LAST UPDATED 25 August 2026
This notice explains how Chasd, trading as Chasd, uses personal information for the service. It covers website visitors, prospective and current customer users, support contacts and people who receive a customer’s invoice reminder.
It also explains when we act as controller and when we process information only for a business customer that controls it.
Chasd is the controller for account administration, billing, support, product security, service improvement and operation of our business.
Privacy enquiries and data-protection complaints: privacy@chasd.co.uk. Legal notices: legal@chasd.co.uk. Registered office: Not configured — production launch blocked.
Privacy enquiries are handled through the address above. If we appoint a statutory data protection officer or representative, we will publish their contact details here.
A customer decides which legitimate B2B invoices and business contacts to manage, why reminders are sent, their wording and how long its records are needed. For that customer content, the customer is normally controller and we act as processor under its documented instructions.
If you received an invoice reminder, contact the creditor named in it first about the invoice, correction, objection, dispute or your data rights. You may also contact us; we will identify and securely route the request to the relevant customer where appropriate.
We receive information directly from users; from other authorised workspace members; from the customer’s Xero organisation; and from Supabase, Stripe, Resend, Xero and hosting systems. Customer-controlled contact and invoice data is not obtained from public sources.
Account and billing information is needed to enter into and perform the service contract. Without a work email we cannot create an account; without required billing or integration information we cannot provide the relevant paid or connected feature. Optional settings can be left blank.
We do not sell personal information, use Xero API data to train or fine-tune AI models, or use debtor correspondence for advertising. Invoice reminders are customer service correspondence, not marketing from Chasd.
Deterministic rules classify replies into operational categories such as promise to pay, says paid or dispute/query. Rules can pause reminders or propose case state. Users can review and correct the result.
Chasd does not decide whether a debt is legally owed, take legal action, determine creditworthiness or make a solely automated decision that has a legal or similarly significant effect on a person.
Authorised members of the relevant customer workspace receive its records according to role. We use Supabase for database hosting and authentication, Vercel for application hosting, Xero for the customer-directed accounting connection, Stripe for billing and Resend for email delivery and receipt.
We may disclose limited information to professional advisers, auditors, insurers, courts, regulators, law enforcement or a buyer of our business where necessary, lawful and subject to suitable confidentiality or process. See our current provider and subprocessor register.
Providers may process information outside the UK. For a restricted transfer we use an applicable UK adequacy regulation or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. Where required, we complete the UK data protection test (also called a transfer risk assessment) and apply supplementary measures.
Contact us for a copy or summary of the safeguards relevant to your information, subject to necessary confidentiality redactions.
Deletion from active systems does not instantly erase isolated rotating backups. Backup copies are unavailable for normal use and expire under documented provider schedules unless a legal hold applies.
Measures include access controls, tenant isolation, encrypted connections, encrypted Xero tokens, signed webhooks, audit records, data-minimised logs, restricted production secrets, backups and incident procedures. No internet service can guarantee absolute security.
Chasd uses authentication, security and user-requested preference storage. We do not use advertising cookies or third-party behavioural analytics cookies. Our cookie notice lists each category, purpose and duration.
Depending on the circumstances, UK data-protection law may give you rights of access, correction, erasure, restriction, portability and objection. You may withdraw consent where consent is used. Rights can have legal exceptions, and portability applies only in specified cases.
Contact the privacy address above. We may verify identity and, for customer-controlled information, involve the relevant customer. We normally respond within one month, subject to lawful extensions.
Email the privacy address with the words ‘data protection complaint’, your contact details, what happened and the outcome you seek. We will acknowledge the complaint within 30 days, investigate without undue delay and tell you the outcome and any action taken. We may request information reasonably needed to investigate.
You may complain to the UK Information Commissioner at ico.org.uk/make-a-complaint. We ask that you contact us first so we can try to resolve the concern, but this does not limit your right to contact the ICO.
Chasd is a business service for adults and is not directed to children. Customers must not use it to pursue debts owed by children.
We may update this notice when the service, providers or law changes. We will change the date above and signpost material changes in the service or by email where appropriate.