Privacy Policy
Last updated: July 2026
CaseFlow Automation Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the TotalSettle total loss settlement platform (the "Service").
CaseFlow Automation Ltd is the data controller for personal data relating to your user account and your use of the Service. For any personal data about your own customers or claimants that you choose to process through the Service, you remain the data controller and we act as your data processor in line with our contract and data processing terms.
We are registered with the Information Commissioner's Office (ICO) under registration number ZC013423.
1. Information We Collect
Personal information you provide
We may collect personal information that you voluntarily provide when using our Service, including:
- Name and email address
- Company name and business contact details
- Account credentials and profile information
- Claimant details you enter into the Service (name, contact information, vehicle registration, postcode, and settlement decision data)
- Claimant mobile number, used to send the secure settlement link by SMS where the operator enables it
You should avoid entering unnecessary personal data about third parties into the Service. We encourage you to collect and input only the minimum data required for the settlement process.
Usage data
We automatically collect certain information when you access the Service, including:
- IP address and browser type
- Pages visited and features used
- Date and time of access
- Device and technical information
- Log data relating to security and performance of the Service
2. How We Use Your Information
We use the information we collect for the following purposes and lawful bases under UK GDPR:
- To provide, operate, and maintain the Service, including generating settlement links and processing claimant responses (performance of a contract).
- Sending settlement links and notifications by email or SMS (performance of a contract).
- To manage your account, billing, and customer support (performance of a contract / legitimate interests).
- To improve and personalise your experience, including troubleshooting, analytics, and feature development (legitimate interests).
- To communicate with you about updates, security alerts, and administrative matters (performance of a contract / legitimate interests).
- To ensure security, prevent fraud and misuse, and protect our rights and those of other users (legitimate interests / legal obligations).
- To comply with legal and regulatory obligations, including responding to lawful requests from authorities (legal obligation).
3. Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Service providers and sub-processors: Third parties that help us operate the Service (hosting, database, monitoring, analytics, email, and SMS providers). SMS delivery is provided by FireText Communications Ltd, a UK sub-processor under a signed data processing agreement, with UK-only message routing. The message contains a secure link only, never claim details. These parties are only allowed to process personal data on our instructions and under appropriate data protection terms.
- Legal and regulatory requirements: Where required to do so by law or in response to valid legal processes, or to protect our rights, property, or safety or that of others.
- Business transfers: In connection with a merger, acquisition, or sale of all or part of our business, subject to appropriate safeguards.
If any service providers are located outside the UK or EEA, we will ensure that appropriate safeguards are in place for international data transfers (such as standard contractual clauses or equivalent measures).
4. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Data is stored in the European Economic Area (AWS eu-central-1, Frankfurt). Transfers between the UK and the EEA are covered by UK GDPR adequacy regulations
- Encryption of data in transit and at rest
- Logical separation and row-level access controls to isolate each operator's data
- Access controls, authentication measures, and least-privilege access
- Secure, unique settlement links verified against the claimant's vehicle registration and postcode
- Personal identifiers in engineer report text replaced with opaque placeholders before any AI processing, and restored locally on return
- Regular security assessments and monitoring
No method of transmission or storage is completely secure, but we work to maintain security in line with industry standards and legal requirements.
4a. AI Processing of Claim Data
TotalSettle uses an AI provider (currently Google Gemini, accessed via the Lovable AI gateway) to extract structured fields from engineer reports and to draft a short plain-English summary for the customer-facing settlement portal.
Before any engineer report text is sent to the AI provider, personal identifiers (including names, vehicle registration, postcode, email, phone, National Insurance number, UK driving licence, and bank or card numbers) are replaced with opaque placeholders. The AI provider does not see the underlying identifiers in the text path. The original values are restored locally on the way back, into the structured case record. The AI provider does not retain the data and does not use it for training.
Where a scanned or image-only PDF defeats text extraction, the original PDF is sent to the AI provider so the fields can still be read. This fallback path cannot be redacted in-place and every use is logged per case. AI outputs are reviewed by a trained handler before any settlement decision is communicated to a customer. AI is not used to make final settlement decisions.
Full detail, including the model used and processing region, is available on our AI data handling page. The sub-processor list and DPA are available on request.
5. Data Retention
We retain personal data only for as long as the settlement needs it. Retention is driven by the state of the case, not by a fixed calendar window:
- On completion. The moment a case completes (the claimant accepts), personal data is automatically scrubbed: claimant name, email, phone, postcode, vehicle registration, engineer comments, finance company and the settlement link token are permanently removed. Uploaded evidence files are deleted from storage and related email logs are redacted.
- 30-day abandonment expiry. Any case still open (pending or in negotiation) 30 days after it was created is automatically anonymised in the same way and marked as expired. Operators receive an email warning 7 days before this happens.
- Operator offboarding. If an operator stops using the Service, its cases, evidence files, email logs and member accounts are fully wiped.
What remains after any purge is an anonymised statistical skeleton (case status, decision, valuation figures, timestamps and reference) so operators can preserve their reporting. There is no standing library of claimant personal data.
Every automatic purge is recorded in an immutable audit entry with a timestamp and reason, so it is possible to evidence exactly when personal data was removed.
Operator account information (business contact details, billing records) and technical log data are retained for as long as necessary to provide the Service and to comply with legal, accounting or reporting obligations.
You may request deletion of your account or specific records, subject to any legal obligations that require us to retain certain information.
6. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation (UK GDPR), you have the following rights in relation to your personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
To exercise any of these rights, please contact us at info@caseflowautomation.co.uk. You also have the right to lodge a complaint with the ICO at www.ico.org.uk.
7. Cookies
We use essential cookies to ensure the proper functioning of the Service, for example to keep you signed in and secure your session. These cookies are necessary for authentication and security purposes and cannot be switched off in our systems.
We do not currently use cookies for advertising purposes. If we introduce analytics or other non-essential cookies in future, we will update this policy and, where required, request your consent.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last updated" date above. If we make material changes, we may also notify you by email or through the Service.
9. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
CaseFlow Automation Ltd
7–9 Macon Court, Crewe, CW1 6EA, United Kingdom
ICO Registration: ZC013423
CaseFlow Automation Ltd. Legal Processes. Streamlined. This document sets out our formal data processing commitments. It does not constitute legal advice.