastructure provider within the European Economic Area. Prompts and outputs are not retained by, accessible to, or used to train the models of the model provider, and we do not use personal data to train any AI or machine learning model. All AI-generated content is presented to the Adviser as a draft for review and approval. No decision with legal or similarly significant effect is made about any individual by automated means.

A small number of authorised technical and support personnel can access Client Data where necessary to operate, maintain, secure and troubleshoot the platform, and to respond to a support request or a request to configure or review a Client Workflow. Where such a request is raised in relation to a particular case, that request is the Adviser’s instruction to us to access the data in that case to the extent necessary to respond. Access is limited to what is necessary for the purpose, and those personnel are subject to confidentiality obligations and data protection training. We record when our personnel access a case record. We do not use data accessed in this way for any other purpose.

3. Legal bases for processing

In respect of Adviser Data, where we are acting as a data controller, we will process such personal information lawfully, fairly and in a transparent manner. We collect and process Adviser Data only where we have legal bases for doing so.

These legal bases depend on the services you use and how you use them. The legal bases that we rely on are:

In respect of Client Data, where we are acting as a data processor, we will only process such personal data in accordance with the specific instructions of the relevant data controller (ie the relevant Adviser). The Adviser must ensure that it has a legal basis for processing Client Data, and this will be set out in the Adviser’s privacy policy.

4. Disclosure to third parties

We do not sell Client Data, and we do not share it with third parties except with the sub-processors we engage to deliver the platform, as described below, or where we are required to do so by law. The extent to which an Adviser may share Client Data it receives from us with third parties will be set out in the Adviser’s privacy policy.

In connection with the services we deliver through our platform, we use third party service providers for hosting and data storage; identity verification and anti-money laundering, sanctions and adverse media screening; electronic signature; AI-assisted processing; email delivery; support messaging; address search; error monitoring and security logging; and website hosting and analytics. Our current sub-processors, the service each provides, where it processes personal data and the safeguard relied on for any transfer, are published at closeeasy.co.uk/subprocessors.

Each of these providers is engaged under a written contract that requires them to process personal data only on our instructions and to apply appropriate security measures.

5. International transfers

Most of the personal information we process is stored in the United Kingdom. As at the date of this policy:

The processing location and transfer safeguard for each provider is set out in our sub-processor register at closeeasy.co.uk/subprocessors.

If we make a transfer to a country not covered by United Kingdom adequacy regulations, then:

6. Data retention

We will retain Adviser Data, where we are acting as a data controller, for as long as the contract between us and the relevant Adviser is operational. Once the contract ends we will retain such information for a further 90 days, after which it will be deleted.

We will retain Client Data, where we are acting as a data processor, in accordance with the instructions of the relevant Adviser. When an Adviser closes a case, whether as appointed or as closed lost, they choose whether the associated Client Data is deleted immediately, deleted after 14 days, or retained until they instruct otherwise. We act on the option the Adviser selects, and we do not delete Client Data on our own initiative. Where a case has been left open with no activity for 12 months, or where Client Data is being retained and appears to us to be no longer required, we will raise this with the Adviser and ask for their instructions. When our contract with the Adviser ends, the Adviser has a retrieval period in which to export their data, after which we delete it in accordance with our data processing agreement. A Client’s personal data that is provided to their Adviser through our platform will be held by that Adviser in accordance with the Adviser’s own data protection policy. The Client should raise any questions relating to their Adviser’s data retention policies directly with their relevant Adviser.

We may retain personal data for a longer period if we are required by law to do so, in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with an Adviser.

In some circumstances we will anonymise personal data (so that it can no longer be associated with an individual) for research or statistical purposes, in which case we may use this information indefinitely without further notice to the individual.

Where an Adviser uses the Monitored check feature for company search and director identity verification, certain records relating to that check are retained by our identity verification provider, Red Flag Alert, beyond the standard deletion process described above. These records remain stored until manually deleted by the Adviser. It is the Adviser’s responsibility to ensure timely deletion of any retained case files and associated information once they are no longer required. This extended retention applies only to checks that have been marked as Monitored at the point of creation. Advisers retain the right to delete applications and all corresponding data at their discretion at any time. Separately, Red Flag Alert retains an archive of screening records for its own anti-money laundering purposes for a period after the end of our contract with it, acting as an independent controller for that archive. We are not able to instruct deletion of that archive within that period.

Further information on Red Flag Alert’s data handling is available at: https://www.redflagalert.com/privacy-centre.

7. Your rights

Individuals have rights under data protection laws in relation to their personal data. These rights are set out below. If you wish to exercise any of these rights please contact us.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. We may need to re-direct some requests from a Client to their relevant Adviser to handle.

Your rights:

To unsubscribe from our e-mail database or opt-out of communications (including marketing communications), please contact us using the details in section 1 of this policy or opt-out using the opt-out facilities provided in the communication.

8. Cookies

A cookie is a small piece of data stored on your device by a website. We use only those cookies that are necessary to operate our platform and to keep you signed in securely. Our website analytics do not use cookies and do not store your IP address; visitors are counted using a short-lived identifier that is discarded within 24 hours, and only aggregated, anonymised statistics are retained.

9. Business transfers

If we or our assets are acquired, or in the event of a corporate restructure or insolvency event, we would include data among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may continue to use your personal information according to this policy. Any transfer of Client Data in those circumstances would be made in accordance with our data processing agreement with the relevant Adviser.

10. Limits of our policy

Our platform may link to external sites that are not operated by us, in particular those of Advisers. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices. When you leave our platform, we encourage you to read the privacy policy of every website you visit. Clients should understand the privacy policy of their relevant Adviser.

11. Changes to this policy

At our discretion, we may change our privacy policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our platform. Continued use of our platform after any changes to this policy will be regarded as acceptance of our amended practices around privacy and personal information.

If we make a significant change to this privacy policy, for example changing a lawful basis on which we process personal information, we may ask you to re-consent to the amended privacy policy.

Take On Ltd
This policy is effective as of 03/09/2026.