How We Protect Your Data
Here is exactly what happens to claimant information, step by step, from upload to automatic deletion.
Your data's journey
The operator uploads
Your handler uploads the engineer report. We extract the valuation figures and the identifiers needed to run the settlement.
Personal details are masked before AI
Before any report text reaches the AI, names, registrations, postcodes, emails, phones, NINOs, driving licences and bank or card numbers are replaced with opaque placeholders. The AI sees placeholders only, and it runs under Zero Data Retention terms, so it does not keep or train on the data. Originals are restored locally on return.
A trained handler reviews
A handler checks what the AI extracted and the plain-English summary before anything is sent. The AI never makes the settlement decision.
The claimant gets a secure link
A unique link goes to the claimant by email or SMS (SMS is UK-routed via our UK SMS provider). They verify with their vehicle registration and postcode before anything is shown. No password, no account.
The claimant decides
They accept or dispute. Disputes go back to the handler with the full history.
Completion triggers the purge
The moment the claimant accepts, personal data is scrubbed automatically: name, contact details, registration, engineer comments, finance company and the link token are permanently removed, evidence files are deleted from storage, and email logs are redacted. Every purge is written to an audit trail.
Abandoned cases expire at 30 days
Any case still open 30 days after creation is anonymised the same way and marked expired. Operators get an email warning 7 days beforehand.
What this means for you
- We cannot lose what we do not keep. Once a case settles or expires, there is no claimant personal data left to breach.
- Your reporting keeps working. An anonymised statistical skeleton (status, decision, valuation figures, dates, reference) stays behind for your dashboards.
- Everything is hosted in the EEA (AWS Frankfurt), encrypted, with row-level security locking each operator's data to their own organisation. Transfers between the UK and the EEA are covered by UK GDPR adequacy regulations.
- Every purge is logged, so you can evidence exactly when personal data was removed.
The short version: use it to settle, then scrub it. We do not keep what the settlement no longer needs.
Why this helps you too
The less data anyone holds, the less there is to lose. Automatic purging minimises your claimants' exposure and supports your own data-minimisation obligations as the data controller.
The release gate
TotalSettle performs almost no AI processing by design, and that is now enforced by the build itself: an automated gate blocks any release that adds communication with an AI service, unless it is a written, approved exception recorded with its reason. Our three existing exceptions, the engineer report reader that prefills the total loss form and its supporting text extraction (both under no-training AI terms named in our client contracts), and an admin-only marketing voiceover tool that never touches case data, are each recorded with reason and approval. A release that adds an unapproved AI call cannot ship.
CaseFlow Automation Ltd. Legal Processes. Streamlined. This page describes the platform's data protection architecture as implemented. It does not constitute legal advice.