Privacy Policy
What we store, who can see it, and how to get it back or get rid of it. In plain English, because a policy nobody reads protects nobody.
Last updated 10 August 2026 · Version 1.1
The short version. A box league is names and scores, so names and scores are nearly all we hold. Only the people who run your club have an email address with us. There are no trackers, no analytics, no ad network, and nothing is sold or shared with anyone, ever. Every league page has one sponsor slot on it, carrying one name and a link: your club's own sponsor on a paid plan, and ours on a free league or a trial (see section 6). Your club's data lives in a database of its own, and you can download all of it as one file, any time, without asking us.
A club that also runs its membership and subs here holds more than names, because a register is more than names: contact details, categories, what is owed and what has been paid. All of it is your club's, none of it is ours to use, and the subs go from your member to your club's own bank account without passing through us. Section 3 lists every field.
1. Who we are
Clayside runs box leagues, club ladders and club championships for racket clubs: tennis, padel, squash, badminton and pickleball. It is a trading name of Agentu Ltd, a company registered in England and Wales.
- Company number: 16191406
- Registered office: 10 Campbell Crescent, East Grinstead, West Sussex, RH19 1JR, United Kingdom
- Email: hello@clayside.app
This policy covers clayside.app, every club subdomain (yourclub.clayside.app), and The Sheet at clayside.app/sheet/.
We have not appointed a Data Protection Officer. We are not required to, and pretending otherwise would just give you a title to write to instead of a person. Use the address above; it reaches someone who can act.
2. Who is responsible for what
Your club decides who goes in its league. We just run the software. For your own account and for signing up, we're the ones responsible.
Under UK GDPR this split has names, and it matters because it decides who you ask for what.
Your club is the controller for what's inside its league: the player names, the results, the roster. Your club chose to put those names in; we never see a membership list, and we don't decide what goes in a box. For that data we are the processor: we hold it and act on your club's instructions, set out in our Terms and in full in our Data processing terms, which are the Article 28 annex a committee can file.
If you're a player and you want your name changed or removed from a league, ask your club first: they can do it themselves in seconds, and they're the ones who decide. If they can't or won't, write to us anyway and we'll help.
We are the controller for the accounts of the people who run clubs (their email address and sign-in) and for the details given when someone starts a league at /setup. That's the part this policy speaks to directly.
3. What we hold
Players are a name. Club admins are a name and an email address. Nobody has a password with us, because there are none.
Inside a club's league
| What | Why it's there |
|---|---|
| Player name | To show who's in the box and who played whom. In a club that runs only its competitions here, it is the only thing held about most players: no email, no phone number, no address, no date of birth, no membership number. A club that also runs its membership here holds more, and the next table is that list. |
| Results and fixtures | Scores, dates, who entered a result and who confirmed it. That last part is what makes a disputed score answerable. |
| Admin accounts | For the club's owner and any box admins: a display name and an email address, so they can sign in and be invited. |
| Sign-in tokens | Held as a one-way hash: we store the fingerprint of a sign-in code, never the code itself. |
| Admin activity log | Who changed what, and when: results deleted, players added, invites sent. It's what lets a club answer "who moved that score?" So it records a name, and sometimes a reason typed by an admin. |
If your club also runs its membership and subs here
This is the club plans, and it is the one part of Clayside where a club holds real personal detail about its members. It is off unless your club is on one of those plans, so most of what follows does not exist in most clubs' databases at all. Everything in it is your club's, recorded by your club, for your club's own purposes; we are the processor and nothing here is ever used for anything of ours.
| What | Why it's there |
|---|---|
| The member record | Name, membership category, whether they are a current member and when they joined or left. This is the register. |
| Contact details | Email address, phone number, postal address and any note your club types, where your club chooses to record them. None is required and a club can run the whole register without any of it. They sit behind a permission of their own, so somebody can keep the register without being able to read the club's contact list. |
| Date of birth | Where your club records one. It is behind the same permission as the contact details, and it does one job in the software besides telling a club a member's age: it is the switch that closes doors for a child. See section 11. |
| Households and tags | Who is on a family rate together and who your club has named as paying for them, plus whatever words your club files people under: committee, coaching, social, life member. Nothing in the leagues ever reads a tag. |
| Subscriptions and payments | What each member was charged for a membership year, what has been paid, and what your club recorded when somebody sent a transfer or handed over a cheque. It is the club's own account of its own money. |
| A Direct Debit instruction | An identifier for the mandate at GoCardless and its status. We never see a bank account number or a sort code: your member types those on GoCardless's own page, and what comes back to us is a reference and whether it is live. See section 6. |
| Applications to join | What somebody typed into your club's joining form, which is a public form filled in by a person your club has not met yet. Deleted on a clock, which is set out in section 8 and is the only clock in this product. |
| A member's own sign-in address | Only where the member has answered a code sent to that address, and only where the club has switched member sign-in on. The address can be the one your club already recorded for them: an address sitting in your club's register signs nobody in, and the code coming back is what turns it into a way in. A member under 18 never holds one at all. |
| The club's activity log | Extended to the register: who added, edited, merged or archived a member, and who collected. It records what moved and never what it said: a change to a phone number is logged as a change to a phone number, and the number itself is not in the log. |
When someone starts a league
The signup form at /setup asks for a club name, the web address you'd like, your email, and your name if you want to give it. Nothing is created at that point. We hold what you typed on its own, send one email to that address with a six-digit code in it, and make the league only when you type the code back in. That is deliberate: a league is a database of its own, and we only make one for an address somebody has proved they can read. If the code is never used, what you typed is deleted within the hour and no league ever existed. We also record the IP address of the signup attempt, for one reason: to stop one machine registering a hundred clubs. It's deleted after 7 days. It is the only IP address stored anywhere in Clayside.
For the same reason (stopping one address from opening an endless number of leagues) we keep a one-way fingerprint of the signup email: sha256 of the address, the same kind of hash as a sign-in code, never the address itself and nothing that runs back into it. It only ever answers "how many leagues has this fingerprint made lately", and we hold it no longer than two years, which is the window the limit works over.
A handful of dates about the club itself
Against your club's own record we keep a few dates about what the club has done: when your first season started and ended, when a season first went live, when the first score was recorded, and when you started a second season. They exist so we can tell whether the product is working: how long a club takes to get a season running, and how many come back for a second one. They decide nothing about your club: your trial is 14 days from the day you create the league, and no date here changes it.
They are dates and nothing else. No visit is recorded, ever. Not a page, not a request, not an IP address, not a browser. This is the same kind of fact as the date your club was created, and it says nothing about any individual.
What we don't do at all
- No analytics. No Google Analytics, no Plausible, no Meta pixel, no Segment, no session recording, no heatmaps. Not "anonymised" analytics. None.
- No ad network, no profiling, no automated decision-making, nothing targeted at anybody and no advert served from anywhere. The one sponsor slot on a league page is typed text and an ordinary link out, and it is described in full in section 6.
- Nothing sold, rented or shared. Not to anyone, at any price, including if we're doing badly.
- No third-party fonts or scripts on the pages you read. Our type is served from our own servers, so a visit to Clayside is not quietly announced to anyone else. The one exception is Cloudflare's anti-bot checks, on the signup form and on your club's pages (see section 6).
- No tracking cookies. There are two cookies. One signs you in, the other is the anti-bot check. Neither follows you anywhere.
- We don't log your IP address or browser when you use a league. Cloudflare sees it carrying the connection and running the anti-bot check, and we never store it.
4. Why we're allowed to hold it
Contract, and a legitimate interest in not being overrun by spam. We don't rely on consent, so there's no banner to dismiss.
| What | Lawful basis |
|---|---|
| Running a club's league; admin accounts and sign-in | Contract: we can't provide the thing without it. |
| Player names and results | Your club's basis, as controller. Usually legitimate interests (running the club's own competition) or contract with its members. |
| Signup IP addresses; the anti-spam check | Legitimate interests: keeping a form that's open to the internet from being abused. We looked at doing it without an IP, and there isn't a way that works. |
| The anti-bot check on your club's pages | Legitimate interests: keeping your members' names and results from being collected in bulk by a script. It runs on your club's address only, and usually without you noticing it at all. |
| The admin activity log | Legitimate interests: a club being able to see who changed a result. |
| Emailing club owners and admins about Clayside | Legitimate interests: telling the people who run a club about the software they run it on. You gave us the address setting the league up, it's only ever about Clayside, and one click gets you off it. |
| Suggested times for a match, and the one that was agreed | Legitimate interests: arranging the matches a league is made of. Names, dates and one short line; no contact detail, because there is none to hold. Deleted after 60 days. |
| Notifications to a device that asked for them | Consent: you tapped Allow on your own phone or computer. We hold the anonymous address your browser gave us for that device and nothing else; switching them off withdraws it and deletes the address. |
| A club's membership register, its subscriptions and its payment records | Your club's basis, as controller. Usually contract with its members, or legitimate interests in running the club. We hold it as processor and decide none of it. |
| An application to join a club | Your club's basis, as controller: steps at your request before a contract, which is what an application is. Deleted on the clock in section 8 whichever way the club decides. |
| Somebody asking to play, through a club's own link | Your club's basis, as controller: steps at your request before a contract, the same as an application. A name, a date of birth and an address they proved with a code, and nothing else. Deleted on the clock in section 8. |
| A member's own sign-in address, and messages about their own membership | Contract, and only after the member has answered a code sent to that address. It is used for their receipts, their renewal and their own Direct Debit, and for nothing else ever. |
| The one message telling a member how to sign in, sent to the address the club holds | Your club's basis, as controller: usually legitimate interests in telling its own members how to use what the club has bought. Your club decides whether to send it. It carries nothing that signs anybody in, it never goes to anybody under 18, and one tap on it stops anything else reaching that address. |
| Accounting records for paid clubs | Legal obligation: UK company and tax law. |
We email club owners and admins now and then about Clayside itself: a new feature, sometimes an offer. You're on that list because you confirmed your email setting a league up here, so a stranger who mistypes an address never ends up on it. There's a one-click unsubscribe on every one, and leaving doesn't touch your sign-in codes. Everything else Clayside sends is a sign-in code, an invite, or a confirmation, which you asked for by using it.
We never email a player about a league. Not a fixture, not a result, not a deadline, not a draw. A player in a box, a ladder or a draw is a name and their scores, and there is no field on that record for an address. That isn't changing.
A club plan is where addresses live, because a membership register is a list of people and how to reach them. Your club types them in or brings them across from its own spreadsheet. It is your club's list, held for your club, and we decide nothing about it. Holding an address opens nothing on its own: the code is the whole of the proof, and nobody signs in until they have answered one.
Your club can send its members one message before any of that, and it presses a button to do it. It says that the address the club holds is how they sign in, and it carries a link to your club's own page. There is no code in it and nothing in it signs anybody in. Nobody gets it twice in a fortnight or more than three times ever, everybody who runs the club is left out, everybody under 18 is left out, and there is a line on every copy that stops it for good. Your club decides whether to send it and to whom; we are the processor.
After that, only the member's own membership. Once somebody has answered a code we email them their receipts, their renewal notice and messages about their own Direct Debit, and nothing else. There is no marketing to a member, no newsletter and no category a club could use to write to one about anything else. A member under 18 never holds a sign-in address, and none of it reaches the leagues: a member with one is still just a name on a box table.
Notifications on your own phone are the one way the app can reach you, and you switch them on yourself. If you tap Allow, your browser gives us an anonymous address for that device: no name, no email, no phone number, and nothing that says who you are. We use it to tell you a score is waiting on you, a draw is up or a deadline is close. Every message is encrypted, so the service carrying it (Apple's, Google's or Mozilla's, depending on your device) cannot read it. Most are sent the moment somebody in your club does something; the only ones on a timer are deadline reminders, and those go out in the morning. Turning them off in the app, or in your browser's settings, ends it and deletes the device's address. Everything the bell has ever shown you can be cleared, one at a time or all at once, and clearing it deletes the rows.
Arranging a match holds dates, not people. If you suggest times for a match, your club's database keeps who suggested them, who they were suggested to, the dates and any time on each, one optional line of up to 120 characters, and which one was agreed. All of that is by name, exactly as a score is. There is no contact detail in it and no field for one, which is the whole reason the feature works this way: nothing about arranging a match tells either player how to reach the other. The rows are deleted after 60 days, and with the club if it goes.
6. Who else sees it
Four suppliers, each doing one job. Nobody else, and never for their own purposes.
| Who | What they get | What for |
|---|---|---|
| Cloudflare | Everything: they host Clayside and store every club's database. Your connection passes through them. | Hosting and storage. They process it on our instructions and don't use it for anything of their own. |
| Cloudflare Turnstile, and Cloudflare's bot check | Your IP address. On the signup page at /setup, and on your club's own pages. | Telling a person from a bot, so that a script can't collect a club's names and results in bulk. No tracking across sites and no profile of anybody. On your club's pages it usually happens invisibly: you see nothing and carry on. It isn't on the public Clayside site, and it isn't on the demos. |
| Resend | The recipient's email address and the message itself. | Delivering sign-in codes, invites, confirmations, and our occasional note to club owners. Nothing else, and never to a player. |
| GoCardless | The name, email and bank details of a club owner who sets up a paid plan. You type them on GoCardless's own page, so we never see the bank details ourselves. | Taking the Direct Debit for the plan your club pays us for. Only ever touched by a club that chooses to pay: no free club, trial or player goes near it. |
| GoCardless again, on your club's own account | The name, email and bank details of a member paying your club's subs. Typed on GoCardless's own page, never on ours and never seen by us. | Collecting your club's membership fees, on club plans only. This is a different relationship from the row above and the two never meet. The account is your club's, opened by your club, and the money goes from your member to your club's bank. We are not in the middle of it, we hold none of it, and we take no percentage of it. For that collection GoCardless is your club's processor rather than ours, under your club's own agreement with them. |
That's the complete list. We'll also hand data over if the law actually requires it (a court order, not a polite request), and if we ever sold the business, the data would move with it, in which case we'd tell you first and this policy would still bind whoever took it on.
The sponsor slot on a league page. A paid plan lets a club put one sponsor's name and link there. On a free league, during a trial and on the demos, that slot carries a sponsor of ours instead: one company, named on the page, who pays us rather than the club. It is what a league that costs a club nothing is paid for by. Either way it is the same thing, and the same promises hold. It is an ordinary link out, not an advert served by anyone: nothing loads from the sponsor, no script of theirs runs, and nobody is tracked across sites. If you follow it, their website can see that the visit came from your club's Clayside address, and not which page you were on. We do not count clicks. There is no redirect through us, no counter behind the link and no record kept of anyone following one, so a sponsor asking us how many people clicked gets the same answer you would: we don't know.
One more disclosure worth naming, because it's easy to miss: if a club owner uses the "Ask about a plan" button in the app, their name, email address, club, and the note they type are emailed to us. That's the point of the button (it's a message to a human), but it does mean the message reaches Agentu Ltd rather than staying inside your club.
7. Where it's stored
Clayside is built and run from the UK, by a UK company, under UK GDPR. Your club's data is stored in Cloudflare's D1 database service and served from Cloudflare's network.
Your club's database is pinned to the EU. When we create it we set a jurisdiction that Cloudflare enforces: not a preference for where it should go, but a constraint on where it is allowed to be. It binds the main copy and every read replica alike.
That's a promise we can keep because it isn't ours to break: the constraint is set once when your database is made and cannot be loosened afterwards, by us or by anyone at Cloudflare.
One honest exception, because a policy that only lists the good parts isn't one:
- Email leaves. Resend delivers sign-in codes and invites, and mail in transit is not covered by anything above.
Cloudflare and Resend are both US-headquartered, so where data does travel it's covered by the safeguards UK law requires for international transfers: the UK Addendum to the EU Standard Contractual Clauses, under each supplier's data processing agreement, and both are certified under the UK–US Data Bridge.
8. How long we keep it
| What | How long |
|---|---|
| Your club's league | For as long as your club has a league with us. It's your history: old seasons are the point, so we don't quietly age them out. |
| Club owner and admin email addresses | Kept while the club is live, because it's how you sign in and how we reach you. If the club is closed, deleted within 30 days (room to change your mind and get it back), then gone, unless a legal or tax obligation means we have to keep a record longer. Cancelling Premier doesn't start this clock: the club carries on, just as One Box. |
| The owner mailing list | If you confirmed your email, we keep it on a list to email you about Clayside. If your club closes, we hold it up to a year after you leave in case you come back, then delete it. One click unsubscribes you from any of these; an unsubscribe we keep on a do-not-contact list so we don't email you again. |
| A signup nobody confirmed | One hour, then it's deleted: what you typed, the address, and the hold on the web address you picked. No league is created until the code is used, so there is no database to delete and never was. A league that does exist is never deleted for going quiet. When a trial ends it carries on as One Box with everything in it. |
| A closed club | Deleted within 30 days of you asking. Export first: once the database is gone, it's gone, and we can't get it back for you. |
| The dates about your club's own use | For the life of the club, then deleted with it. A handful of dates about what the club has done, described above. No visits, no IP addresses, nothing about a person. |
| Signup IP addresses | 7 days. |
| The signup-email fingerprint | 2 years, then deleted. It's a one-way hash, used only to limit how many leagues one address can open, and it's kept no longer than that limit's window. |
| Sign-in codes and links | 15 minutes. Invites, 14 days. |
| Research survey answers | Until the findings are published and a year after, then deleted. An address given so we can send you the findings goes at the same point or sooner. The IP hash behind the form's rate limit, 30 days. See section 12. |
| A club's membership register | Held until your club removes it, and removal takes effect at once. There is no clock on it and nothing ages a member out, which is deliberate: a member who lapses stays on the register, so rejoining next year is a renewal link rather than a fresh signup, and a club can still answer who was a member in 2024. Your club removes anybody, any time, in a few clicks. |
| Subscriptions, payment records and Direct Debit references | For the life of the club. It is your club's own account of its own money, and a year with a hole in it is not an account. Accounting records we hold about a club as our own customer are a different thing and are the 6-year row below. |
| Somebody asking to join through a club's own link | 90 days after your club decides it, accepted or declined, then deleted automatically. A name, a date of birth and an email address, given by somebody who wanted to play. One still waiting on the club is left alone, for the row below's reason. The code that proved their address is deleted within a day whatever happens. |
| An application to join a club | 90 days after your club decides it, accepted or declined, then deleted automatically. An accepted one loses nothing by going: accepting is what copies the person onto the register. One somebody started and never finished goes 90 days after they started it. One still waiting on your committee is left alone, because emptying a committee's in-tray on a clock would be us making the decision. |
| A member's own sign-in address | Until the member removes it, which they do themselves from their own sign-in and which is never refused. It also goes on its own the moment a date of birth is recorded that makes them a junior (see section 11), along with any live code sent to it. |
| A court booking | For the life of the club, and a cancelled one is kept rather than deleted: who booked a court, who cancelled it and when are what a club answers a question with weeks later. It is a name, a court and a time, and nothing else about the person is in it. |
| The admin activity log | For the life of the club, then deleted with it. It's a club's own audit trail, and a trail with holes in it isn't one. It records what changed and never the value that changed, so it is not a second copy of anybody's contact details. |
| Accounting records | 6 years, as UK tax law requires. |
9. Your rights
You can see it, fix it, take it, or have it deleted. Email hello@clayside.app and we'll answer within 30 days. It's free.
Under UK GDPR you can ask us to:
- Show you what we hold about you.
- Correct it if it's wrong: a misspelt name, the wrong email.
- Delete it ("right to erasure").
- Hand it over in a portable file, or send it to someone else.
- Restrict or object to what we do with it, including anything we do on the basis of legitimate interests.
Do it yourself, faster
Some of this doesn't need us at all, and self-service beats waiting on an inbox:
- Export: a club owner can download the club's entire league (every player, every result, every season) as one file, one click, from the app. No request form, no waiting, no charge. That is the whole point of it.
- Correct a name: a club admin can edit it directly.
- Sign out everywhere: signing out ends the session on our side, not just in your browser.
Where to ask
If your request is about a player name in a club's league, your club is the controller: ask them, because it's their decision and they can act today. We'll pass it on and support them if you'd rather come to us.
If it's about your admin account or your signup, ask us directly.
Honest caveat: removing a player from a league doesn't erase the past results they played: a completed season with a hole in the middle isn't a record any more, and the other players in that box have their own interest in an accurate one. If you want your name gone entirely rather than removed from the current roster, say so explicitly and we'll work out with your club how to do it properly.
10. How it's protected
- Each club gets its own separate database. Not a shared table with a club column in it: a different database. One club cannot query another's data, because there's no query that reaches it.
- There are no passwords. You sign in with a link or a six-digit code that expires in 15 minutes. We can't leak a password we never asked you for, and you can't reuse one here that you've used elsewhere.
- Sign-in secrets are stored hashed, never in plain text. A code guessed wrong five times invalidates itself.
- Everything is encrypted in transit (HTTPS, always) and at rest by Cloudflare.
- Access is limited to the people at Agentu who need it to run the service.
If something goes wrong anyway and it puts you at risk, we'll tell the ICO within 72 hours and tell you without undue delay. If you think you've found a security problem, please tell us: our security contact is here.
A limit worth knowing: the shareable link a club posts to its box's group chat is a key. Anyone who has the link can enter scores as anyone in that box. It's built that way on purpose (the alternative is forty accounts and forty forgotten passwords), but treat it like the key to the clubhouse, not a secret.
11. Juniors
Clayside isn't designed for children to sign up to on their own, and you must be 18 to run a club here.
A club may well put junior members' names in a box league, and that's normal, but it's the club's decision as controller, under the club's own safeguarding and consent arrangements. All the league holds about any player is a name and their scores. If you're a parent and you'd rather your child's name wasn't shown, ask the club; they can change it or remove it themselves.
The date of birth, on a club plan
A club that runs its membership here may record a member's date of birth, because a membership category is usually an age band and a club has to know. For a child that date does one more job, and it is the reason we ask clubs to record it rather than leave it out: it is the switch that closes doors.
- A junior never holds a sign-in address. The route that adds one refuses a date of birth under the club's adult age, and refuses it again when the code is answered.
- And a date of birth recorded later takes one away. If a club fills a birthday in a month after somebody added their address, the address and any live code are removed on the spot. That is the ordinary order of events at a club and it used to beat a check asked only once.
- The date itself is behind a permission, with the contact details, and a committee member reading the membership numbers sees how many juniors there are rather than which members they are.
The consequence worth stating plainly: no recorded date of birth means the software treats somebody as an adult. So deleting a child's date of birth does not protect them, it silently switches the protection off, and that is why we keep it for as long as the club keeps the member.
If you're on a club committee weighing this up, our safeguarding page lists in full what a league and a register hold about a person, and what they don't.
12. The box league research survey
If you answered our survey about how clubs run their box leagues: your answers are research, they are published only as totals, and answering puts you on no mailing list. We ask for no marketing consent on that form, deliberately.
In 2026 we are asking clubs across the UK how they run their internal competition, because as far as we can find nobody has ever published an answer. The form is at clayside.app/research/ and the findings will be published free, with no email required to read them.
What the survey collects
- Your answers to the questions on the form. Every one but the first can be left blank.
- Your club, county and role, if you give them. Clearly marked optional on the form, and used to weight the sample and to be able to say how many clubs and how many counties took part.
- An email address, only if you tick the box asking for the findings. If you don't tick it, we don't keep one, and the database itself will not accept an address without that tick.
- A one-way, shortened hash of your IP address, used only to stop the form being filled in a thousand times by a script. It is never joined to anything, and it is erased 30 days later while your answers are kept.
Why we're allowed to hold it
Legitimate interests for the answers themselves: carrying out research into a subject nobody has published on, and publishing the result. The answers are about how a club runs a competition rather than about a person, they are reported only in aggregate, and you can object at any time.
Consent for the email address, and for naming your club as one of those that took part. Two separate boxes, both unticked when you arrive, and we store which wording was on the screen when you ticked. Either can be withdrawn by emailing us.
What we don't do with it
We don't use survey answers to sell you anything, and we don't add respondents to any marketing list. There is no marketing opt-in on the form, on purpose: contacting people for genuine research is not direct marketing, and collecting details to market to them later is precisely what would make it so. If you later ask to hear about what we make, that's a separate decision you take somewhere else.
We also don't publish your club's name against its own answers. Totals, proportions and anonymous quotes only, and a club is named as a participant only if you ticked the box that allows it.
How long we keep it
- The answers: until the findings are published and for a year afterwards, so the working can be checked, then deleted. The published totals stay, because that's the point of the exercise.
- An address given for the findings: deleted once the findings have been sent, and in any case within a year of publication.
- The IP hash: 30 days.
To see your answers, correct them, or have them removed, email hello@clayside.app with the club name you gave and we'll do it.
13. Changes
If we change this policy we'll update the date at the top. If a change actually matters (a new supplier, a new kind of data), we'll email club owners rather than quietly reissuing the page and calling it notice.
14. Contact and complaints
Email hello@clayside.app, or write to Agentu Ltd, 10 Campbell Crescent, East Grinstead, West Sussex, RH19 1JR.
If we get it wrong, please come to us first. We'd rather fix it. But you have the right to complain to the UK's data protection regulator at any point, and you don't need our permission or our blessing:
- Information Commissioner's Office: ico.org.uk/make-a-complaint · 0303 123 1113