Skip to main content
Legal

Privacy Policy.

Effective date: 1 May 2026 · Webcite Technology Systems Ltd

This Privacy Policy explains how Webcite Technology Systems Ltd ("we", "us", "our") collects, uses, and protects personal data when you use Client Engine (ce.webcite.ai), our marketing site (clientengine.webcite.ai), and our company website (webcite.ai).

We are the data controller for personal data collected through our services. We are registered in England and Wales (Company No. 16580236) with our registered office at Workshed, 7 Carriage Works, London Street, Swindon, SN1 5FB. We are registered with the UK Information Commissioner's Office (Reg. No. ZC045226).

For any privacy questions, contact: info@webcite.ai

1 · Scope

This policy applies to:

  1. Visitors to clientengine.webcite.ai and webcite.ai
  2. Account holders and users of Client Engine (ce.webcite.ai)
  3. Prospect contact data uploaded or generated within Client Engine

A separate Data Processing Agreement (DPA) governs prospect data you process through Client Engine. Where Client Engine processes prospect data on your behalf, you are the controller and we are the processor.

2 · Data we collect

Account data. Name, work email, company name, role, password (hashed), authentication tokens. Collected at sign-up and during normal use.

Billing data. Card details are collected and stored by Stripe. We receive only the last four digits of the card, card brand, billing country, and subscription status. We do not store full payment card numbers.

Usage data. Pages visited, features used, credits consumed, API calls made, IP address, browser type, device type, timestamps. Collected automatically when you use the application.

Prospect data (processed on your behalf). Names, work emails, job titles, company names, LinkedIn URLs, phone numbers, enrichment data, signal data, sequence engagement events. You upload, import, or generate this data inside Client Engine. We process it as your data processor.

Communications. Messages you send to us via email, support, or in-app messaging.

3 · How we use your data

PurposeLawful basis (UK GDPR Art. 6)
Provide and operate the serviceContract
Bill you and manage your subscriptionContract
Authenticate users and prevent fraudLegitimate interests, Legal obligation
Send service emails (receipts, security, updates)Contract
Send onboarding and product update emailsLegitimate interests (you can opt out)
Improve the product and debug issuesLegitimate interests
Comply with legal obligationsLegal obligation

4 · Sub-processors

We use the following sub-processors to operate Client Engine. Each is bound by a written contract and is required to apply appropriate technical and organisational security measures.

Current sub-processors

Sub-processorPurposeRegion
Anthropic, PBCLLM inference (signal detection, ICP analysis, sequence generation)USA
OpenAI, LLCLLM inference (fallback / enrichment)USA
Moonshot AI (Kimi)LLM inferenceChina / Singapore
Apollo.ioProspect data and enrichmentUSA
Exa Labs, Inc.Web signal searchUSA
ManyReachEmail sequencing infrastructureUSA
ResendTransactional and marketing emailUSA
Clerk, Inc.User authenticationUSA
Stripe Payments Europe LtdPayment processing and subscriptionsIreland / USA
Railway Corp.Application hostingUSA
Railway PostgresDatabase hostingUSA

Anticipated future sub-processors

We will update this list and notify customers in advance of any new sub-processor coming into use.

Sub-processorPurposeStatus
HeyReachLinkedIn outreach executionPlanned (v2)
PipedriveCRM two-way syncPlanned (v2)

We also access two UK public registers via outbound API calls only. No personal data is sent to either:

  1. Find a Tender Service (UK Government tender database)
  2. Companies House (UK company register)

5 · International transfers

Several of our sub-processors are based outside the UK. Where personal data is transferred outside the UK, we rely on one of the following safeguards under UK GDPR:

  1. UK adequacy regulations (where applicable)
  2. The UK International Data Transfer Addendum to the EU Standard Contractual Clauses
  3. The EU Standard Contractual Clauses
  4. The UK extension to the EU-US Data Privacy Framework (where the recipient is certified)

You can request a copy of the relevant transfer mechanism by emailing info@webcite.ai.

6 · How long we keep your data

CategoryRetention
Account dataFor the life of your account, plus 12 months after closure
Billing records7 years (UK statutory requirement)
Prospect data inside your workspaceControlled by you; deleted within 30 days of workspace deletion
Usage logs12 months
Email logs (sent, delivered, opened)24 months
Support correspondence24 months

7 · Security

We apply appropriate technical and organisational measures including:

  1. Encryption in transit (TLS 1.2+) and at rest
  2. Hashed passwords (no plaintext storage)
  3. Role-based access control inside the application
  4. Least-privilege access to production systems
  5. Regular dependency and vulnerability monitoring
  6. Logging and audit trails for sensitive actions
  7. Secure key management for API credentials

No system is fully secure. If we become aware of a personal data breach affecting your data, we will notify you and the ICO within the timelines required by UK GDPR.

8 · Your rights

Under UK GDPR you have the right to:

  1. Access the personal data we hold about you
  2. Rectify inaccurate data
  3. Erase your data ("right to be forgotten") subject to legal exceptions
  4. Restrict processing
  5. Object to processing based on legitimate interests
  6. Data portability
  7. Withdraw consent where processing is based on consent
  8. Lodge a complaint with the UK ICO (ico.org.uk)

To exercise any of these rights, email info@webcite.ai. We will respond within one month.

9 · Cookies

Client Engine uses strictly necessary cookies for authentication and session management. Our marketing site uses no analytics or tracking cookies at the time of writing. If we add analytics in future, we will update this policy and where required ask for your consent.

10 · Children

Client Engine is a B2B product and is not directed at children under 16. We do not knowingly collect data from children.

11 · Changes to this policy

We may update this policy. The effective date at the top of this page will change. Material changes will be communicated by email to account holders at least 14 days in advance.

12 · Contact

Webcite Technology Systems Ltd Workshed, 7 Carriage Works, London Street, Swindon, SN1 5FB
Email: info@webcite.ai
ICO Reg. No. ZC045226
Company No. 16580236