Privacy Policy
Last updated: June 2026
1. Who we are
ThresholdTrack is a service operated by ThresholdTrack Ltd (“ThresholdTrack”, “we”, “us”), a company registered in England and Wales. This policy explains how we handle personal data in line with the UK GDPR and the Data Protection Act 2018.
For most personal data we process on behalf of solicitor firms and estate agencies, those firms are the data controller and we act as their data processor. For our own account holders, marketing contacts and website visitors, we are the controller. This policy covers both roles and makes clear which applies.
2. The data we process
We process the following categories of personal data:
- Account data: name, email address, role, firm name and password (stored only as a secure hash).
- Case and matter data: property addresses, transaction details, milestone dates, tasks and the names and contact details of parties to a transaction.
- Correspondence content: the full text of emails and messages routed to a matter, which we read to build the timeline and summaries.
- Usage data: log data, device and browser information, and aggregate analytics about how the service is used.
- Enquiry data: information you submit through our contact and demo-request forms.
We ask firms not to store special-category data or sensitive identity documents (such as KYC scans and source-of-funds evidence) in ThresholdTrack during the private beta. These should remain in the firm's existing case-management system.
3. How and why we use it
We use personal data to:
- provide the service: building and maintaining the live timeline, summaries, notifications and risk flags;
- read and interpret matter correspondence to extract stage updates, key dates and action items;
- communicate with you about your account, support requests and service changes;
- keep the service secure, prevent abuse and meet our legal obligations;
- respond to enquiries and, where you have asked, arrange a demonstration.
Our lawful bases are: performance of a contract (providing the service); legitimate interests (running and securing the service, and responding to business enquiries); legal obligation (where the law requires it); and, where relevant, consent (which you may withdraw at any time). Where we act as a processor, the firm determines the purposes and we act on their documented instructions.
4. Artificial intelligence and our sub-processor
To build the timeline and summaries, correspondence text is processed by Anthropic's Claude API. Under Anthropic's commercial API terms, this data is not used to train their models. Anthropic processes data in the United States, so this is an international transfer (see section 6).
The AI reads only the correspondence a firm routes to it. It produces a client-facing timeline and plain- English summaries. It does not give legal advice and a human at the firm remains responsible for the matter.
5. Sharing and sub-processors
We do not sell personal data. We share it only with service providers who process it on our behalf:
- Neon: managed PostgreSQL database hosting (London, eu-west-2).
- Anthropic: AI processing of correspondence (United States).
- Resend: transactional and notification email delivery.
- Vercel: application hosting, content delivery and cookieless analytics.
Each provider is bound by a data-processing agreement. We may also disclose data where required by law, or to establish, exercise or defend legal claims.
6. International transfers
Case data is stored in the United Kingdom. The exception is AI processing, where correspondence text is sent to Anthropic in the United States. That transfer is covered by appropriate safeguards (the UK International Data Transfer Agreement or Standard Contractual Clauses with the UK Addendum), which we are putting in place ahead of general availability.
7. Retention
We keep personal data for as long as needed to provide the service and to meet our legal obligations. Where we act as a processor, retention is set by the firm. Account and case data can be exported or deleted on request; deleted data is removed from active systems within a few days and purged from backups within 30 days.
8. Security
We protect data with encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, audit logging and rate limiting. Full detail is on our security page. No system is perfectly secure, but we work to industry standards and are pursuing formal certification.
9. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to processing;
- data portability;
- withdraw consent where processing is based on it.
Where a firm is the controller, please direct requests to that firm and we will support them. To exercise a right against us as controller, contact us at oli@thresholdtrack.org. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
10. Cookies and analytics
We use privacy-preserving, cookieless analytics to understand aggregate usage. We do not use advertising cookies or cross-site tracking. Strictly necessary cookies may be used to keep you signed in.
11. Changes to this policy
We may update this policy from time to time. We will change the date above and, for material changes, notify account holders.
12. Contact us
For any privacy question or to exercise your rights, email oli@thresholdtrack.org.
