Prices are shown in pounds sterling. Payment is taken in the currency displayed.

Show prices in EUR

Privacy Policy

Company and contact information

Company nameCLA GROUP LIMITED
Trading asCLA Group
Company typePrivate company limited by shares
Company number12992998
Registered inEngland and Wales
Incorporated3 November 2020
Registered office43 Oldbury Road, St Johns, Worcester, Worcestershire, England, WR2 6AA
Emailinfo@clagroup.online
Telephone+44 7361 589243
Websiteclagroup.online

This policy explains how CLA GROUP LIMITED collects, uses and protects personal data. It is provided in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.

1. Controller

The controller is CLA GROUP LIMITED, company number 12992998, registered office 43 Oldbury Road, St Johns, Worcester, Worcestershire, England, WR2 6AA, contactable at info@clagroup.online.

No Data Protection Officer is required or appointed: we are not a public authority, and we do not carry out large-scale systematic monitoring or process special category data on a large scale.

2. What we collect

2.1 From you

  • Orders: name, email address, billing address, country, the service ordered, the amount and the currency.
  • Enquiries: name, email address, telephone number where given, and the content of your message.
  • Your documents: the files you send for editing, and anything within them. Depending on the document, this may include personal data about you or about other people.
  • Correspondence: emails exchanged before, during and after an order.

2.2 Automatically

  • Technical data: IP address, browser, operating system, pages visited and timestamps, from server logs and, where you consent, analytics cookies.

2.3 Payment data

Card numbers are never collected, seen or stored by us. Payments are handled entirely by our payment service provider, which acts as its own controller for that processing. We receive the transaction reference, the amount, the result and the billing details needed for the invoice.

3. A note about your documents

The documents you send are the most sensitive thing we hold, and they deserve a paragraph of their own.

A thesis, a business report or a personal statement may contain confidential information, research data, commercial detail or personal data about third parties. We treat every document as confidential, store it with access limited to the work itself, never use it as a sample or reference, and delete it on the schedule in section 6 or sooner if you ask. If your document contains special category data — health, ethnicity, political opinions and the like — tell us when you order so we can apply the additional care it needs.

4. Why, and on what legal basis

Purpose Legal basis (Art. 6 UK GDPR)
Answering enquiries and preparing quotes Steps at your request before a contract — Art. 6(1)(b)
Carrying out the service ordered Performance of a contract — Art. 6(1)(b)
Invoicing and keeping accounting records Legal obligation — Art. 6(1)(c)
Handling cancellations, complaints and disputes Legal obligation and legitimate interests — Art. 6(1)(c) and (f)
Website security and preventing form abuse Legitimate interests — Art. 6(1)(f)
Analytics cookies Your consent — Art. 6(1)(a)

Where we rely on legitimate interests, we have weighed those interests against your rights, and you may object at any time as described in section 7.

5. Who else sees it

We never sell, rent or trade personal data. It is shared only with, and only as far as necessary:

  • our hosting provider, which runs this website;
  • our payment service provider, which processes payments and its own required checks;
  • our email provider, through which correspondence and documents pass;
  • our accountant and HM Revenue & Customs, for bookkeeping and tax;
  • legal advisers, courts or authorities, where the law requires or a claim needs defending.

Each processor acts under a contract meeting Article 28 UK GDPR. Your documents are not sent to anyone else — the editing is done in-house.

6. How long we keep it

Data Retention
Enquiries that do not lead to an order 12 months from last contact
Customer and order records 3 years after the last order
Invoices and accounting records 6 years, as HMRC requires
Documents you sent for editing 3 months after delivery, then deleted
Server logs 12 months
Cookie consent records 6 months

Ask and we will delete your document sooner — immediately after delivery if you prefer. Say so when you order and we will confirm when it is done.

7. Your rights

Under Articles 15 to 22 UK GDPR you may request access to your data and a copy of it, rectification of anything inaccurate, erasure, restriction of processing, and portability of what you provided; and you may object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before.

Write to info@clagroup.online. We respond within one month, extendable by two further months for complex requests, and we will tell you within the first month if that applies. There is no charge unless a request is manifestly unfounded or excessive.

8. Complaints to the ICO

If you believe your data protection rights have not been respected, you may complain to the UK supervisory authority:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline 0303 123 1113 · ico.org.uk

You may do this regardless of any complaint made to us, though we would rather have the chance to put things right first.

9. International transfers

Data is stored and processed in the United Kingdom or the European Economic Area wherever possible. Where a provider processes data elsewhere, the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards required. A copy is available on request from info@clagroup.online.

9. Security

We use encrypted connections throughout, multi-factor authentication on every account that supports it, access limited to what each task requires, encrypted storage for customer documents, and regular backups.

No system is perfectly secure. Where a personal data breach is likely to result in a risk to your rights, we notify the ICO within 72 hours as Article 33 requires, and tell you directly where the risk is high.

10. Automated decisions

We make no automated decisions producing legal or similarly significant effects about you, and we do not profile you.

11. Children

Our services are directed at adults. Orders may only be placed by a person aged 18 or over, or by a parent or guardian on behalf of a younger student. We do not knowingly collect personal data directly from children under 13. If you believe we hold such data, write to info@clagroup.online and we will delete it.

12. Changes

We may update this policy. The current version is always the one on this page, and we tell customers directly where a change materially affects how their data is handled.