Policy record
Privacy Policy
Last updated 20 July 2026
Neatfile never accesses, reads, uploads, moves or deletes your real files.
SORTED SOFTWARE LTD
8 Dundrennan Drive
Chapelhall
Airdrie
North Lanarkshire
Scotland ML6 8GT
United Kingdom
This policy explains what personal data Neatfile collects, why we hold it, who we share it with and the rights you hold over it. The most important point is structural: Neatfile plans how your files should be organised from a description you type, and never connects to, reads or changes the files themselves.
01Who is responsible for your dataSORTED SOFTWARE LTD is the data controller for everything described here.
SORTED SOFTWARE LTD is the data controller for personal data processed through Neatfile and the website at sortedysoft.shop. We are established in Scotland, United Kingdom, and our registered office is 8 Dundrennan Drive, Chapelhall, Airdrie, North Lanarkshire, Scotland, ML6 8GT, United Kingdom.
You can reach us about anything in this policy by email at support@sortedysoft.shop, by telephone on +44 7570750603, or by post to the address above. We answer privacy requests within one business day and complete them within one month, as UK GDPR requires.
Neatfile is an online-only software service. We do not ship goods, attend premises, or provide any service in person.
02What we collectAccount details, user input, generated results, billing records and basic technical data.
Account and contact data
Your name, email address and, if you send one, the content of your message. If you request a shared team convention we also record the team size and scope you tell us about.
User input, files and example data
User input includes the description of your mess, any example file names you type, and the scope, devices, volume, naming preference and weekly minutes you select. Neatfile never accesses, reads, uploads, moves or deletes your actual files, folders, photos, mailboxes or drives. There is no file-upload, sync or device-connection feature anywhere in the product. Example prompts displayed by us are public product content, are not taken from another user, and do not create a personal-data record until you submit your own input.
AI-generated results
The folder plans, naming conventions, checklists, archive rules, routines, diagrams and walkthrough videos generated from your description, together with the generation status records needed to deliver them to you.
Subscription and payment data
Your plan, billing period, subscription status, invoice history and the last four digits and card brand that our payment processor returns to us. We never see, receive or store your full card number, expiry date or security code.
Technical data
IP address, browser and device type, pages requested, timestamps and error logs, collected by our hosting provider for security, abuse prevention and diagnosing faults.
We do not deliberately collect special category data. Please do not paste passwords, financial details, health information, government identifiers or anything confidential into the bench — a folder plan never requires them.
03Collection sourcesAlmost everything comes directly from you; a small amount comes from our payment and hosting providers.
Directly from you when you type into the bench, subscribe, complete the contact or team convention form, or email us.
Automatically from your browser when you load a page, through our hosting provider's standard request logs and the cookies described in our Cookie Policy.
From our payment processor when a subscription starts, renews, fails, is refunded or is disputed. This is limited to the status and masked card details listed above.
04Why we use it and our legal basesTo run the service, take payment, keep the service safe, meet legal duties and, where you agree, improve it.
To provide the service — performance of a contract
Generating plans, diagrams and walkthroughs from your description, delivering exports, maintaining your subscription and allowance, and answering your support messages.
To take payment — performance of a contract
Creating checkout sessions, processing renewals, issuing refunds and handling disputes through our payment processor.
To keep the service safe and working — legitimate interests
Preventing abuse and fraud, rate-limiting generation, diagnosing faults and protecting our systems. Our interest in a secure, functioning service is balanced against your rights, and this processing is limited to what security and reliability require.
To meet legal obligations — legal obligation
Keeping accounting and tax records and responding to lawful requests from authorities.
To understand and improve the service — consent
Any non-essential analytics or optional communications run only if you agree, and you can withdraw that agreement at any time without affecting the service.
Purpose limitation for generated content
We do not use your descriptions or generated output to train or fine-tune a model ourselves. We send the minimum description and settings needed to the configured generation provider to produce the output you ask for. Provider processing is governed by its data-processing terms, which we review before enabling it.
06International transfersSome processors operate outside the UK, protected by adequacy decisions or standard contractual clauses.
We are based in the United Kingdom. Some of our processors handle data in the European Economic Area, the United States or elsewhere.
Where personal data leaves the UK, we rely on a UK adequacy regulation for that country, or on the UK International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment and technical measures such as encryption in transit and at rest. Email us for details of the safeguards applied to a particular transfer.
07How long we keep itBench text is short-lived; account and billing records follow statutory retention periods.
- User input, typed example data and text plans — processed for the request and held in the current browser session. The application does not write them to our lead database. Closing or refreshing the workspace removes that browser-session copy.
- AI-generated diagrams, walkthroughs and task records — held by the configured AI provider only as long as its delivery and security terms require. Download result files promptly. You may ask us to submit a deletion request to the provider.
- Account and subscription records — kept while your subscription is active and for 12 months after it ends.
- Payment and accounting records — kept for 6 years after the end of the relevant accounting period, as UK tax law requires.
- Contact and team convention submissions — kept for 24 months from the last exchange.
- Security and server logs — kept for up to 90 days.
When a period ends we delete the data or irreversibly anonymise it.
08How we protect itEncryption in transit, access controls, secrets held server-side and a breach notification process.
All traffic is encrypted with TLS. API credentials and payment secrets are held in server-side environment variables and are never exposed to the browser. Administrative access requires authentication and is limited to the people who need it. Provider databases are encrypted at rest.
No online service is perfectly secure. If a personal data breach is likely to result in a risk to your rights we will notify the Information Commissioner's Office within 72 hours and tell you directly where the risk is high.
09Your rightsAccess, correction, erasure, restriction, portability, objection, and the CCPA rights if you are in California.
Under UK GDPR and EU GDPR
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where we have no overriding lawful reason to keep it.
- Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent — at any time, without affecting processing already carried out.
Under the CCPA and CPRA, if you are a California resident
- Know what personal information is collected, used, disclosed and to whom.
- Delete personal information we hold about you, subject to legal exceptions.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information — we do not collect it for this purpose.
- Not be discriminated against for exercising any of these rights.
Do not sell or share my personal information
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. If that ever changes we will publish a clear opt-out mechanism before it takes effect.
To exercise any right, email support@sortedysoft.shop. We may ask a question to confirm your identity, and we do not charge for a request unless it is manifestly unfounded or excessive.
10Automated processing and childrenGeneration is automated but never a decision with legal effect; the service is not for under-13s.
Plans, diagrams and walkthroughs are produced by automated AI processing. This is not automated decision-making that produces a legal or similarly significant effect on you: the output is guidance you choose whether to follow, and a person is always the one who acts on it.
Neatfile is not intended for children under 13, and they may not use it. Users aged 13 to 17 need the consent of a parent or guardian, who accepts the terms on their behalf. If we learn that we hold data about a child under 13 we delete it promptly. A parent or guardian can contact support@sortedysoft.shop to request this.
11Complaints and changesContact us first; you can also complain to the ICO or your local supervisory authority.
If you are unhappy with how we have handled your data, email support@sortedysoft.shop and we will investigate and reply.
You may also complain to the UK Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or to the supervisory authority in your country of residence if you are in the European Economic Area. California residents may contact the California Privacy Protection Agency.
When we change this policy we update the date shown beside the title and, for material changes, tell subscribers by email before the change takes effect. This policy was last updated on 20 July 2026.
Questions about this policy go to support@sortedysoft.shop. Our other policies are the Privacy Policy, Terms of Service, Refund and Cancellation Policy, Cookie Policy, Acceptable Use Policy, Content License and AI Disclaimer.