Hound

Privacy notice

What we hold, and why.

We process two kinds of personal data: the details of the tradesmen who hire us, and the details of the people and businesses who owe them money. This says exactly what we do with both.

Last updated 4 August 2026 · Quezzies Ltd trading as Hound

01

Who we are

Quezzies Ltd (company number 16590159), trading as Hound, registered at 11 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BG. We are the data controller for everything described here.

For anything about your data, write to privacy@hound.credit. A person reads that address.

02

What we process, and the lawful basis for it

Data Why we have it Lawful basis
Client account Name, business email, company details and billing records for the tradesman or firm who hires us. Needed to run the account and take payment. Performance of a contract
Debtor contact Name, business or personal address, email and phone number of the person or company who owes our client money, taken from our client's own accounting records. Legitimate interests
Invoice data Invoice numbers, amounts, dates, payment history and the correspondence we send about them. This is the debt itself. Legitimate interests
Client mobile A mobile number, only if the client chooses to approve chases over WhatsApp. Never used for anything else and never given to anyone. Consent
Site analytics Aggregate page views with no cookies and no cross-site tracking. We cannot identify you from it. Legitimate interests

The legitimate interest is the recovery of a lawful debt: our client is owed money, and pursuing it requires knowing who owes it and how to reach them. We have weighed that against the privacy of the person who owes it, and we limit the processing accordingly — we take only what our client already holds, we use it for nothing but recovering that debt, and we never sell it, profile it, or build a credit opinion from it. Where the data comes to us from our client, it originates from the dealings between them, not from us.

The client mobile sits on consent, and consent can be withdrawn in one word: reply STOP to any WhatsApp, or turn it off in the dashboard. Nothing else about the service changes if you do.

03

Where the debtor data comes from

From our client's accounting system, with their authority. If they use Xero, we connect with read-only access to contacts and invoices. We cannot create, edit or delete anything in their Xero, and we do not read payroll, banking or any other part of it. The connection can be revoked by the client at any time from inside Xero, and we hold no copy of their Xero credentials — only an encrypted token.

Where a debtor is a limited company, we also check the public register at Companies House to confirm the company exists and is trading. That is public information about a company, not personal data about you.

04

Who else touches it

We use a small number of processors, all under contract, none of whom may use the data for their own purposes:

Processor What for Where
Cloudflare Hosting, the database, and the network in front of it UK / EU
Clerk Client sign-in. Never holds debtor data US, standard contractual clauses
Stripe Client payments. We never see full card details US / EU, standard contractual clauses
Resend Sending the chase emails and account email US / EU, standard contractual clauses
Meta (WhatsApp) Messages to a client who opted in. Debtors are never contacted on WhatsApp US / EU, standard contractual clauses
Anthropic Drafting the wording of a chase. Not used for training, and no data is retained by them for it US, standard contractual clauses
Companies House Public checks on limited-company debtors UK

We also pass a debt to a regulated legal partner when it reaches a letter before action or a court claim, and only then. That firm is a controller in its own right for what it does next, and it will tell you so itself. We do not sell debts, and we do not sell, rent or share personal data with anyone for marketing.

05

How long we keep it

  • Debtor and invoice data: six years from the last activity on the debt. That matches the limitation period for a simple contract debt in England and Wales, which is how long a claim could be brought and therefore how long the record could be needed.
  • Client account and billing records: six years from the end of the relationship, which is the period HMRC requires for business records.
  • WhatsApp messages to and from a client: two years, as the record of what was approved and when.
  • Website enquiries: two years, or until you ask us to delete them.

When a client leaves, their debtor data is deleted on the schedule above rather than immediately, because the audit trail of what was sent in whose name is the thing that protects everyone if a debt is later disputed.

06

If you are being chased and want it to stop

Reply to the message. Any reply stops the sequence straight away and puts it in front of a person. That is built into the system, not a favour.

Beyond that, you have the right to object to processing carried out on legitimate interests. Write to privacy@hound.credit with the invoice reference and we will stop processing unless we can show compelling grounds that override your rights — and we will tell you which it is, in writing, within a month.

You also have the right to ask for a copy of what we hold, to have mistakes corrected, to ask for erasure, to ask us to restrict what we do with it, and to receive it in a portable form. There is no charge and we answer within one month.

Two honest limits. Objecting to us does not make the debt go away: the money is still owed to our client, and they may pursue it themselves or through someone else. And if the debt is disputed, say so — a disputed invoice is never put into a chase sequence at all.

Nothing here is decided by a machine on its own. Every message to a private individual is approved by a person before it is sent, and no automated decision is taken that produces a legal effect for you.

07

Security

Accounting tokens are encrypted at rest with keys we hold separately from the data. Access to production is limited to people who need it. Everything travels over TLS. We do not store card numbers at any point.

08

Complaints

Tell us first at privacy@hound.credit and we will try to put it right. You can complain to the Information Commissioner's Office at any time, and you do not have to come to us first:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint

09

Changes

If we change how we process personal data in a way that affects you, we will update this page and change the date at the top. Material changes affecting clients are emailed as well.