Privacy Notice

Last updated [DATE]. Draft for legal review; bracketed fields are placeholders.

This notice explains how CLI Secure Ltd (“we”), company number 10813832, registered office 60 Copthorne Avenue, Ilford, England, IG6 2SQ, ICO registration ZC139349, uses personal data when you visit this website, contact us or sign up for WiFinger. Contact for privacy matters: [email protected].

1. This website

We set no tracking cookies. Server logs record IP address, user agent and pages requested for security and to keep the site running (legitimate interests, UK GDPR Art. 6(1)(f)); they are deleted after 30 days (container logs roll over and application log records are pruned automatically). If we enable privacy-preserving analytics, it is cookie-less and aggregated; details are in the Cookies page.

2. Forms: trial sign-up, demo and contact

We use the details you give us (name, email, company, phone, sector, Wi-Fi vendor, message) to create your account, answer your request and, where you are a business contact, to tell you about WiFinger (contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)). Product news by email is sent only if you tick the optional box, and every email has an unsubscribe link. Forms are protected by Cloudflare Turnstile, which processes connection data to tell people from bots; see Cloudflare’s privacy notice.

3. The WiFinger service (venue guests)

If you connected to a venue’s guest Wi-Fi powered by WiFinger, the venue is the data controller and CLI Secure Ltd (WiFinger) is its processor. The venue’s own privacy notice, shown on the login page, applies. You can withdraw marketing consent at any time using the link in any message, the preference centre or by contacting the venue. We do not use guest data for our own purposes.

Your details at one venue are kept separately for that venue: they are not shared with, or matched to, other venues that use WiFinger, and we never sell them. If you write to us about a venue’s use of your data, we will pass your request to the venue and help it respond. If you signed in with Google, Microsoft, Facebook, LinkedIn or Apple, that company handles the sign-in under its own privacy notice. [LAWYER TO REVIEW]

4. Customer accounts

For customers, we process account and billing data to provide the service, invoice, support and secure it. Data is hosted in the United Kingdom (London). Sub-processors: IONOS SE (hosting, London data centre), Amazon Web Services (encrypted backup storage, London region, from 31 October 2026), Microsoft (Microsoft 365 email delivery), our SMS providers Twilio, Vonage and The SMS Works (when SMS is enabled), Stripe (payments), and the AI provider selected for the AI assistant (Anthropic, OpenAI or Microsoft Azure OpenAI), only when the assistant is enabled. The full list, with locations and transfer safeguards, is on our sub-processors page and in the Data Processing Agreement. Account users can download a copy of their account data or erase their user account from the admin (Account → Your data). [LAWYER TO REVIEW]

5. Why we use your data and our lawful basis

PurposeDataLawful basis (UK GDPR Art. 6(1))
Running your account and providing the serviceName, email, organisation, role, sign-in and security records(b) contract; (f) legitimate interests for users who are not the contracting party
Billing, invoices and tax recordsBilling contact, address, VAT number, invoices, payment status (card details are held by Stripe)(b) contract; (c) legal obligation
Support, service notices and security alertsMessages, support tickets, account and audit records(b) contract; (f) legitimate interests
Keeping the service and website secure, preventing abuseIP address, user agent, sign-in and audit logs(f) legitimate interests
Product news to business contactsName, email(a) consent (the optional box), which you can withdraw at any time

We do not make decisions about you by automated means that have legal or similarly significant effects. The optional AI assistant only drafts text for the customer’s staff to review. [LAWYER TO REVIEW]

6. Who we share data with and international transfers

We share personal data only with the sub-processors listed on our sub-processors page, with our professional advisers under confidentiality, with public authorities where the law requires it, and with a buyer if the WiFinger business is sold (you would be told). Most data stays in the UK. Where a provider processes data outside the UK (for example Stripe, Twilio or Cloudflare in the United States), the transfer is covered by UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework for certified companies, or the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. The safeguard for each provider is shown on the sub-processors page, and you can ask us for a copy. [LAWYER TO REVIEW]

7. Retention

Enquiries: deleted 24 months after the last contact. Customer account data: for the life of the contract; when an account is closed, its operational data is deleted after 30 days, and invoices and billing records are kept for 6 years after the contract ends for legal and accounting purposes, then deleted. Consent records and audit logs are kept as evidence as described in the Data Processing Agreement; we do not currently delete them, including for closed accounts. We intend to limit this to six years after an account is closed and will update this notice when that deletion is in place. Records of WiFinger staff access to guest data are kept for 6 years. These periods are enforced by an automatic retention job. Guest data inside the service: per the venue’s retention settings (defaults described on our Compliance page). [LAWYER TO REVIEW]

8. Security

Data is encrypted in transit and at rest, access is role-based with two-factor authentication, and backups are encrypted before they leave our server and are stored in the UK (Amazon Web Services, London). WiFinger staff cannot see guest contact details by default; access needs a recorded reason, a fresh two-factor code and is shown to the venue. The measures are listed in Schedule 2 of the Data Processing Agreement. [LAWYER TO REVIEW]

9. Your rights

You have the right to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interests, and to withdraw consent. Write to [email protected]. We reply within one month, which we may extend by two further months for complex requests (we will tell you if so). You may complain to the Information Commissioner’s Office (ico.org.uk); we would appreciate the chance to deal with your concern first. [LAWYER TO REVIEW]

10. Changes

We will post changes here and, for material changes affecting customers, email account owners.