Privacy Policy
CleanMyData · SEEKWL LTD · Last updated: 12 August 2026
SEEKWL LTD, trading as CleanMyData ("CleanMyData", "we", "us"), is a company registered in England and Wales (company number 17380801), with its registered office at London, United Kingdom. We operate the website and service available at cleanmydata.co (the "Service").
This policy explains what personal data we process, why, and what rights you have. It is written to comply with the UK GDPR and the EU GDPR. We serve customers in both the United Kingdom and the European Union.
Contact for anything in this policy: support@cleanmydata.co
SEEKWL LTD is registered with the UK Information Commissioner's Office (ICO), registration number ZC217327.
Our EU representative. Because we offer our service to people in the European Union while being established in the United Kingdom, Article 27 of the EU GDPR requires us to appoint a representative in the EU. We are completing this appointment, and this policy will be updated with their contact details as soon as it is confirmed. Until then, EU residents and supervisory authorities can contact us directly at support@cleanmydata.co on any matter relating to our processing of personal data, and you keep the right to complain to your own supervisory authority.
1. The two kinds of data we handle
CleanMyData processes data in two distinct roles, and your rights work differently in each:
a) Your account data: we are the controller. Data about you as a user: your email address, name, plan, sign-in events, and the projects you create. We decide how and why this is processed.
b) The datasets you upload: we are a processor. The files you upload (Excel, CSV) may contain personal data about your own customers, suppliers or staff (names, order records, payment amounts). For that data, you are the controller and we process it only on your instructions: running the analysis you requested. We never use uploaded data for any other purpose. A Data Processing Agreement covering this relationship is available on request at support@cleanmydata.co.
2. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, name | Account creation (invite-only), magic-link sign-in | Contract |
| Sign-in tokens (stored hashed, 15-minute validity, single use) | Passwordless authentication | Contract |
| Session cookie (HttpOnly, Secure, 30 days) | Keeping you signed in | Contract (strictly necessary) |
| Uploaded files and derived results | Running the analysis you request | Contract (as processor, on your instruction) |
| Plan and billing status | Operating free and paid plans | Contract |
| Authentication and security logs (sign-in requested / completed / failed) | Security, abuse prevention | Legitimate interest |
| Technical error reports | Fixing failures in the Service | Legitimate interest |
| Anonymised file structure (column types, relationships, error patterns) | Diagnosing failures, improving the engine | Legitimate interest |
| Waitlist email address (pre-launch form) | Sending launch news you asked for | Consent |
We do not run advertising and we do not sell data. The engine is deterministic software: the same input produces the same output.
We may review anonymised structural information about uploaded files (column types, table relationships, error patterns) to diagnose failures and improve the Service. That is metadata about the shape of a file, not its contents. We do not use the contents of customer data to train machine-learning models, and we never share customer data with third parties.
The launch waitlist. Before launch, cleanmydata.co offers a form to get notified when we launch. If you submit your email address there, we use it only to send you launch news. The legal basis is your consent, which you can withdraw at any time: every email includes an unsubscribe link, and you can also write to support@cleanmydata.co. Waitlist addresses are stored in our support mailbox (Google Workspace) and sent through Postmark (see section 4). We delete waitlist addresses once the launch announcement has been sent, and no later than 12 months after you signed up, unless you have become a customer by then.
3. Cookies
We use only strictly necessary cookies: the session cookie that keeps you signed in. No advertising or cross-site tracking cookies. If we ever add analytics, this policy will be updated first and consent requested where required.
4. Where your data lives, and who helps us run the Service
Your data is stored and processed by a small number of infrastructure providers (subprocessors) under data processing agreements:
| Provider | Role | Location/transfer safeguard |
|---|---|---|
| Google Cloud Platform (Cloud Run, Cloud SQL) | Application hosting, database | European Union (Frankfurt, Germany, europe-west3) |
| Cloudflare (R2) | Encrypted file and results storage | European Union (EU jurisdiction bucket) |
| Postmark | Sending sign-in links | Transfers covered by SCCs/IDTA |
| Sentry | Error monitoring (technical reports) | Transfers covered by SCCs/IDTA |
| Google Workspace (Gmail) | Support mailbox (support@cleanmydata.co) | Transfers covered by SCCs/IDTA |
Where a provider processes data outside the UK/EEA, transfers are protected by the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs). The current subprocessor list is always available on request.
5. How long we keep data
- Uploaded files and results: Free plan: 7 days from the run, then deleted. Premium and Business plans: 90 days from the run, unless you delete them earlier. On any plan, deleting a project permanently removes the uploaded file and every derived result from storage.
- Account data: for the life of your account, then deleted within 30 days of closure.
- Sign-in tokens: 15 minutes (then invalid); token records and auth logs kept up to 12 months for security.
- Database backups: automated and encrypted, retained 7 days (with 7-day point-in-time recovery). Uploaded files and results live in primary storage only and are removed by deletion as described above.
6. Security
Files are stored encrypted. Access to production systems is restricted. Sign-in is passwordless: there is no password to steal. Sign-in links are single-use, valid 15 minutes, and stored only as cryptographic hashes. Every authentication event is logged.
7. Your rights
Under the UK GDPR and EU GDPR you can ask us to: access the personal data we hold about you, correct it, delete it, restrict or object to processing, and receive it in a portable format. Write to support@cleanmydata.co. We respond within one month.
If your personal data appears in a dataset uploaded by one of our customers, that customer is the controller: contact them first, and we will support their response as processor.
You can complain to a supervisory authority: the ICO in the UK (ico.org.uk), or your local authority in the EU (for France, the CNIL).
8. Children
The Service is a business tool and is not directed at anyone under 18.
9. Changes
If we change this policy we will update the date above and, for material changes, notify you by email before they take effect.