Claimsight

Privacy Policy

Last updated: May 22, 2026

1. Who controls your data

This Privacy Policy explains how TJA Development Ltd trading as Claimsight ("we", "us", "our") collects and uses personal data.

For UK GDPR purposes, we are the data controller for personal data processed through this website and platform, except where we process data solely on behalf of business customers as a processor.

Contact details:

2. Personal data we collect

Depending on how you use the Services, we may collect:

  • account information (name, organisation name, email, login details);
  • profile and support information (messages, requests, communication preferences);
  • claim-related data and uploaded evidence (including image metadata and case references);
  • claimant invitation data, claimant identifiers, device identifiers, and app-submitted device context where needed for evidence provenance;
  • precise location metadata attached to evidence where the claimant app requests and receives permission;
  • technical information (IP address, device/browser data, timestamps, log events);
  • billing and transaction information (payment status, credits, invoices; card processing is handled by payment providers).

3. How we use personal data

We use personal data to:

  • provide, operate, secure, and improve the Services;
  • create and manage user accounts and organisation workspaces;
  • perform fraud detection, evidence analysis, and workflow operations;
  • process payments, maintain records, and prevent abuse;
  • communicate operational updates, service messages, and support responses;
  • comply with legal, regulatory, and law enforcement obligations.

4. UK GDPR lawful bases

We rely on one or more of these lawful bases:

  • Contract: where processing is necessary to provide the Services;
  • Legitimate interests: service security, fraud prevention, product improvement, and administration;
  • Legal obligation: where we must retain or disclose information by law;
  • Consent: where specifically requested (you may withdraw consent at any time).

5. Sharing your data

We may share personal data with:

  • cloud hosting, infrastructure, analytics, email, and support providers;
  • payment processors and financial service providers;
  • configured forensic analysis services used to produce evidence indicators;
  • professional advisers (legal, accounting, insurance);
  • regulators, courts, law enforcement, or government bodies where required.

We require service providers to protect personal data and use it only for permitted purposes.

Our public sub-processor summary is available at /sub-processors.

6. International transfers

Where personal data is transferred outside the UK, we implement appropriate safeguards such as UK International Data Transfer Agreements, the UK Addendum to SCCs, adequacy decisions, or other lawful transfer mechanisms.

7. Data retention

We retain personal data only as long as necessary for the purposes set out above, including legal, regulatory, accounting, dispute, and security requirements.

Retention periods vary by data type and customer contract. We may securely delete or anonymise data when no longer required.

Our public retention summary is available at /retention.

8. Security

We use technical and organisational measures to protect personal data, including access controls, encryption where appropriate, auditing, and secure infrastructure practices.

No system is completely secure, and you are responsible for keeping your account credentials confidential.

Our public security overview is available at /security.

9. Your rights

Under UK GDPR, you may have rights to:

  • access your personal data;
  • correct inaccurate data;
  • erase data in certain circumstances;
  • restrict processing;
  • object to processing based on legitimate interests;
  • data portability;
  • withdraw consent where processing relies on consent.

To exercise rights, contact us using the details above. We may need to verify your identity before responding.

10. Complaints

If you are unhappy with how we handle your data, please contact us first.

You also have the right to complain to the Information Commissioner’s Office (ICO):

11. Cookies and similar technologies

We use essential cookies and similar technologies required for authentication, security, and service operation. Where non-essential cookies are used, we will request consent where legally required.

12. Third-party links and services

Our Services may link to or integrate with third-party sites/services. Their privacy practices are governed by their own policies, and we are not responsible for them.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or by email where appropriate.