Privacy Policy
Status: Draft · last revised September 23, 2026
This document is a draft. It has not been finalized and may change before the final version is published. Questions: privacy@dutyrecover.ai.
1. Who we are
DutyRecoverAI will be operated by a UK private limited company that has not yet been incorporated. That company will be responsible for the personal information described in this policy, except where section 2 explains that it acts on behalf of its customers. Its registered name, company number and registered office will be stated here before this policy takes effect.
Contact us about privacy at privacy@dutyrecover.ai. We have not appointed a data protection officer; messages to that address reach the person responsible for privacy at DutyRecoverAI.
This policy covers the DutyRecoverAI website and application at dutyrecover.ai. DutyRecoverAI is a service for businesses and is not intended for children.
2. Our role
Our customers — importers, customs brokers and trade-compliance teams — upload customs and import records to DutyRecoverAI. Much of that information is business information rather than personal information. Where it does include personal information, such as the names and contact details of individuals in entry records or documents, the customer decides how it is used, and we process it on the customer's behalf, as its processor, under our Terms of Service. If your personal information is in a customer's records, that customer's own privacy notice applies, and we will pass any request you send us to that customer.
For everything else in this policy — for example the accounts of the people who use DutyRecoverAI, billing, security, support and our website — we decide how the information is used, and we are the controller.
3. Information we collect
• Account information: your name, email address, organization name, and your role in the account (Admin, Analyst or Read Only). If you are invited, the person who invites you gives us your email address and, in some cases, your name and role. Your password is handled by our authentication provider and stored only in hashed form.
• Billing information: the billing email address, subscription plan and payment status. Card details are entered on Stripe's pages and handled by Stripe; we never receive or store full card numbers.
• Customer content: the customs and import data your organization uploads (for example entry numbers, HTS codes, values, duty amounts, countries of origin, importer and broker names, ports and dates), the files and documents it uploads (for example CSV files, commercial invoices, bills of lading and CBP correspondence, including CBP Form 28 requests), and what the Service produces from them, such as findings, cases, notes, reports and AI-generated drafts.
• Terms acceptance records: which version of the Terms of Service each user accepted, and when.
• Communications: messages you send to our email addresses, and the service emails we send you.
• Early-access requests: the email address, company and role you enter when you join our waitlist.
• Technical and security information: the IP address and browser details of each signed-in session; IP addresses and account or organization identifiers used to limit request rates; and, when an error occurs, an error report and a short, masked replay of the moments before it (section 11).
• Website analytics: pages visited, the referring page, device and browser type, and which site actions are used (for example starting the Recovery Scan or requesting early access, but never what you enter), counted without cookies (section 11).
Where it comes from: from you; from colleagues in your organization, who may invite you or upload records that mention you; from Stripe, which tells us whether payments succeed; from our customers' uploaded records (section 2); and from our own systems, which generate the technical and security information above when you use the Service.
We do not collect government identification numbers, biometric data or precise location, and we do not buy personal information from third parties.
4. How we use it, and our lawful bases
• To create and run your account and provide the Service: performance of our contract with your organization or, where you are not personally the contracting party, our legitimate interest in providing the Service your organization has asked for.
• To process customer content: on our customer's instructions, as its processor (section 2).
• To take payments and manage subscriptions: performance of our contract, and our legal obligation to keep accounting and tax records.
• To send service emails — invitations, password resets, audit-completion notices, deadline alerts, the weekly tariff digest, and onboarding emails about getting started: performance of our contract, or our legitimate interest in helping our customers' users use the Service. You can ask us to stop emails that are not essential to your account by contacting support@dutyrecover.ai.
• To keep the Service secure and working — authentication, rate limiting, preventing fraud and abuse, and diagnosing errors: our legitimate interests in protecting the Service, our customers and their data.
• To record acceptance of our Terms of Service: our legitimate interest in keeping evidence of our agreements with customers.
• To answer support requests and other messages: our legitimate interest in responding to you, or performance of our contract.
• To understand how our website is used, through cookieless analytics: our legitimate interest in improving our website.
• To handle early-access requests: your consent, given when you join the waitlist. You can withdraw it at any time by emailing privacy@dutyrecover.ai.
• To comply with the law, respond to lawful requests from authorities, and establish or defend legal claims: our legal obligations and our legitimate interests.
Where we rely on legitimate interests, we have weighed them against your interests and rights, and you can object (section 9).
You need to give us account information to use the Service. Everything else is optional, although some features need the relevant data to work.
We do not sell personal information, use it for advertising, or use it to train AI models. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you: AI output in the Service is a suggestion for a person to review.
5. AI features
Some features send information to Anthropic, which provides the Claude AI model and processes it in the United States. Each feature sends only the information it needs:
• HTS classification: the product description, country of origin, intended use, and any current HTS code you enter.
• CBP audit-response drafts: the request type, dates and items questioned; your notes; your organization or importer name; entry details (entry numbers, HTS codes, product descriptions, countries of origin, values, duty rates and entry dates); evidence labels and descriptions; and the names and types of uploaded files.
• Case summaries: the case title, detector type, estimated recovery, confidence score, deadline, review stage, importer name, entry count, evidence labels and file names, and reviewer notes.
• CBP Form 28 extraction: the complete PDF you upload, including any personal information in it.
Relevant public CBP rulings are included with classification and audit-response requests. The contents of other documents in the Document Vault are not sent to Anthropic. We do not remove personal information from the fields a feature sends.
Anthropic's commercial terms and data processing addendum do not permit it to train its models on this information. Anthropic deletes API inputs and outputs within 30 days by default. If its safety systems flag an input or output under its usage policy, it may keep that input and output for up to 2 years and the related safety classification scores for up to 7 years, and it may keep information for longer where the law requires. We have not arranged zero data retention with Anthropic.
Classification suggestions and audit-response drafts are stored in DutyRecoverAI as part of your customer content. Information extracted from a CBP Form 28 is shown to you to check, and is saved only if you save the request; the uploaded PDF itself is stored. Case summaries are generated for the packet each time you create one and are not stored separately.
7. International transfers
Our database and file storage are in the UK. Some of the providers in section 6 process information in the United States, the European Union or elsewhere. When personal information is transferred from the UK, we rely on:
• UK adequacy regulations — for example for the European Union, and for US organizations certified under the UK Extension to the EU-U.S. Data Privacy Framework; or
• safeguards approved under UK law, such as the International Data Transfer Addendum to the EU standard contractual clauses, included in the provider's data processing terms.
You can ask us about these safeguards at privacy@dutyrecover.ai.
8. How long we keep it
• Account, organization and customer content: for as long as your organization's account exists. Cancelling a paid plan does not delete anything — your organization moves to the Free plan and its data stays in place until it is deleted.
• After an account is closed, or we receive a verified deletion request: deleted under our documented deletion process, without undue delay and within one month where data protection law applies.
• Terms acceptance records: deleted when the user account they belong to is deleted.
• Accounting and tax records, such as invoices and payment records: up to six years, or longer where the law requires.
• Activity-log entries linked to billing events: after an account is deleted, kept only in anonymized form, without names or other identifiers, for as long as the related accounting records.
• Early-access (waitlist) requests: deleted automatically 12 months after you join, or sooner if you ask.
• Signed-in session details (IP address and browser): until you sign out of that session, or your account is deleted.
• Rate-limiting records: expire automatically — within one hour for records keyed to an IP address.
• Error reports and error replays (Sentry): about 30 days.
• Website analytics: the daily visitor identifier is discarded after 24 hours.
• Information sent to our AI provider: see section 5.
• Support emails: for as long as we need them to deal with your message and any follow-up, and deleted with the related account unless we need them for a legal claim.
We may keep information for longer where a legal obligation to preserve it applies — for example a litigation hold or an authority's preservation request — until that obligation ends.
9. Your rights
Under UK data protection law you have the right to:
• access the personal information we hold about you and receive a copy of it;
• have inaccurate information corrected, or incomplete information completed;
• have your information deleted;
• restrict how we use your information;
• object to our use of your information where we rely on legitimate interests;
• receive information you gave us in a structured, machine-readable format, or have it sent to another organization, where we process it by automated means on the basis of consent or contract; and
• withdraw your consent at any time, where we rely on consent.
These rights have conditions and exceptions set by law. We respond without undue delay and within one month. If a request is complex, or you make several, we may extend this by up to two further months and will tell you why.
If you are outside the UK, you can make the same requests and we will handle them in the same way, together with any additional rights your local law gives you.
If your personal information is in a customer's records (section 2), we will pass your request to that customer and help it respond.
10. How to make a request or a complaint
Email privacy@dutyrecover.ai with the subject "Data request". Tell us your name, the email address linked to your account (if you have one), your organization, and what you are asking for. We may ask for information to confirm your identity before we act.
To delete your organization's account and its data, an administrator of the organization should make the request. Account deletion is not yet self-service.
You can download a CSV report of your organization's recovery opportunities from the Opportunities page at any time. For an export of your other data, email privacy@dutyrecover.ai.
If you are unhappy with how we have handled your information, please tell us first. You also have the right to complain to the UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, telephone 0303 123 1113.
12. Security
We protect personal information with measures that include encryption in transit (TLS) and at rest (AES-256, by our database provider), database row-level security that keeps each organization's data separate, role-based access within each account, private file storage with expiring download links, and rate limiting. Our Security page describes these controls. DutyRecoverAI does not hold a security certification of its own.
No system is completely secure. If a personal data breach is likely to result in a high risk to you, we will tell you without undue delay, and we will report breaches to the ICO where the law requires. Where we process customer content for a customer, we notify that customer as our Terms of Service describe.
13. California residents
We provide this section voluntarily. DutyRecoverAI does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act.
The categories of personal information we collect, where they come from, why we use them, who receives them and how long we keep them are set out in sections 3 to 8. Anyone, wherever they live, can ask to access, correct or delete their personal information as described in sections 9 and 10, and we will not treat you differently for doing so.
14. Changes to this policy
We will update this policy when our practices change. The version and effective date at the top of this page show when it last changed. If we make a material change, we will tell account holders by email or in the Service before it takes effect.
15. Contact us
The operating company's registered name, company number and registered office will be added here when it is incorporated.
Privacy questions and requests: privacy@dutyrecover.ai
General support: support@dutyrecover.ai
Security reports: security@dutyrecover.ai