Privacy Policy

Version 1.0 — Last updated 6 August 2026

CloudRev Intelligence Ltd (“CloudRev”, “we”, “us”) is a company registered in England and Wales, company number 17234811, with its registered office at 71–75 Shelton Street, London WC2H 9JQ. We provide software products for landed cost calculation and inventory cost allocation, currently MarginChief.

This privacy notice explains what personal data we collect about you, why we collect it, who we share it with, and what rights you have. It applies to the marginchief.com website, to the MarginChief application, and to our sales, marketing and support activities.

We are the controller of the personal data described in this notice. If you have any questions, contact us at info@marginchief.com.

Our products are available to businesses worldwide. Which law applies to you depends on where you are, and section 3 explains this.

1. Who and what this notice covers

This notice applies to personal data we hold about:

  • Visitors to our website
  • People who sign up for a free trial or an account
  • Authorised users of a customer’s MarginChief account
  • People at customer or prospective customer organisations who contact us, or whom we contact, about our products
  • People who contact our support function

2. What this notice does not cover

This notice does not cover the data our customers upload into MarginChief.

When a business customer uploads supplier invoices, purchase orders, freight documents and similar records to MarginChief, those documents may contain personal data about other people, such as the names, job titles and business contact details of employees at the customer’s suppliers, freight forwarders and carriers.

In respect of that data, our customer is the controller and we act only as a processor on their instructions. Our processing of it is governed by our Data Processing Agreement, not by this notice.

If you believe your personal data appears in documents that one of our customers has uploaded and you want to exercise your rights over it, please contact that organisation directly. If you contact us instead, we will pass your request to the relevant customer where we can identify them, and will assist them in responding.

3. Which law applies to you

We are established in the United Kingdom. The UK GDPR governs our processing of personal data wherever in the world you are, and it is the standard we apply to everyone.

We market our products principally in the United Kingdom, the United States and Australia. We do not target the European Economic Area: we do not advertise or send marketing there, our prices are not shown in euros, and we publish only in English. On that basis we do not consider the EU GDPR applies to our processing, and we have not appointed a representative under Article 27 of the EU GDPR.

If you are in the European Economic Area and have chosen to use our products, you may still have rights under the EU GDPR. We will handle any request you make under that regulation on the same terms as the rights described in section 10, whether or not it is formally required of us. Contact info@marginchief.com.

Our products are available in other countries, and local data protection law may also give you rights there. We apply the standards in this notice to everyone regardless of location, and if your local law gives you a right we have not listed, contact us at info@marginchief.com and we will deal with your request under that law.

If our position changes and we begin targeting the European Economic Area, we will appoint a representative there and update this section before doing so.

4. Personal data we collect

CategoryWhat it includesWhere it comes from
Account and identity dataFull name, business email address, password (stored hashed), job title, employer name, account and user identifiers.You, when you register or when your organisation’s administrator creates your account.
Subscription and billing dataBilling contact, billing address, country, VAT or GST registration number, plan and subscription history, transaction identifiers, invoice records and payment status. We never see or store card numbers; the payment itself is taken by Paddle.You, at checkout; and from Paddle, which reports transaction outcomes back to us.
Usage and technical dataIP address, browser and device type, operating system, pages viewed, features used, timestamps, referring URL, session and audit log entries, error reports and diagnostic logs.Automatically, when you use the Site or the application.
Support and communications dataThe content of emails, support tickets, contact form submissions and any attachments you send us, and our replies.You.
Marketing and prospect dataName, business email address, employer, job title, business telephone number, and your marketing preferences and engagement (for example whether an email was opened or a link clicked).You; and, where you have not contacted us first, from publicly available business sources, company registers, business directories, professional networking sites and third party list providers. Section 12 tells you how to find out the specific source in your case.
Site usage dataHow our website and application are used: pages visited, features used, referring site, approximate country and region derived from your IP address, device type, browser and screen size, and a pseudonymous identifier that distinguishes one visitor from another. Once you sign in, that identifier is associated with your account. This is produced by PostHog, using its European Union deployment. It is collected only if you consent, and is described in our cookie policy. We do not use session replay, so we do not record your screen or your keystrokes.Automatically, when you visit the website or use the application, if you have consented to analytics.

5. Why we use it, and our lawful basis

Under the UK GDPR we must have a lawful basis for each purpose for which we use personal data. The table below sets these out.

PurposeData usedLawful basis
Creating and administering your account, and providing the ServicesAccount and identity data; usage and technical dataPerformance of a contract with you, or steps at your request before entering into one. Where you are an authorised user under your employer’s account, our legitimate interest in providing the service our customer has contracted for.
Taking payment, invoicing and collecting sums dueSubscription and billing dataPerformance of a contract. Legal obligation, for the retention of accounting and tax records.
Providing customer support and responding to enquiriesSupport and communications data; account and identity dataPerformance of a contract, or our legitimate interest in responding to people who contact us.
Keeping the Services secure, preventing fraud and abuse, and investigating incidentsUsage and technical data; account and identity dataLegitimate interests: protecting our systems, our customers and their data. Legal obligation, where we are required to report a breach.
Diagnosing faults, debugging and improving the ServicesUsage and technical data; support and communications dataLegitimate interests: maintaining and improving a product our customers rely on.
Understanding how our website and product are used, so we can improve themSite usage data; usage and technical dataConsent. Our analytics uses cookies and local storage, so we ask before it loads and it does not run unless you agree. You can withdraw consent at any time through the cookie settings link in our footer, without affecting anything done before you withdrew.
Contacting business prospects about our products, including where we obtained your details from a third party sourceMarketing and prospect dataLegitimate interests under Article 6(1)(f). We do this only where you are contactable as a corporate subscriber under the Privacy and Electronic Communications Regulations 2003. Where you are an individual subscriber, including a sole trader or an ordinary partnership, we send marketing only with your consent. We do not carry out unsolicited prospecting in the European Economic Area.
Sending marketing and product updates to existing customersMarketing and prospect dataOur legitimate interest in marketing similar products to existing customers, relying on the soft opt-in in regulation 22 of the Privacy and Electronic Communications Regulations 2003. You can opt out at any time.
Complying with legal and regulatory obligations, and establishing or defending legal claimsAny of the above as relevantLegal obligation. Legitimate interests in establishing, exercising or defending legal claims.

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests or fundamental rights. You may ask us for information about that assessment, and you have the right to object to processing on this basis (see “Your rights” below).

6. Who we share personal data with

We share personal data only in the circumstances described below. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

  • Service providers. Third parties who help us run, secure and improve our products, or who perform services on our behalf. These include cloud hosting and database providers, email, marketing and customer relationship management (Brevo), website and product analytics (PostHog), operational monitoring, and fraud prevention. They act as our processors, on our instructions, and are bound by written confidentiality and data protection obligations.
  • Our group companies. Companies in the same corporate group as us, which provide software development, maintenance, debugging and technical support. They may access personal data only for those purposes and on the same terms as this notice.
  • Professional advisers and insurers. Lawyers, accountants, auditors and insurers, where we need advice or are required to disclose in connection with a claim.
  • Authorities and law enforcement. Where we are required to do so by law, court order or a regulator, or where we reasonably believe disclosure is necessary to enforce our terms, prevent fraud or illegal activity, or protect the rights, property or safety of CloudRev, our customers or others.
  • A buyer or successor. If we sell or transfer all or part of our business or assets, whether by merger, acquisition, reorganisation, insolvency or a similar transaction. We will take reasonable steps to ensure any transferred data continues to be treated in line with this notice.
  • Anyone you authorise. Where you have asked us to share your information, or given us your permission to do so.
  • In aggregated or anonymised form. Data that has been combined and stripped of identifiers so that it does not identify you, directly or indirectly.

One recipient works differently and is worth naming. Our products are sold through Paddle, which acts as merchant of record and authorised reseller. Paddle sells the subscription to you in its own right, takes payment, issues your receipt or invoice, and appears on your card or bank statement. Because Paddle decides how it handles the payment data it collects, it is an independent controller rather than one of our processors, and its own privacy policy governs that processing. You can read it at paddle.com/legal/privacy.

We maintain a current list of our sub-processors, giving each one’s name, country and the safeguards that apply, on our Sub-processor List. If you would like to know the specific recipients of your personal data, email info@marginchief.com and we will tell you.

7. International transfers

Personal data in the MarginChief application is stored at rest in the United Kingdom, and the artificial intelligence services we use to read and interpret uploaded documents also process that content in the United Kingdom. Our public website at marginchief.com is served instead from a global content delivery network, which does not offer a choice of region; the only personal data involved there is the request metadata in our web logs, such as your IP address and browser. Nothing you enter into the application, and no document you upload, is held on that network. Our operational monitoring, our email and customer relationship management (Brevo, in France), and our analytics (PostHog EU Cloud, in Frankfurt, Germany) are handled in the European Economic Area, which is covered by United Kingdom adequacy regulations, so no additional safeguard is required for those transfers. Where PostHog personnel in the United States access analytics data for support purposes, PostHog’s data processing agreement incorporates the EU standard contractual clauses and the UK Addendum.

Some of the organisations that help us run the Services are located outside the United Kingdom, or can access data from outside it. In particular, our development affiliate in Indonesia may access data held on our United Kingdom systems through its personnel in order to develop, maintain, debug and support the Services.

Indonesia is not covered by UK adequacy regulations. We therefore rely on the UK International Data Transfer Agreement, supported by a documented transfer risk assessment, together with additional safeguards: access is granted on a least-privilege basis to named individuals for specific issues, is time-limited and logged, data is not downloaded or stored outside our United Kingdom systems, encryption keys remain under our control, and redacted or synthetic data is used in preference to live data wherever the task allows.

Where a recipient is in a country covered by UK adequacy regulations, or is a United States organisation certified under the UK Extension to the EU–US Data Privacy Framework, we rely on that adequacy. In all other cases we use the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.

You can ask us for a copy of the safeguards we rely on by emailing info@marginchief.com.

8. How long we keep personal data

DataRetention period
Account and identity dataFor the duration of the subscription. After termination, access is available for 30 days to allow export, and the data is deleted within 90 days, except where we must keep it for the reasons below.
Subscription, billing and accounting recordsSix years from the end of the accounting period to which they relate, to meet our obligations under the Companies Act 2006 and HMRC record-keeping requirements.
Support and communications data24 months from the close of the ticket or the last correspondence.
Web and application request logs30 days. These are the routine traffic logs generated when a page or an interface is requested, and contain your IP address, browser and the page requested. We keep them only long enough to diagnose faults and identify abuse.
Production access and audit logsNot less than 12 months. These record who accessed customer data in our production systems, when and why. We commit to this minimum period in clause 5 of our Data Processing Agreement, so that access can be audited after the event, and we do not delete them earlier.
Marketing and prospect dataUntil you unsubscribe or ask us to stop, or after 24 months of no engagement, whichever is earlier. We keep a minimal suppression record indefinitely so that we do not contact you again.
Site usage dataAnalytics events are kept for 24 months and then deleted. IP addresses are used to derive an approximate country and region and are not retained. If you withdraw consent, we stop collecting immediately; the events already collected are deleted at the end of the 24-month period, or sooner if you ask us to erase them.
Records needed for legal claimsUntil the relevant limitation period expires, normally six years.

9. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit using TLS and at rest, role-based access control on a least-privilege basis, multi-factor authentication on administrative accounts, logging of access to production systems, separation of production from development environments, and written confidentiality obligations and training for everyone with access.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to people’s rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and will notify affected individuals where the law requires.

10. Your rights

Under the UK GDPR you have the following rights. They are not all absolute, and some only apply in particular circumstances.

RightWhat it means
AccessAsk for a copy of the personal data we hold about you, and information about how we use it.
RectificationAsk us to correct personal data that is inaccurate, or complete data that is incomplete.
ErasureAsk us to delete your personal data where there is no good reason for us to continue holding it.
RestrictionAsk us to suspend processing, for example while we check the accuracy of data you have challenged.
PortabilityAsk us to provide the personal data you gave us in a structured, commonly used, machine-readable format, or to send it to another provider, where processing is based on consent or contract and is automated.
ObjectionObject to processing based on our legitimate interests. You can object to direct marketing at any time and we will always stop.
Withdraw consentWhere we rely on consent, withdraw it at any time. This does not affect processing already carried out.
Automated decisionsWe do not make decisions producing legal or similarly significant effects about you by automated means alone.

To exercise any of these rights, email info@marginchief.com or use our data request form. We will respond within one month. We may extend this by two further months for complex requests, and will tell you if we do. We may need to verify your identity first.

There is normally no charge. We may charge a reasonable fee, or refuse, if a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right.

You also have the right to complain to a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office, at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the European Economic Area, you may complain to the supervisory authority in the member state where you live, where you work, or where you believe the problem occurred. A list is maintained by the European Data Protection Board at edpb.europa.eu.

11. Marketing

We send three kinds of email: service messages relating to your account, billing and security, which you cannot opt out of while you hold an account; marketing messages to existing customers about our products; and introductory messages to people at businesses we believe may have a professional interest in what we do.

If we contacted you and you have not dealt with us before, we obtained your business contact details from a publicly available business source, a business directory or company register, a professional networking profile, or a third party list provider. Our first message to you will tell you this, and you can ask us for the specific source at any time by emailing info@marginchief.com.

We only contact people at their place of work about matters relevant to their job. We do not use personal email addresses for this, and we do not send marketing to sole traders or ordinary partnerships without their consent.

We do not send unsolicited marketing email to people in the European Economic Area. The corporate subscriber distinction described above is a United Kingdom rule and does not apply in the EEA, where several member states require prior consent for business marketing email. If you are in the EEA, we will only email you marketing if you have asked us to, or if you are an existing customer and local law permits it.

You have an absolute right to object to direct marketing. Every marketing email contains a one-click unsubscribe link. You can also email info@marginchief.com, and we will stop. We do not require a reason and we will not ask you to justify the request.

When you opt out we keep a minimal suppression record, consisting of your email address and the date, indefinitely. We do this so that we do not contact you again, and it is the only reason we keep it.

We use Brevo, a service provider in France, to send our email and to manage our customer and prospect records. Brevo processes that data on our instructions and does not use it for its own purposes. Because Brevo is in the European Economic Area, no additional transfer safeguard is required.

12. Whether you have to give us your personal data

Account and billing data. You need to give us this to create an account and for us to provide the Services. It is a contractual requirement. If you do not provide it, we cannot open an account for you or supply the product.

Data in the documents you upload. Providing this is necessary for the product to do its job. It is not a statutory requirement, but without it MarginChief cannot calculate landed costs for you.

Support and communications data. You only give us this if you choose to contact us. If you do not, we simply cannot answer your query.

Marketing preferences. Entirely optional. Declining marketing has no effect on your account or your use of the Services.

Site usage data. Collected automatically when you visit the website. You can object to it at any time by emailing info@marginchief.com, and objecting has no effect on your access to the site or the product.

13. Cookies and analytics

We use strictly necessary cookies to keep you signed in, keep your session secure, and remember choices you make in the application. The service cannot work without them, so no consent is required for them under the Privacy and Electronic Communications Regulations 2003 or the equivalent rules in the European Economic Area.

We also use PostHog for website and product analytics, across marginchief.com, app.marginchief.com and our other subdomains. PostHog tells us which pages and features are used, so that we can improve them. It records pages viewed, features used, device and browser information, an approximate location derived from your IP address, and a pseudonymous identifier that distinguishes one visitor from another.

PostHog stores information on your device, so it is not strictly necessary and it is not exempt from the consent rules. We ask for your consent before PostHog loads, and it does not run unless you agree. You can withdraw consent at any time through the cookie settings link in our website footer, and withdrawing is as easy as giving consent.

We use the European Union deployment of PostHog, so analytics data is stored in Frankfurt rather than the United States. We do not use PostHog session replay, so we do not record what you do on screen, and we do not use PostHog for advertising, profiling or automated decision-making.

We do not use advertising or cross-site tracking cookies, and no third party sets cookies through our website for its own purposes.

On our public website the analytics identifier is pseudonymous. Inside the application, once you sign in, we associate it with your account, so this data is linked to you as a named customer and your rights of access and erasure apply to it. Being a paying, signed-in customer does not remove the need for your consent, and refusing analytics does not restrict any part of the service.

Further detail, including the name and lifetime of each cookie, is in our Cookie Policy.

14. Children

Our products are business tools and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact info@marginchief.com and we will delete it.

15. Third-party sites

Our website and product may link to sites we do not control. This notice does not apply to them, and we are not responsible for their privacy practices. Check their own notices before providing personal data.

16. Changes to this notice

We may update this notice. The version and date at the top will change, and we will keep previous versions available. Where a change materially affects how we use your personal data, we will give you notice by email or through the product before it takes effect.

17. Data protection officer

We have assessed that we are not required to appoint a data protection officer under Article 37 of the UK GDPR. Privacy questions are handled by our management team and can be sent to info@marginchief.com.

18. How to contact us

CloudRev Intelligence Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom.

Email: info@marginchief.com

Supervisory authority: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. ico.org.uk, 0303 123 1113.