CreditPilot AI
Legal · Privacy

Privacy Notice

Last updated: 16 September 2026

Download PDF

This notice explains how CreditPilot AI handles personal information in its credit-control system of action. It covers account users and people whose contact or collection information is held in a customer workspace.

Defined roles

Responsibilities depend on the data context

Human review

AI assistance does not make legal decisions

Data rights

Export and request tools are available

Safeguards

Company-scoped access and audit records

Complete notice

How personal information is handled

The summaries support navigation but do not replace the complete wording of each section.

1. Our role

Responsibility depends on the processing context

A subscribing business normally controls the customer, invoice and collection data it uploads. CreditPilot provides the service and processes that data on its instructions. CreditPilot is separately responsible for account administration, security, support, billing and service operation. Roles may vary with the facts.

2. Information handled

The information required to provide and secure the service

We may handle names, business contact details, account credentials, company settings, invoice details, payment status, communications, promises to pay, disputes, workflow actions, audit events, support information and technical security records. We do not ask users to upload special-category data unless it is genuinely necessary and lawful.

3. Purposes and lawful grounds

Why information is used and the grounds that may apply

Information is used to authenticate users, operate and secure workspaces, organise collection work, prepare user-approved communications, provide support, administer the beta and meet legal duties. Depending on the activity, processing may rely on contract, legitimate interests, legal obligation or consent where consent is required. Customer organisations must determine and document the basis for their own collection activity.

4. AI-assisted features

AI output is visible assistance requiring human review

CreditPilot may use AI to suggest priorities, wording, classifications or next actions. These outputs are assistance, may be incomplete and require human review. CreditPilot does not use them to make or execute solely automated legal, credit or enforcement decisions about a person.

5. Sharing and international transfers

Limited sharing with service providers and lawful safeguards

Information is shared only as needed with providers supporting hosting, databases, email, payments, security, support and optional AI functions, or where law requires it. When you use live chat, Tawk.to processes the chat messages and contact details you choose to provide so that our support team can respond. Where personal data is transferred internationally, appropriate contractual or other recognised safeguards should be used and kept under review.

6. Retention and deletion

Records are kept only for justified periods

Information is kept only for as long as needed for the service, the collection purpose, security, legal obligations, dispute resolution or legal claims. Retention can vary by record and customer instruction. Account deletion requests are reviewed before removal because some financial or audit records may lawfully need to be retained.

7. Your rights

Privacy rights depend on applicable law and circumstances

Depending on the applicable UK or EU law and circumstances, you may request access, correction, erasure, restriction, portability or object to processing. You may also complain to the relevant supervisory authority. We may verify identity and will explain if a request cannot be fulfilled in full.

8. How to make a request

Workspace users can export data and record requests

Signed-in users can download workspace data and record a request in Settings. If your details appear in another business's workspace, contact that business first because it normally controls the record; CreditPilot will support verified requests from it. Requests should be answered without undue delay and normally within the applicable statutory period.

9. Security and cookies

Technical safeguards support—but cannot eliminate—risk

We use access controls, password hashing, company-scoped queries, private downloads, audit logging and protective browser headers. No system is risk-free. See our Cookie Notice for essential session cookies.

10. Changes

The notice will evolve with the service

We may update this notice as the service, providers and European availability develop. Material changes will be communicated through an appropriate channel.

Privacy controls

Manage your workspace information and requests.

If your details appear in another business’s workspace, contact that business first because it normally controls the record.

Open privacy settings