Legal

Privacy policy.

Last updated: 19 June 2026

This privacy policy ("Policy") describes how One Company EMEA Ltd, trading as One Credit ("One Credit", "we", "us" or "our"), collects, protects and uses personally identifiable information ("Personal Information") you ("User", "you" or "your") may provide through our website and debtor portal at onecredit.one and any related products or services (collectively, "Website" or "Services"). It also describes the choices available to you regarding our use of your Personal Information and how you can access and update this information. This Policy does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage.

Who We Are and What We Do

One Credit is a debt resolution service operated by One Company EMEA Ltd. We are engaged by business creditors to manage the recovery of outstanding debts on their behalf. In that capacity, we act as a data processor for our creditor clients in relation to debtor information they share with us, and as a data controller in relation to information you provide to us directly through the Website.

Our lawful basis for processing your Personal Information is primarily the performance of a task carried out in the legitimate interests of our creditor clients (recovering lawfully owed debts), compliance with legal obligations, and — where you make a payment or contact us — performance of or steps towards a contract.

Automatic Collection of Information

When you visit the Website our servers automatically record information that your browser sends. This data may include information such as your device's IP address, browser type and version, operating system type and version, language preferences, the webpage you were visiting before you came to our Website, pages of our Website that you visit, the time spent on those pages, access times and dates, and other statistics. Information collected automatically is used only to identify potential cases of abuse and establish statistical information regarding Website usage. This statistical information is not otherwise aggregated in such a way that would identify any particular user of the system.

Collection of Personal Information

You can visit the Website without telling us who you are or revealing any information by which someone could identify you as a specific, identifiable individual. If, however, you wish to use the debtor portal or contact us, you will be asked to provide certain Personal Information. We receive and store any information you knowingly provide to us. When required, this information may include the following:

  • Identification details such as your name and case reference number
  • Contact information such as your email address or postal address
  • Financial information such as invoice amounts, outstanding balances, and payment history
  • Payment information such as card details processed via our payment provider, Stripe
  • Communications you send us, including payment plan requests, dispute information, or general enquiries
  • Technical session data necessary to authenticate your portal access securely

Some Personal Information about you — such as your name, contact details, and the details of the debt — may have been provided to us by the creditor who engaged One Credit. You are welcome to contact us if you have questions about what information we hold and where it originated.

Managing Personal Information

You are able to request deletion or correction of certain Personal Information we hold about you. When you request deletion of Personal Information, we may retain a copy of the unrevised information in our records for the duration necessary to comply with our legal obligations, defend legal claims, or satisfy our obligations to our creditor clients. If you would like to delete your Personal Information or understand what we hold, you can contact us using the details at the end of this Policy.

Storing Personal Information

We will retain and use your Personal Information for the period necessary to comply with our legal obligations, resolve disputes, and enforce our agreements unless a longer retention period is required or permitted by law. We may use aggregated data derived from your Personal Information after you update or delete it, but not in a manner that would identify you personally. Once the retention period expires, Personal Information shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after the expiration of the retention period.

Use and Processing of Collected Information

In order to make our Website and Services available to you, or to meet a legal obligation, we need to collect and use certain Personal Information. If you do not provide the information that we request, we may not be able to provide you with the requested products or services. Any of the information we collect from you may be used for the following purposes:

  • Authenticate and provide access to the debtor portal
  • Display case details, invoice information, and outstanding balances
  • Process payments made through the portal
  • Record and communicate payment arrangements or disputes
  • Send administrative information relating to your case
  • Respond to enquiries and provide support
  • Enforce terms and conditions and policies
  • Protect from abuse and malicious users
  • Respond to legal requests and prevent harm
  • Run and operate our Website and Services

Processing your Personal Information depends on how you interact with our Website and Services. We rely on the following legal bases: (i) legitimate interests pursued by us or our creditor clients in recovering lawfully owed debts; (ii) performance of or steps towards a contract, where you make or arrange a payment; (iii) compliance with a legal obligation to which we are subject; and (iv) your consent, where explicitly given.

Information Transfer and Storage

Our infrastructure is hosted within the European Economic Area and the United Kingdom. Certain third-party service providers (such as Stripe for payment processing) may process data in other jurisdictions. Where data is transferred outside the UK or EEA, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions. You can find out more by contacting us using the details at the end of this Policy.

The Rights of Users

You may exercise certain rights regarding your information processed by us. In particular, you have the right to do the following:

  1. You have the right to withdraw consent where you have previously given your consent to the processing of your information.
  2. You have the right to object to the processing of your information if the processing is carried out on a legal basis other than consent.
  3. You have the right to learn if information is being processed by us, obtain disclosure regarding certain aspects of the processing and obtain a copy of the information undergoing processing.
  4. You have the right to verify the accuracy of your information and ask for it to be updated or corrected.
  5. You have the right, under certain circumstances, to restrict the processing of your information, in which case, we will not process your information for any purpose other than storing it.
  6. You have the right, under certain circumstances, to obtain the erasure of your Personal Information from us.
  7. You have the right to receive your information in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance, where the processing is based on consent or a contract.

The Right to Object to Processing

Where Personal Information is processed for the legitimate interests pursued by us or a third party, you may object to such processing by providing a ground related to your particular situation to justify the objection. Should your Personal Information be processed for direct marketing purposes, you may object to that processing at any time without providing any justification. To learn whether we are processing Personal Information for direct marketing purposes, you may refer to the relevant sections of this document.

How to Exercise These Rights

Any requests to exercise User rights can be directed to us through the contact details provided at the end of this document. These requests can be exercised free of charge and will be addressed as early as possible and within the timeframes required by applicable law. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data rights have not been upheld.

Billing and Payments

We use Stripe, a third-party payment processor, to process payment information securely. One Credit does not store your full card details on our servers. Card data is handled directly by Stripe and is subject to their privacy policy and PCI DSS compliance standards. We suggest that you review Stripe's privacy policy at stripe.com/gb/privacy. We do retain a record of payment transactions (amount, date, associated case reference, and Stripe session ID) for legal and accounting purposes.

Product and Service Providers

We may contract with other companies to provide certain products and services, including hosting, analytics, and payment processing. These service providers are not authorised to use or disclose your information except as necessary to perform services on our behalf or comply with legal requirements. Our current key service providers include:

  • Cloudflare — website hosting and content delivery
  • Stripe — payment processing
  • Umami Analytics — privacy-respecting website analytics (no personal data collected)

Privacy of Children

We do not knowingly collect any Personal Information from children under the age of 13. If you are under the age of 13, please do not submit any Personal Information through our Website or Service. We encourage parents and legal guardians to monitor their children's Internet usage and to help enforce this Policy by instructing their children never to provide Personal Information through our Website or Service without their permission. If you have reason to believe that a child under the age of 13 has provided Personal Information to us through our Website or Service, please contact us.

Cookies and Session Data

The Website uses a small number of technical cookies and session tokens strictly necessary to provide the service. These include:

  • A portal session cookie (oc_portal_session) — an HttpOnly, cryptographically signed token that authenticates your portal session. It is set only when you log into the portal and is cleared when you exit. No personal data is stored in this cookie; it contains only an encrypted reference to your session.

We do not use advertising cookies, tracking pixels, or third-party marketing cookies. You cannot opt out of the session cookie as it is strictly necessary to use the portal. Most web browsers allow you to control cookies through their settings; however, disabling the session cookie will prevent you from accessing the debtor portal.

Analytics

We use Umami Analytics, a privacy-respecting analytics tool, to understand aggregate traffic patterns on our Website. Umami does not collect personally identifiable information, does not use cookies for tracking, and does not share data with third parties. Analytics data is used solely to understand how the Website is used and to improve our services.

Do Not Track Signals

Some browsers incorporate a Do Not Track feature that signals to websites you visit that you do not want to have your online activity tracked. As described in this Policy, we use only privacy-respecting analytics that do not track individuals across websites. We limit our use and collection of your personal information to what is necessary to provide the Service.

Our Website may contain links to other websites that are not owned or controlled by us. Please be aware that we are not responsible for the privacy practices of such other websites or third parties. We encourage you to be aware when you leave our Website and to read the privacy statements of each and every website that may collect Personal Information.

Information Security

We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorised access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards in an effort to protect against unauthorised access, use, modification, and disclosure of Personal Information in its control and custody. Portal sessions are authenticated using cryptographically signed tokens, and all communication is encrypted in transit via HTTPS. However, no data transmission over the Internet or wireless network can be guaranteed to be completely secure.

Data Breach

In the event we become aware that the security of the Website has been compromised or users' Personal Information has been disclosed to unrelated third parties as a result of external activity, including security attacks or fraud, we reserve the right to take reasonably appropriate measures, including investigation, reporting, and notification to and cooperation with law enforcement authorities. In the event of a data breach, we will make reasonable efforts to notify affected individuals if we believe there is a reasonable risk of harm as a result of the breach or if notice is otherwise required by law. We will also notify the Information Commissioner's Office where required by the UK GDPR.

We will disclose any information we collect, use or receive if required or permitted by law, such as to comply with a court order, subpoena, or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request. In the event we go through a business transition, such as a merger or acquisition by another company, or sale of all or a portion of its assets, your Personal Information will likely be among the assets transferred.

Changes and Amendments

We may update this Privacy Policy from time to time in our discretion and will notify you of any material changes to the way in which we treat Personal Information. When changes are made, we will revise the "Last Updated" date at the top of this Policy and may post a notification on the main page of our Website. Any updated version of this Privacy Policy will be effective immediately upon posting unless otherwise specified. Your continued use of the Website or Services after the effective date of the revised Privacy Policy will constitute your consent to those changes.

Acceptance of This Policy

You acknowledge that you have read this Policy and agree to all its terms and conditions. By accessing the Website or its Services you agree to be bound by this Policy. If you do not agree to abide by the terms of this Policy, you are not authorised to use or access the Website and its Services.

Contacting Us

If you would like to contact us to understand more about this Policy or wish to exercise any rights relating to your Personal Information, you may send an email to dpo@onecompany.one. You may also write to us at:

Data Protection Officer
One Company EMEA Ltd
United Kingdom