Legal
Privacy notice
Click Done Ltd, trading as Adler & Finch. Registered in England & Wales, company number 16796604. Email: enquiries@adlerfinch.com. Effective 7 October 2026.
1. Who is responsible
The controller is Click Done Ltd, trading as Adler & Finch, company number 16796604. Email: enquiries@adlerfinch.com. We have no statutory data-protection officer. Write to that email for any privacy request.
This notice covers personal data of the people who contact us and of the people named on a business we are asked to work for. It does not cover your customers. You must not send us their personal data.
2. What we collect, why, and how long
Enquiries and email. If you email us, we collect what you write, including your name, business and email address if you include them. We use this to reply and to run an order. The lawful basis is steps taken at your request before a contract, and then the contract. We keep it for 24 months from the last contact, or for 6 years if it forms part of a paid order or a dispute, so that we can show what was agreed.
Free snapshot form. If you use the form, we store the business name, website, city, country, sector, your name, work email, that you agreed we may email you the snapshot, whether you opted in to occasional marketing, the time of the request and the browser’s user-agent string. Form data is stored in Google Firebase (Firestore) and used only to produce and send the snapshot. We keep it for 12 months, and we delete it on request via enquiries@adlerfinch.com. The lawful basis is your request for the snapshot, and consent for the marketing box if you tick it.
Follow-up email. We email the snapshot because you asked for it and agreed on the form. Further marketing email is sent only if you tick the optional marketing box, or if you reply asking for it. You can withdraw that consent by emailing us. We keep a suppression record so the withdrawal is honoured. The lawful basis for that record is our legitimate interest in not contacting someone who has opted out.
Orders. When you pay, we keep the business name, website, work email, what was bought, the amount, the currency and a payment reference. Stripe collects the card number and processes the payment. We do not receive the full card number. The lawful basis is the contract, and legal obligation for tax records, which we keep for 6 years. Stripe may process that payment data outside the UK, under the transfer safeguards in its data processing agreement.
Facts you supply, and logins. We use the business facts you approve to write the report and do the checklist. We use a login only to carry out the order, and we delete stored logins when the order is closed or you tell us to stop, whichever is sooner. The lawful basis is the contract. We keep the facts and the change log for 24 months after delivery, unless a dispute or a legal duty requires longer.
Server logs. The site is hosted by Google on Firebase Hosting. Google may process your IP address, browser type, and the pages requested, for security and to operate the host. We do not run analytics and we do not use those logs to market to you. We do not keep a separate copy. Google’s retention of hosting logs is typically short and for security. The lawful basis is our legitimate interest in keeping the site secure.
Business contact from public sources. We may email a corporate body, such as a limited company, at a business email address published on its own website or a public directory, to offer this service. We use the business name, that email address, the website and the location. We do not email sole traders, partnerships or personal inboxes from those sources without consent. Every such email identifies Click Done Ltd and includes a way to opt out. The lawful basis is legitimate interests: offering a relevant service to a business, balanced against that business’s right to be left alone. You can object at any time. We keep the contact record for 24 months, and a suppression record after you object.
3. AI tools
To produce a snapshot we send a fixed set of customer questions, together with the business’s public name, location and website, through the official interfaces of the AI tools named in that report. We do not send your email address, your login, or any customer or patient record in those prompts. You must not include that material in anything you ask us to feed into a tool.
Those providers process the prompt in order to return an answer. Some of them process data in the United States and other countries. Where the UK GDPR requires a transfer safeguard, we rely on the provider’s UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision, as that provider makes available.
The snapshot is a report for your business. It is not an automated decision that produces a legal or similarly significant effect on a person.
4. Who else sees it
We use Google Firebase Hosting to host the site, and Google Firebase (Firestore) to store free-snapshot requests. Stripe takes card payments. We do not sell personal data. We do not share it for another company’s marketing. We may disclose it if the law requires, or to defend a legal claim. An email provider, when one is appointed to send the snapshot, will be named here first. Until then the snapshot is sent from our own email.
5. Security
Access to order information is limited to the people and systems that need it to do the work. Logins you grant us are used for that order only. No method of transmission or storage is perfectly secure.
6. Your rights
If the UK GDPR applies, you may ask for access, correction, erasure, restriction, or a copy of data you provided, and you may object to processing based on legitimate interests. Where we rely on consent, you may withdraw it. We respond within one month. You may complain to the Information Commissioner’s Office at ico.org.uk. Please write to us first so we can put it right.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. If a US state privacy law applies to a request, we will honour the rights it gives you, including to know, delete and correct, and to appeal a refusal. If the Australian Privacy Act or the New Zealand Privacy Act 2020 applies, you may ask for access and correction, and you may complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.