Privacy policy
What we collect, why we collect it, who it reaches, and what you can ask us to do about it.
This is a working draft, written from how ClearRegs actually operates rather than from a template. It has not been reviewed by a solicitor, and the points marked [TO CONFIRM] need decisions before it can be published.
ClearRegs is a compliance product with professional-liability exposure. Have this reviewed before it goes live.
1. Who we are
[TO CONFIRM: the data controller. A limited company has not yet been incorporated, so the controller is currently the individual operating ClearRegs. Once the company exists, name it here with its company number and registered office. Registration with the ICO is separately required and is not yet in place.]
For anything in this notice, contact hello (at) clearregs.co.uk.
2. What we collect
Only what the service needs in order to work. There is no advertising, no profiling, and nothing is sold to anyone.
| What | Why we hold it |
|---|---|
| Account details name, email, password | To create and secure your account. Passwords are stored only as a bcrypt hash and cannot be read by us. |
| Project information name, reference, site address, client, building details | It is the content of your compliance register. A site address or a client name can identify a person, so we treat it as personal data. |
| Register content statuses, notes, responsible parties, actions, drawings, uploaded evidence | The record you are building. Uploaded files are stored as provided and we do not inspect them. |
| Audit trail who changed what, and when | An accessible record of how requirements were addressed is the point of the product, and attribution is part of that record. |
| Enquiries name, email, firm, message, IP address | To reply to you. The IP address is kept so we can identify abuse of the form. |
| Search usage the question asked, the answer given, the sources cited | To monitor answer quality and investigate incorrect answers. If you type personal data into a question, it is stored in that log. |
3. Our legal basis
- Contract. Operating your account and keeping the register you asked us to keep.
- Legitimate interests. Keeping the service secure, preventing abuse, and checking the accuracy of answers. We use the minimum needed for those purposes.
- Consent. For anything you volunteer, such as an enquiry. You can withdraw it at any time.
4. Who it reaches
We use a small number of processors. We do not sell or rent personal data, and we share nothing for advertising.
| Who | What reaches them |
|---|---|
| Anthropic | Your question, together with the passages retrieved from the indexed documents, in order to produce an answer. Do not put anything in a question that you would not want processed by a third party. |
| OpenAI | Your question text, converted into a numerical representation used to find the relevant passages. |
| DigitalOcean | Hosting. All application data sits on their infrastructure. [TO CONFIRM: the server region, so the international transfer position can be stated accurately.] |
| Our pages load typefaces from Google's servers, which exposes your IP address to Google. This is avoidable by serving the fonts ourselves, and we intend to. |
We will disclose information where the law requires it.
5. How long we keep it
[TO CONFIRM: retention periods. At present nothing is deleted automatically and the usage logs grow indefinitely, which is not a defensible position. A reasonable starting point: account and project data for as long as the account is open and 12 months after it closes; enquiries 24 months; usage logs 12 months.]
6. Your rights
Under UK GDPR you can ask us for a copy of your data, ask us to correct or delete it, restrict or object to how we use it, or ask for it in a portable form. Write to us and we will respond within one month.
If you are not satisfied you can complain to the Information Commissioner's Office at ico.org.uk.
7. Cookies and storage
We do not use cookies. There is no analytics, no tracking and no advertising technology anywhere on this site.
When you sign in, a sign-in token is stored in your browser's local storage. It is what keeps you signed in, it is not shared with anyone, and signing out removes it.
8. Security
Passwords are hashed with bcrypt. Access to a project is limited to the people invited to it, and every change is attributed to whoever made it. The public endpoints are rate limited.
To be straightforward with you: the service is in invite-only testing and is not yet served over HTTPS at its temporary address. [TO CONFIRM: this must be resolved before real project data is entered, and this paragraph removed once it is.]
9. Changes
If we change this notice we will update the date at the top, and tell account holders directly where the change is significant.