Privacy Policy

Last updated: April 2026


Who we are

Sortful Ltd (trading as Sortful) is a UK-based service business providing automation, communication, and reputation systems for businesses.


What data we collect

1. Client (business) data

When you work with us, we may collect and use various types of information to set up and deliver the service, including for example:

  • Name

  • Business name

  • Email address

  • Phone number

  • Billing details (processed securely via third-party providers)

  • Business or service-related information needed to configure your system

We may also access or integrate with third-party systems you use (such as your CRM or booking system) where required to deliver the service.

2. End-customer data (on your behalf)

As part of delivering the service, we may process data belonging to your customers, including:

  • Name

  • Email address

  • Phone number

We do not own this data. We process it only to provide the agreed service.


How we use data

We use data to:

  • Set up and manage your systems

  • Send review requests and follow-ups (SMS and email)

  • Support automated and AI-assisted communication

  • Integrate with your existing systems where required

  • Communicate with you about your account

  • Process payments and manage billing

We do not sell data or use it for unrelated marketing.


Lawful basis for processing

Under UK GDPR, we rely on:

  • Contract – to deliver the service you have agreed to

  • Legitimate interests – to operate and improve the service

For end-customer data, you (the client) are responsible for ensuring you have the appropriate consent or lawful basis to contact your customers.


Processing on behalf of clients

Sortful acts as a data processor when handling your customers’ data.

You (the client) remain the data controller and are responsible for:

  • Collecting data lawfully

  • Obtaining consent where required

  • Complying with UK GDPR and marketing regulations

We process data only in line with your instructions and to deliver the service.


Third-party processors

We use trusted third-party providers to operate the service, including:

  • GoHighLevel (CRM and messaging systems)

  • Stripe (payment processing)

  • SMS and email delivery providers

We may also connect with systems you already use (such as CRMs or booking platforms) where required.

These providers process data securely and in line with applicable data protection laws.


Data storage and security

  • Data is stored within secure platforms used to deliver the service

  • Access is limited to what is necessary

  • Reasonable measures are taken to protect against unauthorised access, loss, or misuse


Data retention

We keep data only for as long as necessary to:

  • Deliver the service

  • Meet legal, regulatory, or accounting requirements

If you stop using the service, data will be deleted or anonymised within a reasonable period unless we are required to retain it.


Your responsibilities

You are responsible for:

  • Ensuring you have the right to contact your customers

  • Obtaining any required consent for SMS or email communication

  • Ensuring any systems we integrate with are used lawfully

  • Using the system in a lawful and responsible way


Your rights

Under UK GDPR, you have the right to:

  • Access your data

  • Request correction of inaccurate data

  • Request deletion of your data

  • Object to or restrict certain types of processing

To exercise any of these rights, contact us using the details below.


Cookies and website tracking

Our website may use basic cookies or simple tracking tools to:

  • Understand how the site is used

  • Improve performance and user experience

We do not currently use complex or intrusive tracking systems.


Contact

If you have any questions about this Privacy Policy or how data is handled, please contact:

Sortful Ltd
Email: [email protected]


Summary

  • We operate in line with UK data protection laws, including UK GDPR

  • We collect only what is needed to deliver the service

  • We may integrate with your existing systems where required

  • We process customer data on your behalf - not for our own use

  • You remain responsible for your customer data and consent

  • We keep things simple, secure, and transparent