The plain-English version
Before the legal text — here is what BundleCreator does with your data, in 90 seconds.

Knowing the Boundary
How BundleCreator Handles Your Data
Stored and processed in the UK on Google Cloud Run, London region. AES-256 at rest, TLS 1.3 in transit, UK GDPR + Data Protection Act 2018, ICO-regulated. 90 seconds, plain English.
Privacy Policy
Steleo Publishing Limited
Effective Date: 1st August 2025
Last Updated: 24/07/2026
Document Version: 2.0
Scope: This Privacy Policy applies exclusively to BundleCreator.co legal document management services
ENHANCED PRIVACY COMMITMENT: Unlike many competitors, we implement privacy-by-design principles with proactive data minimisation, explicit automated deletion schedules, and zero-tolerance for data monetisation. Your legal documents and professional communications remain strictly confidential and are never used for commercial purposes beyond providing our core service.
1. Introduction
This Privacy Policy ("Policy") governs the collection, processing, and use of personal data by Steleo Publishing Limited ("Steleo," "we," "us," or "our") in connection with the BundleCreator.co service ("Service") and related business operations.
Company Information:
- Steleo Publishing Limited, a company incorporated in England and Wales (Company Number: 11891029)
- Registered Address: 167-169 Great Portland Street, London W1W 5PJ
- Contact: privacy@bundlecreator.co
We are committed to protecting your privacy while maintaining operational flexibility necessary for effective service delivery. This Policy may be updated periodically to reflect changes in our practices, technology, or legal requirements.
2. Legal Professional Privilege and Client Confidentiality
2.1 Privilege Protection Commitment: Steleo Publishing Limited recognises and strictly respects the fundamental importance of legal professional privilege in the UK legal system. We implement specialised safeguards to protect privileged communications and confidential legal materials.
2.2 No Waiver of Privilege: Your use of our Service does not constitute a waiver of legal professional privilege or client confidentiality. We do not access, review, or analyse the content of your legal documents except as strictly necessary for technical service provision.
2.3 Staff Confidentiality: All Steleo employees with potential access to user data are bound by comprehensive confidentiality agreements and undergo specialised training on legal professional privilege requirements. We maintain strict need-to-know access controls.
2.4 Court Order Response: In the unlikely event of a court order or legal process seeking access to privileged materials, we will notify affected users immediately (unless legally prohibited) and will challenge any overly broad requests that may compromise privilege protection.
3. Data Controller vs. Data Processor Relationship
Critical Legal Framework: Steleo Publishing Limited acts solely as a data processor under applicable data protection regulations, including the General Data Protection Regulation (GDPR). Our customers and authorised users function as data controllers for any content and personal data uploaded to or processed through the BundleCreator.co Service.
Customer Responsibilities as Data Controllers:
- Determine the purposes and means of processing personal data within the Service
- Ensure lawful basis for data collection and processing
- Provide appropriate privacy notices to their data subjects
- Handle data subject requests and compliance obligations
Steleo's Role as Data Processor:
- Process data solely according to customer instructions and this Policy
- Implement appropriate technical and organisational security measures
- Assist customers with compliance obligations where reasonably possible
- Not independently determine processing purposes for customer content
Limitation of Liability: Steleo is not responsible for the content, accuracy, or lawfulness of personal data uploaded by customers, nor for customers' data collection methods, processing purposes, or compliance with applicable privacy laws regarding their own data subjects.
3. Information We Collect
3.1 Account and Registration Information
- Email address and authentication credentials
- Name, company information, and contact details
- Billing and payment information (processed through secure third-party providers)
- Account preferences and service configuration settings
3.2 Service Usage Data
- Technical information including IP addresses, browser type, device information
- Service interaction data, feature usage patterns, and performance metrics
- Log files containing access times, pages viewed, and system activities
- Cookies and similar tracking technologies for authentication and user experience
3.3 Customer Support Data
- Communications with our support team
- Technical assistance requests and resolution records
- Feedback, surveys, and service improvement suggestions
3.4 Marketing and Communication Data
- Newsletter subscriptions and communication preferences
- Event participation and webinar attendance
- Marketing campaign interaction data
3.5 Business Relationship Data
- Information about suppliers, partners, and service providers
- Contract and commercial relationship data
- Professional contact information for business operations
4. How We Use Your Information
4.1 Service Provision
- Authenticate users and maintain account security
- Deliver, maintain, and improve the BundleCreator.co Service
- Process transactions and manage billing
- Provide customer support and technical assistance
4.2 Business Operations
- Analyse service usage patterns to improve functionality
- Conduct security monitoring and fraud prevention
- Perform system maintenance and technical administration
- Manage vendor and partner relationships
4.3 Legal and Compliance
- Comply with applicable laws, regulations, and legal processes
- Enforce our Terms of Service and other agreements
- Protect our rights, property, and safety, and that of our users
- Respond to law enforcement requests and court orders
4.4 Communications
- Send service-related announcements and updates (mandatory)
- Provide account notifications and security alerts
- Deliver newsletters and promotional materials (with opt-out options)
- Conduct customer satisfaction surveys
5. Information Sharing and Disclosure
5.1 Third-Party Service Providers
We may share information with carefully selected service providers who assist in delivering our services:
- Cloud infrastructure providers for hosting and data storage
- Payment processors for billing and transaction management
- Analytics and advertising providers — Google (Google Analytics 4, Google Ads), Microsoft (Clarity, on signed-in pages only) and Plausible Analytics — used, where consent is required, only on the basis of your consent, to understand site usage and measure our marketing. See our Cookie Policy for full detail and to manage your choices.
- Customer support tools for efficient service delivery
- Security services for threat detection and prevention
All third-party providers are contractually bound to maintain data confidentiality and use information solely for providing services to us.
5.2 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, personal information may be transferred as part of the business assets. Users will receive at least 30 days advance notice of any change in ownership or control of their personal information.
5.3 Legal Requirements
We may disclose personal information when required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to:
- Comply with applicable laws or respond to valid legal processes
- Protect the rights, property, or safety of Steleo, our users, or the public
- Enforce our agreements and terms of service
- Detect, prevent, or investigate security breaches or fraudulent activities
5.4 Aggregated Information
We may share aggregated, anonymized information that does not identify individual users with partners, advertisers, or other third parties for business intelligence and market analysis purposes.
5A. AI Processing of Your Data
We do not train AI models on your data. BundleCreator never uses customer documents, bundles, or case details to train artificial-intelligence models — ours or any third party’s.
Where we use AI, it is for specific product features under strict privacy controls:
- Mind Mapuses Anthropic’s Claude API, configured with zero data retention. Personally identifiable information — postcodes, phone numbers, names, NHS numbers, case references, and other identifiers — is stripped client-side in your browser before any text is sent to Claude. Raw PDF files are never sent to Claude.
- Read Aloud uses Google Cloud Text-to-Speech to convert selected text into audio. It is a non-generative service and does not train on content.
- Document OCR runs entirely in your browser through Tesseract. Scanned pages never leave your device for OCR processing.
- PII Redaction is a set of pattern-matching rules that run in your browser. No machine-learning model is used and no network call is made.
We do not use Google Gemini, OpenAI (ChatGPT or GPT APIs), Mistral, Cohere, Perplexity, or any other generative AI provider. BundleCreator does not use AI for pricing, eligibility, risk scoring, account suspension, or any other decision affecting you.
If any of this changes — for example if we add a new AI-powered feature or swap providers — we will update this policy and our AI Transparency page before any customer data is processed by a new provider.
6. Data Security and Protection
6.1 Technical Security Measures
We implement comprehensive security measures including:
- Field-Level Encryption: AES-256-GCM encryption for sensitive personal data including applicant names, respondent names, and children's details
- Encryption at Rest: All data encrypted in database storage using AES-256
- Encryption in Transit: TLS 1.3 for all data transmission
- Time-Limited Access URLs: Document access URLs expire after 15 minutes to prevent unauthorised sharing
- Enhanced Audit Logging: 7-year retention of all document access records for UK legal compliance
- Row-Level Security: Database-level access controls prevent unauthorised data access
- Multi-Factor Authentication: Available for all user accounts
- Regular Security Assessments: Penetration testing and security audits
- Employee Training: Comprehensive data protection and security protocol training
6.2 Security Certifications
We maintain relevant security certifications and comply with industry standards to demonstrate our commitment to data protection. Current certifications and compliance frameworks are available upon request.
6.3 Security Limitations
While we implement commercially reasonable security measures and maintain industry best practices, no method of transmission or electronic storage is completely secure. We cannot guarantee absolute security against all potential threats, including sophisticated cyberattacks, system failures, or unauthorised access attempts.
6.4 Incident Response
In the event of a suspected security breach affecting personal data, we will:
- Investigate the incident promptly and thoroughly
- Notify affected users in accordance with applicable legal requirements
- Coordinate with relevant authorities as required by law
- Implement additional security measures to prevent similar incidents
7. International Data Transfers
Personal data may be processed and stored in countries outside your jurisdiction through our global service providers and infrastructure partners. When transferring data internationally, we ensure appropriate safeguards including:
- EU adequacy decisions for transfers from the European Economic Area
- Standard Contractual Clauses approved by relevant data protection authorities
- Other legally recognised transfer mechanisms
- Contractual commitments to maintain equivalent data protection standards
8. Data Retention
8.1 Retention Principles
We retain personal data only as long as necessary for:
- Providing and maintaining the Service
- Fulfilling legal and regulatory obligations
- Resolving disputes and enforcing agreements
- Legitimate business purposes including analytics and improvement
8.2 Specific Retention Periods
- Account information: Retained during active service period plus 7 years for legal compliance
- Usage and technical data: Retained for 3 years for service improvement and security
- Customer support records: Retained for 3 years for quality assurance and legal protection
- Marketing data: Retained until consent withdrawal or legitimate interest cessation
- Billing records: Retained for 7 years for accounting and tax compliance
8.3 Data Deletion
Upon account closure or data retention period expiration, we will securely delete personal data unless longer retention is required by law or for legitimate business purposes such as fraud prevention or legal proceedings.
9. Your Rights and Choices
9.1 Data Subject Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request information about personal data we process about you
- Rectification: Request correction of inaccurate or incomplete information
- Erasure: Request deletion of personal data under certain circumstances
- Portability: Request transfer of data to another service provider
- Restriction: Request limitation of processing activities
- Objection: Object to processing based on legitimate interests or direct marketing
9.2 Exercising Your Rights
To exercise these rights, contact us at privacy@bundlecreator.co with:
- Clear identification of yourself and your relationship to our Service
- Specific description of your request
- Any relevant supporting documentation
We will respond within legally required timeframes and may request additional verification to protect against unauthorised requests.
9.3 Communication Preferences
- Service communications: Required for account security and service operation
- Marketing communications: Opt-out available through email links or account settings
- Newsletter subscriptions: Managed through preference center or unsubscribe links
10. Cookies and Tracking Technologies
10.1 Types of Cookies
We use various cookies and similar technologies:
- Essential cookies: Required for service functionality and security
- Analytics cookies: Help us understand service usage and performance
- Preference cookies: Remember your settings and customisations
- Marketing cookies: Enable targeted communications and advertising
10.2 Cookie Management
You can control cookie settings through your browser preferences, though disabling certain cookies may limit service functionality. Third-party analytics and advertising cookies can be managed through relevant opt-out mechanisms.
11. Children's Privacy
The BundleCreator.co Service is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will take immediate steps to delete the information and terminate the associated account.
12. Regional Privacy Rights
12.1 European Economic Area (EEA)
Under GDPR, EEA residents have specific rights including data portability, erasure, and the ability to lodge complaints with supervisory authorities. Our lawful bases for processing include contract performance, legal compliance, and legitimate interests.
12.2 California Residents
Under the California Consumer Privacy Act (CCPA), California residents have rights to know about, delete, and opt-out of the sale of personal information. We do not sell personal information as defined by CCPA.
12.3 Other Jurisdictions
We comply with applicable data protection laws in all jurisdictions where we operate and will respect additional rights granted by local privacy legislation.
13. Policy Updates and Changes
13.1 Modification Rights
We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or business operations.
13.2 Notice of Changes
- Material changes: We will provide at least 30 days advance notice via email and prominent website notices
- Minor updates: We will update the "Last Updated" date and notify users of changes
- Immediate changes: Required by law or for security purposes may be implemented immediately with subsequent notice
13.3 Acceptance of Changes
Continued use of the Service after policy updates constitutes acceptance of the revised terms. If you disagree with changes, you may terminate your account before the effective date.
14. Contact Information
14.1 Privacy Inquiries
For privacy-related questions, requests, or concerns:
- Email: privacy@bundlecreator.co
- Subject Line: Include "Privacy Policy Inquiry" for faster processing
- Response Time: We aim to respond within 5 business days
14.2 Data Protection Officer
For GDPR-related matters in the EEA:
- Email: dpo@bundlecreator.co
14.3 Regulatory Complaints
You have the right to lodge complaints with relevant data protection authorities in your jurisdiction if you believe we have not addressed your privacy concerns adequately.
15. Effective Date and Governing Law
This Privacy Policy is effective as of 1st August 2025 and is governed by the laws of England and Wales. Previous versions are archived and available upon request.
Document Version: 1.0
This Privacy Policy is designed to provide comprehensive protection for Steleo Publishing Limited while ensuring transparency and compliance with applicable privacy laws. For the most current version, please visit bundlecreator.co/privacy.
Last updated: 24/07/2026
Company: Steleo Publishing Limited