Sorple Privacy Policy

Last updated: 21 September 2026

This Privacy Policy explains how Sorple Limited collects, uses, stores, shares and otherwise processes personal data when people visit www.sorple.com, create or use a Sorple account, contact Sorple, or interact with related services (together, the Service).

Sorple is a business-to-business software service. This Privacy Policy applies to personal data relating to individual users, customer contacts, prospective customer contacts and website visitors.

1. Who controls your personal data

Sorple Limited is the controller of the personal data covered by this Privacy Policy.

Registered office: Longhouse, Freefolk, Whitchurch, RG28 7NW, United Kingdom

Company number: 17389409

Contact email: [email protected]

Sorple does not currently list a separate data protection officer contact. Privacy questions, rights requests and complaints about personal data processing should be sent to [email protected].

2. What personal data Sorple collects

Sorple collects the following categories of personal data.

Account and identity data

When an account is created or administered, Sorple may collect:

  • Name
  • Billing Address
  • Work email address
  • Company name.

Prompt and brief data

Sorple processes prompts, briefs, instructions, search inputs and similar content submitted through the Service.

Users are discouraged from including personal data in prompts or briefs unless it is genuinely necessary. The Service is not intended for special category personal data or other sensitive personal information, and users should not submit such data through prompts or briefs.

If a user chooses to include personal data in a prompt or brief, Sorple may process that information as part of delivering the relevant search, research or related service functionality.

Payment and transaction data

Paid subscriptions, payment card and billing payment details will generally be collected and processed by Sorple’s third-party payment provider rather than stored directly by Sorple. Sorple may still receive limited transaction information such as payment status, subscription status, billing dates and partial account-identifying information needed to manage the customer relationship.

Communications data

If a person contacts Sorple, requests support, responds to onboarding or account emails, or otherwise communicates with Sorple, Sorple may collect the contents of those communications and related contact details.

Usage, technical and log data

Sorple may collect technical and usage information generated through use of the Service, such as account activity, dates and times of access, service events, search activity, browser or device-related metadata, IP address and security or diagnostic logs, where needed for service delivery, security, troubleshooting, abuse prevention and improvement of the Service.

Marketing and account update data

Sorple may use business contact details for product, account, operational and limited marketing communications sent to account users.

3. How Sorple collects personal data

Sorple collects personal data:

  • directly from users and customer contacts when they register, use the Service or contact Sorple;
  • from prompts, briefs and other content submitted into the Service;
  • from customer organisations that create accounts for their personnel;
  • from payment and authentication providers involved in operating the Service; and
  • automatically through the operation, security and administration of the Service, including payment-related website technologies used by Stripe where applicable.

4. How Sorple uses personal data

Sorple uses personal data for the following purposes:

  • to provide and operate the Service;
  • to create and manage user accounts;
  • to authenticate users and secure access to the Service;
  • to process prompts, briefs and submitted requests;
  • to provide search, research and AI-assisted outputs requested through the Service;
  • to communicate about accounts, support issues, service updates and operational notices;
  • to send product updates and limited marketing communications to account users;
  • to administer payments, subscriptions and account status where paid plans are offered;
  • to monitor, secure, troubleshoot and improve the Service;
  • to detect, investigate and prevent fraud, misuse, unauthorised access and other harmful activity;
  • to comply with legal obligations, regulatory requirements and lawful requests; and
  • to establish, exercise or defend legal claims.

Sorple does not use prompts, briefs, user inputs or outputs to train Sorple’s own models or to train third-party AI models.

5. Lawful bases for processing

Under UK GDPR, Sorple relies on the following lawful bases depending on the context.

Performance of a contract

Sorple processes personal data where necessary to provide the Service, create and administer accounts, process submitted prompts and briefs, deliver requested outputs, manage subscriptions and provide support connected with the Service.

Legitimate interests

Sorple processes personal data where necessary for legitimate interests, provided those interests are not overridden by data protection rights. These legitimate interests include:

  • operating, securing and improving the Service;
  • managing customer relationships and account administration;
  • sending product and service communications to business account users;
  • preventing fraud, abuse and misuse;
  • maintaining internal records and business operations; and
  • defending legal rights and enforcing contractual terms.

Legal obligation

Sorple may process personal data where necessary to comply with legal or regulatory obligations, including accounting, tax, compliance, law-enforcement cooperation and record-keeping requirements.

Consent

Where consent is required by law, Sorple will rely on consent. If Sorple relies on consent, the individual has the right to withdraw that consent at any time, although withdrawal will not affect processing carried out before withdrawal.

6. Marketing communications

Sorple may send product updates, service information and limited direct marketing communications to account users at their work email addresses where permitted by applicable law.

Account users can opt out of non-essential marketing emails by using the unsubscribe mechanism in the relevant email or by contacting [email protected]. Sorple may still send service, transactional, billing, account and legal notices where those are necessary for the operation of the customer relationship.

7. AI-related processing

Sorple uses artificial intelligence and automated processing to help generate search and research outputs in response to user prompts and briefs.

Sorple does not use personal data submitted through the Service to train Sorple models or third-party AI models. However, personal data may still be processed by AI-enabled systems where it appears in prompts, briefs or related account activity in order to generate the requested output.

Because personal data in AI systems can make rights handling more complex, Sorple asks users not to include unnecessary personal data in prompts and briefs and not to include special category or other sensitive personal data in the Service.

8. Cookies and similar technologies

Sorple may use cookies or similar technologies that are necessary for the operation of the website and service, including technologies associated with payment processing through Stripe where applicable.

Where cookies or similar technologies are not strictly necessary, Sorple will seek any consent required by applicable law before placing them on a user’s device.

If Sorple later implements broader analytics, advertising or optional website technologies, Sorple may provide additional cookie disclosures or a separate Cookie Policy.

9. Sharing personal data

Sorple may share personal data with the following categories of recipients, to the extent reasonably necessary for the purposes described in this Privacy Policy:

  • authentication providers;
  • payment providers;
  • API and infrastructure providers used to operate the Service;
  • hosting, storage, security and support providers;
  • professional advisers such as lawyers, accountants, auditors and insurers;
  • regulators, courts, law-enforcement agencies and public authorities where required or permitted by law; and
  • actual or prospective buyers, investors or advisers in connection with a corporate transaction, subject to appropriate confidentiality protections.

Sorple does not sell personal data.

10. International transfers

Some of Sorple’s service providers and systems may process personal data outside the United Kingdom. Where this happens, Sorple will seek to ensure that the transfer is made lawfully and that appropriate safeguards are in place in line with UK GDPR requirements.

Depending on the destination and recipient, Sorple may rely on:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or other appropriate safeguards; or
  • another lawful transfer mechanism permitted by UK GDPR in the relevant circumstances.

Information about the relevant transfer safeguard can be requested by contacting [email protected].

11. How long Sorple keeps personal data

Sorple retains personal data while the relevant account remains active and for as long as reasonably necessary for the purposes described in this Privacy Policy.

If an account ends, Sorple intends to delete customer account data from its active production systems 30 days after the account ends, unless a longer retention period is required or permitted by law, regulation, dispute resolution, fraud prevention, security needs or the establishment, exercise or defence of legal claims.

Backups and archive copies may persist for a limited period after deletion from active systems until overwritten or deleted in the ordinary backup cycle.

Sorple may retain communications, transaction records and limited administrative records for longer where reasonably required for compliance, tax, accounting, legal or evidential purposes.

12. Security

Sorple uses technical and organisational measures intended to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.

No system can be guaranteed completely secure, and Sorple does not promise that the Service will be immune from all security incidents, unauthorised access or cyber risks. Users should maintain strong passwords, protect account credentials and avoid submitting unnecessary personal data through prompts or briefs.

13. Individual rights

Under UK data protection law, individuals may have rights including the right to:

  • be informed about how their personal data is used;
  • request access to their personal data;
  • request correction of inaccurate personal data;
  • request erasure of personal data in certain circumstances;
  • request restriction of processing in certain circumstances;
  • object to processing carried out on the basis of legitimate interests in certain circumstances;
  • request data portability in certain circumstances; and
  • withdraw consent where processing is based on consent.

These rights are not absolute and may depend on the legal basis and specific context of the processing.

To exercise rights, contact [email protected]. Sorple may need to verify identity before acting on a request.

14. Complaints

Individuals also have the right to complain to the Information Commissioner’s Office if they believe personal data has been handled unlawfully or unfairly. Information about complaints is available from the ICO.

Sorple would appreciate the opportunity to address concerns first, and privacy-related questions or complaints can be sent to [email protected].

15. Third-party websites and services

The Service may contain links to third-party websites, plug-ins or services. Sorple is not responsible for the privacy practices of third parties, and individuals should review the privacy information provided by those third parties separately.

16. Changes to this Privacy Policy

Sorple may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements or business operations.

The latest version will be posted on the website or otherwise made available through the Service. Where changes materially affect how personal data is processed, Sorple will take reasonable steps to draw those changes to users’ attention.