Privacy policy
Setliva processes personal data in two different roles, and which one applies changes your rights and who you exercise them against. This policy explains both, and sets out how the decisioning works — including the parts that are automated.
Last updated 1 September 2026
The two roles we act in
Setliva ("we", "us") operates setliva.com.
As a processor, for our customers
Most of the personal data we handle is not ours. When a business uses Setliva to recover its receivables or contest its chargebacks, that business decides what is collected and why; we act on its instructions. That business is the controller and we are its processor. The debtors, cardholders and contacts whose data appears in a case are that business’s data subjects, not ours.
If you have received a message from Setliva about a debt or a transaction and want to exercise a data-protection right, the fastest route is the business you owe or transacted with. We will also pass any request we receive straight to them, and tell you that we have.
As a controller, for our own business
We are the controller for our website, our own marketing and sales records, the accounts of people who log in to use the product, and our supplier and billing records.
A data processing addendum governing our processor role is available at /legal/dpa and is executed alongside the main services agreement.
What we process
The categories differ sharply between the two roles.
| Role | Categories | Where it comes from |
|---|---|---|
| Processor | Identity and contact details of debtors and cardholders; invoice, order and transaction records; payment and settlement history; delivery and carrier records; device, session and IP data captured at checkout; records of communications, including messages, call outcomes and promises to pay; consent records for each contact channel | Our customer's own systems of record — accounting ledgers, payment processors, storefronts, carriers, helpdesks and CRMs — connected on that customer's instruction |
| Controller | Name, work email, company, role, the markets you collect in and anything you write to us; account credentials and sign-in events; billing and supplier records; website request logs | Directly from you, through our forms, our product and correspondence |
We do not seek special category data and the product has no field for it. Free-text notes and communication records can nonetheless contain whatever a person chose to write, so customers are asked to keep them to what the matter requires.
We do not knowingly process the data of children. The product is a business tool and is not directed at anyone under 18.
Why we are allowed to process it
Where we are the controller
- Performance of a contract — to provide the product to you, administer your account and invoice you.
- Legitimate interests — to respond to enquiries, to keep the service secure and available, to prevent misuse, and to tell existing business customers about materially relevant changes. We balance these against your interests each time, and you can object.
- Consent — for marketing to people who are not existing customers, which you may withdraw at any time without affecting anything that came before.
- Legal obligation — accounting, tax and responding to lawful requests.
Where we are the processor
The lawful basis is our customer’s to establish, not ours. In practice a creditor recovering a debt it is owed will usually rely on performance of a contract or on legitimate interests, and a merchant defending a chargeback on legitimate interests and on compliance with the card scheme rules it is bound by.
Two of those bases are enforced by the product rather than left to good intentions. Where a channel requires recorded consent — WhatsApp, SMS and voice are configured that way by default — the engine will not compose a message for that channel without it, and falls back to a channel that is permitted. And contact frequency caps are applied as a hard block, not a warning: once an account reaches its limit, no outreach is produced at all.
Automated decision-making and profiling
This section matters more than most, because deciding what to do about a debt or a dispute is the product.
Setliva scores a case and reaches a recommended action automatically. The scoring is rule-based and deterministic: the same case and the same policy always produce the same result, and every fact the decision rests on is recorded against the specific source record it was read from. No large language model is involved in reaching a decision, and none is involved in writing the resulting notice.
A separate set of conditions — we call them gates — override the score outright rather than being weighed against it. Several of them exist precisely to stop a person being pursued when they should not be:
- An invoice carrying an open commercial dispute is suppressed entirely.
- A debt beyond the applicable limitation period is not worked.
- An account in formal insolvency proceedings is routed to a human and pursuit stops.
- A balance already covered by an unapplied credit note is suppressed.
- An account at its contact frequency cap produces no outreach.
- An unexpired promise to pay suppresses further contact until the date has passed.
- A high-value or finely balanced case is routed to a person rather than actioned.
The recommendation is an instruction to our customer, not a legal or financial determination about you, and it does not decide whether a debt exists. Where an automated decision would produce a legal or similarly significant effect, our customer is responsible for ensuring a human reviews it. The product is built for that: every case shows its reasoning step by step, a reviewer can approve, override or return any decision, and an override requires a written reason that is recorded permanently.
You can ask for human intervention, express your point of view, and contest a decision. Direct the request to the business pursuing the matter; we will support them in answering it and can reproduce exactly how any decision was reached.
International transfers
The product is used across markets including the United Kingdom, the European Economic Area, Nigeria, Kenya, Brazil, India and the United States, so data may be transferred between them.
Where data leaves the UK or EEA for a country without an adequacy decision, we rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment. Copies of the mechanism relied on for any given transfer are available on request.
Where regional law requires local processing or notification, that is agreed with the customer as part of onboarding rather than assumed.
How long we keep it
| Record | Retention | Why |
|---|---|---|
| Case and evidence data (processor) | For the term of the customer's agreement, then deleted or returned within 90 days of termination | Set by the customer as controller; we hold it only to provide the service |
| Audit trail entries | Six years from the event, unless the customer specifies longer | Decisions about debt and disputes must remain explainable after the fact, including to a regulator |
| Contact and access enquiries | 24 months from last contact | To answer follow-ups and keep a record of what was asked |
| Billing and accounting records | Seven years | Statutory retention |
| Security and request logs | 12 months | Investigating incidents and abuse |
The audit trail is hash-chained: each entry commits to the one before it, so an entry cannot be altered or removed without breaking verification of everything after it. That is deliberate, and it means audit entries are not deleted in response to an erasure request. Where erasure applies, the personal data in the underlying case is removed and the audit entry is retained in a form that records that a decision occurred without reproducing the personal data behind it.
Your rights
Subject to the conditions in the law that applies to you, you can ask for access to your data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. You can also withdraw consent where consent is what we rely on.
Where we are the controller, write to hello@setliva.com and we will respond within one month. Where we are the processor, contact the business pursuing the matter; if you contact us instead we will forward it promptly and tell you we have done so.
Regional additions
- UK and EEA: you may complain to the supervisory authority for your country.
- Nigeria: the Nigeria Data Protection Act 2023 applies, and you may complain to the Nigeria Data Protection Commission.
- Kenya: the Data Protection Act 2019 applies, and you may complain to the Office of the Data Protection Commissioner.
- Brazil: the Lei Geral de Proteção de Dados applies, and you may complain to the ANPD.
- India: the Digital Personal Data Protection Act 2023 applies as it comes into force.
- United States: where state privacy laws apply, you may request access, deletion and correction, and appeal a refusal. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.
We will not discriminate against you for exercising any of these rights.
Security
Our security practices are set out in full at /legal/security. In summary: data is encrypted in transit and at rest, access is role-based and least-privilege, every consequential action is written to a tamper-evident audit trail, and access to production data is limited to what is needed to run the service.
Changes and contact
We will post any change here and update the date at the top. Where a change materially affects how we handle your data, we will tell affected customers directly and in advance.
Questions, requests and complaints: hello@setliva.com.